Your data & your choices

Privacy Policy

Effective and last updated:

WeaveKit connects AI agents to the tools your workspace uses. This policy explains what information that involves, where it goes, how it is kept, and how you can control it.

1. Who we are and what this covers

WeaveKit is operated by Alejandro Roman ("WeaveKit," "we," "us," or "our"). This policy covers our website at weavekit.ai, our application and APIs on weavekit.dev and its subdomains, and WeaveKit agents, integrations, and mobile interfaces.

We are responsible for information used to operate accounts, bill for the service, communicate with you, and secure WeaveKit. When a business or other organization supplies workspace content and directs its processing, we generally process that content on the organization's behalf. Its own privacy notices and instructions also apply. Contact your workspace administrator about information supplied by your organization; we can help route requests to the appropriate person.

2. Information we collect

Content can include information about other people, such as colleagues, email correspondents, meeting participants, or customers. Only connect accounts and provide information you are authorized to use with WeaveKit.

3. How we use information

We use information to authenticate users; operate workspaces; answer questions; search and summarize connected sources; create drafts, briefings, reminders, and other requested outputs; run configured routines; perform enabled actions; maintain useful context; and show activity, approvals, and costs.

We also use account, billing, and technical information to provide support, process payments, prevent abuse, troubleshoot problems, improve reliability, and meet legal obligations. Connected content is processed for the workspace features you enable, not for unrelated advertising.

Where applicable law requires a legal basis, we rely on performing our agreement with you, your consent for optional access or uses, legitimate interests in operating and securing the service, and compliance with legal obligations. Processing on behalf of an organization follows its lawful instructions. These bases do not expand the uses of Google information permitted below.

4. Google account information

Connecting Google Workspace currently requests access to your account identity and email address, subscribed calendar list, availability, calendar events, and Gmail. The Google consent screen identifies the requested permissions. Accounts connected before a permission was added may have less access until reconnected.

Relevant Google content can be included in AI requests, workspace history, and requested outputs delivered to your configured destinations. Access is governed by the Google permissions granted and the capabilities assigned within WeaveKit.

Limited Use: WeaveKit's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements, and the Google Workspace user data and developer policy.

We do not sell Google user data, use it for advertising, creditworthiness or lending decisions, or use it to train or improve generalized or non-personalized AI or machine learning models. These restrictions also apply to derived data and transfers to service providers.

We restrict human access to Google data to your explicit agreement to view specific information, necessary security or bug investigations, legal requirements, or aggregated and anonymized information used for permitted internal operations. Any transfer in a business acquisition requires your prior consent for Google data. These Google-specific restrictions take precedence over broader descriptions elsewhere in this policy.

Apple Health, when enabled

Connecting Apple Health is optional. With your permission, the iPhone app reads selected workout records (including activity type, indoor/outdoor classification, duration, and available distance and energy), sleep intervals and stages, weight measurements, and daily steps, resting heart rate, and heart-rate variability. Availability depends on the devices and apps that write to Apple Health and the access you allow. This connection does not request permission to write to Apple Health or collect workout routes or clinical records.

Before enabling upload, the app explains that selected information will leave your iPhone and be stored by WeaveKit. You choose the initial history window, up to 90 days. Subsequent synced history is retained until you delete the Health copy or the relevant account is removed; the initial import window is not an automatic retention limit. A separate upload credential, device identifier, source information, timestamps, and sync receipts support this connection.

Health records belong to the person who connects them within the selected workspace. Other workspace members and administrators do not automatically receive access to those records or protected Health conversations. Switching workspaces does not copy Health data into another workspace.

Connecting Health does not itself allow AI processing. Where private Health chat is available, a separate consent identifies the agent, categories, history range, and AI provider before summaries are sent. The initial supported provider is OpenAI. That permission applies to private Health conversations in the app; it does not enable automatic sharing through Slack, general routines, shared agent memory, or GitHub. Health data is not used for advertising, sold, or used by WeaveKit to train general-purpose AI models.

In Health settings, stopping sync retains imported records and does not itself revoke a separate agent grant. Removing an agent grant stops future authorized processing but retains existing protected conversations. Deleting Health data stops uploads and agent access, then removes the live imported records and protected Health conversations, including their derived run records. The app shows deletion in progress until that purge is verified. This does not delete your original Apple Health information or copies you manually exported elsewhere.

