1. Information we collect
Information you provide
- Account information — name, email address, organization, and login credentials when you sign up.
- Content you submit — messages, prompts, files, documents, and other data you or your agents send to the Service so Fo can act on them.
- Connected accounts — when you link a third-party integration (for example Google, email, calendar, Slack, or another tool), we access the data needed to perform the actions you request, under the scopes you grant.
- Payment information — processed by our payment provider; we do not store full card numbers.
- Communications — messages you send to support or feedback you share with us.
Information we collect automatically
- Usage data — features used, actions taken, and interactions with Fo.
- Device and log data — IP address, browser type, device identifiers, and timestamps.
- Cookies and similar technologies — used to keep you signed in and to understand how the Service is used.
2. How we use information
- Provide, operate, and maintain the Service, including letting Fo carry out the tasks you ask of it.
- Authenticate users and secure accounts.
- Improve and develop features, and troubleshoot problems.
- Communicate with you about your account, updates, and support requests.
- Detect, prevent, and address fraud, abuse, and security issues.
- Comply with legal obligations.
3. AI processing
Fo uses large language models and related tooling to process the content you submit and to take actions on your behalf. To deliver these features, relevant content may be sent to third-party model providers strictly to generate a response or complete a requested task. We do not permit these providers to use your content to train their models except where you have explicitly opted in. We do not use Google user data, or any data obtained through Google Workspace APIs, to develop, improve, or train generalized or non-personalized AI and/or machine learning models.
4. Google user data and Limited Use
When you connect a Google account, the Service requests access only to the Google API scopes needed for the features you enable (for example, reading or sending email, reading or managing calendar events, or accessing Drive files). We request access in context and only to the scopes required for the task.
How we access, use, store, and share Google user data
- Access — only under the OAuth scopes you explicitly grant, and only to perform the actions you request through Fo.
- Use — solely to provide and improve the user-facing features you have asked for.
- Store — we retain Google user data only as long as needed to provide those features. OAuth tokens and any cached Google data are encrypted in transit and at rest, and access is restricted on a least-privilege basis.
- Share — we do not share Google user data with third parties except as strictly necessary to provide or improve the feature, to comply with applicable law, or as part of the limited exceptions below.
Specifically, we do not:
- Use Google user data for serving advertisements.
- Sell Google user data.
- Transfer or use Google user data for purposes other than providing or improving user-facing features that are prominent in the Service’s user interface, except as necessary for security, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to users.
- Allow humans to read Google user data, unless: we first obtain your affirmative agreement to view specific data; it is necessary for security purposes (such as investigating abuse); it is necessary to comply with applicable law; or the data is aggregated and anonymized and used for internal operations in line with applicable requirements.
Revoking access
You can disconnect a Google account from within the Service at any time, and you can review or revoke Wajo’s access directly from your Google Account permissions page.
5. How we share information
We do not sell your personal information. We share it only as described here:
- Service providers — infrastructure, hosting, analytics, model, and payment providers who process data on our behalf under contract.
- Integrations you authorize — third-party services you connect, limited to the actions you request.
- Within your organization — if your access is provided through an organization, administrators may access account and usage data.
- Legal and safety — when required by law or to protect the rights, property, or safety of Wajo, our users, or the public.
- Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this Policy.
6. Data retention
We retain personal information for as long as your account is active or as needed to provide the Service, then for the period required to meet legal, accounting, or security obligations. You can request deletion of your data as described below.
7. Security
We use technical and organizational measures, including encryption of data and OAuth tokens in transit and at rest, access controls, and least-privilege handling of connected-account credentials, to protect your information. We follow the security practices required for access to restricted Google API scopes, including periodic assessment under the Cloud Application Security Assessment (CASA) framework. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
8. Your rights and choices
Depending on where you live, you may have the right to access, correct, delete, or port your personal information, and to object to or restrict certain processing. To exercise these rights, contact us at privacy@wajo.ai. You can also update account details in the app and manage or revoke connected integrations at any time.
9. International users
We are based in the United States and process data there. If you access the Service from outside the U.S., you understand your information may be transferred to and processed in the U.S. and other countries.
10. Children
The Service is not intended for anyone under 16, and we do not knowingly collect personal information from children.
11. Changes to this Policy
We may update this Policy from time to time. When we make material changes, we will update the “Last updated” date and, where appropriate, notify you through the Service. If we plan to access or use a type of data that was not disclosed when you first authorized access, we will update this Policy and prompt you to consent before doing so.
12. Contact us
Questions about this Policy or your data? Reach us at:
Wajo, Inc.
369 Prentiss St, San Francisco, CA
privacy@wajo.ai
This is an initial privacy policy provided for transparency and is not legal advice. It should be reviewed by counsel before being relied upon for compliance in any specific jurisdiction or for a specific OAuth verification submission.