Privacy &
Security
Wasp reads your inbox so you do not have to hold everything in your head. That is a lot of trust to ask for. This page explains exactly what happens to your data, in language you can actually check us against.
The short version
This summary is written for humans and is not a substitute for the full policy below, but nothing in the full policy contradicts it.
- We read messages. We do not keep them. Message text is processed in memory and discarded. It is never written to our database.
- We store the commitment, not the conversation. A task title, a deadline, a one line summary, and a link back to the original in your own account.
- Your data trains nothing. Not our models, not our AI providers' models. We use API tiers that exclude training by contract.
- Your data lives in the EU. Database and application servers are hosted in Frankfurt, Germany.
- Wasp never sends email on its own. It can draft a reply. Nothing leaves your account unless you read it and press send.
- You can leave with everything. Export your data or delete your account from inside the app. Deletion is permanent and cascading.
Section 01Who we are
Wasp is an AI personal assistant for professionals. It captures commitments from the tools you already use, keeps them in one list, and holds you to them.
The service is operated by [LEGAL ENTITY NAME], registered at [REGISTERED ADDRESS] ([COMPANY / LICENCE NO.]). In data protection terms we are the data controller for the personal data described on this page, which means we are the party legally responsible for it and the party you can hold to account.
For anything on this page, our privacy contact is privacy@meetwasp.com. For help using the product, write to support@meetwasp.com.
Section 02What Wasp collects
Wasp collects three kinds of data, and it is worth keeping them separate in your head.
a. Account data
Your email address and an encrypted password credential, handled by our authentication provider. Your timezone, working hours, quiet hours and notification preferences. If you subscribe, a customer reference from our payment provider. We never see or store your card details (see Section 07).
b. Data derived from connected accounts
When you connect Gmail, Google Calendar or Slack, Wasp reads recent messages and events to find commitments. What it writes down is deliberately narrow:
- A task or commitment title, rewritten in our own words
- A deadline or committed date, where one was expressed
- A one line summary of why the item exists
- The name or email of a counterparty, where the commitment is to a person
- A deep link back to the original message in your own account
- Message identifiers, used so we never process the same message twice
- A numeric vector of the summary text, used only to spot duplicates
- Message bodies
- Email subject lines
- Attachments, or their filenames
- Contact lists or address books
- Calendar events you were not committed in
- Anything from an account you have not connected
c. Technical and usage data
Server logs containing IP address, timestamp and error diagnostics, retained for security and debugging. Records of how you responded to Wasp's own prompts, such as whether you completed, snoozed or renegotiated a task. These behavioural records are what allow the accountability engine to adapt to you, and they describe your interaction with Wasp, not the content of your messages.
Section 03What Wasp never stores
This is the core of our design, so it is worth stating plainly rather than burying it. When Wasp processes a message, the text of that message exists only in memory and on our processing queue for the seconds it takes to analyse it. It is then discarded. There is no column anywhere in our database that holds the body of one of your messages.
This is not a promise about our intentions. It is a property of how the system is built, and it is the kind of claim you should feel free to ask us to demonstrate.
When you ask Wasp to draft a reply, it reads the thread you are replying to, and a few of your recent sent messages so the draft sounds like you rather than like a robot. That content is used for that single request and is never stored or logged. This only ever happens when you click, never in the background.
Section 04Google user data
If you connect a Google account, Wasp requests only the narrowest permissions that make the product work. You see a plain description of each one before Google ever asks you to approve anything.
| Permission | What Wasp does with it |
|---|---|
| Read Gmail | Finds commitments in messages you receive and promises in messages you send.Read only. Wasp cannot delete, archive or modify your mail. |
| Create Gmail drafts | Writes a reply into the right thread when you ask for one.Optional. Wasp never sends on its own initiative. Nothing leaves your account unless you read the draft and press send yourself. |
| Calendar events | Reads meetings for context and books focus blocks when you place one.Wasp only edits or deletes events it created itself. |
| Calendar availability | Checks when you are free so a focus block never double books you. |
Wasp's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practice that means we do not sell Google user data, we do not use it for advertising, we do not allow humans to read it except where you explicitly ask us for support or where the law requires it, and we do not use it to train generalised AI models.
You can disconnect a Google account at any time from the Trust Center inside Wasp. Disconnecting revokes our access token with Google and permanently deletes the stored credential from our systems. You can also revoke access directly from your Google account permissions page.
Section 05AI processing
Wasp uses large language models to read a message and decide whether it contains a commitment, to write the short summaries you see, and to draft replies when you ask. We send those models the minimum they need and nothing more.
Your data is not used to train AI models. We use the commercial API tiers of our providers, which contractually exclude customer data from model training. This is a deliberate procurement decision, not an assumption: we chose our embedding provider specifically because its API excludes training by default rather than by opt out.
Wasp does not make decisions with legal or similarly significant effects about you. It nudges, escalates and drafts. Every action that touches the outside world, such as sending an email or booking a calendar block, requires you to press the button.
Section 06Why we are allowed to
Where the GDPR or UK GDPR applies to you, we rely on the following legal bases.
| What | Legal basis |
|---|---|
| Running your account | Performance of our contract with you |
| Reading connected accounts | Your explicit consent, given per source and withdrawable at any time |
| Billing and tax records | Legal obligation |
| Security, fraud prevention, debugging | Our legitimate interest in keeping the service safe and working |
| Product emails you can unsubscribe from | Consent, or legitimate interest where permitted |
Withdrawing consent for a connected source is a single click in the Trust Center and takes effect immediately. It does not affect the lawfulness of anything we did before you withdrew it.
