Wizawiz
Sign inGet started
Terms of ServicePrivacy Policy

On this page

  1. 1.Who we are and scope
  2. 2.What personal data we collect
  3. 3.How and why we use personal data
  4. 4.AI features and AI providers
  5. 5.When we share personal data
  6. 6.Cookies and similar technologies
  7. 7.How long we keep personal data
  8. 8.International data transfers
  9. 9.How we protect personal data
  10. 10.Your rights and choices
  11. 11.Children
  12. 12.Emails and other communications
  13. 13.Changes to this Policy
  14. 14.Contact us

Also read: Terms of Service

Legal

Privacy Policy

Last updated
August 23, 2026
Effective
August 23, 2026
Version
1.0

In short

  • Wizawiz is the controller of the personal data described here. Contact us at support@wizawiz.com.
  • We collect what you give us (your email, Google name if you sign in with Google, the prompts, wizards and media you create or upload, payout details for creators and affiliates) and a small amount of technical data (session cookies, error logs, feature-usage events, a hashed IP for referral-fraud checks).
  • Payments are handled by Stripe — we never see your card number. AI features send your prompts and uploads to AI providers (Google, Anthropic, fal.ai and, when enabled, OpenAI-compatible providers) to produce results. We don't use your content to train AI models, and our providers process it only to serve your request under their API terms.
  • We don't sell your personal data, we don't run ads, and we use no third-party analytics or tracking cookies. We set three first-party cookies: your sign-in session, and two short-lived referral/promo-code cookies.
  • We keep your content for as long as your account exists; error logs for 30 days; uploaded videos only while they are analysed. Images you add to wizards are stored in a public media bucket — don't upload anything private there.
  • You can access, correct, export or delete your data and object to or restrict processing. Email support@wizawiz.com; we answer within 30 days (45 days for California requests).
  • Wizawiz is not for children under 13.

This summary is provided for convenience only. It is not part of the agreement and does not replace the full text below, which governs.

1.Who we are and scope

This Privacy Policy explains how Wizawiz ("we", "us") handles personal data when you use the Wizawiz website at wizawiz.com and the related applications and services (the "Service"), and when you communicate with us. Wizawiz is the data controller (the business responsible) for this processing. It applies to everyone who uses the Service — visitors, free and paid users, creators and affiliates.

This Policy does not cover third-party services that you use alongside Wizawiz — for example Google when you sign in with Google, Stripe when you pay, or the platforms where you use the prompts you create — which have their own privacy policies. Our Terms of Service govern your use of the Service; capitalised terms not defined here have the meaning given there.

Privacy contact: support@wizawiz.com. We have not appointed a Data Protection Officer because we are not required to; the privacy contact handles all requests.

2.What personal data we collect

We collect as little as we can. Here is everything, grouped by where it comes from.

2.1Data you give us

Account data
Your email address and a password (stored only as a hash by our authentication provider, Supabase, never in readable form). If you sign in with Google, we receive the basic profile Google shares at sign-in — your Google account email address, name (used as your display name) and profile-picture link — and nothing else: we request no access to your Google services such as Gmail, Drive or Contacts. We also store a normalised form of your email (with dots and "+tags" removed) to detect duplicate accounts, and your role in your workspace.
Your content
The prompts, wizards (steps, options, images), notes, folders, tags and library items you create; the answers you give in wizard steps; text you submit to the Mixer, Safe Pass and generation features; images and short videos you upload to the Prompt Extractor; links you paste (for example a YouTube link); chat messages in the Generate feature; and the AI results you keep. Inputs and results of AI runs are stored in your history so that you can reuse a result you already paid for without being charged again.
Billing data
When you subscribe or buy credits, Stripe collects your card details and billing address directly — we never receive or store your full card number or security code. We store your Stripe customer and subscription identifiers, plan, billing status and dates, your credit ledger (every grant, use, refund and expiry), and purchase records (what, when, how much, currency). On your billing page we display the card brand, last four digits and expiry that Stripe holds, and your invoices, fetched live from Stripe.
Creator and affiliate data
If you publish wizards or join the referral programme: your payout email or account details, payout notes, income and commission ledgers, withdrawal requests and their status, referral code and the workspaces attributed to it. We may ask for identity or tax information (for example a tax form) before paying out; see the Terms.
Promo and referral codes
A promo code you type at sign-up and the referral code from a link you followed.
Communications
The content of emails you send us (support, privacy, legal requests), the email address you send from, and our replies.

