Weacon logo
weacon
How it works What it does Who it is for Comparisons Pricing
Log in Start free

Legal›Privacy policy

Effective 25 August 2026 · Version 1.0

Privacy policy

What weacon collects, why, who else touches it, and how to get a copy or get rid of it.

Contents

  1. 1. Who is responsible
  2. 2. What we collect
  3. 3. Why, and on what basis
  4. 4. AI processing
  5. 5. Who we share it with
  6. 6. How long we keep it
  7. 7. Cookies and analytics
  8. 8. How it is protected
  9. 9. Your rights
  10. 10. Contact and complaints

Data requests: contact@weacon.io — answered within 30 days.

In short

  • →We collect what we need to run the app and bill you. Nothing is sold, ever.
  • →Your data is stored in the EU. The AI features send text to OpenAI in the United States.
  • →Your content is never used to train anyone's AI models.
  • →Ask for a copy of your data, or for its deletion, at any time.
01

Who is responsible

The controller of your personal data is Cattaneo Lorenzo, P.IVA IT01677710194, Italy, operating as weacon. Write to contact@weacon.io about anything on this page.

For account, billing and website data we are the controller — we decide what is collected and why. For the content inside a workspace, the organisation that created it is the controller and weacon is the processor, handling that content on its instructions; the terms of service and this policy together form the agreement required by Article 28 of the GDPR.

02

What we collect

CategoryWhat it includes
AccountYour name and email address, your sign-in credentials, and your workspace membership and settings.
Workspace contentWhatever you and your team put into a workspace — notes, documents, plans, tasks, files, comments and their history — including any personal data it contains.
BillingYour billing email and the subscription records Paddle sends us. Card details are handled by Paddle and never reach us.
TechnicalYour IP address and browser, stored with each sign-in and used to rate-limit abuse.

If you email us, we keep the correspondence.

03

Why, and on what basis

To provide the service — contract

Your account, storing and syncing your content, transactional email, and the AI features you invoke.

To take payment — contract and legal obligation

Subscriptions, invoices, and the VAT and accounting records Italian law requires.

To keep it secure and working — legitimate interest

Abuse prevention, rate limiting, backups and debugging.

To tell you about the product — consent or legitimate interest

Occasional product emails, which you can unsubscribe from in one click. Service and security notices are not optional.

04

AI processing

When you use a feature that turns notes into plans or proposes a documentation update, the relevant text is sent to OpenAI, which acts as our processor and handles it in the United States. That transfer is covered by our data processing agreement with OpenAI, which incorporates the European Commission's standard contractual clauses. Under that agreement your content is not used to train its models. Only the content needed for the request is sent, and AI features run only when a member invokes them. Workspace text is also turned into embeddings — numerical representations used for search and for linking related material — by the same service, and those are stored back in our own database in the EU alongside your content.

05

Who we share it with, and where

We use a short list of providers, each bound by a data processing agreement and used only for the purpose below.

ProviderPurposeWhere
OpenAIAI features and search embeddingsUS
PaddleSubscriptions, invoices and tax, as merchant of record. Receives your IP address to localise pricesUK
Cloudflare R2Storage of uploaded filesEU
Amazon SESSends the email weacon sends youEU
GoogleOnly if you choose to sign in with GoogleUS

Your account, your content, the files you upload and our backups stay in the European Union. Three things leave it: text you send to the AI features is processed by OpenAI in the United States under the standard contractual clauses described above; Paddle operates from the United Kingdom; and signing in with Google, if you choose it, involves Google in the United States. The last two rely on the European Commission's adequacy decisions. Beyond this list we disclose data only when the law requires it, or to a buyer if weacon is ever sold, in which case you will be told first.

06

How long we keep it

Workspace content and accountdeleted straight away
Backups and payment recordsup to 30 days
Text sent to the AI featuresheld by OpenAI up to 30 days

Deleting your account deletes it and its files immediately; the backups and payment records above age out within 30 days. Paddle keeps the invoices themselves under its own retention policy, because it is the seller of record — we do not hold them.

The text the AI features send to OpenAI is kept by OpenAI for up to 30 days so it can check for abuse, then deleted. It is never used to train its models, and we keep no separate copy of it — only the embeddings described above, which live in our own database. Deleting your content here does not reach a copy still inside that 30-day window, so it can outlive the deletion by up to a month.

07

Cookies and analytics

The app sets a small number of strictly necessary cookies: your session, a security token and your interface preferences. There is no advertising network, no cross-site tracking and no third-party marketing pixel — the fonts and scripts the site needs come from our own domain. Website usage is measured with cookieless analytics on our own server, recording page views and referrers without profiling individuals, which is why there is no consent banner.

08

How it is protected

Traffic is encrypted with TLS and data is encrypted at rest. Passwords are stored as one-way hashes, and an account can use a passkey instead. Access to production systems is limited to the operator, and backups are automated. If a breach affects your personal data we will notify the Garante per la protezione dei dati personali within 72 hours where required, and tell affected users directly.

09

Your rights

Under the GDPR you can ask us for a copy of your data, or to correct it, delete it, restrict or object to how we use it, port it elsewhere, or withdraw consent where consent is what we relied on. Write to contact@weacon.io and we will respond within 30 days.

If your account belongs to an organisation's workspace, we will pass the request to its administrators, since the content is theirs to decide on. Deleting your account deletes any workspace where you are the only administrator, along with its content, and strips your name and email address from the account record — so the work you contributed to shared workspaces keeps its history without being attributable to you.

10

Contact and complaints

When this policy changes, the version and date at the top change with it. Changes that affect how your data is used are emailed to account holders 30 days before they take effect.

Data protection contact

weacon · Italy

contact@weacon.io

You may also complain to the Garante per la protezione dei dati personali (Rome), or to the supervisory authority where you live.

Weacon logo
weacon

weacon — from weave and connect — is an AI project management app that keeps notes, plans and documentation in sync.

Product

How it works Notes to plans Following your team Pricing AI project management Project documentation Meeting notes to tasks

Compare

All comparisons weacon vs Jira weacon vs Linear weacon vs Asana weacon vs Trello weacon vs ClickUp

Legal

Terms of service Privacy policy

Contact

contact@weacon.io About weacon
© 2026 weacon. All rights reserved.