Privacy Policy
Windy Word Privacy Policy · Version 22 · Last updated 10 October 2026
Windstorm Labs LLC ("we", "us") provides Windy Word. This policy explains what we receive, what we do not, and what you can do about it.
1. The short version
Windy Word transcribes speech on your device, using engine files stored on your computer. Dictating does not require an internet connection, and when you dictate locally your audio and the resulting text stay on your machine.
We do receive measurements about how the app is used — how long, how often, how long each dictation runs, which engines and languages you choose, what kind of machine you run it on, and approximately where you are (country, region, and city or metro area, from your network address). Measurements are about usage, not about what you said.
Optional cloud features work differently, and section 4 says how. Windy Vault, when it opens and if you use it, will hold secrets for you (section 4b). Windy Mail will keep an address book for you if you turn it on (section 4c). The helpers (AI agents) you create will also have a housing history, a record of the machines they run on (section 5a; coming soon).
We have tried to write this without absolutes. Instead of promising that something can never happen, we describe how the system is built and what we do if something goes wrong (section 9).
2. What the app sends us
For the local app, the app reports:
| Category | Examples |
|---|---|
| Account | Your Windy account identifier; whether your email or phone is confirmed |
| Usage volume | Hours of use per day and per week; number of dictation sessions; total words produced (a count, not the words) |
| Activity state | Whether the app is actively in use or idle |
| Recording characteristics | Length of each dictation (a duration, not the audio); average and distribution of lengths |
| Configuration | Which engines are installed and selected, and the share of your dictation time each one accounts for; preferred and detected languages; translation language pairs used; app version; operating system and platform |
| Settings choices | Which options you have picked in the app — for example recording mode, paste behaviour, theme, widget, alert interval, audio and video quality settings, and which keyboard shortcuts are assigned (the assignment, never what you type with them) |
| Library size | How much space your local recordings and transcripts occupy on your own disk (a byte count and item count — the library itself never leaves your machine) |
| Clone Capture readiness | If you use Clone Capture: how many minutes of usable audio you have captured and coverage percentages — measurements of quantity and completeness, not the audio itself |
| Device characteristics | Processor family and core count; memory; graphics hardware and video memory; architecture; device model identifier (for example "MacBook Air M2"); number of displays; whether running on battery or mains; free disk space at install |
| Approximate location | Country, region, and city or metro area, derived from the network address your app connects from, plus your timezone and the local time of day you use the app |
| Machine condition during a dictation and in app health reports | How busy the processor and the graphics processor were, as percentages; how full the graphics memory was; and how hot the machine was, as a coarse state only (normal, warm, hot, or slowing itself down), where your system reports it. Measured around the moment of a transcription and in the app's periodic health reports, so we can tell a slow engine apart from a busy or overheating computer. These are readings only: never an exact temperature, and never a serial number or any other identifier of your hardware |
| Reliability | Crash and error reports, performance timings, install and update outcomes, permission grants and denials |
| Notices | Whether an in-app notice was shown, dismissed, or acted on |
| Browser button | Whether each press of the Windy Word browser button worked and, if not, at which step and why (for example, the app was not running, or the page does not allow typing); the kind of box it was used in (a text box, a PDF, a browser-internal page, or other); and which browser brand and extension version. Whether the Windy Word extension is installed and switched on in Chrome on this computer: the app reads Chrome's own setting for our extension and nothing else in Chrome's settings, and sends only one of 'not installed', 'off', 'on' or 'unknown'. The measurement is sent by the Windy Word app on your computer; the extension itself sends nothing. Never the page address, site name, page title, field name, or anything you said or typed |
What is not in that list: your audio, your dictated text, your transcripts, your translations, your clipboard, the names of your files, the identity of the applications you paste into (apart from the browser brand shown in the table above), or the contents of your screen.
This is enforced rather than merely intended: our measurement endpoint rejects events whose fields match content-like names — text, body, message, prompt, transcript, subject, completion and similar. An event carrying your words is refused by the server rather than stored.
You can turn this off. Settings ▸ Help improve Windy Word is on unless you turn it off, and the setup wizard explains it before you start. Turning this off stops collection. Delete my usage data, next to it, erases what was collected: it asks us to erase the usage measurements this installation has sent, and it works whether the switch is on or off. We keep a record that you asked, and of your on/off choice, but not the measurements themselves.