2.2Data collected automatically

Session and security data
Authentication cookies that keep you signed in (see Cookies); the time of your sign-ins; and the fact that your email was confirmed.
Usage events
Records of which features you use and when (for example "wizard run", "prompt generated", "Safe Pass run", "media analysed", "promo code redeemed"), with your user and workspace id and limited context such as the feature or plan involved. These are first-party records in our own database — we use no third-party analytics product.
Error and diagnostic logs
When something goes wrong, we log the error message, a stack trace, a request identifier, the page URL (which can include ids in the address), your browser's user-agent string and — if you are signed in — your user and workspace id. Sensitive values such as passwords, tokens and keys are redacted before logging. Your IP address is used only to rate-limit the error-reporting endpoint and is not stored in logs.
Referral-fraud signals
When a referred user signs up, or an affiliate joins, we store a salted, truncated hash of the IP address (which cannot be reversed to the address) and the browser's user-agent string, to detect self-referrals and duplicate accounts. We do not store raw IP addresses.
Link-click counts
Outbound links on our site pass through a redirect that counts total clicks per link. No per-person record, IP or device data is kept.
Data stored on your device
To make the app fast and resilient we store some data in your browser (not on our servers): generated images and videos you preview (in IndexedDB, so that they can be shown again without re-downloading), in-progress wizard answers, editor drafts and view preferences (in local storage), and short-lived hand-offs between pages (in session storage). You can clear these through your browser settings.

2.3Data from third parties

  • Google (if you use Google sign-in): your basic profile (email address, name, profile-picture link), as described above.
  • Stripe: confirmation that a payment, refund, dispute or subscription event happened, the amount, and the customer identifier — but not your card number.
  • Referrers: if you arrive through an affiliate's link, the referral code in that link.

We do not buy personal data from data brokers and we do not combine your data with data from social networks or advertising networks. We do not collect precise geolocation, biometric data, or government identifiers (except tax information a creator or affiliate may choose to provide for payout).

3.How and why we use personal data

We use personal data for the purposes below. Where the GDPR, UK GDPR or a similar law applies, we rely on the legal bases shown.

PurposeData usedLegal basis
Provide the Service: create and secure your account, run wizards and AI features, store your library, show your history and balancesAccount data, your content, usage events, session dataPerformance of our contract with you (the Terms)
Process payments, subscriptions, credits, refunds and invoices; prevent payment fraudBilling data, account dataContract; legal obligation (tax and accounting records)
Run the creator and referral programmes: attribute referrals, calculate and pay income and commissions, detect self-referral and abuse, comply with tax rulesCreator/affiliate data, referral-fraud signals, billing dataContract; legitimate interests (preventing fraud); legal obligation
Keep the Service secure and reliable: authenticate you, rate-limit abuse, diagnose and fix errors, detect duplicate or abusive accountsSession data, error logs, usage events, referral-fraud signalsLegitimate interests (security and integrity of the Service); contract
Moderate content: review wizards submitted for publication, act on reports, enforce the TermsYour content, account dataLegitimate interests (safety, legal compliance, protecting users); legal obligation
Communicate with you about your account: confirmation emails, security notices, billing and programme updates, replies to your requests, notice of changes to our termsAccount data, communicationsContract; legal obligation; legitimate interests
Understand and improve the Service using aggregated feature-usage statistics and error trendsUsage events, error logs (aggregated; not used to profile individuals)Legitimate interests (improving our product)
Comply with law, respond to lawful requests, establish or defend legal claimsAny of the above, as relevantLegal obligation; legitimate interests

What we do not do. We do not sell personal data; we do not share it for cross-context behavioural advertising; we do not show ads; we do not build marketing profiles; we do not use your content to train AI models; and we do not make decisions about you that have legal or similarly significant effects based solely on automated processing. Automated checks do operate for fraud and abuse (for example, an account created with a disposable email address may not receive welcome credits, and self-referrals are not credited) — you can ask for human review of any such outcome by emailing support@wizawiz.com.

4.AI features and AI providers

Many features work by sending your input to a third-party AI model and returning its output. We want you to understand exactly what that involves.

