- Account details— your name and email, and which firm and clients you’re part of.
- Financial and business data — pulled from the systems you connect (an accounting platform like QuickBooks, a point-of-sale, a bank feed), at your direction, to produce the views and findings you asked for.
- Content you create — conversations with the advisor, notes, and the facts Waykeep remembers about a business.
- Basic usage and security logs — enough to run the service, keep it safe, and support you.
- We don’t sell your data, and we don’t run ads.
- We don’t use your data to train our own models, and the AI providers we use (below) contractually don’t train on it either.
- We never send your credentials or encryption keys to any AI model.
We use your data to operate Waykeep for you: to read your connected systems, compute the views and findings your expert’s methodology calls for, power the advisor, remember what matters, keep the service secure, and support you. That’s it.
- Data is encrypted in transit and at rest. The tokens that let us reach your connected systems get an extra layer of envelope encryption — a leak of the database alone yields nothing usable without a separate key.
- Third-party personal information is tokenized at the point it enters Waykeep, so the raw values are isolated from what the expert and the AI ever see.
- Every read is scoped to the tenant it belongs to at the database level, which is what enforces the client–expert firewall below.
Waykeep is two-sided, and the boundary between the two sides is the point of the product. A client’s data is visible to that client and to their expert — the firm advising them — and to no other client.
Within a firm, visibility follows role, and some things a client marks private stay with the client and are not shared up to the expert. Waykeep enforces this in the software, not by policy alone.
We use a small set of sub-processors to run Waykeep. Each sees only what its job needs:
- Anthropic — powers the AI advisor. Conversation content and the business data you surface through it are processed to generate answers; its commercial API does not train on your data.
- OpenAI — computes the search vectors that let Waykeep recall relevant facts. It does not train on your data.
- Neon — the managed database where application data is stored, encrypted at rest.
- Fly.io — hosts and runs the application.
- Resend — sends sign-in and transactional email.
- Google — the sign-in provider (email and basic profile, for authentication only).
- Intuit / QuickBooks and the other platforms you connect — the sources of the financial data you authorize Waykeep to read.
The current list, with data categories and locations, lives in our sub-processor register and stays in step with what the service actually uses.
You can export or delete your data. Disconnecting a connected system stops any further reading of it, and deleting your account removes your personal data, subject to what we must keep for legal or security reasons.
To make a request, email contact@waykeep.ai.
We keep your data for as long as your account is active and as needed to run the service. When it’s no longer needed — or you ask us to delete it — we remove it, keeping only what the law or basic security requires, and for no longer than necessary.
Waykeep is a tool for businesses and is not directed to anyone under 18. We don’t knowingly collect data from children.
We may update this policy over time. Material changes get a notice in-app, and the “last updated” date above always reflects the current version.