3. Approximate location — what we do and do not derive
We derive an approximate location — country, region, and city or metro area — from the network address your app connects from, together with your device's timezone. "Metro area" means a broad market region (for example, the Albany metro), not a neighbourhood and not a point on a map.
We do not collect GPS or precise location, we do not collect your street address, and we do not collect the identity of your wireless network. Location derived from a network address is approximate by nature: it is often wrong at city level, particularly on mobile networks, and we treat it accordingly.
We use it to understand which places the product is used in, which languages matter where, when during the day people dictate, and to make regional offers and announcements relevant to where you are.
3a. Device characteristics, and why we look at them
We record what kind of machine you run the app on — processor, memory, graphics hardware, architecture and device model — and which engines you actually use on it. The engines have very different speed and accuracy characteristics, and the only way we can recommend the right one for a given machine is to measure which ones perform well on which hardware in real use.
We identify the machine by model (for example "MacBook Air M2"), not by serial number, and each installation is associated with a randomly generated identifier rather than anything derived from your hardware. That identifier can be reset by reinstalling and is deleted when you delete your account.
This section is about the Windy Word app on your computer. A helper's housing history is different and is described in section 5a, which will record some hardware details.
We also record how busy and how hot the machine was at the moment of a dictation, because without it the speed figures are unreadable. The same engine on the same laptop can transcribe twice as fast as you speak or three times slower, and the difference is usually that the computer was busy doing something else or had heated up enough to throttle itself. Measured on real machines, one engine fell from 4.9x to 1.5x for exactly that reason. Without knowing the machine's condition we would have blamed the engine and "fixed" the wrong thing.
This is a percentage and a coarse state — never a temperature reading tied to you, never a list of what else you were running, and never the names of other applications.
4. Optional cloud features
If you choose to turn on a cloud feature — cloud compute, Windy storage, or cross-device sync — then the content you send to that feature does leave your device, because that is what the feature does. When you use one:
- audio and text you submit are transmitted to our servers, and processed there or by a service provider acting for us (section 8 names them);
- content is encrypted in transit. Not all of our storage is encrypted at rest yet: the words you keep in Windy storage are stored as plain text in our database;
- content is retained per section 7 and deleted on request;
- you can stop using cloud features at any time and continue locally.
Cloud features are off unless you turn them on. We say this explicitly because "your words stay on your device" is only true of local use, and we would rather be accurate than tidy.
4a. The browser extension
The Windy Word browser extension is a separate, optional install from the Chrome Web Store or Microsoft Edge Add-ons. The app works without it, and removing it from your browser removes everything in this section.
It runs on every website you visit, and we would rather explain that than bury it. The extension's job is to put a dictate button next to the message box you are already typing in. We cannot know in advance which sites those are — for you it may be a support desk, a hospital portal, or your own company's tools — so the extension asks to run on all https pages rather than keeping a list of approved ones. On each page it looks for the site's own microphone or composer, puts our button beside it, and otherwise does nothing.
The extension has no server of its own, and sends nothing to us. It talks to one place: the Windy Word application already installed on the same computer, over the browser's native-messaging channel — a pipe between two programs on your machine that does not cross the network. The messages it sends are the commands start, stop, state and level. They do not include the address of the page, its title, or its contents.
Specifically, the extension does not collect your browsing history, does not record which sites you visit, does not read pages for us, and does not run any code it downloads.
When you dictate through the button, the recording and transcription are done by the desktop app, so sections 1, 2 and 3 apply to them unchanged. The resulting text goes to the message box you clicked in — either typed in by the app or written directly into the editor by the extension. Your archive is the same local archive the app already keeps.
The permissions the browser shows you at install are used as follows: nativeMessaging to reach the desktop app; scripting and access to https pages to place the button; activeTab to act on the tab whose button you clicked; and storage for your own extension settings, held in your browser.
4b. Windy Vault
Coming soon. Not available yet. Today no Windy product holds your secrets in Windy Vault or connects to your Google account. This section describes what Windy Vault will do when it opens, and we will update this policy if that changes.
Windy Vault will keep the passwords, tokens and keys you choose to store, and let your helpers use some of them for you without you pasting them anywhere. It will be off unless you turn it on, and you will agree to the Windy Vault terms first.
