Privacy Policy
WeEngage
Operated by InsightEQ Solutions LLC
Effective Date: August 26, 2026
Last Updated: September 11, 2026
Latest change (September 11, 2026): New feature. You can now rate a help-chat reply with a thumbs up or down. If you do, we store that one rated exchange — the question you asked, the reply, your rating, and any comment you add — so we can find and fix wrong answers (Section 3.3). The rest of the conversation is still not stored on our servers. Nothing changed about what data we collect elsewhere, how it is processed, or your rights.
Earlier change (September 11, 2026): Accuracy update. Session records are printed or saved as PDF from the session view in the app; the earlier references to downloading an HTML or JSON export (Sections 3.1, 4.1, 8.4 and 10.3) described a button that was removed on August 26, 2026. Nothing changed about what data we collect, how it is processed, or your rights.
Earlier change (September 10, 2026): Added Section 3.3 describing the new in-app help chat: what is sent to Anthropic's Claude API when you use it (your chat messages, the page you are on, and — if signed in — your plan tier, nothing else), that conversations are not stored on our servers, and that choosing Email support emails the conversation to us. Section 6.3 updated to match, and the former Section 3.3 (Service Improvement) is now 3.4. Nothing changed about what data we collect elsewhere, how it is processed, or your rights.
Earlier change (September 6, 2026): Section 6.2 now names the specific hosting location (Railway's US West region, California). Also added Section 6.6 describing what is (and is not) shared with Zoom when WeEngage is installed from the Zoom App Marketplace, and what happens when the app is removed. Also corrected the numbering of the Vercel section (now 6.5). Nothing changed about what data we collect, how it is processed, or your rights.
Earlier change (September 5, 2026): Accuracy update. Added Section 6.4 disclosing Stripe as the third-party processor for Pro subscription payments — this was already how billing worked, just not previously named here. Nothing changed about what data we collect, how it is processed, or your rights.
Earlier change (September 2, 2026): Accuracy update. If a free trial ends without ever converting to a paying Pro subscription, sessions from that trial are now retained for 7 days from the trial's end date instead of the previous 365-day window (Section 5.2) — this does not affect a genuine Pro subscriber who later cancels.
Earlier change (August 31, 2026): New feature. When you end a session, you now choose whether to save it or delete it immediately, instead of it being saved automatically (Section 5.1).
Earlier change (August 31, 2026): Accuracy corrections. Corrected the account-deletion process (Section 5.4) to describe the actual self-service flow, replaced outdated PDF-export and "coming soon" JSON-export language (Sections 3, 8.4) with what the app actually offers today, corrected the sign-in token's expiry from a 30-day inactivity window to a fixed 7 days (Section 9.1), and updated the recovery-code claims (Sections 2, 7.3) — codes are now stored as one-way hashes rather than the encrypted-but-in-practice-plaintext claim previously here. Removed a stray second line under the postal address in Section 15 that read as an unrelated second location.
Latest change (August 30, 2026): Accuracy corrections. We clarified that WeEngage uses no cookies — a single sign-in token is kept in your browser's local storage to keep you logged in (Section 9). We removed an outdated statement that sessions auto-close after 2 hours of inactivity; a session now stays open until the facilitator ends it (Section 5.1). We also aligned plan names with the app ("Pro" rather than "Premium"). Nothing changed about what data we collect, how it is processed, who can access it, or your rights.
1. Introduction
WeEngage is a real-time group facilitation and insights tool designed to help facilitators gather participant responses, generate AI-powered insights, and keep a printable record of each session.
This Privacy Policy explains:
- What data we collect
- How we use it (including AI processing)
- Who has access to it
- How long we keep it
- Your rights and choices
Scope: This policy applies to all users of WeEngage, whether you're using the app as a facilitator (creating sessions) or as a participant (joining sessions). It covers all personal data we collect and process.