Revocation cannot recall information already sent to a provider. Provider retention and backup handling follow the separate disclosures below; deleting the live Health copy does not mean every backup or already-processed provider copy disappears immediately. Contact me@alejandroroman.dev about those copies or a Health privacy request. Apple read permissions remain under your control in the system Health settings.

5. AI processing and memory

To carry out a task, WeaveKit sends relevant prompts, conversation context, instructions, and tool results to the AI provider used for that task. This may include personal information from a connected account. The primary model and any configured fallback determine the provider; a retry with a fallback may send the same context to another provider.

Supported providers include OpenAI, Anthropic, Alibaba Cloud (Qwen), MiniMax, Moonshot AI, and Z.ai, depending on the models enabled for your workspace. Features that search saved knowledge may also send text to an embedding provider, such as OpenAI, to create a searchable numerical representation. Connected tools or knowledge services can perform additional AI processing under their own service arrangements.

WeaveKit does not train its own general-purpose AI models using workspace content. Agent personalization uses saved instructions, preferences, examples, and memory as context. Provider processing and retention depend on the applicable API service and its terms; processing a request does not imply that the provider retains no data. The Google data restrictions in section 4 continue to apply when an AI provider processes Google information.

AI-generated information may be inaccurate. You can request correction or deletion of stored personal information and should review outputs before relying on them or approving an external action.

6. Who receives information

We do not sell personal information or share it for cross-context behavioral advertising. Enabling an integration does not make your workspace publicly accessible.

7. Retention and deletion

We keep account information and workspace content for as long as needed to provide your configured service, maintain requested history and context, and fulfill the purposes described here. Retention depends on the record and enabled feature; there is no single automatic deletion period for all workspace data.

For account or workspace deletion, or to remove stored information that is not covered by an available control, email me@alejandroroman.dev. Tell us the account or workspace and the data concerned. We verify your authority, coordinate with the workspace owner when appropriate, and handle the request within applicable legal deadlines. We explain any required retention or copies outside our control rather than treating disconnection as complete deletion.

8. Your controls and rights

You or an authorized workspace administrator can manage integrations and agent capabilities, disable routines, and pause agents. Workspace Voice settings include controls for removing saved voice preferences and profiles. Turning off a feature does not undo processing already completed or recall provider requests already in progress.

To stop WeaveKit's Google access, use Settings โ†’ Integrations โ†’ Google Workspace โ†’ Disconnect. You can also remove WeaveKit in your Google Account's third-party connections. Revoking Google access stops new authorized access; contact us separately to remove information already stored by WeaveKit.

Depending on your location and the circumstances, you may have rights to access, obtain a copy of, correct, delete, restrict, or object to processing of personal information, and to withdraw consent. Withdrawal does not affect processing that was lawful before it. You may also complain to your local data protection authority and, where applicable, appeal a decision about a request by contacting us. We do not discriminate against you for exercising applicable privacy rights.

Send requests to me@alejandroroman.dev. We may need to verify your identity or authority and protect the privacy of other people before fulfilling a request.

9. Security and international processing

We use safeguards that include HTTPS connections, encrypted stored integration credentials, password hashing, workspace-scoped access controls, and measures to redact credentials from logs. Access by service operators is limited to authorized operational needs and the restrictions described in this policy. No system can guarantee absolute security.

WeaveKit and its service providers may process information in the United States and other countries where they operate. A model or connected service can process data outside your country; choosing WeaveKit does not establish a particular data-residency region. Contact us for information about the processing locations, providers, and transfer arrangements relevant to your workspace.

10. Cookies and website connections

The application uses session cookies and browser storage to keep you signed in, protect authentication flows, and remember interface preferences. You can manage cookies in your browser, although blocking necessary cookies may prevent sign-in or other features from working.

Our public homepage loads fonts from Google Fonts, which receives ordinary connection information such as your IP address and browser request details. Hosting providers also receive web request information. We do not currently use advertising cookies or cross-site advertising trackers on the public website.

11. Children

WeaveKit is a work and productivity service intended for adults. It is not directed to children under 13, and we do not knowingly collect personal information directly from children under 13. If you believe a child has provided us personal information, contact us so we can investigate and take appropriate action.

12. Changes and contact

We may update this policy as the service or our practices change. We will update the date above and provide additional notice where required. If a new use of Google data requires renewed consent, we will obtain it before using the data for that purpose.

Privacy questions or requests
Alejandro Roman, operator of WeaveKit
me@alejandroroman.dev