Privacy Policy
We take your privacy seriously. This policy explains — in plain English — what data we collect, why, how we protect it, and what rights you have. If any of it is unclear, email hello@wrapit.pro.
01Who we are
Wrapit is a software product operated by Leipom Devi Himika, an individual based in Bangladesh. For the purposes of GDPR, we act as the data controller for the data we collect directly from you, and as processor for the data you upload while using the service.
Reach us at hello@wrapit.pro for any privacy-related question.
02What we collect
Data you give us directly
| Category | Examples |
|---|---|
| Account info | Name, email address, workspace name, timezone, wrap time, role (manager or doer), avatar accent |
| Content you create | Daily wrap replies, uploaded documents (Brain), messages sent to your team via Wrapit chat, project + team member metadata |
| Billing info | Handled entirely by Paddle. We only store subscription ID, plan tier, renewal date, and workspace mapping — never card numbers or bank details. |
Data we collect from connected tools
When you connect a third-party tool (ClickUp, Slack, Monday, etc.), we read specific data from it — only what's needed to power the features you enabled. Details:
- ClickUp / Monday / Asana / Jira / Linear — projects, tasks, statuses, assignees, comments
- Slack — messages in DMs with the Wrapit bot, and messages in channels you explicitly opted into indexing
- All integrations — the OAuth token itself, encrypted at rest and never exposed to your team
Data we collect automatically
- Usage events — which pages you visited, which features you used, timestamps
- Device info — IP address, browser, operating system (for security + debugging)
- Error reports — via Sentry, when something crashes. Anonymized where possible.
03Why we collect it
We collect data only for the following purposes:
- To run the service — display your projects, deliver EOD summaries, send wrap questions
- To authenticate you — log you in securely, prevent unauthorized access
- To process payments — via Paddle; we don't handle payments ourselves
- To improve Wrapit — aggregated, anonymized usage patterns tell us what's working and what's broken
- To communicate with you — password resets, EOD summaries, occasional product updates (never marketing spam)
- To meet legal obligations — retain financial records, respond to lawful requests
We do not sell your data to third parties. Ever.
04AI & your data
Wrapit uses OpenAI's API to generate wrap questions, extract signal from replies, and synthesize EOD summaries.
Key facts:
- OpenAI's API does not use API data for training (verified in their terms of service)
- Data sent to OpenAI is transmitted over TLS 1.3
- OpenAI retains transient logs for up to 30 days for abuse monitoring, then deletes them
- We only send OpenAI the specific text needed to answer a specific question — not your full corpus
- You can opt out of AI-generated wrap questions by using generic template questions instead (contact us to enable)
05Third-party sub-processors
The following third parties process data on our behalf. Each has been vetted for their security posture. See our Trust page for full details.
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, auth, file storage | Tokyo, Japan (AWS ap-northeast-1) |
| OpenAI | AI question generation + EOD synthesis | US |
| Paddle | Payments | UK + US (region depends on billing country) |
| Vercel | App hosting | Global CDN, primary US |
| Sentry | Error monitoring | US |
| Resend | Transactional email | US |
| Slack, ClickUp, Monday, etc. | Only when you explicitly connect them | Provider-specific |
We update this list when we add or change providers. Material changes are communicated to active users.
06Cookies & tracking
Wrapit uses only essential cookies. These are required to log you in, keep your session alive, and remember your theme preference (dark/light).
We do not use:
- Advertising or marketing cookies
- Third-party analytics tracking (no Google Analytics, no Meta Pixel, no similar)
- Cross-site tracking
- Fingerprinting
Because we don't use non-essential cookies, we don't display a cookie consent banner. This is legal under GDPR and the ePrivacy Directive as long as we only use strictly-necessary cookies.
07How we protect data
Full details are on our Trust page. Summary:
- All data encrypted at rest (AES-256) and in transit (TLS 1.3)
- Row-level security enforced by PostgreSQL — cross-workspace leakage is impossible
- Payment card data never touches our servers (Paddle handles it)
- Passwords hashed with bcrypt; we never see plaintext
- Sub-processors are SOC 2 Type II certified (Supabase, OpenAI, Paddle, Vercel, Sentry, Resend)
- Regular security reviews of all code that touches user data
If a breach occurs and personal data is materially affected, we'll notify affected users within 72 hours of discovery, per GDPR requirements.
08Data retention
We retain your data only as long as needed to run the service:
- Active accounts — data kept until you delete it or your account
- Deleted accounts — 14-day grace period, then permanent deletion. Backups purged within 30 days.
- Deleted workspaces — same 14-day grace + 30-day backup rotation
- Billing records — retained for 7 years to meet accounting and tax obligations (managed by Paddle)
- Anonymized usage logs — retained for up to 1 year for product analytics
09Your rights
Regardless of where you live, you have the following rights over your data. If you're in the EU/UK (GDPR) or California (CCPA), these are legally enforceable.
- Access — get a copy of everything we hold about you. Export from Settings → Data.
- Correction — fix inaccurate data. Most fields are user-editable in Settings.
- Deletion — permanently erase your data. Available in Settings → Data → Delete my account.
- Restriction — pause processing of your data while you dispute something.
- Portability — export in a machine-readable format (JSON). Same tool as Access above.
- Object — ask us to stop specific processing (e.g. product improvement analytics).
- Withdraw consent — cancel your subscription + delete your account at any time.
- Complain — you can lodge a complaint with your local data protection authority. In the EU, find yours at edpb.europa.eu.
To exercise any of these rights, email hello@wrapit.pro. We respond within 30 days.
10International transfers
Wrapit is operated from Bangladesh. Data may be transferred to and processed in countries where our sub-processors operate (US, EU, UK). Each transfer is protected by either:
- An adequacy decision (e.g. EU-US Data Privacy Framework where applicable)
- Standard Contractual Clauses (SCCs) approved by the European Commission
- The sub-processor's binding corporate rules
If you need our specific SCC signatures or a Data Processing Agreement (DPA) for compliance, email hello@wrapit.pro.
11Children's privacy
Wrapit is not intended for anyone under 13. We do not knowingly collect data from children. If you learn a child under 13 has an account, contact hello@wrapit.pro and we'll delete it immediately.
Users aged 13–16 may only use Wrapit with the consent of a parent or legal guardian.
12Changes to this policy
We may update this policy occasionally. Material changes will be announced by email to active users at least 14 days before they take effect. Minor changes (typos, clarifications) take effect immediately.
Continued use of Wrapit after a change means you accept the new policy.
13Contact
Privacy inquiries: hello@wrapit.pro
Security issues: hello@wrapit.pro
General: hello@wrapit.pro