Legal

Privacy Policy

Last updated: 21 July 2026

This privacy policy sets out how Wisp uses and protects your personal data.

1. Important information and who we are

Purpose of this privacy policy

This privacy policy gives you information about how Wisp collects and uses your personal data through your use of this website and the Wisp Service, including any data you may provide to register for the Service, sign up to our newsletter, purchase a product or service, or contact us.

This website and Service are not intended for children and we do not knowingly collect data relating to children.

Controller

Confidential Crab Computing (referred to as “Wisp”, “we”, “us” or “our”) is the controller for data we directly process about visitors to our website and users of the Service. For data that stays on your device, you are the controller — the Wisp software acts on your instructions.

What Wisp is and our privacy principles

Wisp is designed to keep your work, data and prompts yours. That means the protections described below are backed by how the system is built, not only by promises we make on this page.

Our privacy principles:

  • Your chats stay on your device at rest. Messages, attachments, and audit logs are persisted in an encrypted SQLite database on your computer and you hold the only encryption key.
  • The operators of the Wisp Proxy and hardware providers cannot read your prompts in the clear. The Wisp Proxy runs inside a Trusted Execution Environment (TEE). Plaintext prompts and responses are not persisted or logged by either the Proxy or the LLM provider.
  • No analytics, no telemetry, no tracking. The Wisp App does not ship with product analytics, behavioral tracking, advertising SDKs, or crash-reporting services.
  • Nothing is used to train models.We cannot use your prompts, files, or outputs to train, fine-tune, or evaluate AI models. This is guaranteed by TEE architecture and can be verified through TEE’s attestations.

2. The types of personal data we collect about you

Personal data means any information about an individual from which that person can be identified.

We may collect, use, store and transfer different kinds of personal data about you (along with our service providers) which we have grouped together as follows:

  • Identity & Contact Dataincludes name, username, user ID, or similar identifier, profile picture and email address. This data may be shared with Wisp during sign-up if the sign-up method (e.g. Google) discloses certain Identity & Contact data. However, we do not process this data or store it in our database, and instead this data is only stored locally on your machine. Note: Wisp engages with Clerk.com and other providers for authentication and user management purposes.
  • Technical Data for the Wisp website only includes internet protocol (IP) address, device, browser type and version, time zone setting and location, pages visited, events, conversion, session behaviour, operating system and platform, Click ID, visitor ID. The Wisp Service/App does not collect such information.
  • Profile Data includes your username and password for the Wisp Service/App only and survey responses where you exercise the option to provide Wisp with feedback regarding its services.
  • Usage Data includes information regarding the usage of tokens.
  • Marketing and Communications Data includes your email address for receiving marketing materials from us.

In respect of the Wisp website only we also collect, use and share aggregated data such as statistical or demographic data which is not personal data as it does not directly (or indirectly) reveal your identity. For example, we may aggregate individuals’ Usage Data to calculate the percentage of users accessing a specific website feature in order to analyse general trends in how users are interacting with our website to help improve the website and our service offering.

Wisp partners with InflowPay SAS (as Merchant of record) regarding the provision of its services and InflowPay’s Privacy Policy applies to personal data processed in connection with payment and billing activities carried out by InflowPay in connection with the Wisp service. Alongside Identity and Financial Data InflowPay also collects Transaction, Technical and Visit Data. See InflowPay’s Privacy Policy for full details regarding data collected by it and the Third Parties Sources section below regarding information shared by InflowPay with Wisp.

3. How is your personal data collected?

We use different methods to collect data from and about you including through:

Direct interactions

You may give us your personal data when you:

  • create an account;
  • subscribe to our service;
  • request marketing to be sent to you;
  • give us feedback or contact us.

Automated technologies or interactions

As you interact with our website - we will automatically collect Technical Data about your equipment, browsing actions and patterns. We collect this personal data by using server logs and other similar technologies.

