← Back to checkn.co
Draft — pending review. This document is a working draft. It should be reviewed by qualified counsel, and kept accurate to our actual data practices, before checkn relies on it.

Privacy Policy

Last updated: August 5, 2026

This Privacy Policy explains how Willow Works Group LLC, doing business as Willow Digital ("Willow Digital", "we", "us"), collects, uses, and shares information in connection with checkn (the "Service"), available at checkn.co and app.checkn.co.

1. Information we collect

Roster information, provided by your organization

Organizations import the membership list they already keep: names, email addresses, whatever member numbering they use, and whether each member is entitled to vote. We hold this on the organization's behalf. If you are a member and want to know why your details are here, your organization put them here, and it is the right first place to ask.

Credentials

checkn uses passkeys, not passwords. We store the public key of each passkey you register, along with a device label and the times it was used. We never receive your fingerprint, your face, or your device PIN — those stay on your device and are never transmitted. There is no password for us to leak.

Meeting records

Attendance events, quorum snapshots, speaking-queue entries, motions, and votes, each with a timestamp. These are the organization's governance record and are deliberately durable: they are appended to rather than edited, so that a record cannot be quietly revised after the fact.

Technical information

IP address, browser and device type, and log and diagnostic data used to operate and secure the Service. Sign-in and passkey events record the originating IP and user agent as part of the audit trail.

2. Secret ballots

When an organization runs a secret vote, the system is built so that the record of who voted and the record of how they voted cannot be linked back together — including by us. The counts reconcile; the connection does not exist to be looked up.

This means we cannot tell you how a particular member voted in a secret ballot, and we cannot tell your organization either, whoever asks and for whatever reason. That is the point of a secret ballot, and we would rather be unable to answer than merely unwilling.

3. How we use information

We do not sell personal information, and we do not use your organization's roster or meeting records to advertise to anyone.

4. Who processes data on our behalf

5. Your organization's role and ours

For roster and meeting data, your organization decides what is collected and why; we process it on their instructions. Requests to correct or remove roster information should go to your organization first. We will help them act on it.

6. Seeing your own record

Members should be able to see every presence entry recorded for them, how each was established, and every vote attributed to them in a non-secret ballot. A record members cannot inspect is not one they should be asked to trust. This is a commitment about how the product is being built; the member-facing view of it is not finished yet.

7. Retention

Meeting minutes are legal records for many of the organizations we serve, so our default is to keep a record rather than expire it. A specific retention and deletion policy will be published before the first paying customer, and this section will be replaced with it rather than left vague.

8. Location data

We do not collect device location. If a geofencing option is ever offered it will be per-organization, off by default, disclosed plainly, and never the sole basis for a presence record.

9. Children

The Service is not directed to children under 13 and we do not knowingly collect their information. Some organizations we serve have members under 18; those members participate through their organization and the same protections in this policy apply to them.

10. Changes

We may update this policy. Material changes will be announced through the Service or by email before they take effect.

11. Contact

Privacy questions: [email protected].