Legal

Privacy Policy

Effective Date: September 29, 2026. This policy covers Wexa enterprise controls, deployment options, model routing, and how we handle data received from Google APIs (section 4).

1. Information we collect

We collect information you provide directly, including account details, profile information, support requests, payment and billing information, and content you submit through Wexa.

When an organization connects third-party systems, we process connector metadata, authentication tokens, access scopes, configuration records, workflow definitions, prompts, outputs, policy decisions, approval events, audit logs, and operational telemetry needed to provide the platform.

We collect technical data automatically, including device information, browser information, IP address, logs, feature usage, error reports, performance data, security events, and cookie or similar technology data.

We may receive information from identity providers, customer-selected integrations, payment processors, analytics providers, and other service providers used to deliver Wexa.

2. How we use information

We use information to operate, secure, maintain, support, and improve Wexa; provision accounts; provide connectors; run context graph, orchestration, model routing, policy, simulation, approval, and audit features; and communicate service, security, billing, and product updates.

We use operational telemetry to monitor reliability, debug issues, prevent abuse, detect security events, enforce policies, and measure aggregate platform usage.

We do not sell personal information. We do not use customer content, prompts, connected enterprise data, workflow outputs, or audit evidence to train third-party foundation models.

Customer data is used to provide and secure the service. Any model-improvement use of customer content requires explicit written customer authorization or an agreed enterprise contract. This never applies to Google user data, which is covered by section 4.

3. Enterprise data and AI processing

Wexa is designed for enterprise data boundaries. Customer data may include business records, documents, messages, tickets, CRM records, policies, logs, metadata, graph relationships, and evidence generated by governed actions.

Model routing may send selected context to hosted, bring-your-own, or local models according to customer configuration, data classification, policy, region, and deployment posture.

Customers control which systems are connected, which scopes are granted, which models are used, which actions are allowed, and which approvals are required before production writes.

Wexa logs policy decisions, approval decisions, model route metadata, action status, evidence packs, and audit events to support investigation, compliance review, and customer export.

4. Google user data

This section explains how Wexa handles information we receive when you connect a Google account to Wexa through Google APIs ("Google user data"). Where this section differs from any other part of this policy, this section applies to Google user data.

Limited Use

Wexa's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

What Google data we access

We access only the Google services you choose to connect, and only with the permissions you approve on Google's consent screen. Depending on the services you connect, this can include:

  • Gmail: reading and searching your messages, and sending email, when you or an agent you set up asks Wexa to work with your mailbox.
  • Google Drive: finding, reading, downloading, creating, uploading, sharing, and deleting the files you direct Wexa to work with.
  • Google Sheets: reading spreadsheets and updating them, including adding, editing, and removing cells, rows, columns, and sheets.
  • Google Docs: creating documents and updating their content.
  • Google Calendar: reading your events, and creating, updating, or deleting events when you ask. If you use the Wexa meeting assistant, we read your calendar to find the meetings the assistant should join.
  • Google Analytics: read-only access to your accounts, properties, and reports so you can query your analytics data.
  • YouTube: read-only access to your channel and video information, such as channel statistics, when you ask Wexa about your channel.
  • Your Google account email address, so we know which account is connected.

How we use Google data

We use Google user data only to provide the features you use it for: running the searches, reads, and actions you request, answering your questions about your own data, scheduling the meeting assistant, and showing the results to you.

We do not use Google user data for advertising, including personalized, retargeted, or interest-based advertising. We do not sell it, and we do not use it to determine creditworthiness or for lending purposes.

Wexa staff do not read Google user data unless you give us permission for specific data (for example, in a support request), it is necessary for security purposes such as investigating abuse, it is needed to comply with applicable law, or the data has been aggregated and anonymized for internal operations.

AI and model training

We do not use Google user data to develop, improve, or train generalized or non-personalized AI or machine learning models. We do not use it to train our own models, and we do not allow our AI providers to train theirs with it.

When you ask a Wexa agent to work with your Google data, the relevant content is sent to the AI model provider selected for your workspace, such as Amazon Web Services Bedrock or Microsoft Azure OpenAI Service, only to generate the response or action you asked for.

Who we share Google data with

We transfer Google user data only as needed to provide the features you use, for security purposes, to comply with applicable law, or as part of a merger, acquisition, or sale of assets after notice to you. We share it only with these service providers, which process it on our behalf:

  • Recall.ai, our meeting assistant provider. If you connect Google Calendar to the meeting assistant, Recall.ai receives an OAuth token for your calendar and your account email address so it can read your calendar and have the assistant join the meetings you choose. Recall.ai also processes the audio, video, and transcripts of the meetings the assistant joins.
  • AI model providers (Amazon Web Services Bedrock and Microsoft Azure OpenAI Service), which process content only to generate responses, as described above.
  • Cloud infrastructure providers (Microsoft Azure and Amazon Web Services), which host our servers, encrypted secret storage, file storage, and search indexes.
  • Langfuse, our AI monitoring provider, which may receive prompts and responses that contain Google user data so we can find errors and keep agent behavior secure.

