Skip to content
WLOC Cloud

Legal · Draft

Draft document

DRAFT — Not final legal advice. Formal review is tracked in WC-LEGAL-0001 before Public Beta.

Privacy Policy

Draft privacy notice describing minimization and what we never store. Subject to WC-LEGAL-0001 review.

Updated 2026-08-16

What we process

Account email for OTP sign-in, workspace and device metadata you provide, subscription identifiers from Stripe, coarse policy-acceptance region, and operational logs with redacted fields. We process target coordinates you submit for diagnostics or location sessions. Precise coordinates and email addresses are not sent to product analytics.

What we never store

Gateway and Access secrets, session/OTP peppers, EAP passwords, Profile XML, CA private keys, and raw VPN traffic never enter the browser bundle, D1, KV, Durable Objects, queues, analytics, error trackers, or fixtures.

Retention

Storage retention is not the same as what the dashboard shows. Activity records are stored on the order of 90 days (Free accounts still only see the latest three items). Location and diagnostic coordinates are stored on the order of 90 days then removed or blanked. Security audit records are kept on the order of 365 days with identifiers reduced over time. Billing ledgers are kept for about seven years or until a documented legal hold ends, as invoice references without unnecessary personal data. Short-lived sessions, OTP challenges, and download tokens expire in hours to days.

Deletion is not a physical wipe of every record

Delete Account is a cancelable 7-day process. We Restore or Revoke active testing first. After the window, we anonymize identity fields (irreversible tombstones) and remove or blank location history. We do not claim that every billing or security record is physically destroyed: legally retained ledger and audit skeletons may remain without your email or precise coordinates. Data we never stored (Profile XML, EAP passwords, secrets, raw traffic) has no delete action because it never landed.

Coordinates and analytics

Precise coordinates and email addresses are not sent to product analytics. Marketing pages do not inject user email, device IDs, tokens, or live coordinates.

Support access

Support cannot read Profile XML, EAP passwords, private keys, or raw traffic. Privileged Restore/Revoke actions require separate identity, recent authentication, reason, user authorization, and audit.