Privacy Policy
Last updated: 2026-08-06
1. Who we are
WidgetAI (the "Service") is operated by Quassum MB, registered in Lithuania, with a registered address at Vilnius, Lithuania. We are the data controller for personal data processed via the WidgetAI website, web application, API, and iOS application. Contact our privacy contact at [email protected].
2. Scope
This policy covers the WidgetAI marketing website, the WidgetAI web application, our API, and the WidgetAI iOS application (together, the "Service"). Where a section applies only to one of these, we say so.
Privacy at a glance
- Your sensitive device data stays on your device. Apple Health, photos, photo metadata, calendar events, reminders, and currently playing Apple Music information are read locally to render your widgets. We do not upload this data to our servers, analytics services, or AI providers.
- The iOS app contains no advertising or advertising tracking. It does not request App Tracking Transparency permission, collect the advertising identifier (IDFA), or share advertising-conversion events with Meta or Google.
- We store what the Service needs to work. This includes your account, widget documents and revision history, AI editor conversations, subscription state, API connector configurations, and—only if you enable location—an approximate location for location-aware widgets.
- AI editing is optional and user-initiated. When you ask the AI editor to create or change a widget, the prompt, relevant chat history, and widget document are sent to our model providers. The app does not automatically include on-device data values.
- We do not sell personal data. We use the limited service providers described below for hosting, AI generation, authentication, billing, email, product analytics, and app diagnostics.
3. Data we collect
When you create and use an account
- Account data: name, email address, email verification status, and an optional profile image. If you sign up with a password, we store it only in hashed form. If you sign in with Google or Apple, we receive your name, email, and profile image from that provider and store the linked-account reference and its sign-in tokens.
- Session and security data: IP address and browser/device User-Agent of each session, session tokens, and session expiry times.
- Your content: the widgets you create (their full document structure and revision history), your AI chat messages with the editor (prompts, responses, and the edits they produce), and any widgets you publish to or install from the marketplace.
- AI usage data: token counts per AI message and a per-month count of AI edits, used to enforce plan quotas.
- First-party product analytics: a limited, allowlisted set of events—such as completing onboarding, opening the app, viewing a paywall, or completing a purchase—is sent to our API. An event may include your user ID when signed in, or an app-install/device identifier when signed out, together with its timestamp, platform, app version, and limited event properties. We use this data for aggregate product and reliability reporting.
- Product usage analytics (Mixpanel): pseudonymous product analytics via Mixpanel, hosted on Mixpanel's EU servers. Events are tied to your internal user ID—never your name or email. Our iOS app sends events that include your plan tier, which device permissions you have enabled or requested, and device metadata such as device model, OS version, and app version. Permission flags indicate only whether access is enabled or requested; they never contain Health, photo, calendar, reminder, location, or music content. Our servers may also send events about how you use the Service—for example, when you create a widget, together with attributes such as its creation source, size, and internal widget identifier.
- Firebase Crashlytics (iOS): if the app crashes, Google's Firebase Crashlytics sends us crash reports and diagnostic data — stack traces, device model and OS version, and app state at the time of the crash — so we can diagnose and fix stability problems.
- Firebase Performance Monitoring (iOS): Google's Firebase Performance Monitoring collects app and network performance metrics, such as startup time, screen rendering, and network request timing and success rates, so we can measure and improve performance.
- API connector credentials: if you configure a connector to a third-party API, we store the API keys or secrets you provide. These are encrypted at the application level (AES-256-GCM) before storage and are used only to fetch the data you configured. API connectors are separate from the on-device Apple data sources described below.
- Subscription data: your plan tier, subscription status, billing period end, and customer/subscription identifiers from our payment providers. We never receive or store full payment card numbers — payment details are handled by Polar (web purchases) or Apple (iOS in-app purchases).
- Location (optional, iOS only): if you grant the iOS location permission, the app uploads an approximate (city-level, roughly 1 km accuracy) latitude/longitude, a reverse-geocoded place name, and your timezone, captured only while the app is in use. This powers location-aware widgets such as weather. You can disable this at any time in iOS Settings; we then stop receiving updates, and you can ask us to delete the stored value.
