In short
- We keep what the work needs: your account, conversations, files and the connections you gave.
- A conversation goes to the model provider that runs the Kringl, mostly Anthropic. We do not train models on your content.
- We do not sell personal information. It goes only to the providers listed here, to run the service.
- The site kringl.ai measures visits and enquiries with Wizzo's own tools. The landing page of our Facebook and Instagram campaign also measures with the Meta pixel. The full list is in the section on cookies.
- To see, correct, copy or delete your data, write to info@wizzo.co.il and we answer within 30 days.
The summary helps you find your way. The full document below is the binding text.
Who is responsible
Wizzo Software Ltd., which runs Kringl, is responsible for the data collected in the service. Address: 3 Totzeret HaAretz St., Petah Tikva, Israel. Any privacy question: info@wizzo.co.il.
This policy covers the site kringl.ai, the app at web.kringl.ai, the Android and iPhone apps and the desktop program. The browser extension has its own privacy page.
What we collect
| Kind | What exactly | From where |
|---|---|---|
| Account | Name, email, phone, and a password kept only as a hash | From you, at sign-up |
| Workspace and payment | Business name, people and number of seats, a card charging token, last 4 digits, expiry and brand, charge log and invoice details | From you and the payment processor |
| Conversations | Messages, voice notes, files and images you upload, and what the Kringls wrote and captured | From you and the Kringls |
| Work | A copy of the repositories you connected, the Kringls' work logs, and the records of changes made to databases | From the connections you gave |
| Connections and secrets | Tokens for GitHub, Google and the stores, and passwords and keys you saved in the vault | From you |
| Desktop program | Content from the folders you shared, only while a Kringl works on them and only what it needs | From your computer, with your approval |
| Technical | IP address, device and browser type, server logs, a push token for your phone, and crash reports from the app | Automatically |
| Enquiry from the site | Name, phone, email and what you wrote, where you came from (including a campaign ID, if any), and the consent you gave | From you, in the form |
Your phone number is not verified, and is used to contact you.
Required or optional. You are under no legal duty to give us personal data, and giving it is up to you. A name, an email address, a phone number and a password are needed to open an account and enter into the agreement with us, and without them you cannot sign up. Without a payment method, access stops at the end of the 30 day trial. Connections (a repository, a server, a store, a mailbox) are optional, and without them the Kringls do not work in that place. An enquiry on the site is optional too.
Why we use it
| Purpose | Basis |
|---|---|
| Providing the service: running the Kringls on your conversation, code and connections | Our contract with you |
| Billing, invoices and records under tax law | Our contract with you, and a legal duty |
| Security, preventing abuse and fixing faults | Our legitimate interest |
| Improving the service from usage and fault data | Our legitimate interest |
| Getting back to you after an enquiry from the site | Your consent |
| Measuring visits to kringl.ai | Our legitimate interest, and consent where the law requires it |
AI and your data
When a Kringl works, what it needs for the work (the message, pieces of code, files) is sent to the model provider that runs it. That is part of the work, not another use.
We do not train models on your content. What a model provider may do with the data is set by its own terms. When a workspace connects its own model account (for example a Claude subscription), that account's terms and settings also decide whether data is used for training. Check them in the account itself.
The Kringls learn from the work: a lesson found in a project is saved in your workspace's lessons store, so the same mistake is not repeated. The store belongs to the workspace and is not shared with other workspaces, and the workspace admin can switch it off in settings.
Your users' data
When the Kringls work on your product, they may see data of its users, for example in the database or in server logs. You are responsible for that data, and we process it for you, only for the work you asked for.
The Kringls do not send messages, emails or notifications to your users, or delete their data, unless you asked.
Gmail connection (Google user data)
Anyone who chooses to can connect their Gmail inbox to Kringl from their personal area. The connection goes through Google's consent screen, is personal to each user, and can be disconnected in the same place at any moment. Kringl does not touch an inbox the user did not connect themselves.
- What data. With the read scope (gmail.readonly): messages, threads and labels in the user's inbox, according to what they ask in the conversation. With the compose scope (gmail.compose): creating drafts. Kringl does not send email on the user's behalf, does not delete messages and does not change account settings.
- Why. Only to answer the user about their own inbox and to prepare drafts that they check and send themselves. Not for advertising, not for marketing profiles, not for sale and not for training models.
- With whom. The message content relevant to the question is sent to the model provider running the conversation, only to produce the answer. By default that is Anthropic (Claude). When the workspace chose another engine, the provider is OpenAI (Codex), xAI (Grok) or Cursor, together with the model providers Cursor works through (for example Fireworks). When the workspace connected its own account or subscription with such a provider, the content goes through that account and under its terms. The access to the inbox itself runs against Google's Gmail server with the user's token. The data goes to no one else.
