Privacy
Last updated 3 October 2026. Wormhole is a product of vwork Digital Inc., Chilliwack, British Columbia.
Wormhole is built so that we cannot read what people send through it. This page explains what that means in practice, what we do keep, and for how long.
What you send
- Answers, messages and files are encrypted in the sender's browser before they leave the device, using keys that belong only to the recipient's enrolled devices or agent endpoint. We never have those keys and cannot decrypt submissions.
- In mailbox mode we hold the encrypted copy only until the recipient confirms they received it, or until the submission deadline shown on the form (between 5 minutes and 30 days), whichever comes first. Then it is deleted. In live relay mode nothing is stored at all.
- The encrypted copy is kept in a dedicated store with no backups, snapshots or version history. Our database never holds submissions or their keys.
- Deleting our copy cannot delete copies a recipient makes, such as downloads, screenshots, or what an AI agent stores to finish its task. The form tells you who the recipient is, and for agents what they may do with your answers, before you send.
Optional AI checks
A form can ask for an AI check on a specific question. Senders are told on that question. Only that one answer is sent, through vwork Digital's checking service, and it is not stored or logged.
Drafts on your device
While you fill in a form, your answers are saved encrypted in your own browser so a dropped connection does not lose your work. Private (masked) fields and files are never saved. Drafts are deleted when you send, when you choose Cancel and clear, or after 7 days, and they never leave your device.
What we keep
- Accounts: name, email, sign-in methods (passkeys, password hash), workspace membership. Kept until you delete your account.
- Forms: the questions, settings, recipient and the public keys of receiving devices. Kept until the form is removed. Form titles and questions are visible to Wormhole, so keep them neutral.
- Delivery status: an opaque id, state and timestamps for each submission, without content or file names. Kept for 90 days.
- Usage events: content-free events such as "form published" or "submission received", kept for 30 days, used for your dashboard and to keep the service working.
- Abuse protection: sender IP addresses are used briefly for rate limiting and are not stored with forms or submissions.
We do not use analytics or advertising trackers, and we never put submission content in logs, error reports, notifications or emails.
Emails we send
Sign-in links, email confirmations, invitations, and (if you leave it on) a note that something is waiting in your inbox. These emails never contain a form title, the sender, or anything that was submitted.
Service providers
- Cloudflare: hosting, the encrypted mailbox, rate limiting.
- Neon: the database for accounts, forms and delivery status (United States, Oregon).
- Resend: account emails.
Your choices
- Recipients can remove devices, turn off arrival emails, and close or revoke forms at any time. Revoking stops future submissions; it cannot take back what was already delivered.
- You can ask for a copy of your account data or for your account to be deleted by writing to jacob@vwork.digital.