Skip to content

Privacy Policy

Last updated: July 2026

What We Collect

  • Account info (email, display name) from Google Sign-In or email login
  • OAuth tokens for services you connect (e.g. GitHub, Google Cloud) — encrypted with AES-256-GCM at rest. If you sell on the API Marketplace, the upstream API credential you attach to a listing is also stored AES-256-GCM encrypted
  • Chat messages and task history within your workspace
  • Usage data (tasks run, credits used, features accessed)

What We Don't Collect

  • We never store your AI provider API keys — not even encrypted. BYOK keys stay on your device (browser or Studio secure storage) and are sent per-request only; keys included with a request are used in memory to route the call and are never persisted or logged
  • BYOK (Bring Your Own Key) mode: your API keys are stored only on your device (browser storage, Studio secure storage, or encrypted local config) — never on GWC servers. When you run a BYOK request through GWC Cloud, the key is transmitted with that request over TLS, used in memory to route the call to your AI provider, and never persisted or logged
  • We don't access your workspace files except when your AI team needs to
  • We don't sell or share your data with third parties
  • If you use local API key management, your keys never reach our servers at all

How We Use Your Data

  • To provide the GWC platform and process your AI requests
  • To route AI requests using your keys or credits
  • To maintain billing and subscription status
  • We do not use your data to train AI models

AI Providers

When you run an AI request, your prompt — including relevant chat history, code, and workspace file context — is transmitted to the AI provider serving that request (e.g. OpenAI, Google, Anthropic, BytePlus). If your selected model is unavailable, a failover provider processes the request instead (see the Terms of Service for the failover chain).

Requests routed through GWC Cloud run on GWC-managed provider accounts configured not to train on your data. In BYOK mode, requests go directly to your chosen provider under your own agreement with them, and that provider's data retention and privacy policies apply.

Data Storage

All data is stored on secure PostgreSQL databases in the regions where GWC operates: Singapore (primary), the European Union, South Korea, and the United States. Data is isolated per account: every record is scoped to your user ID and protected by authenticated access controls.

Cloud Routing: Requests billed to your allowance or USD balance run through GWC-managed provider accounts — your own AI provider keys are never stored on our servers. OAuth tokens for connected services and API Marketplace listing credentials are encrypted with AES-256-GCM at rest.

BYOK Mode: When using BYOK (Bring Your Own Key), your API keys are stored only on your device (browser storage, Studio secure storage, or encrypted local config). GWC never persists your BYOK keys. Keys sent with a request (including live key validation) are used only in memory for that request and are never written to storage or logs.

Your Rights

  • Export: Download all your data anytime
  • Delete: Request full account deletion
  • Portability: Download your code and project files as ZIP
  • Files are kept for 30 days after account cancellation, then permanently deleted

Third-Party Services

GWC integrates with services you connect (Google Cloud, Stripe, GitHub, AI providers). Each service has its own privacy policy. We only share the minimum data needed for the integration to work.

Mobile Apps

The GWC AI mobile app (com.gwc.ai, iOS and Android) accesses the following device capabilities, each only for the feature named:

  • Camera & photos: only when you attach an image to a chat or capture one for a task. Attachments are treated as chat content (see "What We Collect").
  • Microphone: voice input is transcribed by the device's on-device speech recognition; only the resulting text is sent to our servers — raw audio is never transmitted.
  • Notifications: a Firebase Cloud Messaging (FCM) push token is used to deliver notifications. It is a device identifier, not location or contact data.
  • Local network: GWC Connect reaches your own computer (GWC Studio) over your local Wi-Fi / WebRTC. This uses device and network information for LAN discovery only — the app requests no GPS/location access.
  • On-device storage: session tokens and any BYOK keys are held in the platform secure store on your device, never on our servers.

Purchases and subscriptions are managed on our website; the mobile app displays usage and balance only and initiates no in-app purchases.

Contact

Questions about privacy? Email us at [email protected].

To report harmful or offensive AI output, email the same address with the subject "AI Safety".