LEGAL

Privacy Protocol

Last updated: September 9, 2026

1. Introduction

Wrenda of 33 John Ireland Way, Pulborough, West Sussex, United Kingdom (“we,” “our,” or “us”) is the data controller for the personal data described in this policy. We respect your privacy and are committed to protecting your personal data. This Privacy Policy explains what we collect, why, on what legal basis, how long we keep it, and the rights you have. It is written to meet Articles 13 and 14 of the UK GDPR.

Where we process personal data on behalf of a business customer — for example telemetry about requests to that customer's website — we act as a processor and the customer is the controller. Those arrangements are set out in our Data Processing Agreement.

2. Information We Collect

2.1 Information You Provide

  • Account information (name, email, company name)
  • Payment information (entered into and processed by Stripe; we never see full card numbers)
  • Domain configuration and settings, including the prompts you configure for AI-citation tracking
  • Support communications

2.2 Information Collected Automatically

We deliberately collect as little as we can here, so it is worth being precise about what the proxy does and does not record:

  • Human visitors to proxied websites: requests from ordinary browsers are proxied and handled transiently by the Cloudflare edge network and then passed to the site's origin server. Wrenda writes no log record for that traffic and does not retain website-visitor IP addresses.
  • Crawler telemetry: when a named AI or search crawler (for example GPTBot, ClaudeBot, PerplexityBot, Googlebot) requests a page on a customer domain, we record the bot's user agent, the URL path, the timestamp, the action taken and cache/response metadata. No IP address is stored. These raw records are deleted after 14 days; only aggregated weekly counts are kept beyond that, for 13 months.
  • IP addresses — the only two places we store them:
    • Administrative audit logs: the IP address from which a Wrenda account holder performed an administrative action, kept for 14 days.
    • MCP endpoint records: the IP address and user agent of an AI agent or end user calling a customer's Model Context Protocol endpoint, kept for 14 days.
  • Product usage inside the dashboard: performance metrics, error and event records used to operate and debug the Service, kept for 14 days.
  • Analytics on this marketing website: if — and only if — you accept analytics cookies, Google Analytics collects usage data about your visit. See section 8.

2.3 Information from Third Parties

  • Google OAuth (sign-in) — and, if you connect them, Google Search Console and Google Analytics for SEO/traffic data
  • Google Analytics on this website (only if you accept analytics cookies)
  • Stripe (payment and subscription status)

3. How We Use Your Information, and on What Legal Basis

Every purpose we process personal data for, the lawful basis we rely on, and how long the resulting data is kept:

PurposeLawful basisRetention
Providing and maintaining the Service — your account, domains, crawler and content rules, dashboard and supportContract (Art. 6(1)(b))While your account is active. Deleting your account in Settings → General hard-deletes your account and configuration data.
Taking payment and keeping statutory billing and accounting recordsContract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c))Billing and tax records retained as required by UK tax law, typically 7 years.
Transactional and service email — sign-in and team invites, alerts, scheduled reports and lifecycle noticesContract (Art. 6(1)(b))Email notification records: 12 months.
Delivering the product features you configure — crawler telemetry, AI-citation tracking, page optimisation and agent testing on your own domainsContract (Art. 6(1)(b))Raw crawler telemetry 14 days; weekly aggregates 13 months; AI-citation and page-optimisation history 13 months; agent-test session records 14 days.
Service security, abuse prevention and diagnostics — admin audit logs, MCP endpoint caller records, error and event logsLegitimate interests (Art. 6(1)(f)) — keeping the platform secure, available and diagnosable. We keep these logs short-lived and minimal so the impact on you is limited.14 days.
Product analytics on this website (Google Analytics)Consent (Art. 6(1)(a)) and PECR reg. 6Only while your consent stands. Withdraw it at any time using Cookie settings; retention within Google Analytics is governed by Google.

Where we rely on legitimate interests you have the right to object (section 7); where we rely on consent you can withdraw it at any time, without affecting processing carried out before you withdrew it.

AI processing of content: To optimize pages for AI crawlers and search engines, the content of your configured pages is processed by AI providers (Cloudflare Workers AI, and for some features Anthropic via OpenRouter) to generate enriched, structured versions served to crawlers. This processing may include any data present on those pages, so please do not place personal data on pages you configure for optimization unless you have a basis for it.

4. Data Sharing and Disclosure

We may share your information with:

  • Service providers (sub-processors): Cloudflare (hosting, edge proxy, D1 and KV storage, Workers AI, Browser Rendering), Google APIs (sign-in, and — where you connect them — Search Console and Analytics), Stripe (payments), Microsoft Graph (transactional email), Resend (alert email), Bright Data (querying AI platforms for citation tracking), and OpenRouter with Anthropic (AI text generation). OpenAI is configured as a contingent fallback provider and is not in active use.
  • Legal requirements: when required by law or to establish, exercise or defend legal claims
  • Business transfers: in connection with a merger, acquisition, or sale of assets

We do not sell your personal information to third parties, and we do not use it to train AI models. Business customers can review the sub-processor list, our security commitments and our change-notice undertaking in the Data Processing Agreement.