- Who reads it. No person at Wizzo reads the content of the email, except when: the user explicitly asked us to look at specific messages; it is needed for security, for example to investigate a bug or abuse; the law requires it; or the data is aggregated and anonymised, so no person can be identified from it, for internal operations.
- How it is protected. Access tokens are stored encrypted in the database, separately for each user, and are used only for actions the user asked for. All traffic is encrypted with HTTPS.
- For how long. Inbox content is not stored as a collection: it is read to produce the answer, and only the answer stays in the conversation history. Disconnecting revokes the token at Google and deletes it on our side at once. To delete a conversation or the whole account, write to info@wizzo.co.il.
Limited Use statement, our own and in Google's wording:
Kringl's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Raw or derived user data received from Workspace APIs is not used to develop, improve or train generalized AI or ML models.
The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements.
Cookies and measurement
The site and the app keep what is in the table in your browser. The site's measuring tools are Wizzo's own, not Google Analytics. The one exception is the landing page of our Facebook and Instagram campaign (/he/atar): only there the Meta pixel runs, telling Meta that the page was opened and that a form was sent, to measure the ads and show them to people who may be interested. Meta receives the page address, the IP address, browser details and its own cookies, not the name, phone or link you typed in the form. What Meta does with it is in Meta's own privacy policy.
| Name | Where | What for | How long |
|---|---|---|---|
| portal_token and the workspace cookie | web.kringl.ai | Keeping you signed in and remembering your workspace | 1 year |
| wizzo_a11y_v1 | kringl.ai | Remembering the settings you chose in the accessibility menu | Until deleted |
| _tuid | kringl.ai (Target) | Recognising a returning browser, and knowing where visits and enquiries came from | 1 year |
| The WizzoRadar ID | kringl.ai | Visit statistics: pages, referrer, page speed and click positions for a heatmap | 2 years, plus a visit ID until the browser closes |
| Pilot | kringl.ai | The chat window on the site | Until deleted |
| poosh_reg | kringl.ai | Signing up for browser notifications, only if you allowed them | Up to 30 days, renewed |
| _fbp, _fbc (the Meta pixel) | kringl.ai/he/atar only | Measuring how many people came from the ads and how many left their details | 90 days |
You can block or delete cookies and local storage in your browser settings. The site works without the measuring tools; in the app you cannot stay signed in without them.
How long we keep it
| What | How long |
|---|---|
| Account, conversations, files and the Kringls' memory | While the account is active, and up to 30 days after a deletion request |
| The Kringls' full work logs | 180 days |
| Server logs | 14 days |
| Backups | Rotating backups, the oldest at most six months old |
| A voice recording in a conversation | Turned into text; the recording is not kept. A voice note in the team box is kept like a file |
| Billing records and invoices | 7 years, as tax law requires |
| A managed server that was shut down | A last backup for 30 days |
| An enquiry from the site | Until you ask us to remove it |
A deletion request removes the data from the service. Whatever is already in a backup is removed when that backup rotates out.
Security
All traffic is encrypted with HTTPS. Passwords are kept only as a hash. Connection tokens, and passwords and keys in a project's vault, are stored encrypted. Wizzo staff may access data only to run, support and secure the service. The content of a connected Gmail inbox is not read by a person, except as described in the Gmail connection section.
Please note: a file or image uploaded to a conversation is stored at a long address that is hard to guess, with no password. Anyone who gets the link can open it, so do not pass on a link to a sensitive file.
No method guarantees full security. If a security incident affects your data, we will tell you and the authorities as the law requires.
Your rights
You may see the data kept about you, correct it, ask us to delete it and get a copy of it. You may also ask us to stop marketing to you, and withdraw a consent you gave.
If you live in the European Union you may also restrict processing, object to processing based on legitimate interest, and receive your data in a portable format.
Write to info@wizzo.co.il and we answer within 30 days. Deleting an account or a conversation is done by such a request for now, not by a button in the app.
You may also complain to the Privacy Protection Authority in Israel, or to the data protection authority of your country in the European Union.
Children
Kringl is a work tool for businesses and is not meant for anyone under 18. We do not knowingly collect data about children, and such data that reaches us is deleted.
Changes to this policy
When this policy changes, the date at the top changes. We announce a material change by email or in the app before it applies.
A question about this document? Write to info@wizzo.co.il and a person answers.