Privacy Policy
Last updated July 22, 2026
Walle is a product of Winsen Labs ("Winsen Labs", "we", "us"). This policy explains what data Walle handles, what we store, what we deliberately do not store, and the choices you have. Questions any time: hello@winsen.ai.
The headline: your tool credentials never touch our servers
When you connect a tool (Gmail, Notion, Linear, HubSpot, and others), the OAuth grant or API key is captured and stored by our integration infrastructure partner, Composio, in their secured credential vault. Winsen Labs stores only a reference (an opaque connected-account identifier). We cannot read your passwords or tokens, and they are never written to our database. You can revoke a connection at any time from your connections page, or directly at the provider (for example, your Google account's security settings); revoking makes the stored credential unusable.
What we do store
- Account data: your email address and name, used to sign you in and identify you across Slack and the web app.
- Slack workspace data: your workspace name and identifiers, and the bot token issued when Walle is added to your workspace (encrypted at the application layer). Walle processes the Slack messages it is mentioned in, or sent by DM, in order to respond.
- Conversations and memory: your conversations with Walle and the durable memories derived from them (facts, preferences, events, relationships you share). Memory is the point of Walle: it is what makes the agent useful over time. Memories are scoped to you and never shared across users or workspaces.
- Artifacts: documents, reports, and pages Walle creates for you. Private by default; you control sharing (private with invited emails, or link).
- Usage events: a metered record of actions Walle performs (which tool, when, on whose behalf), used for usage limits and billing.
- Analytics: with your consent (the cookie banner), we use PostHog for product analytics and session recordings of the web app. Nothing is captured before you accept, and declining keeps analytics off.
What we do not do
- We do not store third-party passwords, OAuth tokens, or API keys.
- We do not sell your data, ever.
- We do not use your data to train models. Model providers used by our agent runtime process content transiently to generate responses.
- We do not read your connected tools in the background. Tools run when you ask Walle to do something, or on schedules you explicitly create; outward-facing actions require your explicit approval.
Where your data lives
Walle is not run from a single place, and you are entitled to know which part of it sits where. Three locations matter:
- Stored in Mumbai, India. Your data at rest — account, conversations, memories, artifacts, usage and billing records — is held in our primary database in the Mumbai region.
- Processed in the United States. Generating a reply means sending the relevant conversation content to model providers that process it in the United States. This is processing in transit to produce your answer, not a second copy of your account: content is used to generate the response and is not used to train models.
- Servers in Singapore. The application servers that run the agent, execute your tool calls and serve the console operate from Singapore.
Using Walle therefore involves your data crossing borders between India, Singapore and the United States. If your organisation requires data to remain in one jurisdiction, Walle in its current form is not suitable for you, and we would rather tell you that here than after you have signed up.
Subprocessors
We rely on a small set of infrastructure providers to run Walle. Each one, what it does, and where it does it:
- Composio: holds the credentials for your connected tools in its secured vault and executes tool calls against them. Every integration you connect — Gmail, Calendar, Notion, Linear, HubSpot and the rest — is reached through Composio, and the credential itself lives there rather than with us.
- Supabase: the primary PostgreSQL database, hosted in Mumbai — this is where data is stored.
- Cloudflare: console hosting, object storage for artifacts, and the network edge.
- Together AI: model inference for the agent runtime, processed in the United States.
- Slack: the messaging surface Walle lives in.
- Resend: transactional email. This covers sign-in codes, artifact share invitations, security alerts and billing mail such as the notice that an invoice has been generated. Delivering an email necessarily discloses your email address, the subject and the message body to Resend, which processes it outside India. Billing mail deliberately carries no amounts or tax details — only a pointer to your billing page.
- Trigger.dev: background job processing, including the monthly billing run.
- Razorpay: payment processing. Card details are entered with Razorpay and never reach our servers; we store only the payment identifier, the amount and the currency.
- PostHog: consent-gated product analytics.
Your rights
You can access, export, or delete your data at any time by writing to hello@winsen.ai. Deletion removes your account, conversations, memories, artifacts, and usage records from our systems, and disconnecting a tool deletes its credential at the integration layer. If you are in a jurisdiction with specific data-protection rights (such as the GDPR or CCPA), we honor access, rectification, erasure, and portability requests under those frameworks.
Retention
We keep your data while your account is active. When you delete your account, associated data is removed from production systems promptly and from backups on their rotation schedule.
Changes
If this policy changes materially, we will notify you by email or in the product before the change takes effect.