Privacy policy
wrendesk helps small businesses launch an AI helper from public web content. We collect only what we need to run the product, we never sell your data, and you can export or delete your workspace at any time.
1. What we collect
- Account data - email, name, and authentication identifiers from your sign-in provider.
- Workspace content - URLs you crawl, pages and documents you upload, FAQ entries, and helper configuration (name, tone, colours, languages).
- Conversations - messages exchanged with your helper, including the visitor's IP address (truncated) and a session identifier, used to power analytics, hand-off, and abuse protection.
- Billing data - plan, invoices, and subscription state. Card details are handled by our payment processor; we never see or store them.
- Diagnostic logs - request metadata, errors, and performance traces, retained for up to 30 days.
2. What we do with it
- Train and run the helper you configure, scoped to the content you explicitly approve.
- Show you analytics, conversation history, and knowledge-gap signals inside the wrendesk dashboard.
- Send transactional email (sign-in, billing receipts, escalation notifications). We do not send marketing email without opt-in.
- Detect abuse, debug failures, and maintain service reliability.
3. What we do not do
- We do not sell, rent, or share your workspace content with third parties for advertising.
- We do not train shared foundation models on your private workspace content.
- We do not crawl pages outside the URLs you submit, and we honour
robots.txt.
4. Sub-processors
wrendesk relies on a small set of vendors to deliver the service:
- Cloudflare - hosting, CDN, edge functions.
- Supabase - authentication, database, file storage.
- OpenAI, Anthropic, Google - AI model inference for helper replies. Inputs are sent under each provider's enterprise/API terms with zero-retention configured where available.
- Stripe - payments and subscription billing.
- Resend - transactional email delivery.
5. Data residency & retention
Workspace data is stored in Cloudflare and Supabase regions in the EU and US. Conversation transcripts are retained per your plan's analytics window (7 days on Free, up to unlimited on Team). Deleting a helper removes its training content within 30 days; deleting your workspace removes all associated data within 30 days, except where law requires us to keep records (e.g. invoices).
6. Your rights
You can access, export, correct, or delete your data at any time from inside the app or by emailing [email protected]. If you are in the EEA, UK, or California, you have additional rights under GDPR and CCPA, including the right to object to processing and to lodge a complaint with your local data protection authority.
7. Cookies
wrendesk.com uses a single first-party cookie to remember your theme preference and your sign-in session. The chat widget uses a first-party identifier so visitors can resume a conversation; it does not track visitors across sites and contains no third-party advertising tags.
8. Security
Data is encrypted in transit (TLS 1.2+) and at rest. Access to production systems is restricted to a small set of engineers and gated by SSO, hardware keys, and audit logging. Report a vulnerability to [email protected].
9. Children
wrendesk is not directed to children under 16, and we do not knowingly collect their personal data.
10. Changes
We will post material changes to this page and update the date at the top. Continued use of wrendesk after a change means you accept the updated policy.
11. Contact
Questions or requests? Email [email protected] or [email protected].