- What we will hold. Your items, encrypted (each with its own key); the names of the services you connect, which permissions you gave, and the connection details those services give us; an activity log of every time an item was used or changed (who, what kind of action, which item by an opaque reference, when, and whether it worked, never the secret itself); and the settings you choose.
- How it will be protected. Items will be encrypted before they are stored. Some items will be "agent-usable" (the default): the Vault can open them so your helper can work while you are away. Others will be "passkey-only" (your choice): only you can open them, and the Vault cannot. We will say "encrypted, used only through the Vault" for the first kind and we do not call it zero-knowledge.
- Who can reach it. The Vault will run on Cloudflare. The keys that let it work for your helpers will be held in the same Cloudflare account, so Cloudflare, and the one person who logs in to that account, could technically reach agent-usable items. Passkey-only items are not reachable that way. We do not read your items, and we will not give anyone else a way to. If a court or authority orders us to hand over agent-usable items we may have to, and where the law allows we will tell you first; passkey-only items we cannot open.
- Your helpers. A helper will get only what you approved: a short-lived token for one service (up to 15 minutes for GitHub and up to 1 hour for others), or, for services that only have a permanent key, the key itself under a logged lease. A token a helper already holds keeps working until it expires even if you revoke it, unless the service lets us cancel it. A tricked helper can misuse a token it legitimately holds for that time. Google is the exception: Windy Vault performs Google actions itself (sends the email, creates or changes the event); a helper never receives Google access.
- Copies. We may keep encrypted copies at Cloudflare (R2) and at Backblaze, and, if you choose, in Windy Git, Windy Cloud storage, GitHub or your own server. They will be unreadable without your keys. Your own recovery kit and your own storage copy will be able to open your lockbox on your own computer even if Windy disappeared.
- What we will send to Windy's own monitoring. Counts, timings and pseudonymous references (not your name, not the item, not the secret) so we can notice failures and abuse. This is a security measurement made by our servers; it does not depend on the "Help improve Windy Word" switch in section 2.
- Deleting. Disconnecting a service will delete our copy of its token. That does not cancel the token at that service unless the service lets us, and we will say which when you disconnect. If you delete your account, everything will be locked at once, and 30 days later we will destroy your keys, delete the copies we host, and remove our connections to your services. Encrypted backups can remain until they expire, and they cannot be opened once your keys are gone. Copies you keep in your own storage remain yours.
4b.1 Google data in Windy Vault
Coming soon. Not available yet. Today no Windy product connects to your Google account. This section describes what Windy Vault will ask for and do when the feature opens.
If you connect your Google account to Windy Vault, you will choose which of three permissions to give. We will ask for no others.
- Send email on your behalf (
gmail.send). This will let Windy Vault send an email from your Google account when you or a helper you approved asks it to. It is a send-only permission: with it we cannot read, search or delete your email, and we will not ask for permission to. - View and edit events on all your calendars (
calendar.events). This will let Windy Vault create and change calendar events. Google does not offer a narrower permission that can only create and change events, so this one can also read and delete events on every calendar you can edit. We therefore will set it up so that the Vault makes the create or change itself and never hands a helper the raw token (Google access will never be handed to a helper); and deleting an event will always need your tap. - View your availability in your calendars (
calendar.freebusy). Windy may check when you are free or busy on your Google calendars, only to avoid double-booking you. Windy will see busy and free times, not event titles or details. When a helper asks whether you are free, Windy will tell it only the busy times.
What we will do with it. We will use Google data only to do what you asked in Windy Vault: send the email, create or change the event, or check when you are free or busy to avoid double-booking you. We will store the connection credential Google gives us, encrypted, and the details of the connection (which permissions, when connected). Windy Vault will not keep the text of an email you send, the details of an event it creates or changes, or free or busy results: it will keep only an opaque reference (Google's message or event id), what kind of action it was, whether it worked, a count and the time. The email address of the Google account you connect will be kept only as an encrypted label that only you can read. (Windy Calendar is a separate product: the busy times it uses are covered in its own section 7 rows.)
