Skip to content

Privacy Policy

Last updated: August 2026

What We Collect

  • Account info (email, display name) from Google Sign-In or email login
  • OAuth tokens for services you connect (e.g. GitHub, Google Cloud) — encrypted with AES-256-GCM at rest
  • Chat messages and task history within your workspace
  • Usage data (tasks run, credits used, features accessed)

What We Don't Collect

  • We never store your AI provider API keys — not even encrypted. BYOK (Bring Your Own Key) keys stay on your device (browser or Studio secure storage) and are sent per-request only; keys included with a request are used in memory to route the call and are never persisted or logged
  • BYOK mode: your API keys are stored only on your device (browser storage, Studio secure storage, or encrypted local config) — never on GWC servers. When you run a BYOK request through GWC Cloud, the key is transmitted with that request over TLS, used in memory to route the call to your AI provider, and never persisted or logged
  • We don't access your workspace files except when your AI team needs to
  • We don't sell or share your data with third parties
  • If you use local API key management, your keys never reach our servers at all

How We Use Your Data

  • To provide the GWC platform and process your AI requests
  • To route AI requests using your keys or credits
  • To maintain billing and subscription status
  • We do not use your data to train AI models

AI Providers

When you run an AI request, your prompt — including relevant chat history, code, and workspace file context — is transmitted to the AI provider serving that request (e.g. OpenAI, Google, Anthropic, BytePlus). If your selected model is unavailable, a failover provider processes the request instead (see the Terms of Service for the failover chain).

Requests routed through GWC Cloud run on GWC-managed provider accounts. Where a provider offers a setting to exclude API traffic from model training, we enable it; where a provider does not offer that option, its standard terms apply to the request. In BYOK mode, requests go directly to your chosen provider under your own agreement with them, and that provider's data retention and privacy policies apply.

Where your prompt is processed depends on the model you choose. Providers operate their own infrastructure in their own jurisdictions, and each applies its own retention policy to the request — which may differ from ours and may change without notice to us. In particular, models served by DeepSeek are processed on DeepSeek's infrastructure in the People's Republic of China; models served by Z.AI (Zhipu, the GLM family) are processed by Z.AI, whose operator is based in the People's Republic of China; models served by Alibaba Cloud (Qwen) are processed on Alibaba Cloud's international DashScope endpoint, operated by a company based in the People's Republic of China; models served by BytePlus are processed in Singapore; and models served by Anthropic, OpenAI, Google and xAI are processed on those providers' infrastructure under their published API terms.

If your country restricts the use of AI services processed in another region, do not use GWC allowance or USD balance routing. Get a GWC Connect Pass ($10/mo add-on that unlocks BYOK on Basic) and use BYOK instead: your requests then go directly from your own device to the provider you have chosen, under your own agreement with them, and GWC does not carry or process that traffic. Checking what your country permits is your responsibility — we do not verify the identity, nationality, or location of our users. See the Terms of Service for more.

Data Storage

Your account data, billing records and conversation history are stored in a CockroachDB cluster that GWC runs on its own servers — no managed database provider holds your data. The cluster spans four regions: Singapore (primary), Frankfurt, Seoul and New Jersey. For durability, every record is replicated to at least three of those regions, so your data is stored in the European Union, Korea and the United States as well as Singapore. Data is isolated per account: every record is scoped to your user ID and protected by authenticated access controls. Backup copies of this database are also held off-site in Cloudflare R2 object storage under GWC's own account — see Data Retention below.

Google Cloud services. Three Google services process data on GWC's behalf. Secret Manager stores the connection credentials you provide when you connect an external vault or service — these are your secrets, held encrypted and used only to make the connection you asked for. Cloud Storage holds the documents Work & Design generates for you. Gmail SMTP delivers transactional email — sign-in magic links and verification codes — which means your email address passes through Google to reach you. None of the three is used for advertising or profiling, and none receives your conversations or code.

Cloud Routing: Requests billed to your allowance or USD balance run through GWC-managed provider accounts — your own AI provider keys are never stored on our servers. OAuth tokens for connected services are encrypted with AES-256-GCM at rest.

BYOK Mode: When using BYOK (Bring Your Own Key), your API keys are stored only on your device (browser storage, Studio secure storage, or encrypted local config). GWC never persists your BYOK keys. Keys sent with a request (including live key validation) are used only in memory for that request and are never written to storage or logs.

Data Retention

Conversation content you create in the web and mobile apps is retained until you delete it. Deleting a conversation removes it from our database; deleting your account removes your data entirely, subject to the billing records below.

Database backups held on our own servers are pruned after 14 days. Backup copies in private off-site object storage under our own account are retained until we remove them. Deleted content may therefore persist in a backup after you remove it from the live service.

Billing records — token counts, cost, model and timestamp, never the content of your prompts or replies — are retained for as long as required to operate your account and meet our tax and accounting obligations.

Records from retired GWC commerce services may be retained only as needed to settle or refund historical transactions, resolve disputes, and meet legal and accounting obligations. This can include order records, messages, listing metadata, credentials, and customer deliverables. No new commerce transactions are accepted.

Retention by an AI provider is governed by that provider, not by us. Deleting content from GWC does not delete any copy the provider may hold under its own policy.

Your Rights

  • Export: download your profile, credit balance, your most recent 1,000 usage records, your project list, your saved agents and your preferences as JSON, anytime. Conversation content and project file contents are not included in the export
  • Delete: Request full account deletion — how to delete your account
  • Portability: the export is a machine-readable JSON file you can take elsewhere. We do not currently offer a code or project-file archive download
  • Files are kept for 30 days after account cancellation, then permanently deleted

Third-Party Services

GWC integrates with services you connect (Google Cloud, Stripe, GitHub, AI providers). Each service has its own privacy policy. We only share the minimum data needed for the integration to work.

Mobile Apps

The GWC AI mobile app (com.gwc.ai, iOS and Android) accesses the following device capabilities, each only for the feature named:

  • Camera & photos: only when you attach an image to a chat or capture one for a task. Attachments are treated as chat content (see "What We Collect").
  • Microphone: voice input is transcribed by your device's platform speech recognition (Apple on iOS, Google on Android), which may process the audio on that vendor's servers under its own privacy policy. GWC receives only the resulting text — raw audio is never sent to our servers.
  • Notifications: a Firebase Cloud Messaging (FCM) push token is used to deliver notifications. It is a device identifier, not location or contact data.
  • Local network: GWC Connect reaches your own computer (GWC Studio) over your local Wi-Fi / WebRTC. This uses device and network information for LAN discovery only — the app requests no GPS/location access.
  • On-device storage: session tokens and any BYOK keys are held in the platform secure store on your device, never on our servers.

Purchases and subscriptions are managed on our website; the mobile app displays usage and balance only and initiates no in-app purchases.

Contact

Questions about privacy? Email us at [email protected].

To report harmful or offensive AI output, email the same address with the subject "AI Safety".