# Privacy Policy

Last updated: January 21, 2026

**We cannot see or access your data.** Your context logs, screenshots, and chat history are stored locally on your device only. When you use cloud AI features, your data is processed in real-time with **zero retention**.

Waylight ("Waylight", "we", "us", or "our") provides a desktop productivity and AI assistant application (the "App"). This Privacy Policy explains how we collect, use, store, and share information when you use Waylight and our related services, and describes your rights under applicable data protection laws, including the GDPR.

## 1. Contact
- **Email:** hello@waylight.ai

## 2. What information we collect

### 2.1 Information you provide to us

You may provide:
- **Account and profile data:**
  - Email address
  - Password (stored hashed, never in plain text, so no one can see it)
  - First name, last name
  - Occupation
- **Subscription and billing data** (via Stripe):
  - Email address
  - Billing address and phone number (collected and processed by Stripe)
  - Stripe customer ID and subscription ID (stored by us)
- **Feedback and support data:**
  - Free-form feedback text
  - Optional file attachments (e.g., screenshots, documents)
  - Survey responses

This information is stored primarily in our database and, for payments, by Stripe.

### 2.2 Information collected automatically

When you use Waylight, we may automatically collect:
- **Technical and usage data** (via PostHog, when telemetry is enabled):
  - App version
  - Platform/OS and architecture
  - Basic system information (CPU model, memory, device model)
  - Feature usage events and in-app actions (e.g., "app_session_started", "user_session_started")
  - User ID when authenticated
- **Update check data** (via Velopack/S3):
  - Current app version
  - Platform/OS
  - Anonymous update check requests

Telemetry **does not** include your chat content, context logs, or screenshots.

Update checks do not include any personal identifiers.

### 2.3 Information processed locally on your device

The following categories of data are stored locally on your device and are **not sent to us** unless you explicitly use cloud features:
- Chat history and assistant responses
- Context logs (window titles, app names, timestamps, optional screenshots)
- Local AI model data
- App settings and preferences (including privacy and telemetry settings)

These files live in your OS-specific app data directory and remain under your control.

## 3. How we use your information

We use your information for the following purposes:

- **To provide and maintain the service**
  - Create and manage your account
  - Authenticate you and maintain sessions
  - Provide cloud AI features (via AWS Bedrock) when enabled
  - Manage subscriptions and entitlements (via Stripe)
- **To operate AI and productivity features**
  - Process chat messages, context summaries, and productivity evaluations when you choose to use cloud models
  - Track cloud usage (tokens, costs, model identifiers) for billing and quota enforcement
- **To improve the product** (telemetry, when enabled)
  - Understand feature adoption and performance
  - Plan improvements and fix issues
  - Measure app stability and usage patterns (without inspecting user content)
- **To handle payments**
  - Create and manage Stripe Checkout sessions
  - Link your Stripe subscription to your Waylight account
  - Track subscription status and billing periods
- **To communicate with you**
  - Respond to support requests and feedback
  - Send important service emails (e.g., notices, subscription changes)

We do **not** sell your personal data and do **not** have access to your chats, context logs, or screenshots.

## 4. Legal bases for processing (GDPR)

Where the GDPR applies, we rely on the following legal bases:

- **Contract performance:**
  - Creating and managing your account
  - Providing cloud AI features and synchronization
  - Managing subscriptions and payments
- **Legitimate interests:**
  - Basic product analytics and telemetry (where consent is not required)
  - Preventing abuse and ensuring service reliability
- **Consent:**
  - Optional telemetry/analytics (when treated as consent-based)
  - Certain marketing or survey communications, where applicable
- **Legal obligations:**
  - Complying with tax, accounting, and regulatory requirements related to payments

## 5. How we share information

We share personal data only with the following categories of recipients, and only to the extent necessary:

- **Supabase** (authentication, database, and storage)
  - Stores user accounts, profiles, subscription records, usage events, and feedback.
- **AWS (Bedrock and S3)**
  - Processes chat messages and context summaries for cloud AI when used.
  - Hosts update packages and update metadata.
  - AWS Bedrock meets common compliance standards including ISO, SOC, and CSA STAR Level 2, is HIPAA eligible, and can be used in compliance with GDPR requirements.
- **Stripe** (payment processor)
  - Processes payments, stores billing details, and manages subscriptions.
  - We receive and store Stripe customer and subscription identifiers, status, and billing period data.
- **PostHog** (analytics/telemetry, when enabled)
  - Receives technical and usage events, not user content.

All subprocessors are required to protect your data and may only process it for the purposes described in this policy. We do **not** sell or rent your data to third parties.

## 6. International data transfers

Waylight and its subprocessors may process data in countries outside your own, including the United States.

- Supabase, AWS, Stripe, and PostHog may store or process data in the US or other regions, depending on their configurations.
- Where required, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) or equivalent mechanisms provided by our vendors.

If you require details about specific data residency or transfer safeguards, contact us at hello@waylight.ai.

## 7. Data retention

We retain data only for as long as necessary for the purposes described above:

- **Cloud AI model data:** **Zero data retention.** When you use cloud AI features (AWS Bedrock), your chat messages and context summaries are processed in real-time and are **not stored or retained** by AWS Bedrock or by us. Each request is processed and immediately discarded.
- **Account and profile data:** retained while your account is active and for a period afterward, unless you request deletion.
- **Subscription and billing data:** retained as required for accounting and tax compliance.
- **Cloud usage events:** retained for billing, quota enforcement, and audit purposes.
- **Feedback and survey data:** retained until no longer needed or until you request deletion.
- **Telemetry data:** retained to analyze product usage, subject to deletion policies.
- **Local data on your device:** retained until you delete it. We do not control local file retention.

## 8. Your privacy choices and controls

You have meaningful control over how your data is used:

- **Offline Mode**
  - Disables all non-essential network requests and cloud features, including cloud LLM calls, telemetry, and profile synchronization.
  - Update checks continue to run even in Offline Mode to ensure you can receive important updates.
  - Some authentication flows may still require connectivity the first time you sign in.
- **Telemetry toggle**
  - You can turn telemetry/analytics on or off in the app settings.
  - When disabled, no analytics events are sent to PostHog.
- **Choice of AI mode**
  - You can choose local AI models only to keep all processing on-device.
  - Cloud AI features can be avoided entirely if you prefer not to send content to AWS Bedrock.

## 9. Your rights under GDPR

If you are in the EEA, UK, or similar jurisdictions, you have the following rights:

- **Right of access:** Obtain a copy of your personal data we process.
- **Right to rectification:** Correct inaccurate or incomplete data.
- **Right to erasure:** Request deletion of your data, subject to legal obligations.
- **Right to restriction:** Request that we limit processing in certain circumstances.
- **Right to data portability:** Receive your data in a structured, commonly used format.
- **Right to object:** Object to processing based on legitimate interests, including certain analytics.
- **Right to withdraw consent:** Where processing is based on consent, you may withdraw it at any time (e.g., disabling telemetry).

To exercise these rights, contact us at hello@waylight.ai. You also have the right to lodge a complaint with your local data protection authority.

## 10. Security

We use appropriate technical and organizational measures to protect your personal data, including:

- Encryption of data in transit (HTTPS)
- Hashed passwords for authentication
- Role-based access controls on backend infrastructure
- Encryption of sensitive or personal information

No method of transmission or storage is completely secure, but we work to protect your data to a high standard.

## 11. Children's privacy

Waylight is not intended for use by children under 16, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal information, contact us so we can delete it.

## 12. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. We will update the "Last updated" date at the top and, where appropriate, notify you within the app or by email.