Who it will be shared with. Your Google data will not be sold, will not be used for advertising, and will not be shared with anyone except as follows: the calls we make to Google on your behalf; the people you or your helper address an email or invite to an event; the infrastructure providers in section 8 that run the Vault (they will hold only encrypted data and cannot use it for their own purposes); and where the law requires it. We will not use Google data to train AI models. When a helper you use asks Windy Vault to send an email or change an event, the result (for example that the event was created, or the times you are busy) will go back to that helper, and so to the AI model the helper runs on, as part of the feature you asked for. The Vault itself will not send your Google data to a model. Before Windy Vault opens, we will make sure that any helper of an owner who has connected Google uses, through Windy's routing service, only providers whose terms do not allow training on that content. If your helper runs on a model outside Windy, that model's own terms apply. We cannot promise how long a model provider keeps what it receives.
Who can read it. No one at Windy will read your Google data unless you ask us to, or it is needed for security or to follow the law.
How long. The credential will be kept until you disconnect Google or delete your account, then handled as above. Your activity list (the time, which helper, and the kind of action; never the message or event text) will be kept for 13 months, also after you disconnect.
How to stop it. Disconnect Google in the Vault part of your Windy profile page, and also remove Windy Vault in your Google Account permissions. Removing it at Google is what stops the credential working. When you disconnect, we will ask Google to cancel the permission and delete our copy of the credential; if Google cannot be reached we will still delete our copy and tell you to remove Windy Vault in your Google Account permissions.
Questions or concerns about Windy Vault or your Google data: write to [email protected], [email protected] or [email protected].
Limited Use. The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements. In plain words, we: (1) use Google user data only to provide or improve the Windy Vault features you can see and use; (2) do not transfer it to anyone, except to provide those features with your consent, for security (for example investigating abuse), to comply with the law, or in a sale or merger after your explicit prior consent; (3) do not let people at Windy read it, except with your explicit agreement for specific data, for security, to comply with the law, or in an anonymous aggregated form for running the service; and (4) do not sell it, use it for advertising (including retargeting or interest-based ads), use it to decide credit or lending, or use it to create, train or improve any machine-learning or AI model beyond your own personalised use of the feature.
4c. Your address book in Windy Mail
Coming soon. Not available yet. This section describes what will happen when you turn the feature on.
When you turn it on, Windy Mail will keep an address book for you. For each contact we will store the name, organisation, up to 10 email addresses and up to 10 phone numbers (with your own labels), where the contact came from (a phone import, learned from mail you sent, or added by hand), how many times you emailed them and when last, and when the entry was made or changed. We will not store photos, notes or birthdays. A search string made from the name and emails will be kept only to fill the dropdown when you type an address. A contact will be learned only from addresses you send mail to or reply to, never from mail you receive. A phone import will happen only when you tap Import. When you delete a contact we will keep its email address, with the date, so it is not added again by itself; adding it by hand clears that. Your helpers will not be able to read or change your address book. We will not share it. It will be kept until you delete a contact or your account (up to 20,000 contacts), and it will be included in your account export and removed when you delete your account, including those kept addresses.
5. Account data
We hold your name, email address, optional telephone number, confirmation status, password hash (we do not store your password itself), account creation and sign-in metadata, and entitlements.
Your email address is your recovery channel. Confirming by text message does not replace it: password reset and account recovery are available only by email.
5a. Your helper's housing history
Every helper will have a record, kept by Eternitas (the registry that issues helper numbers), of the machines it runs on and for how long, a bit like a credit file for a computer. It will help you see where your helper has lived, and help us investigate if a helper is used to do harm. Coming soon. Not collected yet. Everything below describes what will happen when it opens.
What we will record, for each machine: the network address the helper connected from; a scrambled machine identifier; the kind of machine (laptop, desktop, server, phone or unknown); the operating system; the processor type (arm64 or x86_64) and model; the graphics model; the type and size of storage; how it connects to the internet; whether it is a virtual machine; the version of the Windy software reporting; the machine's serial number, kept only as a scrambled fingerprint (the full serial number will not be stored in readable form), with its last four characters so you can recognise your own machine; and the dates it was first and last seen there. Anything the helper's software cannot read is simply left out.
Where it will come from. (a) Eternitas will note the network address on three kinds of request from your helper only: when it gets a new access pass, when it registers a key, and when it sends a housing report. It records a new address only when it changes. (b) Your helper's software (Windy Fly or Windy Connect) will send a hardware snapshot when it starts and when something changes, at most once a month. We will not ask you each time.
Who will see it. You will see the details for your own helpers. The public will see only the kind of machine and how long (for example "laptop, 6 months"), never an address, model or serial. Other Windy products will not receive it. Windy staff will not read it unless you ask us to, or it is needed for security or to follow the law.
