Legal
Privacy Policy
Last updated: July 4, 2026
Effective date: July 4, 2026. Wyndrom (“Wyndrom,” “we,” “us”) is operated by Moamn Ali, an individual based in Egypt. This policy explains what we collect, why, and your rights. It applies to wyndrom.com and wyndrom.ai (together, the “Service”).
1. What we collect
Account information. When you sign in with Google, we receive your name, email address, and profile picture from Google. We do not receive or store your Google password.
Content you upload. The Service exists to analyze design content you provide: screenshots and images you upload for critiques, redesigns, and fidelity reviews; images you paste into chat; HTML you paste for rendering; and the text of your chat conversations. This content is stored so you can return to your library, review history, and past conversations. It remains stored until you delete it or delete your account.
Generated content. The Service stores the outputs it generates for you: critique results, redesigns, review findings, chat responses, and related metadata (scores, annotations, timestamps).
Billing information. Credit purchases are processed by Polar Software Inc. (“Polar”) as merchant of record. Polar collects and processes your payment details; we never see or store your card number. We store transaction records (what you bought, when, the amount, and Polar's order reference) to maintain your credit balance and purchase history.
Technical data. Standard server logs, error reports (via Sentry), and usage records (e.g., credits consumed per action, rate-limit counters) needed to operate, secure, and improve the Service. Error reports are configured to exclude your uploaded images, prompts, and message content.
We do not collect data for advertising. We do not sell your data.
2. How your content is processed
To provide analyses, your uploaded images and chat messages are sent to Anthropic PBC (the provider of the Claude AI models), which processes them to generate results. Anthropic acts as our processor for this purpose; their handling is governed by their commercial terms. We send only what is needed to perform the analysis you requested.
Uploaded files are stored in private cloud storage (Vercel Blob) and are accessible only through short-lived signed URLs tied to your account. Account and content records are stored in our database (hosted on Neon/PostgreSQL); balances and sessions are held in Redis (Upstash). Our infrastructure providers (Vercel, Neon, Upstash, Sentry, Anthropic, Polar) each process data only as needed to provide their function.
3. Why we process your data (legal bases)
To provide the Service you request (contract): accounts, analyses, storage, billing.
Legitimate interests: security, abuse prevention (rate limiting), error monitoring, improving the Service.
Legal obligations: transaction records retained as required by applicable law (handled primarily by Polar as merchant of record).
4. Retention and deletion
Your content (uploads, results, conversations) is retained until you delete it or delete your account.
You can delete individual designs, reviews, and conversations in the app at any time; deletion removes the associated stored files.
Account deletion: request it via support@wyndrom.com and we will delete your account and associated content within 30 days, except transaction records we or Polar must retain for legal/accounting purposes.
5. Your rights
Depending on your location, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise any of these, email support@wyndrom.com. We will respond within 30 days. You may also have the right to complain to a data-protection authority in your jurisdiction.
6. Cookies
We use only the cookies necessary to keep you signed in (authentication/session cookies). We do not use advertising or cross-site tracking cookies.
7. Children
The Service is not directed to children under 16, and we do not knowingly collect their data. If you believe a child has provided us data, contact support@wyndrom.com and we will delete it.
8. International transfers
We operate globally using infrastructure located primarily in the United States and Europe. By using the Service, you understand your data may be processed in countries other than your own.
9. Security
We use industry-standard measures: private storage with signed, expiring access URLs; encrypted connections (TLS); scoped API credentials; and webhook signature verification for billing events. No system is perfectly secure; if a breach affects your data, we will notify you as required by law.
10. Changes
We may update this policy. Material changes will be announced on the Service or by email, with the effective date updated above. Continued use after changes means you accept the updated policy.
11. Contact
support@wyndrom.com — Moamn Ali, operator of Wyndrom, Egypt.