Legal

Privacy Policy

What personal data we collect, how we use and share it, AI processing, the mailbox connector, and your rights.

Last updated: July 14, 2026 (July 14, 2026)

This Privacy Policy explains how Willder, operated by Tri Nguyen (pending incorporation as Willder, Inc.) ("Willder", "we", "us") collects, uses, and shares personal data when you visit our website, use the Willder Service, or connect to it through the Model Context Protocol (MCP) server or an integration.

Two roles. For personal data about our own visitors and account holders, Willder is a controller. For personal data contained in the Customer Content that a customer's organization submits to the Service, Willder acts as a processor / service provider on that organization's behalf — that organization is the controller, and its own privacy policy governs. For that data, our commitments are set out in the Data Processing Addendum. This Policy focuses on the data we control.

1. Personal data we collect

You give us:

  • Account and organization data — name, email, organization name, role, and authentication identifiers, via our identity provider.
  • Content you submit — memory episodes and facts, uploaded files, contacts and accounts, agent configurations, corrections, and support communications. This is Customer Content and is handled as a processor (see Section 8 and the DPA).
  • Communications — messages you send us (e.g. support requests, beta feedback).

We collect automatically:

  • Usage and device data — pages viewed, features used, actions taken, approximate location derived from IP, browser and device type, and timestamps.
  • Audit and security logs — the Service records access decisions and memory read/write/delete events (who or what actor, which scope, allowed or denied) as part of its access-control design.
  • Cookies and similar technologies — for authentication, session management, security, and basic analytics. We do not use advertising cookies.

From third parties:

  • Identity provider (authentication) — profile and login data.
  • Connected integrations you enable — for example, when you connect a Gmail or Microsoft mailbox, we access mailbox data to send and receive messages on your behalf; when agents use enrichment providers, we receive business/firmographic data. See Section 6.

We do not intentionally collect special categories of personal data, and the Service is not designed to store them. Please don't submit them as Customer Content unless your organization has a lawful basis to do so.

2. How we use personal data

We use personal data we control to:

  • provide, operate, secure, and maintain the Service and your account;
  • authenticate users and enforce access control, tenancy isolation, and audit logging;
  • respond to support requests and communicate about the Service, including beta updates;
  • monitor, debug, and improve the Service and develop new features (using usage data and aggregated or de-identified data, not by training AI models on Customer Content);
  • prevent fraud, abuse, and security incidents; and
  • comply with law and enforce our Terms.

Legal bases (where GDPR/UK GDPR applies). We rely on: performance of a contract (to provide the Service), legitimate interests (to secure and improve the Service, and to market to businesses), consent (where required, e.g. certain cookies), and legal obligation.

3. AI processing and model providers

To deliver features such as memory extraction, agent briefs, plans, and drafts, we send relevant content to large-language-model providers (currently OpenAI and/or Microsoft Azure OpenAI) for inference.

  • We do not use Customer Content to train AI models, and we contract with model providers on terms that prohibit them from training on your data and that provide no or limited retention (data sent for inference is not retained to train the provider's models).
  • Some memory extraction and reranking runs on models we host ourselves, which do not send data to a third party.

4. How we share personal data

We share personal data only as needed:

  • Subprocessors — vendors that host and power the Service (hosting, database, identity, AI inference, background jobs, observability, and the integrations you enable). They act on our instructions under contract. Our current subprocessors are listed at willder.ai/subprocessors and in the DPA.
  • Within your organization — memory and related data are shared with other members of your organization according to the access grants and scopes your admins configure. This is a core function of the Service, controlled by you.
  • Legal and safety — to comply with law, respond to lawful requests, or protect the rights, safety, and security of Willder, our users, or the public.
  • Business transfers — in connection with a merger, acquisition, financing, or sale of assets (including on incorporation of Willder, Inc.), subject to this Policy.

We do not sell your personal data, and we do not "share" it for cross-context behavioral advertising (as those terms are defined under the CCPA/CPRA).

5. Cookies

We use strictly necessary cookies for authentication and security, and limited analytics to understand product usage. You can control cookies through your browser; disabling necessary cookies may break sign-in.

6. Mailbox connector — Google and Microsoft data

If you connect a mailbox, Willder accesses it to send messages you approve and to read replies to threads Willder started, so those replies can appear in your conversations and (where enabled) your memory.

Google API Services — Limited Use. Willder's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • we only use Google user data to provide and improve the mailbox features you enable;
  • we do not use Google user data for advertising;
  • we do not sell Google user data;
  • we do not use Google user data to train generalized AI/ML models; and
  • we only allow humans to read Google user data with your consent, for security or support, to comply with law, or where the data is aggregated/anonymized.

Microsoft data. Data from Microsoft Graph (Outlook/Microsoft 365) is used equivalently — only to provide the mailbox features you enable — and handled under Microsoft's applicable terms.

You can disconnect a mailbox at any time, which revokes our access going forward.

7. Data retention

We keep personal data for as long as your account is active or as needed to provide the Service, then delete or de-identify it within a commercially reasonable period, except where longer retention is required by law or for security, dispute resolution, or enforcement. Audit logs are retained for a limited period for security and integrity. Backups are purged on a rolling basis. Customer Content retention is governed by the DPA and your instructions.

8. Customer Content (our role as processor)

For personal data inside Customer Content, we act on the instructions of the customer organization that submitted it. We do not use it except to provide the Service and as that organization directs. If you are an individual whose data is in a Willder customer's memory and you want to exercise your rights, please contact that organization; we will support them in responding. Our processor commitments are in the DPA.

9. Security

We protect the Service with measures including default-deny access control enforced at a single checkpoint, tenant isolation, scoped and time-bounded capability tokens for agents, append-only audit logging, encryption in transit, encryption of sensitive stored credentials (e.g. mailbox tokens), and input sanitization and prompt-injection defenses. No system is perfectly secure; you are responsible for configuring access appropriately and protecting your credentials.

10. International transfers

We are based in the United States and may process data there and in other countries where our subprocessors operate. Where we transfer personal data from the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the EU Standard Contractual Clauses and the UK Addendum (see the DPA).

11. Your rights

Depending on where you live, you may have rights to access, correct, delete, port, or restrict your personal data, to object to certain processing, and to withdraw consent.

  • EEA/UK (GDPR): access, rectification, erasure, restriction, portability, objection, and the right to lodge a complaint with a supervisory authority.
  • California (CCPA/CPRA): rights to know, access, delete, correct, and to opt out of sale/share (we don't sell or share) and limit use of sensitive personal information; we won't discriminate against you for exercising them.

To exercise a right for data we control, email legal@willder.ai. We'll verify your request and respond within the time the law requires. For data inside a customer organization's memory, contact that organization (see Section 8).

12. Children

The Service is for business use and is not directed to children under 16. We do not knowingly collect their personal data.

13. Changes to this Policy

We may update this Policy. If a change is material, we'll give reasonable notice. The "Last updated" date reflects the current version.

14. Contact

Questions or requests: legal@willder.ai.