Processed on your device only (never sent to our servers)
- Apple Health: with your permission, the app reads step count, active energy, exercise time, stand hours and activity goals, sleep analysis, heart rate, and resting heart rate. It stores only a small current summary in the app's local shared container so your widgets can display it. Health values are never uploaded, included in analytics, sent to AI providers, or used for advertising.
- Photos: photos you select for photo widgets and their associated date, location, country, and camera metadata are copied into the app's local shared container and read by your widgets on-device.
- Calendar and reminders: widgets that display calendar events or reminders read them locally on your device.
- Apple Music: the currently playing song information used by music widgets is read locally on your device.
Widget documents may contain instructions such as “show today's steps” or “show my next event,” but they do not contain the underlying Health value, photo, event, reminder, or song. We do not receive the contents of these on-device data sources.
When you use the marketing website
- Waitlist sign-ups: email address, source / referrer (if provided), the timestamp of your consent to our terms and privacy policy, IP address and User-Agent of the request, and any subsequent confirmation or unsubscribe timestamps.
- Contact form submissions: the email address and message body you provide.
- Anonymous site analytics: aggregated page views, referrer, country, browser version, and Web Vitals timings via self-hosted Umami. No cookies, no cross-site identifiers.
- Google Analytics & Google Ads (Consent Mode v2): we use Google Analytics 4 and Google Ads via Google's gtag.js with Consent Mode v2. Consent defaults to denied, so no cookies (
_ga,_gid,_gcl_*,_gac_*) are set and no identifiers are stored; until you opt in, Google receives only aggregated, cookieless signals. When you accept analytics and/or advertising cookies we signal consent so the relevant cookies are set and event data (such as page views and sign-ups) is shared with Google. If you submit an email form after accepting advertising cookies, your normalized email is hashed before transmission to Google for enhanced conversion measurement — see our Cookies page.
4. AI processing
When you use the AI editor, your prompt, the relevant chat history, and the widget document being edited are sent to our model providers — Anthropic and/or OpenAI — to generate the response. The app does not automatically include values read from Apple Health, photos, calendar, reminders, or Apple Music. Under these providers' API terms, data submitted via their APIs is not used to train their models. To operate and debug the AI features we may also record traces of model calls (prompts, responses, model, token counts, latency, and your user identifier) in our LLM observability tooling (Langfuse); these traces are subject to the same protections and retention rules as the rest of your account data.
5. Purposes and legal bases (GDPR Art. 6)
- Providing the Service — operating your account, storing and syncing your widgets and chats, processing AI editing requests, marketplace publishing/installs, connectors, and managing your subscription: Art. 6(1)(b) — performance of a contract.
- Location-aware widgets — processing the approximate location you choose to share: Art. 6(1)(a) — consent, given via the iOS permission prompt and withdrawable at any time in iOS Settings.
- Security and abuse prevention — storing IP addresses and User-Agents of sessions and sign-up requests, rate limiting, and fraud detection: Art. 6(1)(f) — legitimate interests. We have balanced this against your rights and concluded the processing is proportionate; you may object at any time.
- Billing and accounting records — Art. 6(1)(c) — legal obligation (tax and accounting law) and Art. 6(1)(b).
- Waitlist and marketing communications — Art. 6(1)(a) — consent. You can withdraw at any time via the unsubscribe link in every email or by emailing our privacy contact.
- Product analytics — aggregated, cookieless site analytics (Umami), limited first-party app events, and pseudonymous product analytics (Mixpanel, EU-hosted, from our iOS app and our servers, no name or email): Art. 6(1)(f) — legitimate interests in measuring and improving the Service. You may object at any time.
- App stability and performance (iOS) — crash reports and diagnostic data (Firebase Crashlytics) and app and network performance metrics (Firebase Performance Monitoring): Art. 6(1)(f) — legitimate interests in diagnosing problems and keeping the Service stable and performant. You may object at any time.
- Website analytics and advertising cookies (Google Analytics and Google Ads) — Art. 6(1)(a) — consent. Your consent governs cookie storage under Consent Mode v2; until you consent only aggregated, cookieless signals are sent. You can withdraw consent at any time via the Cookie settings link.
6. Recipients and processors
We share personal data with the following categories of recipients, only to the extent needed for the purposes above:
- Anthropic (AI model provider) — US; receives AI prompts, chat history, and widget documents when you use AI features; API data is not used for model training.