2. Data We Collect
2.1 Facilitator Data (Account Owners)
When you create a WeEngage account, we collect:
- Authentication data: Email address (primary and backup for recovery)
- Profile information: First name, last name, role, industry, organization name, job title, location (country-state)
- Optional: Profile picture (base64 encoded, max 2MB)
- Account recovery: One-time recovery codes (10 codes; only a one-way cryptographic hash of each code is stored, never the code itself — shown to you once, at generation)
Why: To create and secure your account, help you recover access, and improve the service.
2.2 Session Data (Facilitator-Created)
When you create a session, we collect:
- Session metadata: Session name, session type (e.g., Strategy, Brainstorm), meeting context (facilitator-provided description)
- Session settings: Whether anonymity is enabled, whether AI insights are enabled, participant access codes/tokens
- Timestamps: When the session was created, when it was closed
Why: To organize your sessions, control access, and apply retention rules based on session age and tier.
2.3 Participant Response Data
When participants join your session and submit responses, we collect:
- Response content: The text or data they submit to questions
- Participant identity (optional): Name only if provided and not submitted anonymously
- Response metadata: Whether the response was submitted anonymously, when it was created
- Session linkage: Which session and question the response belongs to
Important: Participants do not need an account. We collect no persistent identity data about participants across sessions.
2.4 Brainstorm-Specific Data
For brainstorm questions, we additionally collect:
- Ideas: The text of ideas submitted
- Clusters: AI-generated or manually-created groupings of ideas and their labels
- Insights: AI-generated themes, tensions, and takeaways derived from clustered ideas
2.5 Login & Authentication Data
For account access, we collect:
- Login codes: 6-digit codes sent to your email (valid for 15 minutes)
- Session tokens: Cryptographic tokens to keep you logged in
- Access logs: Basic application logs (timestamps, error messages)
Third-party: Login codes are sent via SendGrid, our email delivery partner. See Section 6.1.
3. How We Use Your Data
3.1 Session Management & Facilitation
We use your data to:
- Store and retrieve sessions
- Show/hide responses based on your reveal settings
- Control participant access via session codes or tokens
- Print any session’s record, or save it as a PDF, from the session view in the app (open it from Previous Sessions and choose Print Session)
3.2 AI Insights (Claude API)
If you generate AI insights in a session:
We send to Claude (Anthropic's AI model):
- Participant responses (text only)
- Question text
- Session type and context (e.g., "Strategy session")
- Participant names only if responses were not submitted anonymously
We do NOT send:
- Facilitator account details or recovery codes
- Participant IP addresses or session access logs
- Your profile picture or personal metadata
What Claude does:
- Processes the data to generate themes, tensions, insights, follow-up questions
- Returns the insights to us
- Does not train Claude models on your data (per Anthropic's standard API terms)
Important: Claude may briefly retain data for abuse detection/safety monitoring per Anthropic's privacy practices. See Section 6.3.
Your control:
- You can disable AI insights entirely (toggle off when creating a session)
- If you don't generate insights, responses are never sent to Claude
- If you leave the meeting context blank and don't use AI insights, minimal context is sent
3.3 Help Chat (Support Assistant, Claude API)
The Help button on our public pages, the sign-in screen, and the dashboard opens an automated assistant that answers questions from the published User Guide.
If you use the help chat, we send to Claude (Anthropic's AI model):
- The messages you type into the chat, and the assistant's earlier replies in that conversation
- Which page you are on (e.g. "pricing")
- If you are signed in, your plan tier only (Free, Trial, Pro, or complimentary)
We do NOT send:
- Your name, email address, or any other account detail
- Any session, response, participant, or billing data
- Anything at all if you never open the chat
The assistant has no access to our database or to any account. It cannot look up, change, or delete anything; it can only write a reply.
Storage: We do not store help-chat conversations on our servers. The conversation is kept in your browser tab only and is gone when the tab closes. We keep short-lived, per-visitor counters (by account, or by IP address if you are not signed in) purely to limit misuse; they contain no message text and expire within a day. If you choose Email support inside the chat, the conversation and the email address you give (or your account email, if signed in) are emailed to our support inbox so a person can reply — that email is retained like any other support correspondence.
