Wakeline
legal

Privacy Policy

How we collect, use, and protect data — in plain language, including exactly what the SDK does on customers' sites.

Last updated: August 21, 2026

Overview

This policy explains what we collect, why, and what you can do about it. It covers the Wakeline marketing site (wakeline.io), the Wakeline dashboard, and the in-app guides our SDK renders on customers' websites and apps.

Two kinds of people interact with Wakeline: customers (you, with a Wakeline account) and end users (the people using our customers' products, where the SDK runs). The rules differ for each, and this policy says which is which.

Information we collect

Account data you give us — your name, email, organization, and password (stored only as a secure hash, never in plain text).

Product usage from your Wakeline dashboard, so we can operate, secure, and improve the service.

Billing information is handled by our payment provider — card numbers never touch Wakeline's servers. We keep records of your plan, invoices, and payment status.

End-user data on behalf of our customers — when a customer installs the SDK, it processes the identifiers and traits that customer chooses to send (via their identify() call), plus interaction events: which guides were seen, completed, or dismissed, what was clicked, and answers to surveys and forms the customer runs.

Session replay, specifically

Customers can enable session replay, which records end-user interactions (clicks, scrolls, navigation, interface changes) on the customer's own site so they can diagnose experience problems.

Masking of sensitive inputs is on by default: passwords, emails, and phone numbers are hidden before anything leaves the end user's browser, and any element a customer marks with a data-wakeline-mask attribute is masked unconditionally — masked content is never transmitted to us.

Customers control the recording sample rate and a retention window of 1–365 days (30 by default); older sessions are deleted automatically, and any individual session can be deleted immediately, including for privacy requests.

How we use information

To provide and secure the service: authenticate you, render and target guides, honor frequency caps and dismissals, and report analytics back to the customer who owns the data.

To communicate with you about your account and important service changes.

If your workspace enables AI features (guide drafting, auto-translation), the text you submit for those features is sent to our AI provider to generate the result. End-user analytics data is not used to train AI models.

We do not sell personal information, and we do not use end-user data for advertising.

Customer data & roles

For end-user data captured through the SDK, our customers are the data controllers and Wakeline is the processor: we process that data only to provide the service and on the customer's instructions. Customers are responsible for having a lawful basis for the data they choose to collect and for providing any required notices to their end users.

A Data Processing Agreement (DPA) is available on the Enterprise plan; contact us if your compliance process requires one.

Cookies & local storage

On wakeline.io we use essential cookies only — to keep you signed in. There are no advertising trackers on this site.

On customers' sites, the SDK uses local storage on end-user devices to remember which guides someone has seen, so frequency caps and “don't show again” are honored. For identified users, that history is stored with their profile so it follows them across devices.

Sharing & subprocessors

We share data only with the service providers that run Wakeline, under agreements that require them to protect it: our cloud hosting provider (where the service and its databases run), Cloudflare (networking and content delivery), Resend (transactional email such as verification and password-reset messages), Lemon Squeezy (payment processing), and Google (Gemini API — only when a workspace uses AI features, and only the submitted text).

We may also disclose information if required by law, and we'll tell you when legally permitted to do so.

Security

Traffic is encrypted in transit. Credentials are stored as bcrypt hashes; verification and reset tokens are random, stored hashed, single-use, and expiring. Dashboard access follows least-privilege team roles (Admin, Editor, Viewer).

The SDK's publishable key is deliberately limited: it can read a project's published guides and write interaction events — nothing else — and can be revoked and reissued at any time.

Retention & deletion

Account data is kept while your account is active. End-user event data is kept per each customer's configured retention window, with a purge tool that deletes events older than a chosen age.

Right-to-be-forgotten tooling is built in: customers can erase a single end user (identity and events, everywhere) or, with explicit admin confirmation, wipe all end-user data. On account termination, we make your data available for export for a reasonable period, then delete it.

Your rights

Depending on where you live (including under the GDPR and CCPA), you may have rights to access, correct, export, restrict, or delete your personal data, and to complain to a supervisory authority. To exercise them, email privacy@wakeline.io — we'll respond within the timelines the law requires.

If you're an end user of a product that uses Wakeline, the company whose product you were using controls your data — contact them, and we'll support their request with the tooling above.

International transfers

Wakeline's infrastructure may be located outside your country. Wherever data is processed, it's protected by this policy and by our agreements with the providers listed above.

Children

Wakeline is not directed at children and we don't knowingly collect data from anyone under 16. If you believe we hold such data, email privacy@wakeline.io and we'll delete it.

Changes

We may update this policy as the product evolves. We'll post the new version here and update the date below; material changes will be flagged to account holders.

Contact

Questions about privacy? Email privacy@wakeline.io.