- OpenAI (AI model provider) — US; same scope as Anthropic.
- Langfuse (LLM observability) — EU; receives traces of AI model calls.
- Resend (email delivery) — EU/US; receives recipient email addresses and email content.
- Polar (payment processing for web purchases, acting as merchant of record) — EU/US; receives your email and subscription details and processes your payment.
- Apple (App Store and in-app purchases; Sign in with Apple) — under Apple's own terms and privacy policy.
- RevenueCat (in-app purchase infrastructure) — US; receives your user identifier and subscription entitlement state.
- Mixpanel (product analytics) — EU data residency; receives an internal user identifier and product-usage events. From our iOS app: plan tier, device-permission flags, and device metadata. From our servers: events about your use of the Service, such as widget creation, with limited attributes such as creation source and size. It does not receive your name, email, or the contents of on-device Apple data sources.
- Google (Sign in with Google; website Google Analytics 4 and Google Ads; iOS Firebase diagnostics) — sign-in operates under Google's terms; the website analytics/ads tags operate under Consent Mode v2 and receive aggregated, cookieless signals by default and, once you consent, cookie-based analytics or advertising events. In the iOS app, Firebase Crashlytics receives crash reports and diagnostic data, while Firebase Performance Monitoring receives app and network performance metrics. The iOS app does not include Firebase Analytics or Google advertising-conversion measurement.
- Vercel (web hosting) — EU/US.
- Railway (API, background-job, and database hosting) — US; hosts our application database.
- Self-hosted Umami analytics — runs on our infrastructure; no third party receives identifiable data.
We do not sell personal data.
7. International transfers
Where personal data is transferred outside the EEA/UK, we rely on adequacy decisions (including the EU-US Data Privacy Framework, where the recipient is certified) and/or the Standard Contractual Clauses incorporated into the recipient's standard service terms.
8. Retention
- Account data and your content (widgets, revisions, AI chats, connectors, subscription state, location): for the life of your account. When you request deletion, your account enters a 30-day grace period during which you can cancel the request; after it elapses, your account and all associated data are permanently deleted.
- Sessions: expire after 30 days.
- Email verification tokens: 24 hours.
- Billing and accounting records: retained for the period required by applicable tax and accounting law, even after account deletion.
- Waitlist data: retained until the iOS app launches plus twelve (12) months, after which it is deleted unless you have converted to a customer account. You may request earlier deletion at any time.
- Contact form messages: retained as long as needed to handle your enquiry.
9. Your rights (GDPR Art. 15–22)
You have the right to access, rectify, erase, restrict, port, and object to processing of your personal data, and to withdraw consent at any time without affecting prior processing.
- Export: you can export a machine-readable copy of your account data directly from account settings.
- Deletion: you can request account deletion directly from account settings; deletion completes after a 30-day grace period during which you may cancel.
- Everything else: email [email protected]. We respond within one month.
10. Security
We operate an information security program aligned with the SOC 2 Trust Services Criteria and the control objectives of ISO/IEC 27001. Measures include: encryption in transit (TLS) for all traffic; encryption at rest for stored data; additional application-level AES-256-GCM encryption for stored connector credentials; password hashing; HttpOnly, Secure session cookies; least-privilege access controls and logical separation of customer data; rate limiting and abuse detection; and review of the subprocessors listed above. This section describes our practices and is not a representation that we hold any particular certification or attestation; where we obtain formal certifications, we will make them available on request. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
11. Right to lodge a complaint
You may lodge a complaint with the supervisory authority in your Member State of habitual residence, place of work, or place of the alleged infringement. Our lead supervisory authority is the Lithuanian State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija).
12. Children
The Service is not intended for children under 16, and we do not knowingly collect personal data from them.
13. Automated decision-making
We do not make automated decisions that produce legal or similarly significant effects about you. AI features generate content at your request and do not evaluate you. Where you consent to Google advertising cookies on our website, Google may use the resulting data for advertising under its own policies; you can withdraw consent at any time via the Cookie settings link.
14. Changes to this policy
We will update the "Last updated" date above when we make material changes. If changes affect your rights we will notify you by email or in-app notice.