Privacy
Privacy Policy
This Privacy Policy explains what data Woes collects, how we use and protect it, who processes it on our behalf, and the choices and rights you have.
Effective date: July 4, 2026 · Last updated: July 18, 2026
Who we are
Woes is an API-native developer support platform. It unifies live chat, email, Discord, an operator inbox, API documentation ingestion, authenticated API testing, and a grounded AI support agent. In this policy, “Woes,” “we,” “us,” and “our” refer to the Woes service, and this policy covers woes.dev, the Woes web application, the embeddable chat widget, and the Woes API.
For account and workspace administration data, Woes acts as a data controller. For the support conversations and customer data a workspace processes through Woes, we act as a processor on behalf of that workspace, which remains the controller of its end-customer data. If you are the end customer of a business that uses Woes, please direct privacy requests to that business first.
Data we collect
- Account and workspace data. Your name, email address, authentication credentials, workspace profile, team members and their roles, and billing contact details.
- Support content. Live chat, email, and Discord messages, issue records, internal notes, tags, attachments, and the troubleshooting details customers provide across channels.
- Customer and visitor data. When someone contacts a workspace through the chat widget or another channel, we process their messages and any identity they provide, plus technical data such as IP address, derived geolocation (approximate country and region), browser user agent, referrer, and page context. We keep raw technical signals for security and operations and surface only derived, coarse geolocation in workspace-facing analytics.
- API context. The documentation, schemas, examples, endpoint paths, authentication descriptions, and request and response shapes a workspace ingests to ground the support agent.
- API credentials. Credentials a workspace adds for authenticated API testing. These are stored separately from source content, encrypted at rest, and redacted before any model call.
- Bring-your-own-AI keys.If a workspace connects its own AI provider key, that key is stored encrypted and used only for that workspace’s selected AI processing path.
- Usage, billing, and analytics. Plan and seat counts, AI resolution and API-call usage, product analytics, error diagnostics, and billing metadata. Card and payment details are handled by our payment processor; Woes does not store full card numbers.
- Survey responses. CSAT and NPS ratings and comments submitted by customers.
- Cookies and similar technologies. Essential session and authentication cookies, and privacy-conscious product analytics.
How we use data
- Operate, maintain, and secure the Woes platform.
- Route, answer, and resolve support conversations across channels.
- Ground the AI support agent in workspace-scoped API context and recent conversation history.
- Run authenticated API tests a workspace configures.
- Process subscriptions, metered usage, and billing.
- Measure performance, diagnose errors, and improve reliability and product quality.
- Detect, prevent, and respond to abuse, fraud, and security incidents.
- Communicate service, security, and account notices.
- Comply with legal obligations and enforce our terms.
AI processing
The Woes agent answers from workspace-scoped API evidence, recent conversation context, and safe verification results. To generate responses, workspace content may be processed by our AI sub-processors (Anthropic, OpenAI, and Google). API credentials are redacted before model calls. When bring-your-own-AI is enabled and Woes can safely resolve the configured credential, answer generation uses that credential. If the credential cannot be resolved or the selected service fails, Woes does not silently reroute the answer through a different platform provider; it asks for a retry or hands the conversation to an operator instead. Retrieval and indexing may still use a Woes platform AI sub-processor. Woes does not use your workspace content to train its own models, and we send content to AI providers only to provide the Service for your workspace.
How we share data
Woes does not sell your personal data and does not share it for cross-context behavioral advertising. We share data only with the service providers that host and power Woes (our sub-processors, listed below), with integrations you explicitly connect, and where required by law or to protect the safety, rights, and security of Woes, our customers, and the public.
When you connect an integration such as Discord, Slack, Jira, GitHub, HubSpot, or Linear, data is exchanged with that third party at your direction and under its terms and privacy policy.
Sub-processors
We use the following sub-processors to provide the service. Each processes data only as needed to perform its function.
- Supabase— database, authentication, and file storage for workspace data.
- Vercel— application hosting and product analytics.
- Stripe— subscription billing and payment processing.
- Resend— transactional and support email delivery and inbound email routing.
- Sentry— error monitoring and diagnostics.
- Anthropic, OpenAI, and Google— AI model processing for the support agent.
Integrations a workspace chooses to connect (Discord, Slack, Jira, GitHub, HubSpot, and Linear) act as additional third parties under your control.
Data retention
We retain workspace data for as long as the workspace is active and as needed to provide the service. When you delete content or close an account, we delete or anonymize the associated data within a commercially reasonable period, except where we must retain limited records to meet legal, tax, accounting, or security obligations. Residual copies may persist briefly in encrypted backups before they cycle out.
Security
Woes encrypts data in transit and at rest, stores API credentials and bring-your-own-AI keys encrypted and separated from source content, redacts secrets before model calls, and enforces tenant isolation so each workspace can access only its own records. Access is role-scoped, rate limits guard public surfaces, and administrative actions are audited. See the Trust overview for more detail.
International data transfers
Woes and its sub-processors may process data in the United States and other countries. Where data is transferred across borders, we rely on appropriate safeguards and require our sub-processors to protect it consistent with this policy.
Your rights and choices
Depending on where you live, you may have the right to access, correct, delete, export, or restrict the processing of your personal data, and to object to certain processing or withdraw consent. If you are in the European Economic Area or the United Kingdom, these rights arise under the GDPR; if you are a California resident, they arise under the CCPA and CPRA. Woes does not sell or share personal data for cross-context behavioral advertising.
To exercise a right for your Woes account, contact us at the address below. If your data was submitted to a workspace as its end customer, that workspace is the controller, and we will assist it in responding to your request.
Children
Woes is a business tool that is not directed to children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.
Changes to this policy
We may update this policy as the product and our practices evolve. When we do, we will revise the effective date above, and we will provide additional notice for material changes.
Contact
Privacy questions can be sent to support@woes.dev. Product and early-access questions can be sent to hello@woes.dev. See also our Terms of Service and Trust overview.