Ratings: Each reply has a thumbs-up / thumbs-down control. If you use it, we store that one exchange — the question you asked, the reply you rated, your rating, any comment you add, the page you were on, and, if you are signed in, your account identifier and plan tier — so we can review and correct wrong answers. Nothing else from the conversation is stored, and nothing is stored if you never rate a reply. Your IP address is not stored with a rating (a one-way hash of the visitor counter key is kept only so that changing your rating updates the same record). Ratings are retained until we delete them and are covered by the account-deletion and erasure rights in Sections 5.4 and 8.3 when tied to an account.
Model training: As with AI insights, your messages are not used to train Claude models (per Anthropic's standard API terms). See Section 6.3.
3.4 Service Improvement
We may use aggregated, anonymized data to:
- Understand how the app is used
- Identify bugs or performance issues
- Improve features
We do not: Profile individuals, make automated decisions about users, or use data for purposes other than operating WeEngage.
4. Who Has Access to Your Data
4.1 You (Facilitator)
- Full access to your account, sessions, and all responses
- Can print or save session records and share them with others (your responsibility)
- Can view AI insights and their session's own response statistics (e.g. how many participants answered each question)
4.2 Session Participants
- See only responses that you (the facilitator) have revealed
- Cannot see unrevealed responses
- Do not have persistent access (no account means no login)
4.3 Third-Party Service Providers
See Section 6: Third-Party Processors.
4.4 We Do NOT Share or Sell Data
- We do not sell, license, or share your data with third parties for marketing, profiling, or research
- We do not use participant responses for any purpose other than the session context
- We do not disclose data to competitors, advertisers, or data brokers
5. Data Retention & Deletion
5.1 Active Sessions
Sessions remain in our system and visible to you while status = active. A session stays active until you (the facilitator) end it — it does not close automatically after a period of inactivity. As a housekeeping measure, a session that has been completely untouched for 30 days is closed by an automated cleanup.
When you end a session, you choose what happens to it: Save & End Session keeps its responses and insights under the retention window in Section 5.2 below, or End Without Saving deletes them immediately — the same effect as the manual deletion described in Section 5.3, just applied the moment the session ends rather than afterward from "Previous Sessions."
5.2 Closed Sessions (Retention Windows)
Free Plan:
- Sessions visible in "Previous Sessions" for 7 days after closure
- After 7 days: soft-deleted (hidden from your view)
- Remain in database for 90 days (audit trail)
- Hard-deleted (permanently removed) after 90 days
Pro Plan:
- Sessions visible in "Previous Sessions" for 365 days after closure
- After 365 days: soft-deleted
- Remain in database for 90 days
- Hard-deleted after 90 days
Free trial that ends without upgrading: The 365-day window above applies to sessions created while you were on an active trial. But if your trial ends and you never become a paying Pro subscriber, that window is shortened: sessions from that trial are instead retained for 7 days from the date your trial ends, not the original 365. This does not apply if you have ever actually paid for Pro — if you upgrade and later cancel, sessions you created while on Pro keep the full 365-day window above. If this shortened window applies to your account, you will see a notice in the app showing how many days remain, and a note in your trial-ended email.
5.3 Manual Deletion
You can manually delete sessions anytime from "Previous Sessions":
- Sets
deleted_at = now(soft-delete, hidden from your view) - 90-day audit period applies
- After 90 days: permanent hard-delete
Important: Deleted sessions cannot be recovered after 90 days. You will see a notification in your profile when a session is about to expire.
