Legal

Privacy Policy

Last updated May 2, 2026

What we collect

We collect the data you submit while using Weekwright and the metadata our infrastructure produces while operating the service:

  • Account data — email address, display name, and the password hash used by Firebase Authentication.
  • Organization data — organizations you create or join, your role within them, and your access timestamps.
  • Scheduling data — employees, positions, locations, schedules, shifts, time-off requests, swaps, compliance rules, and notes you write.
  • Operational data — audit log entries (who did what, when), notification records, AI conversation history if you use the chat, and aggregated usage metrics.
  • Billing data — handled by Stripe; we store the Stripe customer ID, plan, status, seat count, and renewal date, not card details.

How we use it

To operate the service, secure your account, bill you, surface AI features you opted into, and improve the product. We do not sell your data and do not share it with third parties for advertising.

Subprocessors

We rely on a small set of subprocessors to run Weekwright. By using the service you agree we may share the data described above with them as needed to deliver the service:

  • Google Cloud (Firebase Auth, Cloud SQL, Firestore, Cloud Run, Cloud Storage) — primary infrastructure; hosts your data at rest and in transit.
  • Vercel — application hosting (Next.js runtime); processes requests in transit but does not store your data.
  • Stripe — billing and payments; receives customer email, plan choice, and seat count.
  • Anthropic (Claude API) — used only when you invoke an AI feature on a plan that includes it; receives the context needed for that request (employees, availability, shifts, your prompt). Claude does not train its base models on this data.

Where data lives

Application data is stored in Google Cloud regions in the United States (the SQL Connect service is currently provisioned in us-east1). Stripe processes payments according to their own regional policies. Backups are encrypted and rotated.

How long we keep it

Active organization data is retained while your account is active. On account or organization deletion, data is held for 30 days for recovery and then permanently removed, except where law requires longer retention (financial records, etc.). The audit log retains entries for the period your plan specifies (90 days on FREE / Pro / AI; 7 years on Business).

Your rights

You can access, export, or delete your organization's data at any time from the dashboard or by contacting us. EU and UK users have rights under GDPR / UK GDPR (access, rectification, erasure, portability, restriction, objection); California users have rights under CCPA. To exercise any of these, contact us and we'll respond within 30 days.

Security

We use industry-standard practices: HTTPS everywhere, encrypted data at rest, scoped service-account credentials, App Check on client requests, and per-org row-level access policies enforced by Cloud SQL. We do not promise unbreakable security — no system is perfect — but we treat customer data with the seriousness it deserves and disclose breaches as required by law.

Cookies

We use essential cookies to keep you signed in (session cookie) and to remember UI preferences (locale, theme). We do not use third-party advertising cookies.

Children

Weekwright is intended for use by businesses. The service is not directed to children under 16 and we do not knowingly collect personal data from them.

Changes

We may update this policy from time to time. Material changes will be announced in-app or by email. Continued use after the effective date constitutes acceptance.

Contact

Questions about this policy or your data? Contact us.

Privacy Policy · Weekwright