Device-local processing

The Wisp Service/App and local agent store the following locally and do not transmit it to Cloud:

  • the content of your chat sessions, including prompts, model responses, and any attachments you add (these items are transmitted to the Cloud initially for processing but are stored on your device at rest later on);
  • the audit log of tool calls made by the agent — which files it read or wrote, which commands it ran, and the parameters used (sensitive fields such as API keys, passwords, and tokens are redacted before logging);
  • local preferences and the identifier of the project folder you have selected.

This data is encrypted at rest in a local SQLite database on your computer using AES-based encryption. You can delete it at any time by removing the local database files and uninstalling the application.

Third parties sources

We may receive personal data about you from various third parties as set out below:

  • Technical Data is collected from the following parties:
    • analytics providers
    • advertising networks
    • search information providers.
  • Name, Email, Financial and Transaction Data (billing country, certain card details and payment method) is collected from InflowPay.
  • Authentication and user management information including name, username, user ID, or similar identifier, profile picture and email address (Clerk.com, other providers). This data may be shared with Wisp during sign-up if the sign-up method (e.g. Google) discloses certain Identity & Contact data. However, we do not process this data or store it in our database, and instead this data is only stored locally on your machine.

The website uses Google Analytics, Google Ads and social media pixels for advertisements, which provide segmented Technical Data to us. Posthog is also used for product analytics.

4. How we use your personal data

Legal basis

The law requires us to have a legal basis for collecting and using your personal data. This does not extend to user prompts, chat logs or information shared with the Wisp Agent as this data is not collected or retained by us. We rely on one or more of the following legal bases:

  • Performance of the Service: Where we need to perform the Service we provide or are about to provide to you.
  • Legitimate interests: We may use your personal data where it is necessary to conduct our business and pursue our legitimate interests, for example to prevent fraud and enable us to give you the best and most secure customer experience. We make sure we consider and balance any potential impact on you and your rights (both positive and negative) before we process your personal data for our legitimate interests. We do not use your personal data for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law).
  • Legal obligation: We may use your personal data where it is necessary for compliance with a legal obligation that we are subject to (for example, where a national authority uses its binding legal powers to compel us to provide information). We will identify the relevant legal obligation when we rely on this legal basis.
  • Consent: We rely on consent only where we have obtained your active agreement to use your personal data for a specified purpose, for example if you subscribe to an email newsletter.

What we do not do

  • We do not run product analytics, A/B tests, session replay, or any behavioral tracking in the Wisp App.
  • We do not send crash reports or stack traces off your device by default.
  • We cannot store the content of your chats on our servers.
  • We do not sell your data. We do not share data with advertisers in the Wisp App (but data regarding the Wisp Website is shared with advertisers).
  • We cannot use your prompts, files, or outputs to train, fine-tune, or evaluate AI models.

How data is used

Where we do process data, we use it only to:

  • provide the Service — route model requests, and return responses to your desktop;
  • keep the Service secure — detect and block abuse of the Proxy such as credential stuffing, unusual request volumes, or attempts to circumvent the TEE;
  • meet legal obligations — respond to valid legal process and enforce Terms.

Purposes for which your personal data will be used

Purpose/UseType of dataLegal basis
To register you as a new customer and to manage your account and account access(a) Identity (b) ContactPerformance of the Service
To process and deliver the Service including: (a) Manage payments, fees and charges; (b) Collect and recover money owed(a) Identity (b) Contact (c) Financial (d) Transaction (e) Marketing and Communications

(a) Performance of the Service

(b) Necessary for legitimate interests

To manage the relationship with you which will include: (a) Notifying you about changes to our services (including new services, offers, promotions or marketing), terms or privacy policy (b) Dealing with your requests, complaints and queries(a) Contact (b) Marketing and Communications

(a) Performance of the Service

(b) Necessary to comply with a legal obligation

(c) Necessary for our legitimate interests (to keep our records updated and manage our relationship with you)

To administer and protect our business and this website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data)(a) Technical(a) Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud)
To use data analytics to track the usage of tokens and LLM, improve our website, products/services, customer relationships and experiences and to measure the effectiveness of our communications and marketing(a) Technical (b) UsageNecessary for our legitimate interests (to track usage, define types of customers for our products and services, to keep our website updated and relevant, to develop our business and to inform our marketing strategy)
Data Subject Access Requests

Identity

Contact

Technical

(a) Necessary to comply with a legal obligation

Direct marketing

You will receive marketing communications from us if you have requested information from us or use our services and have not opted out of receiving marketing communication.

