Privacy policy

How we handle
personal data.

Version 2026-08-22. Effective 22 August 2026. This policy covers the Winglo website, accounts, and the Service. Processing we do for you as a processor is also governed by the DPA.

For counsel and procurement

Winglo is the controller of the marketing website and of account, billing, and security data. Winglo is the processor of Customer Data you submit to the Service. That processor work is governed by the Data Processing Addendum. We do not sell personal data. We do not use Customer Data to train foundation models. We do not accept protected health information.

1. Who we are and what this policy covers

Winglo ("we", "us", "our") operates the Winglo website and the Winglo platform (the "Service"). This Privacy Policy explains how we collect, use, disclose, and retain personal data.

It covers (a) visitors to winglo.ai and related marketing pages, (b) people who request access, contact us, or create an account, and (c) personal data inside a Customer workspace. For (c), the Customer is the controller and this policy should be read with the DPA.

We have not appointed a data protection officer or an Article 27 EU representative. Those appointments, if they are made, will appear here. Until then, privacy questions go to privacy@winglo.ai.

2. Roles

Controller. Winglo is the controller of personal data we collect for our own purposes: the website, access requests, accounts, authentication, billing, support, security of the Service, and product analytics we run after consent.

Processor. When a Customer (or its users) submits or connects data to a workspace, Winglo processes that Customer Data on the Customer's instructions, to provide the Service. The Customer is the controller. Our processor terms are in the DPA, which is incorporated into the Terms of Service.

3. Personal data we collect

Website and access requests

If you browse the site or submit a form, we collect contact details you provide (name, email, company, role, team size, message), technical data (IP address, browser, device, pages viewed), and the referral source if a page passes one.

Account and billing

When you create or are invited to a workspace we collect email address, name, business name, role, authentication data, and workspace settings. If you start a paid plan or trial, Stripe collects payment-card details. Winglo receives billing metadata (plan, status, last four digits, expiry) and does not store the full card number.

Customer Data in the Service

AI employees process the operational data the Customer connects or types: analytics, search and CRM records, content drafts, workflow configuration, and similar business content. Winglo does not choose that data. The Customer does. This data is processed to run the job the Customer asked for. It is not used to train a foundation model.

Usage and telemetry

We collect product-usage events (page views, feature use, error rates) to operate and improve the Service. Essential events needed to run the product may include account identifiers. Non-essential analytics cookies and PostHog product analytics run only after you accept them.

Communications

If you email us or use a contact form, we keep the message, your address, and our reply, for support and a record of the request.

4. Legal bases (GDPR and UK GDPR)

Where those laws apply to processing we do as a controller, we rely on:

  • Contract (Article 6(1)(b)): creating and administering an account, providing the Service you requested, and sending transactional messages about that Service
  • Legitimate interests (Article 6(1)(f)): securing the Service, preventing abuse, understanding how the product is used at an aggregate level, and answering sales or partnership enquiries, in each case where those interests are not overridden by your rights
  • Consent (Article 6(1)(a)): non-essential cookies and optional product analytics. You may withdraw consent without affecting the lawfulness of processing before withdrawal
  • Legal obligation (Article 6(1)(c)): tax, accounting, and responding to a lawful demand

Where we act as a processor, the Customer's legal bases are the Customer's responsibility. Our basis for that processing is the Customer's documented instructions and the DPA.

5. How we use personal data we control

  • To operate the website, access forms, and accounts
  • To authenticate users and manage workspace access
  • To bill, collect tax where required, and send invoices and trial notices
  • To send transactional communications (security alerts, workspace notifications)
  • To provide support and respond to security or legal requests
  • To detect and prevent fraud, abuse, or security incidents
  • To understand product use and improve the Service, without using Customer Data to train a model
  • To comply with law

We do not sell personal data. We do not use Customer Data for advertising. We do not share personal data with third parties for their own marketing.

6. Customer Data we process for you

Customer Data is processed only on documented instructions: this policy, the Terms, the DPA, and what authorized users do in the workspace (connecting a source, starting a job, exporting or deleting).

Winglo contractually requires its model providers not to use Customer Data to train or fine-tune a foundation model. Winglo does not use Customer Data to train a model of its own.

Each inference is logged with the model identifier, timestamp, workspace, and a record of the input and output sufficient for the Customer's audit. Logs are retained for the subscription plus 90 days, unless the Customer has contracted a different retention.

7. Recipients

We disclose personal data to the service providers who help us operate, as listed in Schedule B of the DPA. That list is the current list. There is no separate directory.

