Legal

Privacy Policy

How WipStack handles account data, project context, connected-source evidence, billing information, and your privacy rights.

Effective and last updated: August 22, 2026

1. Who controls your data

WipStack is currently a beta software service (“WipStack,” “we,” “us”). For privacy questions or to exercise your rights, use our contact form and state that your message is a privacy request.

2. Information we collect

Account and workspace information

Your name, email address, account identifier, authentication status, and private personal workspace. Authentication is provided by Clerk. WipStack is individual-only during the current beta; team workspaces are not enabled.

Project information and files

Project names, descriptions, current state, status, progress, follow-up dates, next moves, ordering, archived state, and other information you add to WipStack. When you upload a project file, we also store its name, type, size, storage identifier, upload time, and the file itself in private object storage. A file you upload directly is not converted into project context unless you choose an action such as Use as context. When you deliberately forward a file to your private WipStack email address, supported readable attachments are automatically extracted into that email’s project context after the project is confirmed. Secret-shaped extracted content is rejected from project context rather than silently stored.

Slack and inbound email capture

If you connect Slack, WipStack stores the Slack workspace and user identifiers, granted scopes, encrypted OAuth credential, connection status, and the message or thread you explicitly push. WipStack does not continuously read the workspace. If you create an inbound capture address, WipStack stores the assigned address, your selected approved-sender list in private account metadata, sender, recipient, subject, message content, attachment metadata, processing result, and project match. The inbound address is receive-only. An approved sender must be verified on the owning WipStack account and within the current plan limit. After processing an accepted capture, WipStack may email the sender a filing receipt containing the project, next move, due signal, and a private sign-in link. If you use Gmail’s forwarding-address setup, WipStack may relay Google’s confirmation message to the primary verified email on your account so you can approve that forwarding address.

Approved source context and connected AI work sessions

When you use WipStack’s MCP tools, Slack or email capture, explicit browser capture, paste, or import, WipStack may store the provider name, source title, compact summary, excerpt, contribution type, match reason, match confidence, original source link, and capture time. When ChatGPT or Claude opens a project through MCP, WipStack also stores a tenant-scoped work-session ID, project and provider labels, short activity and result summaries, status, timestamps, and the ID of any correlated approved evidence. WipStack does not receive a complete provider transcript through this signal. WipStack is designed to capture approved project evidence, not passwords, authentication cookies, or a hidden crawl of an entire private account.

Prompts, reports, and model credentials

We store prompt requests and generated project superprompts. If you explicitly request an AI-assisted import, reconciliation, enhanced report, Slack capture, or email capture, the project facts and approved evidence needed for that request may be sent to OpenAI through WipStack’s included model connection or to the OpenAI or Anthropic API key you select. Personal API keys and provider OAuth tokens are encrypted, kept server-side, and never returned to your browser after saving. Standard reports, sharing, PDF export, projects, approved context, follow-ups, and storing or downloading project files do not call a model and do not require a key.

Billing and usage

Stripe processes payment details. WipStack receives identifiers and subscription information such as customer ID, subscription ID, plan, status, and billing period, but not full card numbers. WipStack records measured tokens, estimated model cost, and request count for AI actions it performs so it can show usage and enforce a per-user monthly included-AI allowance. When the allowance is reached, optional AI enhancement pauses until the next month while non-AI features remain available. When your own OpenAI or Anthropic API key is active, the selected provider bills that API project under its terms and the WipStack-funded allowance does not apply to those requests.

Newsletter, contact, and technical information

We collect the email address and consent time when you subscribe, and the contact details and message you submit through the contact form. Vercel and our security providers may process IP address, browser/device information, request logs, and error data needed to deliver and protect the service.

Connected AI access records

WipStack stores the verified OAuth client identifier and that client’s read or write grant. For each MCP tool call, WipStack records the client identifier, tool name, project identifier when applicable, required access, outcome, and time. The audit record does not store the OAuth token, prompt, tool arguments, or detected credential.

3. Why we use information and our legal bases

  • Performing our contract: creating your account, storing projects, producing reports, delivering paid features, and providing support.
  • Your consent: optional cookies, newsletter messages, approved source connections, and AI enhancement you explicitly request. You may withdraw consent prospectively.
  • Legitimate interests: securing the service, preventing abuse, diagnosing failures, and improving the beta in ways that do not override your rights.
  • Legal obligations: accounting, tax, fraud prevention, lawful requests, and enforcing applicable terms.

4. Service providers

We use carefully selected providers to operate WipStack:

  • Clerk: individual account authentication.
  • Neon: hosted Postgres database storage.
  • Vercel: application hosting, private project-file object storage, delivery, and operational logs.
  • Stripe: checkout, subscriptions, invoicing, and payment processing.
  • OpenAI or another configured model provider: only when an AI-powered feature is connected and requested.
  • Connected platforms: the AI, code, research, or delivery services you choose to authorize.

These providers process information under their own terms and privacy notices as well as our contractual arrangements with them.

5. Sharing and sale of data

We do not sell personal information. We do not share it for cross-context behavioral advertising. We share information only with service providers needed to operate WipStack, services you direct us to connect, professional advisers under confidentiality, a successor in a corporate transaction, or authorities when legally required.

6. International transfers

WipStack and its providers may process information outside your country. Where required, transfers from the EEA, United Kingdom, or Switzerland rely on an adequacy decision, approved contractual safeguards such as Standard Contractual Clauses, or another lawful transfer mechanism.

7. Retention

We keep account and project information while your account is active and for a limited period afterward when needed for recovery, security, disputes, and legal obligations. Newsletter data is kept until you unsubscribe or ask for deletion. Contact messages are retained as needed to respond and maintain a support record. Payment and tax records may be retained for legally required periods. Uploaded project files and approved source evidence are deleted when the related project or account is deleted, subject to temporary provider processing, backups, security retention, and legal holds.

8. Your rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing; receive a portable copy; withdraw consent; and complain to a supervisory authority. You may also appeal certain privacy decisions where local law provides that right.

Submit a request through Contact. We may need to verify your identity and authority to protect the account. Authorized agents should identify the person they represent and provide appropriate permission.

9. Security and tenant isolation

WipStack uses authenticated requests, encrypted connections, tenant-scoped database queries, encryption for connected model credentials, provider signature verification for billing webhooks, and narrow source-authorization patterns. Model credentials are used only in server-side requests and are never exposed in WipStack’s client code. Read the current Security & Compliance Report for the implemented controls, service providers, evidence snapshot, and assurance limits. No service can guarantee absolute security; please report suspected misuse promptly through Contact.

10. Children

WipStack is not directed to children under 16, and we do not knowingly collect their personal information. If you believe a child has provided information, contact us so we can investigate and delete it where appropriate.

11. Changes

We may update this policy as the beta and supported integrations change. We will post the revised date and provide additional notice when a material change requires it.