5. Data Retention

We retain personal data only for as long as necessary for the purpose it was collected for. Deletion of the short-lived logs below is enforced automatically by a nightly scheduled job, not by hand.

  • Account & domain configuration: retained while your account is active
  • Raw crawler telemetry: 14 days
  • Administrative audit logs (including account-holder IP addresses): 14 days
  • Event logs and MCP endpoint records (including caller IP addresses): 14 days
  • MCP tool execution records: 14 days
  • Agent-test session records: 14 days
  • Aggregated weekly analytics: 13 months
  • AI-citation prompts and the responses collected from AI platforms: 13 months
  • Page-optimization records (the optimized versions and their history): 13 months
  • Email notification records (alerts, reports and lifecycle mail we sent you): 12 months
  • Billing records: retained as required for tax/accounting purposes, typically up to 7 years

Cached copies of optimized pages expire on their configured TTL and are purged when you remove the domain or rule.

6. Data Security

We implement appropriate technical and organizational measures to protect your data (UK GDPR Art. 32), including:

  • Encryption in transit (TLS) and at rest, provided by the Cloudflare platform we run on
  • Dependency vulnerability auditing and secret scanning run in our continuous-integration pipeline on every change
  • Least-privilege, scoped API tokens for every internal integration
  • Access controls and authentication requirements, with sign-in delegated to Google; where any password hash exists it is stored with bcrypt and a per-password salt
  • Tenant isolation: every query is scoped to your account, and short retention windows limit the data at risk
  • Point-in-time database recovery and nightly encrypted backups

You can report a suspected vulnerability to hello@wrenda.ai; our contact details are also published at /.well-known/security.txt.

7. Your Rights

Under the UK GDPR you have the right to:

  • Access your personal data (Art. 15)
  • Correct inaccurate data (Art. 16)
  • Delete your data (Art. 17)
  • Restrict processing (Art. 18)
  • Receive your data in a portable format (Art. 20)
  • Object to processing based on legitimate interests, and to direct marketing (Art. 21)
  • Withdraw consent at any time, as easily as you gave it (Art. 7(3))

Self-service: account holders can export all of their data and permanently delete their account from Settings → General inside the app. Both are immediate hard deletes, not soft deletes.

Response time: to exercise any of these rights, contact us at hello@wrenda.ai. We will respond within one month of receiving your request, as required by Art. 12(3) UK GDPR. If a request is particularly complex, or you have made several, we may extend that by up to two further months — and we will tell you, and why, within the first month. There is no charge for a request unless it is manifestly unfounded or excessive.

If you are an end user of a website that uses Wrenda rather than a Wrenda account holder, that website's operator is the controller for your data — please contact them first; we will assist them in responding to you.

California residents (CCPA): we do not sell or share your personal information as defined by the CCPA. You may request access to or deletion of your information using the contact above.

8. Cookies and Local Storage

Strictly necessary and functional storage — set without consent because the site cannot work without it, and never used to track you:

  • Your cookie choice itself, stored in this browser's local storage so we do not ask again on every page
  • A one-flag sessionStorage marker recording that the site's boot animation has already played, so it plays once per browser session rather than on every page view
  • In the authenticated app: your sign-in token and interface state (selected domain, an in-progress setup wizard, dismissed banners) held in your browser's local and session storage so the dashboard works across page loads

Optional analytics — consent only. Google Analytics (measurement ID G-2J1PZLBP61) is the only non-essential cookie or storage we use. It is not loaded at all unless you press Accept in our cookie banner. Decline and no analytics script is loaded and no analytics cookie is set.

Changing or withdrawing your choice is as easy as giving it: use here or in the site footer at any time. Switching from Accept to Decline stops analytics loading, disables further Google Analytics measurement in your browser and clears the analytics cookies we can reach on this domain. You can also manage cookies through your browser settings.

9. International Data Transfers

Your data may be transferred to and processed in countries other than your own — we are based in the United Kingdom and several of our sub-processors (for example Cloudflare, Stripe, Google, Microsoft, Anthropic and OpenRouter) are US-based. Where required, such transfers rely on the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or equivalent Standard Contractual Clauses, as incorporated into the data processing terms each of those providers publishes and which we accept when using their services. EU/UK customers can contact us for details of where specific data is processed.

10. Automated Decision-Making

We do not make decisions producing legal or similarly significant effects about you by automated means, and we do not carry out profiling of individuals. AI is used to rewrite web page content, not to evaluate people.

11. Children's Privacy

The Service is not intended for children under 16. We do not knowingly collect personal information from children. If you believe we have collected such information, please contact us immediately.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the “Last updated” date. Where a change materially affects how we use your data we will tell account holders by email before it takes effect.

13. Contact Us

Data protection enquiries: hello@wrenda.ai

Wrenda, 33 John Ireland Way, Pulborough, West Sussex, United Kingdom

We are a small UK business and are not required to appoint a Data Protection Officer; data protection enquiries, access requests and complaints all go to the address above and are handled by the business owner.

If you are unhappy with how we have handled your personal data you have the right to lodge a complaint with the UK Information Commissioner's Office — ico.org.uk, helpline 0303 123 1113 — or with the supervisory authority where you live or work. We would appreciate the chance to put things right first.