Privacy Policy
How WenOX processes account, usage, content, payment, and technical data.
1. Scope and controller
This notice covers personal data processed through WenOX websites, accounts, API services, and CLI connections. The intended controller following restoration is ATSIZ YAZILIM LTD, company no. 16324501, at 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ. For enterprise content, WenOX may be a processor under a separate data processing agreement while remaining controller for account administration and billing.
2. Data we process
- Account data: name, email, optional profile information, protected credentials, linked Google/GitHub identifiers, verification, and agreement records, received from you or your selected identity provider.
- Usage and transactions: model identifiers, request/session references, token counts, Credit usage, limits, wallet entries, orders, gifts, referrals, and payment/refund status.
- Content: prompts, selected code/files, tool results, and outputs transmitted to fulfil AI requests, plus material you deliberately attach to support cases.
- Technical and security data: IP address, browser/device information, cookies, sessions, error details, anti-abuse signals, and security events.
- Payment data: transaction reference, amount/currency, billing details, and status received from the provider chosen at checkout. Full card credentials are handled by the payment provider.
3. Purposes and lawful bases
- Contract: create/authenticate accounts, deliver requests and purchases, calculate usage, manage limits, and provide support.
- Legitimate interests, balanced against your rights: prevent fraud/abuse, protect accounts and infrastructure, investigate faults, and improve reliability.
- Legal obligation: accounting/tax records, valid disclosures, and regulatory compliance.
- Consent: optional marketing or non-essential tracking where required. You may withdraw consent without affecting earlier lawful processing. Reading this policy is not blanket consent.
Necessary account and transaction information is required for paid access; refusing it may prevent service. Optional profile fields are voluntary. Automated usage/security controls may restrict access; you may ask support to review a disputed restriction, including any legally protected automated-decision rights.
4. AI content and CLI
Selected content is sent to the model infrastructure needed to answer your request. Do not submit unnecessary personal data, secrets, or content you cannot lawfully share. CLI features may read project files, generate tool results, and run authorised actions depending on the feature and permissions you enable. Local session files are distinct from server usage records.
Request metadata supports metering and limits. This notice does not guarantee zero retention by all upstream providers or identical data practices across every model. Provider retention, processing, and any training permissions depend on the applicable service and written enterprise commitments. A new processing purpose needs an appropriate lawful basis and updated notice; this policy does not grant blanket permission to train on customer content.
6. Retention and security
Account data is kept while needed to supply the account. Usage/security records are kept as needed for billing, fraud prevention, administration, and disputes; financial records follow statutory periods. After closure, data needed for legal duties or claims may remain; other data is deleted or anonymised under the operational retention schedule. Backups can remain until their normal rotation. The exact retention schedule and upstream content settings must be verified before this review draft is published.
We use proportionate technical and organisational safeguards, including access controls and credential protection. Absolute internet security cannot be guaranteed. Protect your credentials and report suspected incidents; reportable breaches are handled and notified as required by law.
7. Rights and complaints
Subject to law and its exceptions, you may request access, correction, deletion, restriction, portability, object to processing, withdraw consent, and request review of qualifying automated decisions. Use dashboard support or the company contact page, mark it as a privacy request, and supply proportionate identity information rather than passwords/API keys. We respond within the legal deadline and explain any lawful restriction. Controller identity and a monitored privacy contact must be verified before publication.
You may complain to the UK Information Commissioner's Office at ico.org.uk or another competent supervisory authority. Local rights, including applicable Turkish data-protection rights, apply where their legal conditions are met. Services are intended for adults; contact us if a child may have supplied data. Material policy changes are communicated as required.
Contact us with your account or order reference.