Privacy Policy

Last updated: August 8, 2026

This Privacy Policy explains how Wayke ("Wayke", "we", "us") collects, uses, and protects information when you use wayke.io (the "Service"). It also describes the rights you have over your personal data under the EU General Data Protection Regulation (GDPR) and the Brazilian Lei Geral de Proteção de Dados (LGPD).

Wayke is operated as a personal project. You can reach us at [email protected] for any privacy-related question or request.

1. Information we collect

We only collect what we need to operate the Service:

  • Account information. Your email address and the verification codes used to confirm it. If you sign in with LinkedIn, we receive your name, email, and basic public profile fields that LinkedIn returns under the openid profile email scopes.
  • Your search configuration. The search groups, keywords, subreddits, channel settings and exclusion rules you set up to tell the Service which conversations you care about.
  • Channel connections. For channels that run through a real browser (LinkedIn, X), you sign in yourself in a browser on your own computer, driven by the Wayke desktop agent; that browser profile stays on your machine and we never receive or store your password for those platforms. For channels that use an official API (such as Reddit), the API credentials you provide are stored encrypted at rest. We also record which devices you have paired with your account, together with a hashed device token.
  • Discovered conversations.The public posts that match your searches, together with what we derive from them: the post link and text, its author's public name, headline, profile link, stated location and follower count, public reaction and comment counts, our relevance and opportunity scores with their reasoning, and any reply we draft for you. See section 3.
  • Service activity. Your discovery runs, the actions you take on queued posts, and account events such as sign-ins. If you receive our emails, we also record engagement events reported by our email provider (delivery, opens, clicks, unsubscribes, bounces and spam reports).
  • Technical data. Standard server logs produced by our hosting provider (IP address, user-agent, timestamps) used for security, debugging, and abuse prevention.

We use Google Ads conversion trackingto measure how effective our advertising is — specifically, to learn when a visit that began with one of our ads results in a sign-up. This is provided by Google's tag (gtag.js), which sets Google advertising cookies (such as _gcl_*) and may read the gclid click identifier from ad-landing URLs. Aside from this, we do not use general third-party analytics. We also use localStorage to hold your access token, a flag that stops the same sign-up being counted twice, and a UI preference for the search group you last had selected; and sessionStorage for transient OAuth state during sign-in.

2. How we use your information

  • To create and secure your account.
  • To run discovery passes on the channels you connect and find public conversations matching your searches.
  • To score those conversations for relevance and opportunity, explain the score, and draft a suggested reply for you to review.
  • To send transactional emails (verification codes, and alerts you opt in to).
  • To measure the effectiveness of our advertising (see section 5).
  • To operate, monitor, and improve the Service and prevent abuse.

Nothing is published on your behalf. Drafted replies stay in your review queue until you choose to post them yourself.

3. Information about other people

The Service works by surfacing public posts written by other people, so the conversations in your queue contain their personal data — typically a public display name, headline, profile link and the text they published. We collect this only from content that is publicly visible on the channel in question, only where it matches the searches you configured, and we use it solely to rank the conversation and draft your reply. We do not build advertising profiles of post authors, and we do not sell this data.

If you are the author of a post that appeared in someone's queue and you want it removed from our systems, email us at [email protected] and we will delete it. Section 8 describes the rights you can exercise, and they apply whether or not you have a Wayke account.

4. Legal bases (GDPR) and LGPD grounds

Where the GDPR applies, we rely on the following legal bases:

  • Contract (Art. 6(1)(b)): to create your account, connect the channels you choose, and run the discovery passes and drafting that are the Service.
  • Consent (Art. 6(1)(a)): for optional alert emails, and for connecting a channel and storing the credentials it needs.
  • Legitimate interests (Art. 6(1)(f)): to operate, secure, and improve the Service, and to process the public posts described in section 3 so we can rank them for the user who searched for them.

Where the LGPD applies, equivalent grounds under Art. 7 are used: execution of a contract (VII), consent (I), and the data controller's legitimate interests (IX).

5. Service providers (sub-processors)

We use a small number of trusted providers to run the Service. Each only processes the data needed for its role:

  • Netlify — hosting and content delivery for the web front-end. Receives standard request metadata (IP, user-agent).
  • OpenAI — the large language model provider used to classify discovered posts, score them, and draft suggested replies. The post text, your search configuration and your business context are sent to OpenAI for inference. Per their terms, content submitted via their API is not used to train their models.
  • LinkedIn— if you choose to sign in with LinkedIn, LinkedIn authenticates you and returns the profile fields you authorize. Separately, if you connect LinkedIn or X as a channel, you sign in to that platform yourself in a browser on your own machine. Those platforms' own processing is governed by their privacy policies.
  • Reddit and X — where a channel reads public content through an official API, our requests to that API carry the search terms you configured and the credentials you supplied for it.
  • Brevo — sends our transactional and alert emails, and reports back delivery and engagement events. Receives your email address and message contents.
  • Google (Google Ads)— measures conversions from our advertising. When you arrive from a Google ad and later sign up, Google's tag records the conversion and may receive the associated click identifier and standard request metadata. Governed by Google's privacy policy.

We do not sell your personal data. Apart from the Google Ads conversion measurement described above, we do not share your data for third-party advertising.

6. International data transfers

Several of the providers listed above are based in the United States or process data across multiple regions. Where personal data of EU or Brazilian users is transferred outside their region, we rely on the safeguards offered by those providers (such as Standard Contractual Clauses or equivalent frameworks).

7. Data retention

  • Account data is kept while your account is active.
  • Your search configuration and channel credentials are kept until you change or remove them, or your account is closed. Disconnecting a channel deletes the credentials stored for it.
  • Discovered posts and their scores are kept while they are relevant to your queue and are deleted when the search group they belong to is deleted, or when your account is closed.
  • Server logs are retained for a short period for security and debugging, then discarded by our infrastructure provider.
  • When you delete your account, we delete or anonymize your personal data within 30 days, except where we are legally required to retain it.

8. Your rights

Under the GDPR (EU/UK) and the LGPD (Brazil), you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate or incomplete data.
  • Delete your data (right to erasure / right to deletion), subject to legal exceptions.
  • Receive a copy of your data in a portable format.
  • Restrict or object to certain processing.
  • Withdraw consent at any time, without affecting prior processing.
  • Lodge a complaint with your supervisory authority (in the EU) or with the ANPD in Brazil.

To exercise any of these rights, email [email protected]. We may ask for information to verify your identity before responding.

9. Security

We use industry-standard measures to protect your data, including encryption in transit (TLS), short-lived access tokens, scoped database access, and least-privilege controls on third-party integrations. Channel credentials are encrypted at rest, and device tokens for paired desktop agents are stored only as hashes. For browser-based channels, your platform login stays in a browser profile on your own machine rather than on our servers. No system is perfectly secure; if you believe your account has been compromised, contact us immediately.

10. Children

The Service is intended for adults using it for professional purposes. We do not knowingly collect personal data from anyone under 16. If you believe a minor has provided us with personal data, contact us and we will delete it.

11. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above and, for material changes, notify you by email or through the Service before the change takes effect.

12. Contact

Questions or requests related to this Privacy Policy can be sent to [email protected].