How long. Network address records: 13 months, then deleted on a rolling basis. Hardware snapshots: for as long as the helper's number exists.
When a helper is deleted. We will not erase the record. The details will be sealed with the rest of the helper's history: you and the public will stop seeing them, and no part of our service shows them. Today there is no way to open sealed details; if we ever build one, it will be only for an investigation of misuse, and we will describe it here first. The kind of machine and how long will stay visible.
Your own network address. A network address can identify you or your household. We will not sell it or use it for advertising.
6. Communications, and how consent works
Service messages — account, security, billing and material service changes. These are part of operating your account and are not marketing.
In-app notices — from time to time, dismissible.
Marketing email and text messages — sent only if you opt in. At signup this is a separate, unticked checkbox, not something bundled into accepting the Terms. You can withdraw at any time from account settings, by the unsubscribe link, or by replying STOP to a text. Withdrawing marketing consent does not affect your free local licence or your ability to use the app.
We keep this separate on purpose. Under GDPR consent must be freely given, specific, informed and unambiguous, and consent buried inside accepted terms does not qualify. US law requires separate express written consent for marketing texts. A single "I agree" covering both verification and marketing would not be valid in either place.
7. How long we keep things
| Data | Retention |
|---|---|
| Account record | While your account exists; deleted on request, subject to legal retention duties |
| Usage measurements | Aggregated; identifiable form kept no longer than 24 months |
| Crash and error reports | 12 months |
| Cloud content (if you use cloud features) | Until you delete it, or account closure. Deleted items sit in the trash for 30 days. After that they are removed from the live service. Encrypted backups of our database can still hold the text of deleted words for up to 90 more days. Media copies are normally removed within about 8 days of the purge |
| Translation history | 12 months from each translation, or sooner if you delete it, clear your history, or close your account |
| Translation cache (the text of a translation, without your account details, kept to answer repeat requests faster) | Up to 1 hour, in memory only; never written to disk |
| Cloud dictation service records (which engine, how long it took, whether it worked; never the audio or the text) | 13 months |
| Voice Project donations (only if you choose to donate) | Up to 24 months, or until you ask us to delete them |
| Marketing preferences and consent records | Kept as evidence of consent while relevant, and after withdrawal as evidence that you withdrew |
| Text-message and call consent proof (a protected fingerprint of the phone number, not the number itself; whether consent was given or withdrawn; how and when; and which consent wording was shown. It holds no names or message content) | 4 years, then erased automatically. It stays after you delete your account, so that we can show consent if it is ever disputed |
| Windy Calendar: details of people who book you (name, email, phone, and the note they leave) | Until 180 days after the appointment ends, then erased; we keep only that an appointment took place. Sooner if you close your account, or if that person asks us to |
| Windy Calendar: busy times from another calendar you connect (only when you are busy, never what the event is) | The next 60 days only, refreshed about every 30 minutes; deleted at once when you disconnect it or close your account. The private link you gave us is stored encrypted and deleted at the same time |
| Windy Calendar: people you invite to a meeting (name, email, and whether they accepted) | Until 180 days after the meeting ends, then erased. Sooner if you close your account, or if that person asks us to |
| Windy Calendar: "don't email me again" requests from people you invited | Only a scrambled fingerprint of the address, never the address itself; kept until that person asks us to forget them |
| Windy Mail address book (coming soon): contacts and the list of deleted addresses | Until you delete them or your account; included in your export; erased with your account |
| Helper housing history (coming soon): network addresses seen | 13 months, rolling; a deleted helper's are sealed rather than deleted (section 5a) |
| Helper housing history (coming soon): hardware snapshots (machine kind, operating system, processor, graphics, storage, connection, virtual or not, version of the Windy software reporting, scrambled identifier and serial with last four characters, dates) | For as long as the helper's number exists; sealed, not erased, when the helper is deleted |
| Windy Vault (coming soon): your items (encrypted), the services you connected and the permissions you gave | Until you delete them or disconnect; then handled as in 4b. If you delete your account: locked at once, destroyed after 30 days |
| Windy Vault (coming soon): activity log (who, what kind of action, which item by reference, when, whether it worked) | Will be kept 13 months |
| Windy Vault (coming soon): monitoring counts and pseudonymous references sent to Windy's monitoring | Will be kept 90 days |
| Windy Vault (coming soon): encrypted copies at Cloudflare and Backblaze, and in storage you choose | The Backblaze copy will have a 90-day lifecycle; others until you delete them or close your account. Copies in your own storage remain yours |
8. Who else is involved
We use service providers to operate the Service, including hosting and content delivery, email delivery, text-message delivery, payment processing for paid features, and error and usage measurement. They act on our instructions and are bound by contract.