The main recipients today are:

  • Cloudflare: application compute, content delivery, object storage, and DNS
  • Supabase (Ireland): database, authentication, and file storage
  • Anthropic, and OpenAI when a workspace selects an OpenAI model: inference under no-training terms
  • Stripe: payment processing for trials and paid plans
  • Resend: transactional email
  • PostHog (EU cloud): product analytics after analytics consent
  • Firecrawl and Apify: research jobs the Customer starts
  • Orshot: rendering of marketing designs produced in the Service
  • Postiz, operated by Winglo: social publishing when the Customer connects channels
  • Customer-authorized connectors (for example Slack, HubSpot, Google Analytics) that the Customer connects

We may also disclose personal data if required by law, legal process, or a competent authority, or in connection with a merger or acquisition, with notice to affected Customers where the law allows.

8. International transfers

Customer Data at rest is stored in the European Union. The primary database and authentication currently run on Supabase in Ireland (AWS eu-west-1).

Application compute and object storage run on Cloudflare's network. Inference is sent to the model providers above. Those transfers may involve processing outside the EU or the UK. We do not claim that no personal data ever leaves the EU.

Restricted transfers are covered by the Standard Contractual Clauses (Module 2, 2021/914) and, where UK GDPR applies, the ICO International Data Transfer Addendum, as set out in the DPA. A US region is on the roadmap and is not live.

9. Retention

During an active subscription, we retain Customer Data for as long as the Customer's plan or Order Form specifies. The current plan defaults are published on Pricing.

After cancellation or a valid deletion request, operational Customer Data is deleted within 30 days and audit logs within 90 days, unless a longer period is required by law or contracted by the Customer.

Account and billing records we hold as a controller are kept for the life of the account and then for as long as tax and accounting law requires.

Website analytics (if consented) are kept only as long as needed to produce the product metrics we use, and can be stopped by withdrawing consent.

10. Security

We implement encryption at rest (AES-256) and in transit (TLS 1.3). Workspaces are isolated per tenant. Access to Customer Data by Winglo personnel is limited, logged, and subject to confidentiality. A fuller description is on Security and in Schedule C of the DPA.

SOC 2 Type II and a third-party penetration test are on the roadmap. They are not live. We will not describe a planned audit as complete.

11. Your rights

Where GDPR, UK GDPR, or the Swiss FADP apply, you may have the right to access, rectify, erase, restrict, or port personal data, to object to processing based on legitimate interests, to withdraw consent, and not to be subject to a solely automated decision with legal or similarly significant effects.

If the request concerns Customer Data in a workspace, we will direct it to the Customer (the controller) and assist the Customer as the DPA requires. Workspace owners can also export or erase from Settings, including the Danger Zone deletion path, which removes the business profile, AI-employee configuration, reports, chat history, alerts, campaigns, and analytics for that workspace.

If the request concerns data we control (website, account, billing), email privacy@winglo.ai with the subject "Data rights request." We respond within 30 days.

You may lodge a complaint with a supervisory authority. For processing we do in connection with EU hosting, that will often be the Irish Data Protection Commission. UK residents may also contact the ICO. You may also contact the authority of your usual residence or place of work.

12. Cookies

Strictly necessary cookies keep you signed in and protect the session. They do not require consent under the ePrivacy Directive.

Non-essential cookies and PostHog product analytics are blocked until you accept them in the cookie banner. You can change that choice by clearing site storage for winglo.ai, which will show the banner again.

We do not respond to browser "Do Not Track" signals as a substitute for the banner. The banner is the control.

13. Children

The Service is for organizations. It is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe we have, contact privacy@winglo.ai and we will delete it.

14. Automated processing and AI

The Service uses models to draft, summarize, and recommend. That output is assistive. Winglo does not, as a controller, make solely automated decisions that produce legal or similarly significant effects about website visitors or account holders.

If a Customer uses Output to make a decision about a person, that use is the Customer's. The Terms require human review before operational use.

15. Selling and sharing

We do not sell personal data. We do not share personal data for cross-context behavioral advertising. If a US state law uses those words in a defined way, we treat the statements in this section as our representation under that law.

16. Changes

We may update this policy as the Service evolves. The version and effective date appear at the top of this page. Material changes will be notified to account holders by email at least 14 days before they take effect. If you do not agree, stop using the Service and request deletion.

17. Contact

Privacy and data-subject requests: privacy@winglo.ai

Legal: legal@winglo.ai

Security incidents: security@winglo.ai