Draft: the operator details in [brackets] still need filling in (LEGAL_* settings). Have a lawyer review these pages before launch.

Privacy policy

Effective 27 September 2026

Wirk ("the service") is operated by [Company legal name — set LEGAL_COMPANY_NAME], [registered address — set LEGAL_ADDRESS] ("we", "us"). It lets businesses create social media content, answer their inbox, run ads and automate work with AI. This policy explains what we collect, why, who we share it with, and how to have it deleted. Questions: [privacy contact email — set LEGAL_CONTACT_EMAIL].

Who is responsible for what

For your account and workspace we decide how data is used, so we are the controller. The messages, comments and reviews your workspace receives from its own customers are processed on the workspace's behalf: the business that owns the workspace is the controller of that data and we act as its processor.

What we collect

  • Account: your email address and name, and the workspaces and roles you belong to. We don't use passwords; you sign in with a one-time code sent to your email.
  • Workspace content: chats with the AI, artifacts (posts, documents, campaigns), workflows, schedules, the content calendar, brand and knowledge documents, and files you upload or generate.
  • Connected accounts: when a workspace connects Facebook, Instagram, Google or Slack, we store the access tokens the provider gives us (encrypted with AES-256-GCM), the name of the person who connected, and the pages, ad accounts or locations they chose.
  • Inbox data: comments, direct messages and reviews received by the connected pages and profiles, with the sender's public name or handle, and the replies sent.
  • Landing pages: what visitors type into a workspace's page forms (such as name, phone, email and message), and, if the page takes payments, the amount, currency and payment status. Card details are entered on Stripe's pages; payments go to the business's own Stripe account.
  • Page visits: for each visit to a live page, the page, time, where the visitor came from (referrer and campaign tags), device type and country. We don't set analytics cookies or store IP addresses; a visitor is counted with a one-way code made from the day, the page, the IP address and the browser, which changes every day.
  • Chat apps: if you link Slack, Microsoft Teams, WhatsApp, Telegram or Apple Messages, we store your account id on that app, where to reply, and the messages you exchange with the assistant there.
  • Client review links: when a workspace shares a review link, the decisions and comments the client leaves on it.
  • Push notifications: if you turn them on, the push address your browser gives us for that device.
  • Ads: campaign settings and performance numbers (spend, clicks, impressions) from the ad accounts you connect.
  • Billing: your plan, credit balance and purchase history. Card details are entered on our payment provider's pages (Whop or Stripe) and never reach us.
  • Usage and security: credits used, which AI model ran, token counts, and an audit log of actions such as approvals and setting changes.
  • Sign-in activity: each time a sign-in code is requested or used, the email address, the IP address, the country worked out from it (looked up on our own servers), and the browser and device type. We keep this for 180 days to protect accounts and investigate misuse. Our web server also keeps standard access logs (IP address, time and page requested) for up to 30 days.

How we use it

  • To run the features you ask for: generating content, drafting replies, publishing, scheduling and reporting.
  • To bill you and enforce plan limits.
  • To keep the service secure, prevent abuse, and fix problems.
  • Conversations with the AI assistant may be reviewed by Wirk staff to improve the service.
  • To email you sign-in codes, invitations and important account notices (such as a failed payment). We don't send marketing email without your consent.

Nothing is published, sent or spent on a connected account unless a workspace admin approves it, or the workspace has turned on a specific automatic reply rule. We do not sell personal data, and we don't use your content to train AI models.

Data from Google

If you connect a Google account, we use Google Business Profile data to read and reply to your reviews, and Google Ads data to create campaigns you approve and show their results. Wirk's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We don't use Google user data for advertising, don't sell it, and don't let people read it except with your consent, for security, or where the law requires.

Data from Meta (Facebook and Instagram)

If you connect Meta, we use your Pages, Instagram accounts and ad accounts only to publish posts you approve, receive and answer comments and messages, and run and report on ads you approve. You can remove access at any time in Integrations, or in your Facebook settings under Business Integrations. See data deletion for how to have this data removed.

Who we share it with

We share data only with the service providers needed to run the service, each under a contract that limits how they may use it:

ProviderWhy
AnthropicAI model that writes and analyses content (the prompts and workspace content needed for each request)
fal.aiImage generation (the image prompt)
Magnific (Freepik)Image upscaling (the image being enlarged)
SearchAPIWeb search when the AI needs current information (the search query)
WhopPayments for plans and credits (workspace id, billing email, purchases)
StripePayments (workspace name, billing email, purchases)
ResendSending email (your email address and the message)
Amazon Web Services (Amazon SES)Sending a workspace's email campaigns to its contacts, and reporting bounces, spam complaints and opens (the contact's email address and name, and the email)
Slack, Microsoft, Meta (WhatsApp), Telegram and AppleChat apps you link (your messages with the assistant on that app)
Browser push services (Google, Mozilla, Microsoft, Apple)Delivering push notifications you turn on (the notification text)
OpenMeterUsage metering (the workspace id and usage numbers only, no names or content)
Trigger.devRunning background jobs such as scheduled posts
Hosting, database and file storage providersStoring and serving the service and its data

When your workspace connects a service, such as Meta, Google, Google Drive, Slack, PostProxy, its own email server or its own AI key or tools, we send it what you ask us to publish or send. That service's own privacy policy then applies. We may also disclose data if the law requires it.

Cookies

We use a sign-in cookie to keep you signed in, a cookie to remember your language, and, when you arrive from a link with campaign tags or from another website, a cookie that remembers which one (for 90 days), so we know which of our campaigns brought in new accounts. On live landing pages, a cookie may remember which version of the page a visitor saw during a page test. We don't use advertising or analytics cookies.

International transfers

Our providers may process data outside your country. Where the law requires, we rely on appropriate safeguards such as standard contractual clauses.

How long we keep it

  • Sign-in codes expire after 10 minutes, and chat-app link codes after 10 minutes.
  • Page visit records are deleted after about 13 months.
  • Workspace data is kept while the workspace exists. When an owner deletes a workspace, its data and files are deleted from the live systems right away. Backups roll off on our database provider's backup schedule.
  • Disconnecting an account deletes its stored tokens and revokes them with the provider where the provider allows it.
  • We keep billing records as long as tax and accounting law requires.

Security

Traffic is encrypted in transit. Provider tokens are encrypted at rest. Each workspace's data is kept separate, and webhooks from providers are verified by signature. No system is perfectly secure; if a breach affects you, we'll tell you as the law requires.

Your rights

Depending on where you live, you may have the right to access, correct, export or delete your data, and to object to or restrict some processing. Email [privacy contact email — set LEGAL_CONTACT_EMAIL] and we'll answer within 30 days. If your data is in a business's workspace (for example, you messaged that business), contact the business first; we'll help them respond. You can also complain to your local data protection authority.

Children

The service is for businesses and isn't meant for anyone under 18.

Changes

If we change this policy in a material way, we'll tell workspace owners by email or in the app before the change takes effect.