Draft pending counsel review — not yet in force
Privacy Policy
What we collect
- Account data: email, name, authentication identifiers (Google subject id or a password hash — never the password).
- Organization data your team enters: clients, projects, tasks, rates, time entries, notes.
- Operational logs (requests, errors) retained briefly for reliability and security; error reports exclude request bodies.
What we do NOT do
- No selling or sharing of personal data for advertising.
- No tracking pixels in the application.
- No training of AI models on your organization’s data.
Processors
Infrastructure: Amazon Web Services (hosting, email), Neon (database), Stripe (payments — card data never touches our servers), Google (optional sign-in), Sentry (error reports). Each processes data solely to provide their service to us.
Retention & deletion
Organization data is retained while the organization exists and for 90 days after cancellation (the Exit Guarantee window), then deleted. Account deletion requests: support@winno.ws.
Security
TLS everywhere, passwords hashed with argon2id, TOTP secrets encrypted at rest, tenancy enforced at the query layer, audit logging on sensitive changes.