We do not transfer Google user data to data brokers, advertising platforms, or any other third party.

How we protect Google data

OAuth tokens are stored in an encrypted secrets vault. Google user data is encrypted in transit using TLS and encrypted at rest by our infrastructure providers. Access is limited to the systems and staff that need it to provide the service.

How long we keep Google data

We keep OAuth tokens while your Google account is connected. Content we fetch to complete a request is used for that request. Content you choose to index for search, and records of agent actions that include Google user data, are kept while the connection is active so your features keep working.

When you disconnect a Google service or delete your Wexa account, we delete the related OAuth tokens right away, and we delete the related Google user data, including indexed content, action records, stored files, and meeting transcripts, within 30 days.

How to revoke access

  • In Wexa: remove the Google connector from your workspace's connector settings, or disconnect your calendar from the meeting assistant.
  • In your Google Account: go to myaccount.google.com/permissions, select Wexa, and remove access.
  • By email: write to hello@wexa.ai and we will disconnect your Google account and delete your Google user data for you.

When you disconnect in Wexa, we revoke our access with Google, delete the tokens we hold, remove your calendar from Recall.ai, and delete the related Google user data within 30 days. If you remove access from your Google Account instead, Wexa can no longer reach your Google data, and we delete the Google user data we hold within 30 days of the access being revoked.

5. How we share information

We share information with service providers that help us provide hosting, security, infrastructure, payment processing, customer support, analytics, logging, email delivery, and operational services. These providers are contractually required to protect information and use it only for authorized purposes.

When a customer connects third-party integrations, Wexa exchanges data with those systems as directed by the customer and subject to customer-granted scopes. Google user data is shared only as described in section 4.

We may disclose information to comply with law, enforce agreements, protect rights and safety, investigate abuse, or respond to valid legal process.

If Wexa is involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred subject to appropriate confidentiality and security protections.

6. Security controls

We use administrative, technical, and organizational safeguards designed to protect information from unauthorized access, loss, misuse, disclosure, alteration, or destruction.

Controls may include encryption in transit, encryption at rest, access controls, role-based permissions, authentication, logging, monitoring, vulnerability management, incident response processes, least-privilege access, and vendor review.

Enterprise deployments may include SSO, SAML/OIDC, SCIM, MFA, private cloud, VPC, on-prem, air-gapped, customer-managed secrets, data residency, model sovereignty, and audit export depending on configuration and contract.

No system is perfectly secure. Customers must protect credentials, configure permissions carefully, and promptly report suspected unauthorized access.

7. Retention and deletion

We retain information for as long as needed to provide services, meet legal obligations, resolve disputes, enforce agreements, maintain security, and support legitimate business purposes.

Account data is retained while the account remains active and for a reasonable period after deletion. Logs, audit evidence, and security records may be retained longer where required by law, contract, security, or compliance obligations. Google user data follows the retention periods in section 4.

Customers may request deletion of account data by using product controls or contacting hello@wexa.ai. Deletion may not remove information retained in backups, audit records, legal holds, or records we must retain to comply with law or enforce agreements.

8. Cookies and tracking

We use essential cookies for authentication, session integrity, security, preferences, and service functionality. We may use analytics cookies to understand usage and improve performance.

Marketing cookies, if used, support campaign measurement and may be managed through browser settings or any cookie controls we provide.

9. International transfers

Wexa is headquartered in the United States. Information may be processed in the United States and other countries where Wexa, customers, service providers, or configured infrastructure operate.

For cross-border transfers, we use safeguards such as data processing agreements, standard contractual clauses, customer-controlled deployment options, and other lawful transfer mechanisms where applicable.

10. Privacy rights

Depending on location, individuals may have rights to access, correct, delete, port, restrict, or object to processing of personal information. Individuals may also opt out of certain marketing communications.

California residents may have rights under the CCPA/CPRA, including rights to know, delete, correct, and opt out of sale or sharing. Wexa does not sell personal information.

Individuals in the EEA, United Kingdom, or Switzerland may have GDPR rights and may contact a supervisory authority. We process personal data based on contract, consent, legal obligation, or legitimate interests as applicable.

To exercise privacy rights, contact hello@wexa.ai. We may need to verify identity or route requests through the customer organization that controls the relevant workspace.

11. Children

Wexa is not intended for children under 18 or the age of majority in the relevant jurisdiction. We do not knowingly collect personal information from children.

12. Changes

We may update this Privacy Policy to reflect product, legal, or operational changes. Material changes will be posted on this page or communicated through appropriate service channels.

13. Contact

Wexa, Inc.

Headquarters: San Francisco, California 94114, US

Privacy: hello@wexa.ai

Support: support@wexa.ai