Privacy Policy
Last updated: August 3, 2026
Wimbly, Inc. (“Wimbly,” “we,” “us,” or “our”) respects your privacy. This Privacy Policy explains how we collect, use, share, and protect personal information when you visit our website, create an account, or use our AI business development analyst (collectively, the “Service”).
If you have questions about this Policy, please contact us at founders@wimbly.ai or at Wimbly, Inc., 130 East 63rd Street, New York, NY 10065.
1. Scope and Roles
Wimbly, Inc. provides a business-development platform for legal and
professional-services firms.
This policy covers two different relationships. When we handle information
about visitors to our website and people who hold Wimbly accounts — names,
work email addresses, billing details — we decide how that information is used
and we are responsible for it directly.
When we handle the content our customers put into Wimbly — their email,
documents, matter information, and the outputs we generate from them — we act
only on that customer's instructions. Under United States state privacy laws we
are a service provider for that content. The customer decides what goes in, who
may see it, and when it is deleted. The terms governing that relationship are
set out in our Data Processing Addendum, available on request.
2. Information We Collect
2.1 Account information
Account information. Name, work email address, employer, role, and password or single sign-on identifier.
Billing information. Billing contact, billing address, and tax identifiers. Payment card details are handled directly by our payment processor (see Section 5); we do not store full card numbers on our systems.
Communications. Messages you send us, support tickets, and survey responses.
Customer Data. Documents, files, prompts, and other content you submit to the Service, plus the outputs the Service generates for you.
2.2 Information from laptop and connected accounts
The Service can read information from your device and connected business applications, but only after you grant explicit permission, and only to the extent needed to do the work you have asked it to do.
Files and folders you select. When you point the Service at a file, folder, or shared drive, we access only the items in scope and only for the duration of the task. We do not browse other parts of your file system.
Email and calendar. If you connect Gmail, Outlook, or another mail/calendar provider, we access messages, calendar events, and contact metadata you authorize, using read-only or task-specific scopes wherever the provider supports them.
Other local applications. If you connect Slack, your CRM, or similar tools, we access the data you authorize through the relevant API.
You can revoke any of these permissions at any time, either in the Service or directly with the upstream provider (for example, in your Google or Microsoft account).
2.3 Information collected automatically
Usage data. Pages visited, features used, clicks, search queries within the Service, time spent, and similar diagnostic information.
Device and log data. IP address, browser type and version, operating system, device identifiers, referring URL, and timestamps.
Cookies and similar technologies. Strictly necessary cookies required to make the Service work, plus, where you consent, analytics and marketing cookies. You can manage cookie preferences through our cookie banner or your browser settings.
2.4 Information from third parties
We may receive information about you from business partners, marketing platforms, or publicly available sources, for example to verify a corporate domain or enrich a sales contact record. We will only use such information consistent with this Policy.
2.5 Information from the Wimbly extension
If you install the Wimbly browser extension or the Wimbly add-in for Outlook, we receive the messages you type to the assistant and the drafts you approve. If you separately turn on the LinkedIn features, we also receive professional information from LinkedIn. Section 13 describes both in full.
2.6 Sensitive information
Some of what we handle is sensitive personal information under California law — specifically, the contents of the mailbox you connect. Section 9 explains your rights over it.
3. How We Use Information
We use information to:
Provide, operate, secure, and improve the Service, including authenticating users, maintaining session state, and supporting integrations you connect.
Process Customer Data on your instructions to generate outputs.
Communicate with you about your account, security, support, and product updates.
Send marketing communications about Wimbly, where permitted by law and subject to your right to opt out.
Detect, prevent, and respond to fraud, abuse, security incidents, and violations of our Terms.
Comply with legal obligations, enforce our agreements, and establish or defend legal claims.
4. AI Processing and Our Position on Training
AI is at the core of the Service. We have built our data practices to reflect the sensitivity of the information our customers share with us, including standards informed by professional and legal services norms.
No training on Customer Data. We do not use Customer Data, including your prompts, uploaded documents, connected-account data, or generated outputs, to train, fine-tune, or improve our own foundation models or any third-party foundation models.
Zero retention with model providers. Wimbly currently uses Anthropic as its sole AI model provider under enterprise terms that prohibit training on Customer Data and provide zero data retention. Before adding or changing AI model providers, we will update this policy and our subprocessor list in Section 5.
Outputs. Outputs are generated for your account and are part of your Customer Data. AI outputs can be inaccurate or incomplete; you are responsible for reviewing them before relying on them.
Aggregated and de-identified data. We may use aggregated or de-identified data that does not identify you or your customers to operate, secure, and analyze the Service. We will not attempt to re-identify any such data.
No automated decisions with legal effect. We do not use the Service to make decisions about you that produce legal or similarly significant effects without meaningful human involvement.
