Privacy Policy

Last updated July 22, 2026

Walle is a product of Winsen Labs ("Winsen Labs", "we", "us"). This policy explains what data Walle handles, what we store, what we deliberately do not store, and the choices you have. Questions any time: hello@winsen.ai.

The headline: your tool credentials never touch our servers

When you connect a tool (Gmail, Notion, Linear, HubSpot, and others), the OAuth grant or API key is captured and stored by our integration infrastructure partner, Composio, in their secured credential vault. Winsen Labs stores only a reference (an opaque connected-account identifier). We cannot read your passwords or tokens, and they are never written to our database. You can revoke a connection at any time from your connections page, or directly at the provider (for example, your Google account's security settings); revoking makes the stored credential unusable.

What we do store

What we do not do

Subprocessors

We rely on a small set of infrastructure providers to run Walle:

Your rights

You can access, export, or delete your data at any time by writing to hello@winsen.ai. Deletion removes your account, conversations, memories, artifacts, and usage records from our systems, and disconnecting a tool deletes its credential at the integration layer. If you are in a jurisdiction with specific data-protection rights (such as the GDPR or CCPA), we honor access, rectification, erasure, and portability requests under those frameworks.

Retention

We keep your data while your account is active. When you delete your account, associated data is removed from production systems promptly and from backups on their rotation schedule.

Changes

If this policy changes materially, we will notify you by email or in the product before the change takes effect.