5.4 Account Deletion
You can delete your own account anytime, self-service, from your profile settings — no need to contact us. Upon deletion:
- Your account data (name, email, profile) is deleted
- Sessions you owned remain in the system but become orphaned immediately — they stay intact and accessible via their session link, just no longer tied to your account
5.5 Participant Data Deletion
Participants have no persistent accounts and no direct way to request deletion. However:
- You (the facilitator) can delete individual responses before a session is revealed
- You can delete entire sessions, which removes all associated responses
- Participants can contact us to request deletion of their responses; we will work with you to comply
6. Third-Party Data Processors
6.1 SendGrid (Email Delivery)
Data shared: Email addresses (for login codes only)
Purpose: Send 6-digit login codes to your email
Retention: Per SendGrid's privacy policy
Your control: You must provide an email to use WeEngage
6.2 Railway (Backend Infrastructure & Data Storage)
Data shared: All session data, responses, user accounts, AI insights
Purpose: Store and retrieve all WeEngage data
Retention: Indefinite (unless you delete)
Security: Railway provides encrypted data at rest and in transit; see their security docs
Compliance: Railway has a Data Processing Addendum (DPA) with EU Standard Contractual Clauses (SCCs) for GDPR compliance
Railway DPA
Railway Compliance Documentation
Where your data lives: WeEngage's database and API run in Railway's US West region (California, USA). For users in the EU, EEA, and UK this is a transfer outside the EU, protected by Standard Contractual Clauses as part of Railway's DPA.
6.3 Anthropic (Claude AI API)
Data shared: Response text, question text, session context (if AI insights are enabled); help-chat messages, the current page, and your plan tier (if you use the help chat — Section 3.3)
Purpose: Generate AI insights (themes, tensions, follow-up questions); answer help-chat questions from the User Guide
Retention: Per Anthropic's standard API data retention policy (brief retention for abuse detection, not model training)
Model training: Your data is not used to train Claude models by default
Your control: You can disable AI insights per session; if disabled, no data is sent to Claude. The help chat only sends what you type into it; if you never open it, nothing is sent
Important: We strongly recommend reviewing Anthropic's Privacy Policy and Commercial Terms directly, as their practices and policies may change.
6.4 Stripe (Payment Processing)
Data shared: Email, name, and an internal account identifier — for Pro subscribers only; Free-plan users are never sent to Stripe
Purpose: Process your Pro subscription payment and manage billing (invoices, cancellations, payment method updates)
Retention: Per Stripe's privacy policy
Your control: Your card details are entered directly on Stripe's own hosted checkout page — WeEngage's servers never see or store your card number
Anthropic Privacy Policy
Anthropic Commercial Terms
6.5 Vercel (Frontend Hosting)
Data shared: Session state, JWT authentication tokens (stored in your browser)
Purpose: Host the WeEngage interface
Retention: Session-only (cleared on logout)
Security: No sensitive data persisted on Vercel servers
6.6 Zoom (Zoom App Marketplace)
This section applies only if you add WeEngage to Zoom from the Zoom App Marketplace. Using WeEngage in a browser, or in Microsoft Teams, involves no data exchange with Zoom.
Data shared: When you add the app, Zoom sends WeEngage a one-time authorization code so the installation can complete and WeEngage can open inside your Zoom client. When you remove the app, Zoom sends a removal notification containing your Zoom user ID and account ID. WeEngage requests no access to your Zoom meetings, participants, contacts, recordings, chat, or any other Zoom data, and your Zoom identity is never linked to your WeEngage account.
Purpose: Complete the installation and open WeEngage in the Zoom apps panel; acknowledge removal
Retention: The authorization code is used once and never stored. The removal notification is logged for audit purposes only and is not kept in our database; any Zoom-related data is deleted within 10 days of Zoom notifying us of removal, in line with Zoom's marketplace requirements
Your control: Remove WeEngage at any time from the Zoom App Marketplace under Manage › Added Apps. Removing the Zoom app does not delete your WeEngage account or sessions; see Section 5 for account deletion
7. Data Protection & Security
7.1 In Transit
- All data transmitted between your browser and our servers is encrypted via HTTPS
- Session access is protected by cryptographic tokens (not just simple codes)
7.2 At Rest
- Data is stored in a PostgreSQL database on Railway
- Railway provides encryption at rest (AES-256)
- Database access is restricted to application code
7.3 Access Controls
- Only application code (via your session) can access session data
- We do not have broad database access
- Recovery codes are stored as one-way hashes, not the codes themselves; they cannot be used to access your account without your email
7.4 What We Don't Do (Yet)
- We do not offer end-to-end encryption (session data is visible to facilitators and to Claude if AI insights are enabled)
- We do not currently perform penetration testing or formal security audits
- We do not use hardware security modules (HSMs) for key management
8. Your Rights & Choices (GDPR, CCPA, PIPEDA)
8.1 Right to Access (DSAR - Data Subject Access Request)
You can request all personal data we hold about you.