  • What is sent. Only the content needed for the feature you trigger: the prompt text or wizard answers (Mixer, Safe Pass, wizard AI drafting, generation previews, chat), the image or video you upload or the link you paste (Prompt Extractor), and reference images you attach to a generation. We do not send your email, name, payment data or account identifiers to AI providers.
  • Which providers. Text features are served by Google (Gemini) or Anthropic (Claude), and — only if we enable them — OpenAI-compatible providers (OpenAI, OpenRouter, DeepSeek, Groq). All image and video analysis is served by Google Gemini. Image and video generation previews are served by fal.ai. Requests go from our servers to the provider over encrypted connections using our accounts; your browser never contacts a provider directly.
  • No training. We do not use your content to train or fine-tune AI models. Our providers process your content as our service providers under their business/API terms: Google (paid Gemini API), Anthropic and OpenAI state that they do not use API inputs or outputs to train their models; fal.ai and other providers may use de-identified, aggregated usage data to improve their services as described in their terms. Providers may retain API inputs and outputs for a limited period (typically up to 30 days) for abuse monitoring and legal compliance, under their own policies.
  • Uploaded videos are uploaded by your browser directly to a private storage bucket (Cloudflare R2) using a short-lived signed link, streamed from there to Google's file service for analysis, and then deleted from both places once the analysis finishes or fails (with a one-day automatic clean-up as a safety net). Uploaded images are converted in your browser and sent inline with the request; they are not stored on our servers for the Extractor.
  • YouTube links are analysed by Google fetching the public video; we send the video's canonical address, and only the first 60 seconds are analysed.
  • Results (and the inputs that produced them) are stored in your account's history so you can reuse them without paying again; you can see them in your history and ask us to delete them.
  • Output about people. AI output can describe or depict people inaccurately. You are responsible for the lawful use of anything you generate about real people; see the Terms.

5.When we share personal data

We share personal data only in these situations:

  • Service providers (processors) that process data on our behalf and on our instructions, listed in the table below. Each is bound by a contract that restricts its use of the data to providing its service to us.
  • Other users and the public, at your direction. If you publish a wizard, its name, description, thumbnail and your display name are visible to all users (and the wizard itself becomes public once approved). If you create a share link for a prompt, anyone with the link can see that prompt (without your name, workspace or email). Images you upload for wizard options, covers or page content are stored in a public media bucket and are accessible to anyone who has their address — do not upload images there that you want to keep private.
  • Legal reasons. To comply with a law, regulation, legal process or enforceable government request; to enforce our Terms; to detect, prevent or address fraud, security or technical issues; or to protect the rights, property or safety of Wizawiz, our users or the public.
  • Business transfers. If we are involved in a merger, acquisition, financing, reorganisation or sale of assets, personal data may be transferred as part of that transaction. We will notify you (for example by email or a notice in the Service) before your data becomes subject to a different privacy policy.
  • With your consent, or at your direction, in any other case.

We do not sell personal data and have not done so in the preceding 12 months. We do not share personal data with third parties for their own marketing.

5.1Our service providers

ProviderWhat it does for usData involved
VercelHosts the website and application, runs our server code and scheduled jobsAll data that passes through the Service
SupabaseAuthentication (passwords, Google sign-in, sessions) and our database (PostgreSQL)Account data, your content, billing records, ledgers, logs
StripePayment processing, subscriptions, invoices, customer billing portalCard and billing details (collected by Stripe directly), email, payment events
Cloudflare (R2)Object storage: a private bucket for videos awaiting analysis; a public bucket for site media and images you add to wizardsUploaded media
Google (Gemini API, Files API)AI model provider for text features and all image/video analysis; also processes YouTube links you submitPrompts, wizard answers, uploaded images and videos, links
Anthropic (Claude API)AI model provider for text featuresPrompts and wizard answers
fal.aiAI model provider for image, video and audio generationPrompts and reference images
nanobananaapi.aiAI model provider for Nano Banana image generationPrompts and reference images
OpenAI, OpenRouter, DeepSeek, GroqOptional AI model providers for text features — used only when we enable themPrompts and wizard answers
Google (Sign in with Google)Optional sign-in methodYour Google email, name and profile-picture link

We may add or replace providers; we will update this table when we do. Your email provider and, if you are a creator or affiliate, your payout provider (for example PayPal) also receive the data needed to deliver messages or payments to you.

6.Cookies and similar technologies

We use only strictly necessary, first-party cookies. There are no advertising cookies, no third-party analytics cookies and no social-media pixels on the Service, and we do not use cookies to track you across other websites. Because none of our cookies require consent under EU/UK ePrivacy rules, we do not show a cookie banner.

