← wingscript
wingscript icon

Privacy Policy

Version 2.3 — Effective September 1, 2026

wingscript ("we", "us", "our") provides a real-time conversation intelligence tool delivered as a Chrome browser extension, web application, macOS companion app, and iOS app. This policy covers those products and the wingscript.com website. It describes what data we collect, how we use it, and your rights.

1. Data Controller

Weavery, LLC, a California limited liability company doing business as wingscript ("wingscript"), is the data controller of the Personal Data you provide through wingscript's applications and website. For questions about how your data is handled, contact us at support@wingscript.com.

2. What We Collect

Data TypeWhatWhere Processed
Audio During a session, audio from your microphone and — with your permission — from your meeting or call is streamed over an encrypted connection and transcribed in real time, either on our servers or by our speech-to-text provider, Deepgram. The iOS app streams audio directly to Deepgram. Audio is processed transiently for transcription and deleted immediately; it is never stored. Only the resulting text transcript is retained. Azure (US regions); Deepgram
Transcripts Text transcripts of your sessions, used for real-time analysis and session history. Azure (US regions)
Google Account Email, name, and profile picture obtained via Google OAuth. Used for authentication. Azure (US regions)
Calendar Read-only access to upcoming Google Calendar events for meeting context. Cached temporarily. Azure (US regions)
CRM Data If you connect Salesforce or HubSpot, we pull account name and deal stage. No bulk sync. Azure (US regions), via Nango
Phone Calls If you place a call through wingscript's dialing feature, the number you dial, call status, and call audio pass through Twilio, our telephony carrier, to connect the call and enable real-time transcription. Azure (US regions); Twilio
Dialpad Call Events If your organization connects Dialpad, we receive call-state events (that a call has started or ended, and which rep it belongs to) so wingscript can prepare your session automatically. No call audio or content comes from Dialpad. Azure (US regions)
Cue Interactions Which cue cards are shown and a similarity signal indicating whether the suggestion was adopted. Azure (US regions)
Learning Data Coaching lessons extracted from sessions, framework scores, and skill progress snapshots. Azure (US regions)
LinkedIn Profiles When you enable the LinkedIn connector, name, headline, company, and LinkedIn URL are captured from LinkedIn profile pages you visit. This data enriches meeting attendee context. This feature requires you to grant an optional permission. Azure (US regions)
Chat History Conversations with the wingscript chat assistant are stored to maintain context across sessions. Azure (US regions)
Knowledge Base Documents and content you upload or sync via connectors (Google Drive, Notion) for meeting preparation and cue enrichment. Azure (US regions)
Contact Enrichment Name, title, and company retrieved from Apollo.io to provide context about meeting attendees. No bulk data is imported. Azure (US regions), via Apollo.io
Billing If you purchase a paid plan, payment is processed by Stripe. Your card details are collected directly by Stripe and never touch our servers. We store your plan, subscription status, and seat counts. Stripe; Azure (US regions)
Usage Analytics Content-free product events (for example, "session started" or "feature used") tied to your account identity (name, email, organization, plan tier), forwarded to Mixpanel so we can understand how wingscript is used. Conversation content — transcripts, cue text, chat messages, document text — is never included in analytics events; this is enforced in our ingestion code. Azure (US regions); Mixpanel
Onboarding Survey Optional one-tap answers you may give during setup — your role, sales-team size, where your calls happen, and how you intend to use wingscript. Used to tailor coaching defaults and to suggest the right plan for you; stored with your account, and included in the account-identity properties forwarded to Mixpanel. Every question is skippable, and answers can be changed or deleted at any time (see Your Rights). Azure (US regions); Mixpanel
Push Subscriptions Web Push endpoint stored to deliver calendar update notifications. No content data is included in push payloads. Azure (US regions)
Website Forms If you request a demo on wingscript.com, the name, work email, and team size you enter are sent to our servers and delivered to our inbox as an email via Resend, our email delivery provider. Demo requests are not stored in our database — the delivered email is the only copy. Azure (US regions); Resend
Server Logs Standard request logs (IP address, request metadata, timestamps) generated when you use our applications or website, kept for security and operations. Azure (US regions)

3. Other People on Your Calls

wingscript transcribes conversations, so the words of the people you talk to are part of your transcripts. Those people are not wingscript users and do not see this policy, so this allocation of responsibility matters:

4. Chrome Extension Permissions

PermissionWhy
identityGoogle OAuth sign-in
sidePanelDisplay cue cards alongside your meeting
storageSave local settings, auth tokens, and connector state
tabsDetect active meeting tabs (Google Meet, Zoom) and detect LinkedIn profile pages when the LinkedIn connector is enabled
notificationsCalendar reminders for upcoming meetings
scriptingDynamically inject a content script on LinkedIn profile pages when the LinkedIn connector is enabled by the user
linkedin.com (optional)Requested only when you enable the LinkedIn connector. Allows capturing profile data from LinkedIn pages you visit to enrich meeting attendee context.

5. How We Use Your Data

We do not sell your data. We do not use your data for advertising. We do not train AI models on your data.

6. Third-Party Services

These providers are permitted to use your data only to provide their services to us.

7. Other Disclosures

We have never sold personal information, and we do not share personal information for cross-context behavioral advertising.

8. Data Storage & Retention

9. Your Rights

All Users

To exercise any of these rights, email support@wingscript.com. We will verify your request using the email associated with your account and respond within 45 days. You may use an authorized agent to submit a request on your behalf.

California Residents (CCPA/CPRA)

EU/EEA Residents (GDPR)

You have the right to access, rectify, erase, restrict processing, object to processing, and port your data. Our legal bases for processing are: performance of our contract with you (providing the service you signed up for), our legitimate interests (securing and improving the service), and your consent (optional features such as connectors, which you can withdraw at any time by disconnecting them).

10. Do Not Track and Global Privacy Control

Some browsers can send "Do Not Track" or Global Privacy Control signals. Because we do not sell or share personal information and do not serve targeted advertising, there is no sale or tracking to opt out of, and we do not change our data collection in response to these signals.

11. Cookies & Local Storage

12. Security

13. International Users

wingscript is operated from the United States, and data is stored and processed in US regions. If you use wingscript from outside the US, you understand that your data will be transferred to and processed in the United States.

14. Changes to This Policy

We will update this page when our practices change. The effective date at the top reflects the most recent revision. Material changes will be communicated via email to registered users.

15. Google API Limited Use Disclosure

wingscript's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

As a Chrome extension, wingscript's handling of this data also adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements.

Specifically, data obtained from Google APIs (your Google profile information, calendar events, and the Google Sheets files wingscript creates in your Drive when you export call data) is:

Human access to Google API data is limited to debugging issues at your request, investigating security incidents, or complying with legal obligations.

16. Children's Privacy

wingscript is intended for use by business professionals. We do not knowingly collect Personal Data from children under the age of 18. If you are under 18, do not use wingscript or provide any information through the extension or web application. If we learn that we have collected Personal Data from a child under 18, we will delete that information promptly. If you believe we may have collected data from a child under 18, please contact us at support@wingscript.com.

17. Contact

For privacy questions or data requests — including California and GDPR requests — contact us at support@wingscript.com.