Privacy Policy
Last updated: 27 September 2026
1. What we collect
When you create an account: your name, your email address, and the name and domains of your organisation. When you use Whaily: the prompts you configure, the competitors and domains you choose to track, the notes and comments you write, and a record of which pages in the app you opened and when. When you sign in: the method you used, a coarse device description such as “Chrome on macOS”, and a partial IP address, never the full one. When you accept the Terms of Service and this policy: which versions you accepted, when, where (sign-up, setting up a brand, or buying a plan) and the IP address and browser it came from, kept as proof of the agreement for as long as your account is open. We email you a copy of the terms you accepted.
We do store the full text of the AI answers we collect for you. That is the product: an answer is the evidence behind every number we show, and you can read any of them in the app. Those answers routinely name people and companies other than you, because that is what the models wrote.
2. How we use it
To run the service and nothing else: sending your prompts to AI models, measuring where you and your competitors appear in the answers, producing recommendations, and sending the email you asked for. We do not sell your data. We do not use your prompts or your results to train any model of our own, and we do not licence them to anyone who does.
2a. Why we are allowed to
We rely on three grounds. Running the service you signed up for covers your account, your prompts, the answers we store and the mail the product has to send you: without those there is no product. Keeping the service safe and working covers sign-in records, rate limiting, error logs and the counts we use to see whether a feature is used at all. Your consent covers anything optional, which today means marketing email and error reporting in the browser (Sentry, see the cookie policy), and you can withdraw it without losing the service.
We do not sell personal data, we do not share it for advertising, and nothing on this page is a legitimate-interest claim for either.
3. Your prompts go to AI model providers
This is the central thing to understand about Whaily, so it has its own section. To measure what AI says about your brand, we send the prompts you configure to the providers who run those models, and we store what they send back. Today that is Anthropic, DeepSeek, Google, OpenAI, Perplexity, xAI. Each receives the prompt text and processes it under its own terms and privacy policy.
Your prompts are questions about a market, so they usually contain no personal data. If you write personal data into a prompt, it goes to the provider you assigned that prompt to. If you supply your own provider keys, your prompts go to your own accounts with those providers instead of ours.
3a. Your prompts leave the EU
The database is in the EU, and the model providers are not. This section exists because that is the one thing in the list above a reader cannot work out for themselves, and the list is read out of the same registry the product runs on rather than written by hand, so it cannot fall behind the models we actually call.
- China: DeepSeek
- United States: Anthropic, Google, OpenAI, Perplexity, xAI
For the United States, which covers these providers and the US companies in section 4, the route is: EU-US Data Privacy Framework where the company is certified under it, otherwise the European Commission standard contractual clauses in its data processing terms.
China: No adequacy decision covers China, so we limit what goes there: only the prompt text you write and company names (your organisation, its industry and your competitors). We never send them your name, your email address or any other account or contact data. If you type personal data into a prompt yourself, it travels with that prompt.
If you would rather your prompt text did not reach a particular provider, you can turn that model off for your organisation, or supply your own keys so the call goes to your own account instead of ours.
4. Everyone who receives your data
The complete list, and what each one gets. The subprocessor list adds where each one processes data and the legal route for any transfer outside the EU.
- Vercel
- Every request you make to whaily.com, including your IP address and your session cookie.
- Neon
- Accounts, organisations, the prompts you configure, the domains you track, notes, and every AI answer we store.
- Google Cloud
- The prompts, brands and domains a job works on, and the answers it collects.
- Cloudflare
- Your IP address and browser details when you visit, and the fact that a form was submitted.
- Resend
- Your email address and the content of each message.
- Google sign-in
- The sign-in request. Google returns your name and email address to us.
- Stripe and Link
- Your email address, your organisation name, the plan you buy, and the card and billing details you enter on Stripe’s own page. We never see or store card numbers.
- Sentry
- The error, the page address, your browser and operating system, and your IP address as your browser connects. No name, email address or cookies.
- TypeSafe
- Stored AI answers, the text of cited public pages, and the brand and competitor names being scored.
- DataForSEO
- The keywords, domains and brand names we look up for you.
- Anthropic
- The prompt text you write and company names. When it is the model we analyse with, also stored answers and the text of your own public pages, to read brands and sentiment out of them. We store what it sends back.
- DeepSeek
- The prompt text you write and company names. We store the answer it sends back.
- The prompt text you write and company names. When it is the model we analyse with, also stored answers and the text of your own public pages, to read brands and sentiment out of them. We store what it sends back.
- OpenAI
- The prompt text you write and company names. When it is the model we analyse with, also stored answers and the text of your own public pages, to read brands and sentiment out of them. We store what it sends back.
- Perplexity
- The prompt text you write and company names. When it is the model we analyse with, also stored answers and the text of your own public pages, to read brands and sentiment out of them. We store what it sends back.
- xAI
- The prompt text you write and company names. When it is the model we analyse with, also stored answers and the text of your own public pages, to read brands and sentiment out of them. We store what it sends back.
Payments go through Stripe, with Link as the merchant of record. You enter card details on Stripe’s own page, and we never see or store a card number.
5. Data we get from somewhere other than you
Some of what we hold did not come from you. We read the public pages that AI answers cite, including your competitors’ pages, and keep their titles and text. We buy search-ranking data for the keywords you track. And the AI answers themselves name companies and sometimes people who never signed up to anything here. We keep that material because it is the evidence for a measurement, we do not use it to build profiles of individuals, and we will remove any of it on request.
6. How long we keep things
Your account data for as long as your account is open. Ask us to delete your account and we will remove your personal data within 30 days, with two deliberate exceptions. We keep a copy of each email we send you, with any sign-in and invitation links removed, for one year alongside the record that it was sent, because that is what proves what we sent and to which address. Anonymous aggregate counts that identify nobody may be kept indefinitely.
Shorter windows apply to operational records: sign-in and security events for 90 days, the record of pages you opened for 90 days, device records for 180 days.
6a. How we protect it
Everything travels over TLS and the database is encrypted at rest by our host. Every query the product makes is scoped to one organisation, so one customer's data is not reachable from another customer's session. Sessions are signed cookies rather than tokens in the URL. If you supply your own provider keys they are encrypted with a separate key before they are stored, and nothing in the product can display them again afterwards.
What we do not claim: we are a small team, this is not a certified environment, and we have not been audited against a security standard. If that matters for your purchase, ask us and we will tell you exactly where we are rather than point at a badge.
7. Your rights
You can ask us for a copy of your data, ask us to correct it, ask us to delete it, ask for it in a portable form, object to our using it, or ask us to stop using it while a complaint is open. Deletion is handled by a person rather than a button today: email us and we will confirm when it is done. We answer within one month, and if something will take longer we will say so inside that month rather than go quiet.
Nothing here makes an automated decision about you. The models score brands and pages, never people, and no output of the product decides anything about a person's access, price or treatment.
If you are in the European Economic Area or the UK you can also complain to your local data protection authority, and you do not have to come to us first.
To stop receiving email from us, use the unsubscribe link in any message we sent you. It works whether or not you have a Whaily account, and it works on a message that is years old.
8. Contact
For anything on this page, including a deletion request, email hello@whaily.com.
9. Who is responsible
Whaily is run by its founder in Sweden. Contact: hello@whaily.com.
10. Changes to this policy
The date at the top changes when the text does. Two kinds of change get told to you rather than left for you to find: a new place your data goes, and a new purpose we use it for. Both reach account holders by email before they take effect. A wording fix or a clearer explanation of something we already did does not.
