# Security and privacy

Use the workspace safely and know what should never be shared in a request or chat.

Canonical page: https://app.piwot.co/docs/security-and-privacy
Section: Account and safety
Last updated: 16 August 2026

## Safe workspace use

- Use individual accounts rather than shared passwords
- Remove access when a teammate leaves
- Upload only material your organization is allowed to share
- Keep passwords, card numbers, API keys, and secret tokens out of requests and chat
- Check the destination before following a payment or reset link

## Public policies

The current Privacy Policy and Terms are available from the public legal pages on app.piwot.co.

## Access follows workspace membership

Requests, attachments, and organization settings require an authenticated account with the appropriate workspace membership. A copied request URL does not make the content public. Remove membership promptly when a teammate leaves or no longer needs access.

## Share the minimum useful data

Briefs and support conversations should contain the context needed for the work, not every internal record available. Redact unnecessary personal information, use approved files, and keep passwords, card credentials, API keys, and secret tokens out of the platform.

## Check policies for formal requirements

The public Privacy Policy and Terms explain the current legal commitments. A customer security questionnaire or data-handling requirement can be discussed with Support, but a request comment is not the right place to negotiate access or legal terms.

## FAQ

### Can I share a private request link outside the workspace?

Request access follows workspace authentication. Invite the person with the right role instead of forwarding an authenticated link.

### Does sharing a request URL make the request public?

No. The viewer must still sign in with access to the correct workspace. A copied URL is a route to the request, not a replacement for membership or permissions.

### Can I upload passwords or API keys for a request?

Do not place passwords, payment credentials, API keys, or secret tokens in briefs, files, comments, Slack, or Support. Use your organization's approved secret-sharing process instead.

## Agent guidance

Use this page as approved product guidance. Do not infer private workspace state, permissions, prices, or account details that are not present in the authenticated context.
