Privacy policy
The plain-English version of what we collect, why, who touches it, and what you can do about it. It is written to be read, and no claim here goes further than the code does. Effective 11 July 2026.
Who we are
Withose is operated from the United Kingdom and is the data controller for the personal data described on this page. You can reach us about anything here at hello@withose.com.
What we collect
Your account: the email address you sign in with, and a display name if you set one. Your workspace: its name, members, and connection status for Slack or Microsoft Teams. Captured conversations: the specific messages a member of your team explicitly selects and submits, which are encrypted at rest with your workspace's own key (see our security page). Stakeholders: the names and email addresses of people you invite to weigh in on a decision, who do not need an account. Billing: handled by Stripe; we store your plan and subscription status but never your card details. Product usage: first-party event records such as “a decision was drafted”, used to understand how the product is used, plus anonymous page-view counts on our public marketing pages (the page visited and which site referred you; no IP address, no identifier, no profile). We run no advertising trackers and use no third-party analytics services.
What we deliberately do not collect
Withose has no access to your chat platform's full message history and does not subscribe to its event stream. Messages reach us only when someone on your team explicitly captures them, having reviewed exactly what was selected first. We do not buy data about you, enrich your profile from third parties, or track you across other websites.
How we use your data
To run the product: drafting decision cards, gathering stakeholder positions, producing syntheses, and keeping your archive searchable. To send the emails the product needs: sign-in links, invitations, decision notifications, billing notices, and a small number of onboarding emails from the founder. To operate billing through Stripe. To understand product usage through our own first-party events. Our legal bases under UK GDPR are performance of a contract (running the service you signed up for), legitimate interests (product analytics, service emails), and consent where we ask for it specifically.
AI processing
Drafting and synthesis send the messages you explicitly captured to Anthropic's Claude API over TLS. Anthropic does not use API data to train its models by default, and we operate no training pipeline of our own on your content. AI processing happens per request, on the content you chose, and nothing more.
Who processes data on our behalf
Vercel (application hosting), Turso (database), Anthropic (AI processing described above), Stripe (payments), and Resend (email delivery). If you connect Slack or Microsoft Teams, those platforms process data under their own terms and your organisation's agreements with them. Some of these providers are based in the United States; where personal data leaves the UK we rely on appropriate safeguards such as standard contractual clauses.
How long we keep it
For as long as your workspace exists. Deleting a workspace destroys its encryption key, which makes the captured content cryptographically unrecoverable, including in older backups. In-progress capture drafts are purged automatically after 48 hours. Account and billing records are kept only as long as needed for the service and our legal obligations.
Cookies
One essential cookie: the session cookie that keeps you signed in. No advertising cookies, no cross-site tracking, no third-party analytics scripts.
Your rights
Under UK GDPR you can ask for access to your personal data, correction, deletion, restriction of processing, portability, or object to processing based on legitimate interests. Email hello@withose.com and a person will handle it. You also have the right to complain to the Information Commissioner's Office (ico.org.uk) if you think we have handled your data badly.
Children
Withose is a workplace product and is not directed at anyone under 16.
Changes
If this policy changes in a way that matters, we will say so plainly: a notice in the product or an email, not a silent edit. This version is effective 11 July 2026.
See also our security page for how captured content is encrypted, and our terms of service.