Where a cloud feature uses a third-party model provider, the provider handling your content is identified in that feature before you use it. Today that is:
- Groq, Inc. (speech recognition): receives the audio of cloud dictation on the standard tier, and of spoken translation, to turn it into text.
- Text translation. Between English and Spanish, French, German or Portuguese, your text is translated on Windy's own computers. For every other language pair, and whenever our own computers are busy, the text is passed on through Windy's own routing service to model providers whose terms do not allow them to train on it.
- Your AI helper (its replies in Windy Chat and the other places your helper answers): what you say to your helper is sent, through Windy's own routing service, to AI model providers to get its answers. Today these are Windy's own computers; Groq, Inc.; Cloudflare, Inc. (Workers AI); and OpenRouter, Inc., which passes a request on to other model hosts and which we ask not to let those hosts train on it. For an account owner's own agents, Anthropic, PBC; and, only for models chosen on paid or connected accounts, Cerebras Systems, Inc. and SambaNova Systems, Inc. Providers whose free terms may allow training on messages (Google's free Gemini tier and NVIDIA's trial API) are not used for your messages unless you choose otherwise. Each provider's own terms govern what it does with a request it receives, including how long it keeps it. The notice shown when you hatch a helper says the same in short, and we keep a record that you agreed to it.
- Cloudflare, Inc. will run the computers and the storage (R2) for Windy Vault. It will hold encrypted items and, as section 4b says, could technically reach the keys that let the Vault work for your helpers.
- Backblaze, Inc. will hold an encrypted backup copy for Windy Vault.
- GitHub, Inc., and the other services you connect (for example Cloudflare, Google) will receive the requests the Vault or your helper makes on your behalf, under their own terms.
- Google LLC: see 4b.1.
We do not sell your personal data. We do not share it with data brokers.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes.
9. If data reaches us that should not have
Systems fail and people make mistakes. Rather than promise this cannot occur, here is our commitment if it does:
- We will stop the flow as soon as we identify it.
- We will delete the affected content, and confirm deletion with any processor that received it.
- We will notify regulators and affected users where the law requires, within the time limits it sets.
- We will publish what happened and what we changed.
This is a description of our process, not an admission that it has happened.
10. Your rights
Depending on where you live, you may have the right to access, correct, delete, port, restrict or object to processing of your personal data, to withdraw consent, and to complain to a supervisory authority. Residents of the EU/EEA and the UK have these under GDPR; residents of India have comparable rights under the DPDP Act; residents of California and several other US states have rights under state privacy laws.
We do not require you to give a reason, and exercising these rights will not degrade your use of the app.
- Access and export: available in the app, or by request
- Deletion: available in the app, or by request
- Marketing withdrawal: account settings, unsubscribe link, or reply STOP
Your helper's housing history (coming soon). You will be able to see and export the details of your own helpers' housing history from your account. Because of the purpose in section 5a, a deleted helper's housing details will be kept sealed instead of erased; if you ask us about them we will tell you what we hold and why.
Contact [email protected]. We respond within the period applicable law requires, and within 30 days where no period is set.
For EU/EEA users, our representative is [EU REPRESENTATIVE — REQUIRED IF NO EU ESTABLISHMENT]. For India, our Data Protection Officer is [DPO — REQUIRED UNDER DPDP FOR SIGNIFICANT DATA FIDUCIARIES].
11. International transfers
We operate globally, so data may be processed in countries other than yours, including the United States. Where we transfer personal data out of the EU/EEA or UK we rely on appropriate safeguards such as Standard Contractual Clauses.
12. Children
The Service is not directed at children under 13. We do not knowingly collect their personal data. If you believe a child has created an account, contact [email protected] and we will delete it.
13. Changes
We will post changes here and update the date above. For material changes we will give notice in the app, by email, or both before they take effect, and we will ask for fresh consent where the law requires it.
14. Contact
Windstorm Labs LLC, Eagle Mountain, Utah, USA · [email protected]