Privacy Policy
The short version
- We store the sign-in tokens for your ChatGPT account on our servers. That is unusual for a SaaS, and it is the whole point of Wirebot: your assistant keeps working while your devices are off. Tokens are encrypted, used only to run your own instance, and you can revoke them at any time.
- Your files, chats, and sessions live on a dedicated instance that is yours alone — not in a shared database.
- We never sell your data, never show ads, and never train AI models on your content.
- Wirebot is an independent, one-person business. There is no data team mining your chats. The business model is simple: you pay for hosting, and that's it.
This summary is here to help. The full policy below is what applies.
1. Who we are
Wirebot ("Wirebot", "we", "us") is the website wirebot.ai and the Wirebot Cloud hosting service, operated by Stephan Gomer, a sole proprietor (jednoosobowa działalność gospodarcza) established in Poland. For anything related to this policy, contact support@wirebot.ai.
This policy covers the website and Wirebot Cloud. If you self-host the open-source Wirebot software on your own hardware, we receive no data from it at all — this policy simply has nothing to apply to.
2. What we store, and why
Wirebot is deliberately minimal: we store what the service needs in order to run, and little else.
Account data
Your email address and the messenger accounts you connect (for example, your Telegram user ID). We use these to sign you in, provision your bot, bill you, and contact you about the service.
Your ChatGPT credentials
This is the main way Wirebot differs from a typical SaaS. When you connect your ChatGPT account, we store the resulting OAuth tokens on our servers. Most products keep credentials only on your device; Wirebot cannot, because your dedicated instance needs them to talk to OpenAI on your behalf 24 hours a day, including when every device you own is off.
These tokens are:
- stored encrypted at rest;
- used only by your own instance, to operate your assistant;
- never used by us to access your ChatGPT account for any other purpose;
- deleted when you disconnect your account or your subscription ends.
You stay in control from the outside too: you can invalidate the tokens we hold at any time from your OpenAI account's security settings (for example, "log out of all devices").
Messenger credentials
The bot tokens and related settings for the Telegram, Slack, or Discord bots you connect. Same treatment as above: encrypted, used only to run your bot, deleted when you disconnect.
Your instance content
Your assistant runs on a dedicated instance that is yours alone. Whatever accumulates there is your private content: files you send it, conversation history, the assistant's memory, browser sessions, and any logins you ask it to save. This can include sensitive information — you decide what to give it. Instances are isolated from one another, and your data never mixes with other customers'.
Billing data
Payments are processed by Stripe. We never see or store your full card number. We keep subscription status and invoice records (as Stripe provides them) for accounting and tax purposes.
Technical data
Standard server logs (IP addresses, request and error logs) for security and operations, and basic product analytics on the website and dashboard so we can see which features are used. We do not use advertising trackers, and analytics never includes your instance content.
3. How we use your data
- To provide the service: provisioning and running your instance, connecting your accounts, delivering messages.
- To bill you and keep required accounting records.
- To answer your support requests.
- To keep the service secure and prevent abuse.
- To comply with legal obligations.
Where the GDPR applies, our legal bases are: performance of our contract with you (most of the above), legitimate interests (security, abuse prevention, minimal analytics), legal obligation (accounting, tax), and consent where we ask for it.
4. What we never do
- We never sell or rent your data to anyone. No data brokers, no "partners".
- We show no ads and do no cross-site tracking.
- We never use your content to train AI models, and we don't let anyone else do so. (Your prompts do go to OpenAI — under your own account and OpenAI's terms; check your OpenAI data-control settings for how they handle it.)
- We don't read your conversations or files. Day-to-day operation is fully automated. A human looks at your content only if you ask for support on something that requires it, if we have to investigate abuse or a security incident, or if the law requires it.
5. Who else processes your data
We use a small number of service providers, each of which receives only what its role requires:
- Infrastructure providers — the data centers our servers run in.
- Stripe — payment processing.
- OpenAI — your prompts and the assistant's responses go to OpenAI under your own ChatGPT account and OpenAI's terms. Wirebot is not affiliated with OpenAI.
- Telegram, Slack, Discord — your messages necessarily pass through the platform you chat on, under that platform's privacy policy.
- Email and analytics providers — transactional email, and usage analytics for the website and dashboard only.
We may also disclose data if the law genuinely requires it, or in connection with a sale or reorganization of the business — in which case this policy continues to protect it.
6. Where your data lives
Our infrastructure runs with reputable cloud providers. Where personal data of EU, EEA, or UK users is transferred outside those regions, we rely on adequacy decisions or standard contractual clauses.
7. Security — and honesty about it
We protect your data with encryption in transit (TLS) and at rest for credentials and tokens, per-user isolation of instances, restricted production access, and prompt security updates. The service is intentionally small and simple, which keeps the attack surface small too.
We also owe you honesty: no online service — not us, not the biggest companies in the world — can promise perfect security. What we promise is sensible engineering, storing as little as possible, and telling you the truth. If a security incident affects your data, we will notify you without undue delay, tell you what we know and what we're doing about it, and, where the GDPR applies, notify the supervisory authority within 72 hours.
8. How long we keep things
- Instance content — kept while your subscription is active, plus a 30-day grace period after it ends (so you can come back or export), then permanently deleted.
- Backups — deleted copies age out of backups within about 35 days.
- ChatGPT and messenger tokens — deleted when you disconnect the account, and at the latest when your instance is deleted.
- Server logs — kept up to 90 days.
- Billing records — kept as long as tax and accounting law requires.
9. Your rights
You can ask us at any time to access, correct, export, or delete your personal data, to restrict or object to processing, or to withdraw consent you previously gave. If you are in the EU or EEA, these are your GDPR rights, and you can also complain to your local supervisory authority. Wherever you are, the simplest path is the same: email support@wirebot.ai and we'll sort it out. We may need to verify that a request really comes from you.
Most of it you can do yourself, instantly: disconnect accounts, delete files on your instance, or cancel your subscription from the dashboard — deletion then follows the schedule in section 8.
10. Children
Wirebot is a paid service that operates an autonomous assistant under your accounts. It is not intended for anyone under 18, and we don't knowingly collect data from anyone under 18.
11. Changes to this policy
If we make material changes, we will notify you by email or in the dashboard with reasonable advance notice before they take effect. The current version always lives at wirebot.ai/privacy.html.
12. Contact
Stephan Gomer
Warszawa, Poland
NIP: 1133096755
support@wirebot.ai