← Back to WAG AI SOLUTION

Privacy Policy

Last updated: September 14, 2026

WAG AI SOLUTION (“the Service”, “we”, “us”) is a client, job, and invoice management tool built for contractors. This policy explains what information we collect when you use the Service, how it is used, and the choices you have. By signing in to the Service, you agree to the practices described here.

1. Information we collect

We collect information in two ways: what Google shares with us when you sign in, and what you enter directly into the Service.

From Google, at sign-in:

  • Your name, email address, and profile picture.
  • Permission to send email on your behalf (Gmail send scope) — used only when you click “Send” on an invoice you created, to email that invoice from your own Gmail account.
  • Permission to create and manage calendar events on your behalf (Calendar events scope) — used only to create, update, or read events for jobs you schedule in the Service, and to import events you create directly in your Google Calendar back into the Service.

Directly from you, while using the Service:

  • Business data you create: clients, jobs, invoices, price lists, and any notes or files attached to them.
  • Company profile details you enter in Settings — company name, contact email/phone, address, uploaded logo, and language preference.

2. How we use this information

  • To create and maintain your private workspace.
  • To generate invoice PDFs and send them from your own Gmail account, only when you initiate the send.
  • To create and sync calendar events for jobs, only for jobs you schedule or import.
  • To power the in-app Assistant, which may read your clients, price lists, jobs, and invoices to draft invoices you explicitly request. The Assistant never receives the content of your Gmail messages or Calendar events — see Section 7.
  • To operate, maintain, and improve the Service (e.g. troubleshooting errors).

We do not sell your data. We do not use your Google account data for advertising, and we do not share it with third parties except the infrastructure providers strictly needed to run the Service (see below).

3. Data isolation between accounts

Each Google account that signs in gets its own private workspace. Clients, jobs, invoices, and settings created under one account are never visible to another account.

4. Where data is stored

Application data is stored in a managed PostgreSQL database (Neon). The application itself is hosted on Vercel. Both providers process data solely to operate the Service on our behalf and do not use it for their own purposes.

5. How we protect your data

We apply the following safeguards to protect your data, including the sensitive Google account access (Gmail send and Calendar events) described in Section 1:

  • Encryption in transit. All connections between your device, the Service, our database, and Google's APIs are encrypted using TLS/HTTPS. The Service is not accessible over unencrypted HTTP.
  • Encryption at rest for OAuth tokens. The Google access and refresh tokens that let the Service send email or manage calendar events on your behalf are encrypted at rest (AES-256-GCM) before being stored in our database. They are decrypted only in memory, at the moment a request is made to a Google API, and are never exposed in logs, backups, or client-side code.
  • Workspace-level data isolation. Your business data and settings are scoped to your own account/workspace and are never visible to another account (see Section 3).
  • Passwordless sign-in. We never collect or store a password for your account — sign-in is handled entirely by Google's own authentication, so there is no password of yours for us to protect or that could leak.
  • Restricted internal access. OAuth tokens and account data are used only by the Service's automated systems to perform the action you requested (e.g. sending an invoice, syncing a calendar) — not browsed manually by any employee or contractor.
  • Security headers and rate limiting. The Service applies standard web-security headers (including X-Frame-Options, X-Content-Type-Options, and Referrer-Policy) and rate-limits sensitive endpoints to reduce exposure to common web attacks such as clickjacking and abuse.
  • Managed infrastructure. Our database and hosting providers (see Section 4) maintain their own security and compliance programs and are used solely to operate the Service on our behalf.

If we become aware of a data breach affecting your information, we will notify you and take appropriate action in accordance with applicable law.

6. Data retention and deletion

We retain your data for as long as your account is active. You may request deletion of your account and all associated data at any time by emailing chairbackia@gmail.com. We will delete your data within a reasonable time after verifying the request.

7. Google user data and limited use

WAG AI SOLUTION's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Gmail and Calendar access is used only for the specific, user-initiated features described above, and is never used to build advertising profiles, sold, or shared for purposes unrelated to providing the Service.

AI Assistant and Limited Use. The in-app Assistant is powered by Anthropic's Claude API, accessed directly through Anthropic's commercial API (not a consumer product, and not through any aggregator or gateway). The Assistant only has access to your own business records that you entered directly into the Service — clients, price list items, jobs, and invoices. It never receives the content of your Gmail messages or Calendar events, and no data obtained through the Gmail or Calendar scopes is ever transmitted to Anthropic or any other AI/ML service. Per Anthropic's Commercial Terms of Service, data submitted through its commercial API is not used to train or improve Anthropic's models.

8. Revoking access

You can revoke the Service's access to your Google account at any time from your Google Account permissions page.

9. Children's privacy

The Service is intended for business use by contractors and is not directed at children under 13. We do not knowingly collect information from children.

10. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the “Last updated” date above.

11. Contact

Questions about this policy or your data can be sent to chairbackia@gmail.com.