5. How We Share Information
We do not sell personal information, and we do not “share” it for cross-context behavioral advertising as those terms are defined by California Law. We have not done so in the preceding twelve months.
We share information only with the categories of recipients below:
Sub Processors who help us run the Service. Here is our full list of sub-processors https://app.wimbly.ai/sub-processors
Business tools we use to run our company. Marketing automation and CRM, communications tools, and payment processors. These vendors process information about visitors, prospective customers, and account holders, not Customer Data.
Integrations you authorize. When you connect the Service to Gmail, Outlook, your CRM, or another application, information flows between that application and the Service in line with the access you granted.
Professional advisors. Lawyers, auditors, accountants, and insurers, under confidentiality.
In a corporate transaction. If we are involved in a merger, acquisition, financing, or sale of assets, information may be disclosed to the counterparty and their advisors, subject to confidentiality.
For legal reasons. When we believe in good faith that disclosure is required by law, regulation, legal process, or government request, or is necessary to protect the rights, property, or safety of Wimbly, our customers, or others. Where legally permitted, we will notify the affected customer before disclosing Customer Data.
We will give you a reasonable opportunity to object to material changes.
6. Retention
We keep personal information only as long as necessary for the purposes for which it was collected, plus a reasonable period to comply with legal obligations and to defend legal claims.
Audit records. Wimbly retains content-free audit logs recording access activity, including who accessed particular resources and when, without retaining the underlying content. These records are retained for seven years to support security, compliance, and record-keeping requirements. Audit records may remain after the deletion of Customer Data and are not subject to deletion requests where retention is necessary to preserve an accurate record of system activity.
Customer Data. Retained for the duration of your subscription. After termination, we will, on written request received within 30 days, make Customer Data available for export and will then delete or anonymize it within an additional 30 days, except where longer retention is required by law.
Account and billing information. Retained for the life of the account and for up to seven years after closure for tax, accounting, and audit purposes.
Usage and log data. Retained in identifiable form for up to 12 months, then deleted or aggregated.
Marketing data. Retained until you unsubscribe or object, plus a short suppression period to honor your opt-out.
Where you ask us to delete information sooner, we will do so unless we have a lawful basis to keep it.
7. Security
We take the security of your information seriously, especially because professional users entrust us with confidential business material.
Encryption in transit and at rest. Customer Data is encrypted in transit using TLS 1.2 or higher and at rest using AES-256.
Access controls. Access to production systems and Customer Data is limited to a small number of authorized personnel on a need-to-know basis, protected by single sign-on, multi-factor authentication, and audit logging.
Network and infrastructure security. Wimbly is operated from the United States, and all Customer Data is stored and processed in U.S. regions. We use a limited number of specialized infrastructure providers for application hosting, database and graph storage, workflow execution, object storage, and email delivery. Each provider is contractually bound and reviewed before onboarding. Our current sub processors are listed in Section 5
Vendor diligence. Subprocessors are reviewed before onboarding and re-reviewed periodically.
Personnel. Employees and contractors with access to personal information are bound by written confidentiality obligations and receive security and privacy training.
Incident response. We maintain a written security incident response plan. If we become aware of a personal data breach affecting your information, we will notify you without undue delay and in line with applicable law.
No system can be guaranteed to be 100% secure. We will continue to invest in our security program, including pursuing recognized industry certifications (such as SOC 2) as we scale.
8. Where We Operate
Wimbly is offered only in the United States. As stated in our Terms and Conditions, the Service is available only to individuals located in, and organisations established in, the United States, and is not offered to residents of the European Union, the European Economic Area, the United Kingdom, or Switzerland.
We store and process personal information in the United States. We do not offer the Service to, and do not knowingly collect personal information from, individuals in those regions.
If we begin offering Wimbly outside the United States, we will update this policy and put appropriate transfer mechanisms in place before doing so.
9. Your Rights
Depending on where you live, you may have the following rights with respect to your personal information:
Access the personal information we hold about you.
Correct information that is inaccurate or incomplete.
Delete personal information, subject to legal exceptions.
Restrict or object to certain processing, including processing based on legitimate interests.
Receive your information in a portable format.
Withdraw consent where processing is based on consent, without affecting the lawfulness of prior processing.
Right to limit the use of sensitive personal information. The contents of the mailbox you connect are sensitive personal information under California law, because we are not the intended recipient of those messages. We use them only to provide the features you asked for, and never to infer characteristics about you. You may ask us to limit their use further at any time.
Non-discrimination. We will not deny you service, charge you a different price, or give you a lower quality of service because you exercised any of these rights.
Authorised agents. You may authorise someone else to make a request on your behalf. We will ask for proof that you gave them permission, and we may ask you to confirm it directly.
For California residents, you also have rights under the CCPA, including the right to know, delete, correct, and limit the use of sensitive personal information, and the right not to be discriminated against for exercising those rights. We do not sell or share personal information for cross-context behavioral advertising.
