weai
โ† Legal

Privacy policy

What personal data Weai collects, why, who else touches it, and how to exercise your rights (GDPR / LOPDGDD).

Last updated: 2026-09-28

1. Who is responsible

The controller is the operator identified in the Legal notice. Contact for any privacy matter: see the contact address on that page.

2. Data we process

Account: email, name, password (stored only as a bcrypt hash), optional avatar, session records (browser user-agent, expiry).

Service: the instances you create (name, status, connection state, API token) and request metadata passing through your subdomain (HTTP method, path, status code, duration, timestamp). We do not store message bodies in our own database.

Billing: Stripe customer and subscription identifiers, plan and order amounts. Card data is entered on Stripe and never reaches our servers.

Assistant: the conversations you have with the in-app assistant.

3. Why and legal basis

To provide the service you request (contract, Art. 6.1.b): account, instances, gateway, assistant.

To bill you and meet tax obligations (Art. 6.1.b and 6.1.c).

To keep the service secure and prevent abuse (legitimate interest, Art. 6.1.f).

We do not sell personal data and do not use it for advertising.

4. Who else processes it

Stripe Payments Europe (payments and invoicing). Cloudflare (DNS, network proxy). An email delivery provider (verification codes). An AI model provider configured for the assistant, which receives the text you send to it. WhatsApp traffic for your instance is handled by the WhatsApp connection software running on our infrastructure. Servers are hosted in the European Union (Finland). Some providers may process data outside the EU under standard contractual clauses.

5. How long we keep it

Account data while your account exists. Billing records for the period required by tax law. Gateway request metadata and sessions are kept until account deletion; we do not yet purge them automatically.

6. Your rights

You may request access, rectification, erasure, restriction, portability and object to processing by emailing the contact address. You can download your data and delete your account yourself from Profile > Your data. You may also complain to the Spanish data protection authority (AEPD, aepd.es).

7. Security

Passwords are hashed; sessions use HTTP-only cookies; traffic is encrypted with TLS; instance tokens are per instance. No system is perfectly secure, and we will notify affected users and the authority of breaches as the law requires.

8. Children

Weai is not directed to people under 18 and we do not knowingly collect their data.

This document is general information written for this service and is not legal advice.