Section 07Sub-processors
We use a small number of infrastructure providers to run Wasp. Each is bound by a data processing agreement, and each is listed here rather than hidden. Providers marked transient may process message text in the moment but never retain it on our behalf.
| Provider | Purpose | Region |
|---|---|---|
| Supabase | Database, authentication, realtime updates | EU, Frankfurt |
| Fly.io | Application backend | EU, Frankfurt |
| Vercel | Web application and site hosting | Global edge network |
| Inngest | Background job queueTransient. Message text passes through the queue during analysis and is not retained. | United States |
| Anthropic | Language models for detection, summaries and draftsTransient. Excluded from model training by contract. | United States |
| OpenAI | Text embeddings used to detect duplicatesTransient. Excluded from model training by contract. | United States |
| Gmail and Calendar connectorsOnly if you connect a Google account. | Global | |
| Slack | Slack connectorOnly if you connect a Slack workspace. | United States |
| Paddle | Payments, billing and taxMerchant of record. Paddle handles card data directly. We never receive it. | United Kingdom, EU, United States |
We will update this list before adding a new sub-processor that handles personal data. We do not sell your personal data, and we do not share it with advertisers or data brokers.
Section 08Where your data lives
Your database records and the servers that run Wasp are hosted in Frankfurt, Germany, inside the European Union. We chose an EU region deliberately.
Some processing happens outside the EU. When a message is analysed, its text is sent transiently to our AI providers and job queue in the United States, and is not retained there. Where personal data is transferred outside the EU, UK or your own jurisdiction, we rely on the European Commission's Standard Contractual Clauses, or an adequacy decision where one exists, together with the technical measures described in Section 11.
Section 09How long we keep it
| Data | Retention |
|---|---|
| Message bodies | Not retained at all. Discarded within seconds of processing. |
| Tasks, promises and commitments | Until you delete them, or until you delete your account |
| Links back to source messages | 90 days from capture, then automatically expired |
| OAuth credentials | Until you disconnect the source or delete your account |
| Server and security logs | [30 / 90] days |
| Billing and tax records | As required by law, typically 7 years, held by our payment provider |
| Everything else, after account deletion | Deleted immediately, with backups aging out within [30] days |
Section 10Your rights and controls
Depending on where you live, you have rights under the GDPR, the UK GDPR, the UAE Personal Data Protection Law, the California Consumer Privacy Act or a comparable law. We apply the following to everyone, regardless of where you are, because maintaining two standards of respect is not a policy we want.
- Access. Get a copy of your data. Available as a one click export inside the app.
- Correction. Fix anything inaccurate, directly in the app or by asking us.
- Deletion. Delete your account and everything attached to it, from Settings. This is permanent and cascading.
- Portability. Your export is machine readable, so you can take it elsewhere.
- Withdraw consent. Disconnect any source at any time from the Trust Center.
- Object or restrict. Ask us to stop or limit a particular use of your data.
- No sale, no targeted advertising. We do not do either, so there is nothing to opt out of.
- No discrimination. Exercising any of these rights will never degrade your service.
Most of these you can exercise yourself without asking us. For anything else, email privacy@meetwasp.com and we will respond within 30 days. If you are in the EEA or UK and we have not resolved your concern, you have the right to complain to your local supervisory authority.
Section 11Security
Some specifics, since a page that only says "we take security seriously" tells you nothing.
- Encryption in transit. All traffic uses TLS. There is no unencrypted path into Wasp.
- Encryption at rest. The database is encrypted at rest by our hosting provider.
- OAuth token vault. Your connected account credentials get a second, application level layer of AES-256-GCM encryption before they are written. A database dump alone does not yield usable tokens.
- Row level isolation. Every table enforces owner only access at the database level, not merely in application code. A query for someone else's data returns nothing even if the application is wrong.
- Least privilege by design. Server owned records cannot be forged or altered by a signed in user, and the app requests the narrowest permission scopes that work.
- Disclosure before access. You see exactly what a connector will read before consent is requested, never after.
- No standing human access. We do not read your data. Access to production is restricted, and any support access needs your explicit request.
Reporting a vulnerability
If you believe you have found a security issue, email security@meetwasp.com with enough detail to reproduce it. We will acknowledge within three business days. We will not pursue legal action against researchers who act in good faith, avoid privacy violations and give us reasonable time to fix the issue before publishing.
Independent assurance
Our infrastructure providers hold their own certifications, including SOC 2 and ISO 27001. Wasp has not yet completed its own independent audit, and we would rather tell you that than imply otherwise. If a formal certification is a requirement for you, contact us and we will tell you honestly where we are.
Breach notification
If a breach affects your personal data and is likely to result in a risk to your rights, we will notify you and the relevant supervisory authority without undue delay, and within 72 hours of becoming aware where the law requires it.
Section 13Children
Wasp is a professional product and is not directed at children. It is not intended for anyone under 16, and you may not use it if you are under 16. If we learn that we hold data from a child, we will delete it.
Section 14Changes to this policy
If we change this policy we will update the date at the top of the page. If the change is material, such as adding a sub-processor that handles your data or changing what we store, we will tell you by email or in the app before it takes effect, so that you can decide whether to stay.
Section 15Contact us
For any privacy question, data request or complaint, email privacy@meetwasp.com. For product help or billing, support@meetwasp.com. For security reports, security@meetwasp.com. Write to us at [LEGAL ENTITY NAME], [REGISTERED ADDRESS].
If you would like something explained rather than merely disclosed, ask. A privacy policy that nobody understands is not really a disclosure.