Privacy Policy (draft)
This is a draft pending legal review.
Draft — not yet reviewed by a lawyer. Last updated: October 5, 2026.
This policy explains what waper collects, why, who processes it, and the choices you have.
What we collect
- Account: email address, name, password hash (never the password itself), and, if you sign in with Google, your Google profile name and picture.
- What you do in waper: watches you create or follow, feedback and saves, notes, questions, research requests, published pages, settings (language, time zone, notification preferences) and API keys (stored only as a one-way hash).
- Delivery data: push subscriptions for your browsers, which emails we sent, and whether you came back to waper through a link in an email (links carry a one-time token; we use it to adjust how often we write to you). Emails contain no tracking pixels.
- Videos and audio you transcribe: the links you submit, the files you upload, and the resulting transcripts and summaries. Uploaded files are deleted from storage within 12 hours; the transcript stays in your library until you remove it.
- Telegram (optional): if you link the waper bot, your Telegram user ID, chat ID, username or display name and language, plus the messages you send to the bot and the replies it sends. You can unlink it in settings; sending `/stop` pauses notifications.
- Connected apps (optional): when you connect an app such as Gmail, Google Calendar, Notion or Slack, the account label of the connection, the permissions you granted, and what waper reads from it to do what you asked (for example the senders, subjects and short summaries of newsletters, or the titles and times of meetings). We keep summaries, metadata and links, not full copies of your email or documents. Sign-in tokens for these apps are held by our connection provider (see below); tokens you paste in yourself (for example a Readwise token) are stored encrypted. Disconnecting revokes access and deletes the stored connection.
- Billing: your plan, trial dates and the customer and subscription IDs from our payment provider. We never see or store your card details.
- Technical data: IP address, browser and device type in security logs and rate limits, kept for a short time.
How we use it
To run the service (collect sources, write briefs, answer questions, deliver email and notifications), to keep accounts secure and prevent abuse, to process payments, and to improve waper. We do not sell personal data and do not show ads.
AI processing
- Public watches (shared briefs anyone can read) are summarized through Cloudflare AI Gateway by DeepSeek models via ZenMux, with OpenRouter as a fallback. Only public source material is sent.
- Your private content (questions, notes, research, private watches, files you upload, and what waper reads from apps you connect) is processed by third-party model providers through Cloudflare AI Gateway (OpenRouter, ZenMux) only to provide the features you use. waper does not use your content to train models.
- Search embeddings for watch discovery are computed with Cloudflare Workers AI.
- Videos and audio are transcribed on our own servers or, when you are waiting for the result, by ElevenLabs, by Alibaba Cloud's speech recognition through ZenMux, or by Google's Gemini through OpenRouter. Transcripts are then proofread for typos by a language model. Transcripts of public videos and podcasts are shared between users who transcribe the same link; transcripts of files you upload are visible only to you.
Who processes data for us
- Cloudflare — hosting, database, storage, security (Access, Turnstile), AI Gateway and Workers AI.
- Resend — sending email.
- Creem — payments, as the merchant of record.
- Google — only if you choose Google sign-in, and for speech recognition fallback as described above.
- ElevenLabs and Alibaba Cloud (through ZenMux) — speech recognition for videos and audio you transcribe.
- Composio — manages the sign-in and API calls for apps you choose to connect; it holds the access tokens for those apps and passes their data to waper only when waper acts for you.
- Telegram — delivers messages between you and the waper bot if you link it.
- Exa and Firecrawl — web search used when finding sources for a watch; they receive the search terms, not your account data.
- Model providers — as described above.
- Our own servers — fetching public sources, search, page rendering and speech recognition; they do not receive your account data.
Cookies
We use essential cookies on waper.ai only: a session cookie to keep you signed in, and a cookie that remembers the interface language you chose. Sites on waper.page set no cookies. We do not use advertising or cross-site tracking cookies.
Retention and deletion
We keep your data while your account exists. You can delete your account in settings; we then delete your account data, notes, questions and published pages, except records we must keep by law (for example invoices kept by our payment provider). Backups expire within 30 days.
Your rights
Depending on where you live, you can ask to access, correct, export or delete your data, or object to certain processing. Contact us at privacy@waper.ai. You can also complain to your local data protection authority.
Children
waper is not for children under 16.
Changes
We will post changes here and notify you by email before material changes take effect.
_The legal entity responsible for your data (the controller) and the international transfer mechanisms will be added after legal review._