Privacy Policy

Last updated: 19 July 2026. This policy describes how waypoint.dog (“we”, “us”) handles personal data when you use the service at waypoint.dog and its tool subdomains.

Who we are

waypoint.dog is an AI-powered Startup Operating System. You can contact us about privacy at the support channel listed on the site.

Data we collect

  • Account data — email address and profile details from Auth.js sign-in (magic link via Resend, Google, and/or GitHub).
  • Usage data — projects, tool runs (generations), project context, and related metadata needed to provide the product.
  • Billing data — credit purchases and refunds processed by Paddle (we store payment references and credit ledger entries; card details are handled by Paddle).
  • Generated content — AI outputs and uploaded or stored assets (for example brand logos in object storage).
  • Technical logs — operational logs and error reports (for example Sentry) for reliability and security.

How we use data

We use personal data to:

  • Authenticate you and keep sessions across apex and tool subdomains
  • Run tools, reserve and consume credits, and store project context
  • Process purchases and refunds via Paddle
  • Provide account settings, data export, and account deletion
  • Secure the service (rate limiting, abuse prevention, fraud checks)
  • Measure product usage with analytics only after you consent (see Cookies)

Legal basis

We process data to perform our contract with you (providing the service) and, where appropriate, for legitimate interests such as securing the platform and improving reliability. Where required, we rely on consent (for example non-essential analytics cookies).

Processors and subprocessors

We use service providers to operate the product, including:

  • Hosting and edge (Vercel)
  • Database (Neon)
  • Auth email delivery (Resend) and OAuth providers (Google, GitHub)
  • Payments (Paddle)
  • Object storage (Cloudflare R2)
  • Redis / queues (Upstash) for rate limiting and background jobs
  • AI model providers for text and image generation
  • Error monitoring (Sentry)
  • Product analytics (PostHog), only when cookie consent is granted

Cookies and analytics

Essential cookies support authentication and security. PostHog analytics load in the browser only after you accept analytics via the cookie consent banner (`waypoint_cookie_consent`). You can decline analytics and still use the core product.

Retention

Account and project data are retained while your account exists. Generations and context remain until you delete the related project or account. Soft-deleted accounts are purged after 30 days (or immediately if you choose hard delete). Certain payment records may be retained in anonymized form for accounting and fraud prevention.

Your rights

Depending on your location, you may have rights to:

  • Access / export — request a copy of your data from Settings (ZIP export via `/api/gdpr/export`, or JSON via the product API). Recent re-authentication is required.
  • Erasure — delete your account from Settings (soft-delete with delayed purge, or immediate hard delete).
  • Correction — update profile details available in the product or by contacting support.

International transfers

Processors may process data in the United States or other countries. Where required, we rely on appropriate transfer mechanisms provided by those processors.

Children

The service is not directed to children under 16. We do not knowingly collect personal data from children.

Changes

We may update this policy as the product evolves. Material changes will be reflected by updating the date above and, where appropriate, additional notice in the product.

See also our Terms of Service.