Wisty

Privacy policy

Last updated September 21, 2026

This policy explains how Wisty collects and uses personal data when you visit our website or use our service.

1. Who we are and scope

Wisty Labs AS, org. nr. 938 423 490, Elisenbergveien 34, 0263 Oslo, Norway ("Wisty", "we") is the controller for personal data used to administer accounts, manage billing and communications, and analyse use of our website and service. Contact legal@wisty.ai with questions.

When we process personal data on a customer’s behalf, the customer is the controller, or acts for its own controller, and Wisty is its processor. That processing is governed by the data processing agreement.

2. Information we collect

Account and access information includes names, email addresses, sign-in details, workspace membership, and Salesforce user and org identifiers. We receive it from you, your organisation, and your sign-in provider, and store relevant records with our identity and database providers.

Website and product usage information includes page views, feature usage, browser and device information, error reports, and session replays of the standalone builder. For builder accounts, we link this usage information to your name, email address, and workspace name, so we can support you and see how the product is used. Viewer surfaces produce cookieless usage events that carry no names or email addresses.

We collect your email address when you join the waitlist. Billing records include your billing contact, plan, invoices, and payment status. Payment card details are collected by Polar and do not reach Wisty. Support records include your messages, attachments, and our replies.

3. Purposes and legal bases

We process personal data to provide the service, administer accounts and billing, respond to requests, prevent abuse, and maintain security and reliability. We rely on contract performance where the individual is a party to the contract, and legitimate interests in administering our business relationship where they act for a customer organisation. We retain accounting records to meet legal obligations.

Providing the service includes sending service email to workspace administrators: notice that a trial is ending or has ended, billing and security notices, and notice of changes to our terms, this policy, or our subprocessors. These emails are part of the service, so they carry no unsubscribe option. We do not track whether they are opened.

Our legitimate interests also include responding to requested waitlist invitations, handling support, preventing repeated trial claims, and measuring service use where consent is not required. Where applicable law requires consent for analytics or similar technologies, consent is the required basis. We do not sell personal data, use it for advertising, or use it to train AI models.

4. Customer data and AI processing

Customers provide instructions, files, and Salesforce metadata to generate apps. Apps read Salesforce data at runtime under the signed-in user’s permissions. The customer determines the purposes for which its apps process personal data.

Generation models receive instructions, relevant attachments, metadata, and project code. Wisty does not retrieve Salesforce records for generation context, but personal data included in chat or attachments is processed with that content. Image generation uses descriptions written by the generating AI. The security page explains the data flow.

Under the DPA, we record generation traces to investigate errors, evaluate generation quality, and improve generation. Access is restricted to authorised personnel. This content is not used to train AI models.

We may also produce aggregated, de-identified statistics about how the service is used, such as the kinds of apps customers build, and publish them. These statistics do not identify any customer, user, or individual.

5. Sharing and service providers

We use providers for hosting, authentication, analytics, and support. They process data for the purposes described in this policy under applicable contractual safeguards.

ProviderPurposeProcessing location
ClerkAccount authentication and administrationUnited States
ResendDelivery of service emailUnited States
ConvexDatabase and backend hostingUnited States
VercelWebsite and application hostingUnited States; global delivery network
CloudflarePublished-app delivery and network securityGlobal network
PostHogUsage analytics, error reporting, and support toolsEuropean Union
BraintrustAI generation tracesEuropean Union

Providers processing customer content, including AI providers, are listed in the DPA subprocessor register. A provider’s role depends on the processing it performs.

Polar Software Inc. acts as merchant of record and as a controller for payment data it collects. Its privacy policy applies to that processing. We may also disclose personal data where required by law or necessary to protect the service and its users.

6. Retention

DataRetention
Account informationFor the life of the account. Workspace deletion removes workspace membership and associated workspace data, not an account used in other workspaces.
Waitlist emailUntil you create an account or request removal, and at most 12 months after you joined.
Product analytics eventsUntil 2 years after the account's last activity. Removed in a yearly sweep.
Session replays3 months.
AI generation traces14 days. This does not delete the original project or chat.
Billing recordsFor the period required by applicable accounting law.
Support correspondenceAs needed to resolve the matter and retain a record for related follow-up or legal claims.
Service email recordsThe service emails we sent to workspace administrators and their delivery status, kept for 2 years after sending as a record that a required notice was given.
Trial-abuse recordsSalesforce org id and sign-up email, retained for 24 months after workspace deletion.

Deleting a workspace starts removal of its customer data; deleting an account starts removal of the corresponding account data. These actions do not automatically erase billing records, trial-abuse records, or telemetry retained on the schedules above. Personal-data erasure requests are assessed under applicable law.

Customer-data deletion, including backups and provider-held copies, is governed by the DPA. The security page describes the technical process.

7. Cookies and analytics

The website uses cookieless analytics without persistent browser identifiers. Page-view events are processed to produce usage statistics. The standalone builder uses authentication cookies and a browser analytics identifier. Salesforce viewer surfaces collect cookieless analytics and do not record sessions.

Builder session replays mask form inputs. The cross-origin preview is not captured, and the host’s write-approval content is excluded from capture. Other visible builder content may appear in replays. We use no advertising or cross-site tracking cookies.

8. International transfers

Wisty is established in Norway. Our providers process data in the EEA, the United States, and through global delivery networks. Where data is transferred outside the EEA, we use an applicable adequacy decision, including the EU-US Data Privacy Framework for covered recipients, or Standard Contractual Clauses with supplementary measures where required. Contact us for information about the safeguards relevant to your data.

9. Your rights

Subject to applicable law, you may request access, correction, deletion, restriction, or portability of your personal data and object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it without affecting prior lawful processing. We may need to verify your identity.

Send requests to legal@wisty.ai. We respond within one month. If an extension is permitted because of the complexity or number of requests, we will explain it within that month. For data processed on your organisation’s behalf, contact that organisation; we assist it under the DPA.

You may complain to Datatilsynet or the competent supervisory authority where you live or work.

10. Security

We use technical and organisational measures to protect personal data, including encryption and access controls. These are described on the security page.

11. Changes and contact

We will notify account holders by email or in the service before material changes take effect. The date above identifies the current version.

Wisty Labs AS, org. nr. 938 423 490, Elisenbergveien 34, 0263 Oslo, Norway. Privacy questions and requests: legal@wisty.ai.