Privacy Policy
Effective date: 26 March 2026
Weaxen (“we”, “our”, or “us”) is operated by Mindlace. We respect your privacy and are committed to protecting the personal data you share with us. This Privacy Policy explains how we collect, use, store, and share your information when you use the Weaxen platform at weaxen.mindlace.co.uk.
1. Information We Collect
We collect the following types of information:
Account Information
When you create an account, we collect your name, email address, and profile picture. If you sign in with Google, we receive your name, email address, and avatar from your Google account. You may also provide a job title when joining an organisation.
Project Content
Content you create, upload, or collaborate on within the platform, including text, research artefacts, design documents, and chat messages with AI assistants. This content is stored to enable real-time collaboration and version history.
Usage Data
Information about how you interact with our services, including which features you use, API requests made, and AI token consumption. This helps us improve the platform and manage resource allocation.
Device and Technical Data
IP address, browser type, operating system, and device identifiers collected automatically when you access the platform.
2. How We Use Your Information
We use collected information to:
- Provide, maintain, and improve our services
- Process your content through AI services to deliver platform features such as research generation, content structuring, and chat-based assistance
- Personalise your experience on the platform
- Communicate with you about updates, features, or support matters
- Ensure security, prevent fraud, and enforce rate limits
- Monitor and fix errors and technical issues
- Comply with legal obligations
3. Third-Party Services and Data Sharing
We do not sell your personal data. We share information with the following third-party service providers solely to operate the platform:
- Supabase — database hosting, user authentication, and real-time collaboration infrastructure. Stores account information, project content, and session data.
- AI Providers (via OpenRouter) — project content and chat messages are sent to AI language models (including Anthropic Claude and Perplexity) to power research generation, content structuring, and AI chat features. These providers process your content to generate responses but do not retain it for their own training purposes.
- Sentry — error tracking and performance monitoring. Receives technical and device data alongside error context to help us diagnose and fix issues. No personally identifiable information beyond user IDs is sent.
- Resend — transactional email delivery. Receives your email address to send account verification, password reset, and platform notification emails.
- Upstash — rate limiting infrastructure. Processes IP addresses and request metadata to enforce usage limits and protect against abuse.
- Vercel— application hosting and deployment. All request data passes through Vercel's infrastructure.
- Google — OAuth authentication. If you choose to sign in with Google, we receive your name, email address, and profile picture from Google.
4. Cookies and Local Storage
We use the following cookies to operate the platform:
- Session cookies — managed by Supabase to maintain your authenticated session. These are essential for the platform to function and cannot be disabled.
- Organisation context cookie — remembers the last organisation you accessed for faster navigation. Expires after one year.
- Sign-up flow cookies — temporary cookies used during account creation and OAuth sign-in. These expire within minutes of being set.
We do not use advertising or third-party tracking cookies.
5. Data Retention
We retain your data for as long as your account is active or as needed to provide our services. If you delete your account, there is a 14-day recovery window during which you can restore your account and data. After this period, your data is permanently deleted from our systems.
6. Data Security
We implement industry-standard security measures to protect your data, including:
- Row-level security policies ensuring users can only access data belonging to their organisation
- Encrypted connections (HTTPS) for all data in transit
- Content Security Policy headers to protect against cross-site scripting
- Rate limiting to prevent abuse
- HTTP Strict Transport Security (HSTS) in production environments
However, no method of transmission over the Internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Request portability of your data
- Object to or restrict certain processing of your data
To exercise any of these rights, contact us at hello@weaxen.mindlace.co.uk.
8. International Data Transfers
Your data may be processed in regions where our third-party service providers operate, which may be outside of your country of residence. We ensure that appropriate safeguards are in place when transferring data internationally.
9. Children's Privacy
Weaxen is not intended for use by children under the age of 16. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us so we can take appropriate action.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes through the platform or via email. Your continued use of the platform after changes constitutes acceptance of the updated policy.
11. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us at hello@weaxen.mindlace.co.uk.