How: Email us at support@weengage.app with "Data Access Request" in the subject line.
Timeline: We will respond within 30 days.
What you'll get:
- A summary of personal data (emails, names, profile info, etc.)
- A list of sessions you created
- Options to export or review your data
8.2 Right to Rectification
You can correct or update your personal data.
- Edit your profile via "Edit Profile" in Settings
- Correct responses before a session is revealed
- Contact us to correct data we hold (e.g., correct your email if misspelled)
8.3 Right to Erasure (Right to be Forgotten)
You can request deletion of your personal data.
- Delete individual responses (before session reveal)
- Delete entire sessions (soft-delete, then hard-delete after 90 days)
- Request account deletion (contact us)
Limitation: We retain soft-deleted data for 90 days for compliance audits. After 90 days, data is permanently deleted.
8.4 Right to Data Portability
You can get your data in a portable format.
- Print or save as PDF any individual session anytime, directly in the app (open it from Previous Sessions and choose Print Session)
- Request a full export of your account and all its sessions bundled together (contact us — this isn't yet self-service)
- Data will be provided in a structured, machine-readable format
8.5 Right to Restrict Processing
You can limit how we use your data.
- Disable AI insights per session (data won't be sent to Claude)
- Request we not use your data for service improvement
How: Contact us with specific restrictions.
8.6 Right to Object
You can object to certain processing.
- Object to AI insights processing (we'll disable for your sessions)
- Object to automated decision-making (we don't do this)
- Object to profiling (we don't do this)
How: Contact us; we'll accommodate within 30 days.
8.7 Right to Withdraw Consent
You can withdraw consent to data processing.
- Withdraw consent to use your email for login codes (you can no longer access your account)
- Withdraw consent to AI insights (we'll disable for future sessions)
Limitation: You cannot withdraw consent for responses already submitted to a session. Once a response is submitted and insights are generated, that processing cannot be reversed. However, you can request that we delete the response and regenerate the insights without it.
9. Cookies & Tracking
9.1 Login Storage (We Use No Cookies)
WeEngage does not use cookies. To keep you logged in, we store a single sign-in token in your browser's local storage after you sign in:
- What it is: An authentication token (a JWT)
- Purpose: To confirm your identity so you don't have to log in again on every page
- Expiry: 7 days from sign-in, regardless of activity — you'll need to log in again after that
- Scope: WeEngage only, first-party — it is never sent to a third party
This token is strictly necessary to operate the app. We store nothing in your browser for analytics, advertising, or tracking.
9.2 No Analytics, Advertising, or Third-Party Tracking
- We do not use any website analytics service (Google Analytics, Plausible, Mixpanel, or similar)
- We do not use tracking pixels, advertising cookies, or browser fingerprinting
- We do not allow third parties to track you on WeEngage
- Because we set no non-essential cookies or storage, WeEngage does not display a cookie-consent banner
Our hosting providers keep standard server access logs for security and reliability, as any website host does; we do not use these for analytics or profiling.
9.3 Your Choice
You can clear WeEngage's local storage from your browser settings at any time. Doing so simply logs you out — it has no other effect.
