W
Wiblo

Privacy Policy

Last updated: August 25, 2026

1. About Wiblo and this policy

Wiblo runs service businesses in shared workspaces operated by people and by software agents: bookings and scheduling, services, availability, clients, and teams. This policy explains how Wiblo (“we”) handles information across the website at wiblo.app, the web and mobile applications, the command-line tools, and the API (together, the “Service”). It forms part of our Terms of Service.

Two roles matter throughout this policy:

  • Customers: the businesses and people who hold Wiblo accounts and run workspaces. For your information, we are the controller, and this policy describes what we do with it.
  • Your clients: the people who book with a Customer’s business, including through public booking pages. Their information belongs to the Customer’s workspace. The Customer is the controller and we process it only on the Customer’s behalf to provide the Service. If you booked with a business that uses Wiblo and have questions about your information, please contact that business directly. We will refer any request you send us to them.

2. Information we collect

Information you provide. Your account details: email address, password (stored only as a hash), and, if you set them, a display name and profile image. Profile images are served from a public address, so anyone with the link can view them. Your workspace content: workspace names and branding, services and prices, schedules and availability, bookings, client records, team member details, and the repositories and files your workspace holds. Messages you send us for support.

Billing information. If you purchase a paid plan, Stripe, our payment processor, collects your payment card details and billing address to process the charge. We never see or store your full card number; we keep the transaction records, your plan, and your billing contact details. Stripe handles your payment details under its own privacy policy.

Information collected automatically. Technical logs generated when you, your team, or your agents use the Service: sign-in and token activity, IP addresses (retained hashed for token telemetry, and briefly in raw form to complete CLI device authorization), browser and device information, and API request logs. Cookies are described in section 6.

Information from third parties. If you sign in with Google, we receive your email address and basic profile information (name, profile image) from Google. We never see your Google password.

Information from your clients (on your behalf). When someone books with your business, including through a public booking page and without a Wiblo account, we collect what the booking flow asks of them: name, email address, time zone, and, where your booking setup requests it, a phone number for reminders and answers to your custom questions. This is Customer workspace data, processed on the Customer’s behalf.

3. How we use information

We use information to provide and operate the Service: to authenticate you, run your workspace, deliver bookings and calendars, process payments and manage subscriptions, send the emails the Service requires (confirmation and password emails, workspace invitations, booking notifications, receipts), secure the Service against abuse (including rate limiting and bot protection on public booking endpoints), provide support, and improve the product. We may also send you product news and offers by email; every such email includes an unsubscribe link, and service messages continue whether or not you opt out.

We do not sell personal information. We do not use your content for advertising. We currently run no third-party analytics or tracking on the Service. Information that has been aggregated or de-identified so it no longer identifies you is not personal information, and we will not attempt to re-identify it except as the law permits.

4. AI features and agent runs

Agent runs are powered by third-party large language models. When you start a run, we send its content to our AI infrastructure providers (currently Anthropic’s Claude models, routed through Vercel’s AI Gateway) to operate the feature: your instructions, the conversation, and the workspace data and repository contents the agent reads to do its job. Agents execute in isolated, short-lived sandbox environments with narrowly scoped, expiring credentials.

We keep the event log of each run, so you can review what the agent did, and per-run usage metering. We do not use your content to train AI models, and we access our AI providers through their business offerings, whose terms do not permit them to train on your content either.

5. How we share information

Your content is visible to the people and agents you or your workspace administrators authorize: workspace members see the workspaces they belong to. Beyond that, we share information only:

  • With the service providers that run Wiblo for us, and only so they can provide those services: Supabase (database, authentication, and file storage), Vercel (hosting, agent sandboxes, and bot protection), Upstash (rate limiting), Resend (transactional email delivery), Google (sign-in), Anthropic via Vercel’s AI Gateway (AI features), GitHub (workspace repository hosting), and Stripe (payment processing and billing).
  • When the law requires it, or to protect the rights, safety, or property of Wiblo, our users, or others.
  • In a business transfer: if Wiblo is involved in a merger, acquisition, or sale of assets, information may transfer with it, and this policy will continue to apply to it.
  • At your direction, such as when you connect a third-party service to your workspace.

6. Cookies

We use cookies to keep you signed in and to secure your session. These are essential to the Service. We set no advertising cookies and no third-party analytics cookies. Because we do not sell or share personal information or track you across other services, there is nothing on the Service for a “Do Not Track” or Global Privacy Control signal to opt you out of; the Service behaves the same either way.

7. Retention and deletion

We keep your information while your account is active. If you delete content or a workspace, or ask us to delete your account, we delete the associated information within a reasonable period. We keep limited records where security, audit, or legal reasons require it (for example, a minimal log of workspace deletions and transaction records we must retain for tax and accounting), and residual copies in encrypted backups expire on their own schedule. Access tokens are stored only as hashes and expire or can be revoked at any time. To request deletion, email support@wiblo.app.

8. Security

We protect information with industry-standard measures: encryption in transit, hashed passwords and access tokens, workspace-level access controls enforced in the database, short-lived scoped credentials for agent runs, and isolated sandboxes for agent execution. No system is perfectly secure. If we learn of a breach affecting your data, we will notify you as the law requires.

9. International transfers

Wiblo is based in the United States, and information is processed there. Our service providers may process information in other countries as well. Where information moves across borders, we rely on appropriate safeguards, such as the providers’ standard contractual clauses and equivalent mechanisms.

10. Your rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. You can exercise them by emailing support@wiblo.app; we will verify your identity and respond within the period the applicable law requires. You may also have the right to complain to your data protection authority. If you are a client of a business that uses Wiblo, your request should go to that business (see section 1); we will support them in fulfilling it.

11. US state privacy rights

If you live in California or another US state with a consumer privacy law, those laws may give you specific rights: to know what personal information we collect and why, to access and port it, to correct it, to delete it, and to appeal a decision we make about a request. We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not use it for profiling that produces legal or similarly significant effects, so there is no sale or sharing to opt out of. We will never discriminate against you for exercising a privacy right. To exercise any of these rights, or to appeal a response, email support@wiblo.app; an authorized agent may submit a request on your behalf with proof of authorization.

12. Children

The Service is not directed at children. You must be at least 16 years old to hold a Wiblo account, and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided us information, contact us and we will delete it.

13. Changes to this policy

We may update this policy from time to time. If a change is material, we will give you reasonable notice before it takes effect, for example by email or a notice in the product.

14. Contact

Questions or requests about your information? Email support@wiblo.app.

This policy is effective as of August 13, 2026.