CookiePurposeLifetime
sb-…-auth-token (set by Supabase, may be split into parts)Keeps you signed in and protects your sessionPersistent: refreshed while you use the Service (up to 400 days); removed when you sign out
wizawiz_refRemembers the referral code from a link you followed until you sign up, so the referrer can be credited30 days, deleted once consumed at sign-up
wizawiz_promoRemembers a promo code you entered until your account is created30 days, deleted once consumed at sign-up
  • Browser storage. As described above, the app stores previews, drafts and preferences in your browser's IndexedDB, local storage and session storage. This data stays on your device; clearing your browser data removes it.
  • Do Not Track and Global Privacy Control. We do not track users across sites or sell or share personal data, so there is nothing for these signals to switch off; we treat a Global Privacy Control signal as a valid request to opt out of any sale or sharing, which we do not perform.
  • Embedded media. Admin-authored pages may embed YouTube (privacy-enhanced "nocookie" mode) or Vimeo players; those providers may set cookies only if you interact with the player, under their own policies.

7.How long we keep personal data

We keep personal data only as long as needed for the purposes described here, then delete or anonymise it. Typical periods:

DataRetention
Account data, your content, AI run history, credit and income ledgersFor as long as your account exists. After you delete your account (or we close it), we delete or anonymise it within 30 days, except as noted below.
Billing and tax records (invoices, payments, payouts, commissions)Up to 10 years after the transaction, as required by tax and accounting law.
Uploaded videos for the Prompt ExtractorDeleted when analysis finishes or fails; automatic clean-up within 1 day as a safety net. Analysis job records are deleted after 7 days.
Images added to wizards, covers and pages (public media bucket)Until you remove them from your content or ask us to delete them. Copies may persist in caches for a limited time after deletion.
Error and diagnostic logs30 days.
Usage eventsFor the life of the account, then deleted or anonymised with the account.
Referral-fraud signals (hashed IP, user agent)For the life of the referral record; deleted with the account, except where needed for an open fraud investigation or dispute.
Support and legal communicationsUp to 3 years after the matter is closed, or longer if needed for a legal claim.
Records needed to establish, exercise or defend legal claims, or to enforce a banUntil the claim or the need expires.

Backups are overwritten on a rolling basis within a further short period. Content you have published or shared may remain with users who have already run, cloned or exported it.

8.International data transfers

Wizawiz is a global service. Your data is processed where we and our service providers operate — including the United States (hosting, payments and AI providers), the region of our database provider, and other countries where the providers listed above run their infrastructure — which may be outside the country where you live and may have different data-protection laws.

Where we transfer personal data from the European Economic Area, the United Kingdom or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards: principally the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum) in our contracts with providers, and, for providers certified under the EU-U.S. Data Privacy Framework and its UK and Swiss extensions, that framework. You can ask us for more information about these safeguards at support@wizawiz.com.

9.How we protect personal data

We use technical and organisational measures appropriate to the risk: encryption in transit (TLS with HTTP Strict Transport Security) and at rest with our hosting, database and storage providers; passwords stored only as salted hashes by our authentication provider; card data handled entirely by a PCI-DSS-compliant payment processor; strict browser security headers (content-security policy, frame denial); administrative access restricted to named, confirmed accounts; redaction of secrets from logs; short-lived signed links for uploads; and deletion of media after processing. No system is perfectly secure, so we cannot guarantee absolute security. If we learn of a breach affecting your personal data, we will notify you and the relevant authorities as the law requires. Help us by using a strong, unique password and keeping your sign-in methods secure.

10.Your rights and choices

Depending on where you live you may have some or all of the following rights regarding your personal data. We extend the core rights below to all users, wherever they live:

  • Access — to know whether we process your personal data and to receive a copy of it, together with the information in this Policy.
  • Correction — to have inaccurate or incomplete data corrected. You can change some data yourself in your settings.
  • Deletion — to have your personal data deleted, subject to the exceptions noted in the retention section (for example billing records we must keep). Deleting your account permanently removes your workspace, content, credits and — unless you request a final payout of an eligible balance beforehand — income; published wizards are un-published.
  • Portability — to receive the data you provided in a structured, commonly used, machine-readable format (your wizards can also be exported as JSON from the app).
  • Objection and restriction — to object to processing based on our legitimate interests, or ask us to restrict processing, in the circumstances allowed by law.
  • Withdraw consent — where processing is based on consent, at any time, without affecting earlier processing.
  • Complain — to your local data-protection authority (in the EU/EEA, the supervisory authority of your country; in the UK, the Information Commissioner's Office). We would appreciate the chance to address your concern first.

