What we collect, and what we never do with it.
We collect what's needed to run the product, nothing more. We don't sell your data and we don't run third-party advertising trackers.
§ 1Data we collect
- Account data — email address and authentication identifiers.
- Subscription data — plan, status, and billing metadata (card details are held by our payment processor, not by us).
- Product data — saved claims, follows, and reading history used to power your dashboard.
- Technical data — IP address, device/browser type, and basic request logs for security and reliability.
§ 2Lawful basis for processing (GDPR)
For users in the EEA/UK, we process account and subscription data to perform our contract with you; product and technical data on the basis of our legitimate interest in operating and securing the service; and any marketing email on the basis of your consent, which you can withdraw at any time.
§ 3Third-party processors
We share data only with the processors needed to run Whalespan, each under a data-processing agreement:
- Supabase — application database and authentication.
- Stripe — subscription billing and payment processing.
- Inngest — background job orchestration for the audit pipeline.
- OpenAI / Anthropic — language-model inference for claim extraction and analysis (no training on your data).
- Semantic Scholar — academic literature lookup. We send query text, not personal data.
§ 4Retention
We keep account and subscription data for as long as your account is active and for up to 24 months afterward to meet tax and legal obligations. Request logs are retained for 90 days. When you delete your account, we delete or anonymize your personal data within 30 days, except where retention is legally required.
§ 5Your rights
You can access, correct, export, or delete your personal data, and object to or restrict certain processing. Email privacy@whalespan.com and we will respond within 30 days. You may also lodge a complaint with your local data-protection authority.
§ 6Cookies
We use strictly-necessary cookies for authentication and session security, and a minimal first-party analytics cookie to understand aggregate usage. We do not use third-party advertising or cross-site tracking cookies.
§ 7California privacy rights (CCPA)
We do not sell or share your personal information as those terms are defined under the CCPA, and we have not done so in the preceding twelve months. California residents may exercise their rights to know, delete, and correct by contacting privacy@whalespan.com. We will not discriminate against you for exercising these rights.
§ 8Contact
For any privacy request or question, write to privacy@whalespan.com. Whalespan is operated from the United States.