Skip to content

What we send to AI, and where it goes

Technical version: AI data egress — the disclosure source of truth

Draft — not yet published. This is how we intend to explain it. Some of it is still waiting on answers we do not have yet, and those parts are marked.

The short version

To write your resume and cover letter, an AI model has to read your resume and cover letter. There is no version of this where it works and the model never sees who you are.

What we can tell you honestly is whose AI account it goes to, what exactly gets sent, and what we do to limit where else it can go.

Whose AI it is depends on which version you run

Desktop app. It goes to your AI account — the API key you set up, or the AI tool you are already signed into on your own machine. Your resume reaches your AI provider under the terms you already agreed to with them, not ours.

To be precise about what that does and does not mean: the app itself still assembles the request on your machine, so WorkWingman code handles your information on the way past. What it does not do is route it through a WorkWingman server or a WorkWingman AI account. We are not a stop on the journey; we are the thing that packs the envelope.

One thing worth being clear about, because it is easy to assume otherwise: using your own key does not automatically mean nothing is stored. Your provider has its own rules about how long it keeps things, and on some plan types those rules include using your data to improve their models. That is between you and them, but you should know it is a real question and not assume "my key" means "private".

Cloud version. It goes to AI accounts we own. There we are in the middle of it, and the responsibility is ours. Note the plural: writing uses one provider, and the picture, voice and music features use several others. We will publish the full list of the companies involved alongside the retention answer we are still waiting on.

What actually gets sent

For anything that writes on your behalf:

  • Your name — the preferred one if you gave us one, otherwise your legal name. (Exception: the student document path works from an academic fact pack and sends no name or contact details at all.)
  • Your work history, education, certifications and skills
  • Your stories, your writing samples and your voice settings, where the task uses them
  • For federal applications, the extra facts those forms demand — including supervisor contact details, hours and salary
  • The job description and any company research for the role you are targeting
  • If you use interview coaching: your notes and past retrospectives, and also your work history, education and stories — that feature sends more than the word "notes" suggests
  • Your resume file's full text, when you first upload it so we can read it in
  • If you use the study or media features: whatever you type as an image, speech or music prompt — and for the image-sharpening and image-to-video features, the actual image file itself, not just your description of it

Your email address, phone number and postal address are not part of the drafting request — the app puts those into the finished document itself, after the model has done its work.

We do not send the model a copy of everything you have ever put in the app. Each task gets the fields that task needs. But "the fields that task needs" for writing a resume is most of your career, and it would be misleading to leave you with a smaller picture than that.

What we do not do

We are not going to tell you your information is anonymized before the AI sees it. It is not. It cannot be, for the parts that write documents about you — a cover letter with your name removed is not a cover letter. We would rather say that plainly than let you believe something comforting and untrue.

What we do instead

  • Each task gets a hand-picked set of fields, assembled per request. There is no code path that dumps your whole stored profile into a prompt.
  • Outside text is wrapped and labelled so the AI treats it as material to work from rather than instructions to follow, and any forged wrapper inside it is defused first. Job postings have been used elsewhere to smuggle commands into AI tools, and this is our defense against that — but we will not tell you it is airtight. Defenses of this kind reduce the risk; no one in the industry can currently eliminate it. We also do not yet apply this wrapping on every single feature: the interview-coaching path does not use it today, and that is a gap we are closing, not a detail we are hiding.
  • It cannot invent a job you never had — on your resume and cover letter. Those drafts are checked against your profile and rejected if they state an employer, a degree or a date you did not give us. Two honest limits on that: the student document path uses a different and stricter rule (the AI gets a fixed list of facts and must cite each one), and the interview-coaching feature does not run this particular check at all.
  • On most paths, the AI gets no tools — no access to your files, no access to your password vault, no ability to browse, and its answers are text for you to review rather than commands the app runs. We have to be exact about "most": when we call an AI provider's API directly, and when we drive the Claude or Grok command-line tools, we explicitly switch tools off. We found while writing this that the Codex command-line option does not currently do that, and we are fixing it. If you use that option today, treat it as having the access your own terminal has.
  • Our cost-tracking records don't contain your documents. That record holds counts, timings and model names — there is no field for what you wrote, and nothing writes your text into it. Being exact rather than flattering: two of its fields are ordinary text fields (which provider, which model), so this is a strong rule about what we put in, not a physical impossibility. And it covers the usage ledger only — it is not a promise that a crash report could never capture a fragment, which is a separate problem we track separately.

Still being worked out

For the cloud version, we are confirming with our providers exactly how long they keep what we send and whether any of it is used for training. We will update this section once that is confirmed in writing. Until then we would rather leave the question open than answer it from memory.

One more thing, about other people

Job descriptions and company research were written by someone else. If we ever read your inbox to track applications, those messages contain other people's information too — people who never agreed to anything with us. We have not shipped that feature, and this is one of the reasons.