To exercise any of these rights, email founders@wimbly.ai. We may need to verify your identity before responding. If we process your information on behalf of a customer (for example, you are an end user whose data was uploaded by a corporate customer), we will refer your request to that customer.
10. Marketing and Your Choices
You can opt out of marketing emails at any time using the unsubscribe link in any message or by emailing founders@wimbly.ai. We will continue to send you transactional and account-related communications.
Cookies. Our website uses only the cookies strictly necessary to make it work. We do not use analytics, advertising or tracking cookies, and we do not allow third parties to track you across our site.
11. Children
The Service is not directed to children under 18, and we do not knowingly collect personal information from them. If you believe we have collected information about a child, please contact us so we can delete it.
12. Third-Party Services
The Service may include links to third-party websites or integrate with third-party applications. Those third parties are responsible for their own privacy practices. We encourage you to review their policies before sharing information with them.
13. The Wimbly Browser Extension and Outlook Add-in
Wimbly offers a browser extension for Microsoft Edge and Google Chrome, and an add-in for Microsoft Outlook. Both display the same Wimbly assistant alongside your mailbox.
What they read. When you open the Wimbly panel, it reads the message you currently have open in Outlook or Gmail — its sender, recipients, subject and body — so the assistant has the context of the conversation in front of you. It reads only the message on screen, only while the panel is open, and does not scan, index or bulk-read your mailbox. That message stays in the panel; the extension does not upload it. Reading your mailbox on our servers is a separate thing you turn on, described in Section 14.
What they store on your device. A revocable sign-in token, the identifier of your current conversation, a record of which panel messages you have already seen, and a short queue of items waiting to upload. No message content is stored, and no password or Google or Microsoft account token is ever stored.
What they send to us. The messages you type to the assistant, the drafts you approve, and the requests you make of the panel.
Drafts. Drafts are placed in your own composer or your own mailbox drafts folder for you to review, edit and send yourself. Wimbly does not send email on your behalf.
LinkedIn. Wimbly uses LinkedIn in two distinct ways. Both are optional and both require you to opt in.
Relationship capture. If you turn this on and grant the additional permission your browser requests, the extension records the public professional details displayed on LinkedIn profile and company pages you visit: for a person, their public profile identifier, name, headline, current company and location; for a company, its identifier, name, industry and approximate size. Each record also carries the page address and the time it was read. The extension reads only what is already displayed on pages you choose to visit.
Connections export. If you ask Wimbly to import your professional network, the extension opens LinkedIn's own "Download your data" page and, on your instruction, selects the connections archive and submits LinkedIn's request form on your behalf. LinkedIn prepares the archive and notifies you. When you provide that archive to Wimbly, we store the original file and extract the people in your network — their names, profiles and the organisations they work for — to map your firm's professional relationships. We request only your connections. We do not post, send messages, or otherwise act on LinkedIn as you.
Information about people who are not Wimbly users. Both LinkedIn features collect information about people who do not use Wimbly — the professionals whose profiles you view, and the people in your own network. We collect only professional information that LinkedIn already displays publicly, and we use it solely to map your firm's professional relationships. This information stays within the firm that collected it.
If you are not a Wimbly user and believe we hold information about you, write to founders@wimbly.ai and we will tell you what we hold and delete it on request.
You can withdraw the LinkedIn permission at any time in your browser's extension settings, and you can ask us to delete an imported archive and the relationship data derived from it.
14. Connected Mailboxes
With your permission, Wimbly connects to your work mailbox to provide the features described in this policy: understanding your professional relationships and history, surfacing follow-ups, and drafting messages.
Microsoft 365 and Outlook. We read messages, calendar events and contact information in the mailbox you connect, and create draft messages in it.
Gmail. We read the messages in the mailbox you connect, and create draft messages in it.
In both cases Wimbly cannot send email on your behalf. We do not use mailbox data for advertising, and we do not use it to develop, improve or train generalised AI models.
Google API Services. Wimbly's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Gmail data only to provide user-facing features in Wimbly. We do not transfer it except as necessary to provide those features, for security purposes, or to comply with applicable law. We do not use it for advertising, and we do not use it to develop, improve or train generalised AI models. No Wimbly employee reads your messages except where you have given your specific prior agreement to view a particular message, to investigate a security issue or abuse, or where required by law.
15. Changes to This Policy
We may update this Policy from time to time. If we make material changes, we will notify you through the Service or by email before the changes take effect, and will update the “Last updated” date above. Your continued use of the Service after the effective date constitutes acceptance.
16. Contact Us
For privacy questions, requests, or complaints, contact us at:
Wimbly, Inc. 130 East 63rd Street New York, NY 10065
If you are in the European Economic Area or United Kingdom and would like to contact us about this Policy or your rights, you may also use the email address above. We will respond within the timeframes required by applicable law.