10. Sensitive Data & Responsible Use
10.1 Types of Sensitive Data Often Discussed
Participants and facilitators may share sensitive information in sessions, including:
- Organizational change (layoffs, restructures)
- Performance feedback or personal criticism
- Health, wellness, or personal struggles
- Conflict or interpersonal issues
- Strategic decisions or competitive information
- User research or customer feedback
10.2 Our Protections
- Anonymity by default: Participants can submit anonymously to protect identity
- Visibility controls: Responses are hidden until you reveal them
- No email broadcasts: Responses are not automatically emailed to others
- Private sessions: Only participants with the session code/token can join
- No public listing: Sessions are never listed publicly
- Encryption in transit: All data is encrypted when transmitted
10.3 Facilitator Responsibilities
As a facilitator, you should:
- Inform participants that responses may be AI-processed (via the session entry banner)
- Enable anonymity for sensitive topics
- Be transparent about session context and data retention
- Only use data for the stated purpose (e.g., don't use strategy session responses for performance reviews without telling people)
- Protect any session record you print or save — treat the copy as carefully as the original
- Consider participant consent if you plan to share session data outside the facilitation group
Important: WeEngage provides the tools for privacy, but you as the facilitator are responsible for using them ethically.
11. Incident Response & Breach Notification
11.1 If We Detect a Data Breach
We will:
- Investigate immediately to determine scope and impact
- Notify affected users without undue delay (GDPR: within 72 hours; US states: within 30 days)
- Notify regulators if required by law
- Provide guidance on steps you can take to protect your data
11.2 What We'll Tell You
- What data was accessed or compromised
- When the breach occurred
- What we're doing to prevent future breaches
- Contact information for questions
11.3 What We're Monitoring
- Application error logs and alerts
- Unauthorized access attempts
- Database anomalies
11.4 What We're Not (Yet) Doing
- Formal penetration testing
- Real-time Security Information Event Management (SIEM)
12. Children & Minors
WeEngage is not intended for children under 13. We do not knowingly collect data from children under 13.
If you are between 13 and 18, you may use WeEngage with parental consent. Parents can contact us to exercise rights on behalf of minors.
13. International Users & Data Transfers
13.1 GDPR (European Union, UK, EEA)
If you are located in the EU, UK, or EEA:
- You have the rights outlined in Section 8 above
- Your data may be transferred to the US (Railway) via Standard Contractual Clauses
- You can file a complaint with your local Data Protection Authority
13.2 CCPA (California)
If you are a California resident:
- You have rights to access, delete, and opt-out (see Section 8)
- We do not sell your personal information
- You can contact us to exercise your rights
13.3 PIPEDA (Canada)
If you are a Canadian resident:
- You have rights to access and correct your information
- You can request deletion (subject to legal holds)
- You can contact us to exercise your rights
13.4 Other Jurisdictions
If you are located in another country with data protection laws, we will make reasonable efforts to comply. Contact us to discuss.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect:
- Changes to our service (e.g., new features, new processors)
- Changes to third-party practices (e.g., Anthropic's API terms)
- Legal or regulatory requirements
How we'll notify you:
- If the change is material, we'll notify you via email or in-app notification
- If the change is about AI or data sharing, we'll require explicit opt-in for new processing
- If you disagree, you can delete your account
Version history: We will maintain a version log of significant changes.
15. Contact Us
Questions about this Privacy Policy?
Email: support@weengage.app
Postal Address:
InsightEQ Solutions LLC
980 Broadway #137, Thornwood, NY 10594
Data Protection Officer (if applicable):
[NAME/EMAIL] (or direct to main contact above)
Response time: We aim to respond to privacy inquiries within 10 business days.
16. Legal Basis for Processing (GDPR)
We process your data based on:
| Processing | Legal Basis |
|---|---|
| Account creation & login | Contractual necessity (you initiate) |
| Session management & facilitation | Contractual necessity (you create sessions) |
| AI insights (Claude API) | Your explicit consent (you enable AI insights) |
| Email delivery (login codes) | Contractual necessity (authentication) |
| Service improvement | Legitimate interest (improve the product) |
| Fraud prevention & security | Legitimate interest (protect the service) |
| Compliance with legal obligations | Legal obligation (law enforcement, courts) |
End of Privacy Policy
Document Version: 1.5
Status: Ready for review and integration
Date: September 2, 2026