Opting out of marketing

You can ask to stop sending you marketing communications at any time. If you opt out of receiving marketing communications, you will still receive service-related communications that are essential for administrative or customer service purposes.

Third-party processors

Wisp is connected to certain third-party providers and allows you to connect to others. When those integrations are used the third party’s terms and privacy policy may apply.

Wisp App

  • LLM providers (such as Redpill and Tinfoil) — receive your model requests after the TEE Proxy forwards them, and return model responses (although these companies cannot read prompts as they are only decrypted inside TEEs). By design, these providers can not read, store or train on your prompts, all of which is verifiable by the user. These providers do have their own policies which may govern how they process, or how and for how long they store other types of data.
  • Web-search providers (such as Brave Search) — receive the search queries issued by the agent when you use the web-search tool (in such circumstances the search request is performed by the Wisp Proxy rather than you).
  • Identity providers (such as Google) — receive a sign-in request if you enable the optional Gmail, Drive, or Calendar connectors, and return the identity and tokens you have authorized. Where you connect to these providers the authorization token is stored encrypted on your device and no person at Wisp has access to it.
  • TEE infrastructure providers — (such as Phala) host the enclave that the Wisp Proxy runs in and provide TEE attestations, but do not have visibility into traffic inside the enclave.
  • Authentication and user management — Clerk.com and other providers.
Fetching a URL or running a web search through the Wisp Proxy will send the relevant URL or query to that destination. If you ask the agent to call an external API, that API will receive the request you authorized through the Wisp Proxy in order to shield your identity.

Website

  • Payments — InflowPay SAS acts as Merchant of Record.
  • Cookies — Osano, Inc. for cookies management and compliance.

5. Data security

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality (this does not relate to your prompts or attachments within the Wisp App as they are unreadable).

We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

No system can guarantee absolute security, and you are responsible for protecting the device the desktop app runs on (full-disk encryption, screen lock, OS updates).

6. Data retention

We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for. We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.

In some circumstances you can ask us to delete your data: see clause 7 below for further information.

By design, your prompts and attachments within the Wisp App cannot be retained by Wisp.

7. Your legal rights

You have a number of rights under data protection laws in relation to your personal data.

You have the right to:

  • Request accessto your personal data (commonly known as a “subject access request”). This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.
  • Request correction of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.
  • Request erasure of your personal data in certain circumstances. This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your personal data to comply with local law. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.
  • Objection You also have the absolute right to object any time to the processing of your personal data for direct marketing purposes.
  • Request the transfer of your personal data to you or to a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.

Exercising your rights

If you wish to exercise any of the rights set out above, please contact us privacy@usewisp.io.

No fee usually required

You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we could refuse to comply with your request in these circumstances.

What we may need from you

We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.

Time limit to respond

We try to respond to all legitimate requests within one month. Occasionally it could take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.

8. Cookies

  • You may set your Cookie preferences for the Wisp website through the banner on the site.
  • You may change or withdraw your Cookie preference.
  • For Cookie Consent on the Wisp website the visitor’s IP address and a device identifier, which is encrypted and de-identified/hashed is collected by Osano, Inc.

We honor Global Privacy Control (GPC) signals and, where applicable, Do Not Track (DNT) signals sent by your browser. Where we detect one of these signals, we treat it as a valid opt-out request under applicable law.

9. Contact details

If you have any questions about this privacy policy or about the use of your personal data or you want to exercise your privacy rights, please contact privacy@usewisp.io

10. Complaints

You have the right to make a complaint with a competent data protection supervisory authority.

11. Changes to the privacy policy and your duty to inform us of changes

We keep our privacy policy under regular review. This version was last updated on 21 July 2026.