Privacy Policy
This Privacy Policy describes how Wrasse Inc. ("Wrasse," "we," "our," or "us") collects, uses, stores, and discloses information when you use our services at wrasse.ai (the "Service"). It applies to everyone who uses Wrasse, wherever you are.
The short version: your agent's conversations and actions are yours. We do not train models on them, we do not sell them, and we do not aggregate them with anyone else's. What we hold, we hold in order to run your agent and to give you a record of what it did. If a specific question isn't answered here, write to security@wrasse.ai and we will answer it.
1. Information we collect
Account information
When you create an account, we collect your name and email address. Payment details are collected and processed by our payment processor; full payment card numbers never reach Wrasse infrastructure and we cannot retrieve them. We store the billing metadata the processor returns — the card brand, its last four digits, its expiry, and the subscription state — so the dashboard can show you what you are paying for.
Agent activity
When your Wrasse agent runs, we record every tool call it makes, every message it sends, and every memory item it writes. This is the audit log. It exists so that you can see what your agent did, replay it, and reverse it — and so that a disputed action has a record rather than a recollection.
Conversation content
Conversations between you and your agent are stored against your account and encrypted at rest. We use this content to serve your agent's responses and to maintain memory across sessions. We do not use it for model training, for advertising, or for any purpose other than running your agent for you.
Connected accounts
If you connect a third-party account (a calendar, a mailbox, a CRM), we store the access and refresh tokens that authorise your agent to act there. These are bearer credentials, so they are encrypted at rest under an envelope scheme with a separate key-management service and are never written to logs. You can revoke a connection at any time from your dashboard, and revoking it deletes the stored tokens.
Technical metadata
We collect standard server logs — IP address, user-agent, request timestamps — for security and reliability purposes.
We do not run third-party analytics, advertising, or tracking scripts on this website. There is no analytics tag, no advertising pixel, and no cross-site tracker on wrasse.ai. We do not set cookies for advertising or profiling; the only cookies the Service sets are the ones required to keep you signed in.
2. Text messaging
If you connect a phone number to your Wrasse account, we collect that number and the content of messages exchanged between you and your assistant, so that the assistant can reply to you and deliver reminders you have asked for.
We do not share or sell your mobile opt-in information, phone number, or messaging consent to any third party. Message content is processed by the messaging provider we use to deliver messages, and by the model provider that generates your assistant's replies, solely to provide the service to you. No mobile information is shared with third parties or affiliates for marketing or promotional purposes.
Connecting a number is always something you start: you request a pairing code while signed in, then text that code from your own handset. We never add a number you did not send us a message from.
You can disconnect a number at any time by replying STOP to any message, or
from the Channels page in your account. Reply HELP for assistance, or see the
SMS help page. Message and data rates may apply. Message frequency
depends on your own use.
3. How we use information
- To operate your agent and the Service.
- To process payments through our payment processor.
- To send transactional communications — account notifications, security alerts, and audit-log exports you request.
- To detect and respond to security incidents and abuse.
- To meter usage against the plan you are on.
- To improve the Service in aggregate, anonymised form.
We do not use your data to train AI models. We do not sell or share your personal data with third parties for advertising. We do not aggregate your conversation content with other users' content for any reason. We do not sell personal information as that term is defined under the California Consumer Privacy Act, and we have not done so in the preceding twelve months.
Legal bases (UK/EEA)
Where UK or EU data protection law applies, we rely on: performance of a contract for running your agent and billing you; legitimate interests for security, abuse prevention and service reliability; consent for connecting a phone number or a third-party account, which you can withdraw at any time; and legal obligation where we must retain or disclose data by law.
4. Service providers
The Service relies on the third parties below. Each is bound by a data processing agreement consistent with applicable data protection law, and each receives only the data needed for its function.
- Anthropic — large language model inference. Subject to Anthropic's commercial terms; data is not retained for training under our commercial agreement.
- Stripe — payment processing. Card details go to Stripe directly and are not stored by us.
- Fly.io — infrastructure hosting for the platform and your agent's container.
- Cloudflare (R2) — object storage for audit and compliance exports you request, documents your agent generates, and files you upload to a chat.
- DigitalOcean — static hosting for this marketing website.
- MessagePipe (MangoZest Labs) — transactional email delivery, which in turn dispatches through underlying email providers.
- Honeycomb — application telemetry. Operational metadata only; no message content or agent output is sent.
- Channel providers — where you connect a channel, and only that one: Telegram, Meta (WhatsApp), Slack, or your SMS/RCS provider.
We do not currently use a third-party error-monitoring or product-analytics service, and we do not use a third-party authentication provider — sign-in links are issued and verified by Wrasse itself. Application errors are captured in our own server logs, described in §1 and retained per §7.
The current list, with each provider's purpose and processing location, is maintained at wrasse.ai/subprocessors. We will give notice there before adding a subprocessor that processes customer content.
5. International data transfers and residency
Wrasse runs your agent in one of two regions: US East (Virginia) or London (United Kingdom). At signup we route you to a region based on your locale signal, and your container is then pinned to that region — it does not move between regions on its own, and reprovisioning reuses the region already stored for you.
If you need a specific region, write to security@wrasse.ai before you provision. Data does not cross regions except where an incident requires engineering support, and that access is recorded in your audit trail. Where personal data is transferred out of the UK or EEA, we rely on Standard Contractual Clauses and the UK Addendum.
6. Your rights
Depending on your jurisdiction, you may have the following rights:
- Access — request a copy of your data. You can export it directly from your dashboard.
- Correction — correct inaccurate data.
- Deletion — delete your account and associated data. We complete deletion within 30 days.
- Portability — receive your data in a machine-readable format.
- Objection and restriction — object to, or ask us to restrict, certain processing.
- Withdraw consent — for any processing based on consent, without affecting processing already carried out.
- Non-discrimination — we will not degrade the Service because you exercised a right.
Exercise any of these by writing to security@wrasse.ai. We respond within 30 days and may need to verify your identity first. You may also authorise an agent to make a request on your behalf. If you are in the UK or EEA you have the right to complain to your supervisory authority; we would appreciate the chance to resolve it first.
7. Data retention
- Account data — retained while your account is active.
- Conversations and memory items — retained until you delete them.
- Audit records — the full payload of each recorded action is retained for 90 days; the digest of the action, which is what makes the record tamper-evident, is retained indefinitely so the history stays verifiable.
- Server and security logs — 90 days.
- Billing records — retained as long as tax and accounting law requires, independent of account closure.
Closing your account starts a 30-day grace period, so you can recover if you change your mind, followed by deletion. Backups age out on their own cycle and are not restored selectively.
8. Security
Every user's agent runs in its own isolated container, which cannot reach the network except to hosts its bundle explicitly allows, and every action it takes is checked against your policy before it executes. Credentials are encrypted at rest under an envelope scheme, and the keys the model providers are called with never enter your container at all.
The full picture — isolation, credential custody, the audit plane, our certification roadmap and how to report a vulnerability — is on the security page.
9. Children
The Service is not intended for anyone under 18, and we do not knowingly collect data from minors. If you believe a minor has provided us with information, write to security@wrasse.ai and we will delete it.
10. Changes to this policy
We may update this Privacy Policy. Material changes will be communicated by email to active users at least 30 days before they take effect, and the "Last updated" date above will change. Continued use after the effective date constitutes acceptance.
11. Contact
Privacy questions, requests, or complaints: security@wrasse.ai. Wrasse Inc. is the data controller for the personal data described in this policy.