How to exercise your rights. Email support@wizawiz.com from the email address on your account (or include enough information for us to verify that you are the account holder — we will not act on requests we cannot verify, to protect your data). An authorised agent may submit a request on your behalf with proof of authority. We respond within 30 days (45 days for requests under California law), extendable where the law allows if a request is complex; we will tell you if so. We do not charge for requests unless they are manifestly unfounded or excessive, and we will never discriminate against you for exercising your rights.

10.1Additional information for residents of US states

If you live in California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia or another state with a comprehensive privacy law, you have rights to access, correct, delete and obtain a copy of your personal data and to opt out of its sale, its sharing or processing for targeted advertising, and profiling in furtherance of decisions with legal or similarly significant effects. We do not sell personal data, do not process it for targeted advertising and do not engage in such profiling, so there is nothing to opt out of; if that ever changes we will provide a clear opt-out, and we honour Global Privacy Control signals. If we deny a request you may appeal by replying to our decision email; if the appeal is denied, you may contact your state attorney general.

California (CCPA/CPRA). In the preceding 12 months we have collected the categories of personal information listed in the table below, from the sources and for the purposes described in this Policy. We disclose them to the service providers listed above for business purposes only. We do not collect or use sensitive personal information to infer characteristics about you; the only sensitive categories we handle are account log-in credentials (processed by our authentication provider) and, for creators and affiliates who choose to provide it, payout or tax information used solely for payment. California residents may also request the information described in California Civil Code § 1798.83 ("Shine the Light"); as we do not share personal information with third parties for their direct marketing, the answer will be that we do not.

CCPA categoryCollected?Examples
IdentifiersYesEmail address, account id, Stripe customer id, display name, payout email
Customer records (Cal. Civ. Code § 1798.80(e))YesName (if provided via Google), email, billing records (card details held by Stripe only)
Commercial informationYesPlan, purchases, credit ledger, income and commission records
Internet or network activityYesFeature-usage events, error logs (page URL, user agent), session data
Geolocation dataNo (precise). A salted, truncated hash of the IP address is stored for referral-fraud checks—
Audio, visual or similar informationYes, if you upload themImages and short videos you submit for analysis or add to wizards
Professional or employment informationNo—
Education informationNo—
InferencesNo — we do not build profiles—
Sensitive personal informationLimitedLog-in credentials (via Supabase); optional tax information for payouts
Protected characteristics; biometric dataNo—

10.2Other regions

  • European Economic Area, United Kingdom and Switzerland. The rights above are those under the GDPR, UK GDPR and Swiss FADP. Our legal bases are set out in the table in the section on how we use data. Where we rely on legitimate interests we have balanced them against your rights; you can ask us about that assessment.
  • Brazil. You have the rights provided by the LGPD, including confirmation of processing, access, correction, anonymisation, portability, deletion, and information about sharing; contact the privacy email above.
  • Canada. You may access and correct your personal information and withdraw consent, subject to legal and contractual restrictions, and may complain to the Office of the Privacy Commissioner of Canada.
  • Australia. You may access and correct your personal information under the Privacy Act 1988 and complain to the Office of the Australian Information Commissioner.

11.Children

The Service is not directed to children under 13 and we do not knowingly collect personal data from them. If you are under 13, do not use the Service or give us any information. If we learn that we have collected personal data from a child under 13 (or under the age of digital consent where they live, without verifiable parental consent), we will delete it and close the account. If you believe a child has given us data, contact support@wizawiz.com.

12.Emails and other communications

We send service emails that are necessary to run your account — such as confirming your email address, security alerts, notices about billing, payouts or changes to our terms. You cannot opt out of these while you have an account. We do not currently send marketing emails or newsletters; if we introduce them, we will only send them with your consent where the law requires it, and every marketing email will include an unsubscribe link.

13.Changes to this Policy

We may update this Policy to reflect changes to the Service, our providers or the law. When we do, we will change the "Last updated" date and version above. If a change materially affects how we use your personal data, we will give you at least 30 days' notice by email or a prominent notice in the Service before it takes effect, and where required seek your consent. Previous versions are available on request.

14.Contact us

Privacy questions and requests: support@wizawiz.com. General support: support@wizawiz.com. If you are in the EU/EEA or UK and we have appointed a representative under Article 27 GDPR / UK GDPR, their details will be shown here.

Questions about this document? Email support@wizawiz.com.

Use your browser's print function to save a copy.

© 2026 Wizawiz. All rights reserved.

Terms of ServicePrivacy PolicyHome