ASKINSTEAD LEGAL
Privacy Policy
Effective 3 September 2026
AskInstead is operated by Weaveflow LLC, a Wyoming limited liability company.
This policy explains how Weaveflow LLC, a Wyoming limited liability company, processes personal data through AskInstead.
Weaveflow LLC controls the data described here, unless an organization controls recipient data through its own AskInstead use.
We collect what the Service needs. We do not sell personal data.
1. Data we collect
Account and organization data
We collect names, email addresses, authentication details, organization details, roles, preferences, and email-verification status.
Conversation and response data
We process prompts, objectives, questions, introductions, answers, transcripts, recordings, summaries, extracted fields, and conversation settings.
A recipient can provide an optional name. The sender controls the questions and receives the completed result.
Usage and security data
We process response counts, voice duration, provider cost, session state, timestamps, rate-limit records, device details, IP-derived security data, and service logs.
Billing data
Stripe processes card details. We receive customer, subscription, invoice, payment, refund, dispute, and tax-related records.
We do not store complete payment card numbers.
Website analytics and attribution
DataFast counts visits, referrers, page activity, safe product events, and payment attribution.
Its default tracker uses first-party visitor and session cookies on the askinstead.com domain.
We do not send prompts, answers, recordings, names, or email addresses in analytics events.
A valid affiliate reference can be stored in a first-party cookie for 30 days. We use it only for attribution.
Customer support data
When a signed-in user opens support chat, we send their name, email, organization, and plan to Crisp.
Crisp also processes support messages, chat session identifiers, IP addresses, device details, and message timestamps.
Crisp processes any file that a user chooses to send through support chat.
Developer and integration data
We process API key hashes, visible key hints, permissions, expiry, last use, connected application details, and authorization status.
We process webhook addresses, selected events, encrypted signing secrets, delivery attempts, response codes, and short error details.
We do not store the full API key after creation. We show each API key and webhook signing secret once.
2. How we use data
- Provide accounts, conversations, voice, text, follow-up questions, results, exports, and deletion controls.
- Process payments, subscriptions, Free allowances, top-ups, refunds, chargebacks, and plan limits.
- Send account, security, response, usage, and billing emails.
- Provide customer support, route support messages, and resolve reported problems.
- Provide API access, AI assistant connections, and customer-selected webhook delivery.
- Prevent abuse, fraud, unauthorized access, and service disruption.
- Measure safe product use and improve Service reliability.
- Meet legal duties and enforce our terms.
3. AI processing
AskInstead uses AI to draft conversations, ask follow-ups, summarize answers, and extract structured fields.
We send only the content needed for those functions to the applicable AI provider.
AskInstead does not use customer conversation content to train its own public model.
Provider API terms govern whether those providers retain or use submitted data.
4. Processors
These providers process data for AskInstead:
- Supabase, Inc. (Supabase) — authentication, database, and stored product data.
- Stripe, Inc. (Stripe) — payments, subscriptions, refunds, invoices, and fraud controls.
- OpenAI OpCo, LLC (OpenAI API) — conversation drafting and AI result processing.
- Eleven Labs Inc. (ElevenLabs) — voice conversations, audio processing, and transcripts.
- Plus Five Five, Inc. (Resend) — transactional email delivery.
- Cloudflare, Inc. (Cloudflare and Turnstile) — network delivery, bot checks, and security.
- Google LLC (Google Sign-In) — optional account sign-in.
- DataFast — website analytics and payment attribution.
- CRISP IM SAS (Crisp) — customer support chat, message delivery, and support history.
DataFast’s published terms do not name a separate contracting company. We will update this page if its legal identity changes.
Providers can use their own subprocessors. Their contracts and privacy documents describe those relationships.
5. Cookies and browser storage
- AskInstead session data keeps an account signed in and protects authenticated requests.
- datafast_visitor_id recognizes one browser for website analytics and payment attribution.
- datafast_session_id groups activity into one website visit.
- askinstead_affiliate_ref keeps a valid referral code for 30 days.
- Google Sign-In storage supports optional Google authentication and follows Google’s controls.
- Local draft storage preserves an unfinished creator draft through sign-in for up to 24 hours.
- crisp-client/* restores support messages after a user opens support chat.
The initial launch uses the default DataFast tracker without a consent popup. Browser controls can block or delete cookies.
AskInstead loads Crisp only after a user selects support. Crisp does not set a chat cookie before that action.
Crisp chat cookies expire after six months by default. A later support visit can renew that period.
6. Sharing
We share data with the organization that created a conversation and with providers needed to operate the Service.
We can disclose data when law requires it, or when necessary to protect people, rights, and Service security.
We do not attach recordings, transcripts, or answers to analytics events or routine notification emails.
We send data to a connected application when an authorized user requests that data through the API or MCP.
We send selected event details to webhook addresses that an organization owner configures.
The organization controls its connected applications and webhook destinations. Those third parties can apply their own privacy terms.
7. Retention
Anonymous stored drafts expire after 24 hours. Local browser drafts also expire after 24 hours.
Anonymous test links expire after 24 hours. Shared draft-review links expire after seven days.
Test transcripts and briefs remain available for up to 24 hours, or until their preview link expires.
Preview audio recording starts off. Voice still requires audio processing to conduct the conversation.
A private result link shows one test response. Anyone with that complete link can view it until expiry or deletion.
A draft-review link allows setup edits and account saving. It does not show test answers.
Saving a preview to an account copies its setup, not its test answers. Automated cleanup removes expired preview data.
The browser keeps preview access tokens in session storage. Preview and private-result pages do not send analytics events.
Free results follow the retention limit shown in the dashboard. The Free allowance itself does not expire.
Paid-plan results use the plan retention period: 90 days, 180 days, or 365 days.
Recordings, transcripts, answers, summaries, and fields follow the result retention period.
We keep support messages while needed to resolve requests, protect the Service, and meet legal duties.
Crisp can retain a support conversation until AskInstead deletes it.
We delete rejected, incomplete, or temporary data according to operational cleanup schedules.
We keep invoices, payment records, security records, and legal records when law or dispute handling requires them.
We keep developer audit records as needed for security. We keep customer webhook event and delivery history for 30 days.
8. Your choices and rights
Depending on your location, you can request access, correction, export, deletion, restriction, or objection.
Account owners can manage much of their organization data in AskInstead.
Recipients can request deletion after a response. The organization receives that request.
Preview participants can delete their own test answers from the private result page. Provider audio deletion runs in the background.
A user can ask us to delete support messages, subject to security and legal record duties.
Send privacy requests to privacy@askinstead.com.
We can ask for information that confirms identity before we complete a request.
9. International processing
Weaveflow LLC is based in the United States. Providers can process data in the United States and other countries.
Where required, providers use safeguards such as standard contractual clauses for international transfers.
10. Security
We use reasonable technical and organizational controls to protect Service data.
No transmission or storage method is completely secure. Report a suspected account issue promptly.
11. Children
AskInstead is not directed to children. Account holders must be at least 18 years old.
Do not send a conversation to a child unless you have a lawful basis and all required guardian permission.
12. Policy changes
We can update this policy. We will post the new effective date and give notice when required.
13. Contact
Send privacy questions and requests to privacy@askinstead.com.
