Transport

TLS 1.3 on every page. HSTS (max-age 2 years, includeSubDomains, preload). Strict-origin referrer policy so the previous page is never leaked to a third party.

Encryption at rest

The database is encrypted at the storage layer. Backups are encrypted before they leave the VM. Sensitive uploads — settlement agreements, tribunal-narrative drafts, evidence documents — are application-layer encrypted with a per-document key (envelope encryption); the master key lives in our secrets vault and rotates quarterly.

What we hold, what we don’t

  • What we hold: your email, your sector if you tell us, your saved questions and answers, your orders and their inputs, your uploaded documents, your sessions for active sign-ins.
  • What we never hold: your employer’s name unless you put it in an intake; your bank details (Stripe holds those); your raw payslips after a Check My Payslip run (deterministic; nothing persists).

Anonymous use

You can use the homepage search, the library, the Rights Check and the three free tools without an account. The free contract checker runs entirely as a single request and stores nothing.

Sub-processors

NureWorker uses a small set of well-known sub-processors. Each is bound by a Data Processing Agreement (DPA) under UK GDPR. Full list in the Trust Centre: Anthropic, Resend, Stripe UK, Hetzner, Sentry, Cloudflare.

Account deletion and retention

Self-service account deletion from /account/data. Soft-delete is immediate (you are signed out everywhere); hard-delete of personal data runs after 30 days. Order transaction records are anonymised but retained 6 years for HMRC compliance.

Content-gap log

When the homepage search can’t find an answer for you, we keep the text of your question — and nothing else (no user ID, no IP) — for up to 30 daysso we can write a guide to close the gap. The log is purged daily by an automated job. We’re telling you because we believe in saying so.

What we never do

  • Train AI models on your questions, uploads or orders.
  • Sell your data, share it with employers, or feed it into any ad network.
  • Embed third-party analytics that profile users across sites. Plausible (self-hosted, cookieless) is the only product analytics we run.
  • Retain content beyond the retention window stated in our privacy policy.

Incident reporting

Suspected vulnerability? Email security@workers-rights.co.uk. We acknowledge in one working day. We will not pursue legal action against good-faith security research.

Last reviewed: May 2026.