Legal
Privacy Policy
Last updated 24 August 2026
Draft, pending legal review. This document is published so that anyone evaluating Largwit can see the terms we intend to operate under. It has not yet been reviewed by counsel and is not a binding agreement. A customer contract will be a signed agreement, and where the two differ, the signed agreement governs.
Largwit holds two very different kinds of data, and most policies blur them. The first section separates them, because the distinction decides everything that follows.
In short: we collect very little about you directly, we do not sell it, there are no advertising trackers, and the datasets our customers put into the platform are theirs rather than ours. We do not train on them.
1Two different kinds of data
This distinction runs through everything below, so it comes first.
Account data is the small amount of information we hold about the people who use Largwit: name, work email, the organization they belong to, and records of their activity in the product. For this we are the controller and this policy describes what we do with it.
Customer content is everything an organization uploads or produces through the platform: their datasets, the annotations made from them, and the review history behind those. For this we are only a processor. We hold it on the customer’s instructions and do not decide what it is used for. If you are a data subject whose personal data appears inside customer content, the organization using Largwit is your point of contact, and we will help them respond to you.
2What we collect about you
When you use Largwit we collect:
- Identity and contact details — name, work email address, and the organization you were invited into.
- Authentication records — hashed passwords, session records, and sign-in attempts including the address they came from. We keep failed attempts because that is how account attacks are detected.
- Activity records — what you did in the product and when. On a platform where people are paid for work and assessed on its quality, this record is the product rather than a by-product.
- Technical data — IP address, browser and device type, and timings, taken from requests.
- What you send us — the content of enquiries and support messages.
We do not use advertising cookies or third-party analytics trackers on the product. The cookie that keeps you signed in is necessary for the service to function.
3Why we use it, and on what basis
- To run the service — to authenticate you, route work to you, and show your organization what has happened. Necessary to perform our contract.
- To keep it secure — to detect attacks, investigate abuse and protect accounts. Our legitimate interest in a platform that is not compromised, and yours.
- To support you — to answer what you write to us. Contract, or legitimate interest where you are not the customer.
- To improve the product — using aggregate patterns such as error rates and how long operations take. Legitimate interest. This never involves reading customer content.
- To meet legal obligations — where we are required to keep records or respond to lawful requests.
We do not sell personal data, we do not share it for advertising, and we do not use customer content to train models, whether ours or anyone else’s.
4Who else sees it
Your organization. If you were invited into an organization, its administrators can see your account details and your activity in it. That is the point of the product, and it is worth being plain about: work you do on Largwit is visible to the people who gave you the work.
Sub-processors. We use a small number of providers to run the service. Each is bound by contract to process data only on our instructions:
- Microsoft Azure — hosting, database and storage. Currently Central US.
We will keep this list current, and where a change affects the processing of customer content we will tell customers before it takes effect so they can object.
Nobody else, except where the law compels disclosure, in which case we will tell the affected customer unless forbidden, or in connection with a sale of the business, in which case the same protections must follow the data.
5Where it is processed
Largwit currently runs in the United States. If you are in the United Kingdom, the European Economic Area or another region with transfer restrictions, your data is transferred there.
To be completed: the transfer mechanism. Standard contractual clauses with a transfer impact assessment is the expected answer, and it needs to be in place, not asserted. A customer requiring data residency in a particular region should ask before signing, because today the answer is that we do not yet offer it.
6How long we keep it
Account data is kept while the account is active and for a period afterwards, so that an organization’s records of who did what remain intelligible. Sign-in and audit records are kept longer than ordinary account data because they exist to answer questions after the fact.
Customer content is kept for as long as the customer keeps it. When an organization leaves, its content is available for export for at least thirty days and is then deleted, other than backup copies which age out on their ordinary cycle.
To be completed: concrete periods for each category, and the backup retention window.
7How it is protected
Passwords are hashed with Argon2id, sessions are opaque tokens stored only as hashes, traffic is encrypted in transit, and every customer is separated from every other by database-level policies rather than by application filters. Our staff have no standing access to customer content. Ask us for detail on any control and we will answer it directly.
8Your rights
Depending on where you live, you may have the right to ask for a copy of your personal data, to have it corrected, to have it deleted, to restrict or object to how we use it, to receive it in a portable form, and to complain to a supervisory authority.
Write to hello@largwit.com. We will respond within one month, and will tell you if we need longer and why.
Where your data sits inside customer content, we will pass your request to the organization responsible and support them in answering it, because they, not we, decide what happens to it.
Some data cannot be deleted on request while an account is active: the audit record of what was done in an organization is exactly the thing it exists to preserve, and removing entries from it would defeat the purpose it serves for everyone else.
9Children
Largwit is a tool for work and is not directed at anyone under 18. We do not knowingly collect their data, and will delete it if we learn we have.
10Changes, and how to reach us
We will update this policy as the platform changes. The date at the top always reflects the current version, and we will tell customers before a material change takes effect.
For anything in this policy, write to hello@largwit.com.
To be completed: the controlling entity, a postal address, and whether a data protection officer or an EU/UK representative is required.