WIPJar

WIPJar Privacy Policy

Effective: September 30, 2026

WIPJar is a product of Kiwi Bar, Inc. ("WIPJar," "we," "us"), 29 West 36th Street, New York, NY 10018. This policy describes what we collect, why, and what we never do. Questions: support@wipjar.com.

What WIPJar does

WIPJar builds a shared map of your organization's working relationships from the message headers of connected work mailboxes — who corresponded with whom, and when. It does not read the content of your email.

Information we collect

Account information. Your name, work email address, and organization membership. We use passwordless sign-in; we never ask you for a password.

Mailbox metadata. When you connect a work mailbox, we request read access to message headers only: sender, recipients, timestamps, and message and thread identifiers. We do not access, receive, or store message bodies or attachments. Subject lines are neither stored nor displayed. For Google accounts we request the gmail.metadata scope; for Microsoft accounts we request openid, profile, email, offline_access and Mail.ReadBasic. Microsoft may also include User.Read, which it adds to app registrations by default; it reads only the signed-in user's own profile.

Derived relationship data. From mailbox metadata we compute aggregate signals per contact (for example: message counts, first and last activity) and relationship classifications. These aggregates are the product.

Enrichment details. If your organization has turned on enrichment, we receive professional details about people in your organization's relationship map from a business-data provider — job title, employer, role history and a link to a public professional profile — and store them for your organization. See Enrichment below.

Information you send us. If you submit a request to speak with WIPJar about paid services, we collect the name, work email, organization, and message you provide.

Service logs. Server-side operational events (sign-ins, sync runs, errors) as counts and identifiers. We do not use third-party analytics or advertising trackers. Cookies are limited to authentication and session management.

How we use information

To operate the service: build and display your organization's relationship map, share parts of it with a partner organization when your organization and you turn that on (see Sharing with partner organizations below), run mailbox syncs, send transactional email (sign-in links, invitations, notifications), provide support, and maintain security. If your organization has turned on enrichment, we also look up professional details for people in your organization's relationship map, as described under Enrichment below. We do not use your data to train machine-learning models. We do not sell or rent your data. We never send mail from your mailbox.

Enrichment (optional)

Enrichment is off unless an administrator of your organization asks us to turn it on. When it is on, WIPJar looks up professional details for people in your organization's relationship map — job title, employer, role history and a link to a public professional profile — so they can be shown beside each contact. These details come from a business-data provider, not from your mailbox.

To look a contact up, we send the provider one of two things: a one-way hash (SHA-256) of the contact's email address, or the contact's name and company web domain. We do not send the email address itself, and we never send message content, because we never have it. Not every contact is looked up, and not every lookup returns a result.

We do not send information received from Google APIs to enrichment providers.

An administrator can turn enrichment off at any time by writing to support@wipjar.com, and we then stop looking contacts up. To have details we already obtained removed, write to the same address.

Google user data — Limited Use

WIPJar's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide and improve the user-facing features described here, is never transferred to third parties except as necessary to provide those features, with consent, or for security or legal compliance, is never used for advertising, and is never read by humans except with your explicit consent, for security purposes, or to comply with law. Microsoft user data is handled under the same restrictions.

Visibility inside your organization

Your organization's relationship map is shared: every member of your WIPJar organization can see the full organization graph, including relationships derived from other members' connected mailboxes. We disclose this at signup and again when you connect a mailbox.

Sharing with partner organizations (optional)

Partner sharing is off unless your organization and you turn it on. Each connection links your organization with one other organization, so that each can see which of the other's people work with which outside organizations.

Both organizations' administrators must agree to connect. Connecting shows each organization's name and web domain to the other.

Your mailbox is included only if you opt it in, for that partner. It is off by default, and you can opt out at any time.

For each outside organization your mailbox shows you working with, the partner's members then see your name, your work email address, that organization's web domain, and a band showing how strong the working relationship is.

The partner never sees the names or email addresses of people outside your organization, message counts, dates, subject lines or message content, enrichment details, or anything involving a domain your organization excludes from sharing. Free-mail and personal email domains are never shared.

Nothing is copied into the partner's account. What the partner sees is drawn from a list your organization holds and is checked again every time it is read, so sharing stops as soon as either administrator ends the connection, you opt out, or your organization excludes a domain.

We record who connected, opted in, opted out or ended a connection, and when.

When someone leaves

The graph belongs to the organization. If a member departs or is removed, the contacts, counts and dates already derived from their mailbox remain in the organization's graph, as they do when a mailbox is disconnected. Removing a member does not disconnect their mailbox; disconnecting is a separate step, and it stops new mail. To have derived data removed, write to support@wipjar.com; removal is subject to legal retention requirements.

Service providers

Apart from partner sharing that your organization and you turn on, we share data only with the providers we use to operate WIPJar, only as needed: Supabase (database and authentication), Railway (application hosting), Cloudflare (DNS and static site hosting), Resend (transactional email), Anthropic (AI-assisted operator tooling), and, only for an organization that has turned on enrichment, People Data Labs, Inc. (enrichment lookups, in the form described under Enrichment above; United States). We will keep this list current. Data is stored in the United States. Google and Microsoft are not subprocessors; they are providers you connect to WIPJar under your own consent, governed by your agreements with them.

Retention and deletion

Connected-mailbox analysis covers the last 12 months by default, up to 50,000 messages per mailbox, and a longer period only when your organization agrees in writing. If you disconnect a mailbox, we stop ingesting new mail; a sync already in progress may finish the run it has started. You can also remove WIPJar's access to a Google account at any time from your Google Account's security settings; for a Microsoft work account, your organization's administrator can remove it. Either one stops new mail, as disconnecting does. The contacts, counts and dates already derived from that mailbox remain in the organization's graph, as they do when a member departs. To have them removed, or to delete your account, write to support@wipjar.com; removal and deletion are subject to legal retention requirements.

Security

Data is encrypted in transit and at rest. Mailbox access credentials are stored encrypted, and access is limited to what the service requires.

Children

WIPJar is a business tool for work email and is not directed at anyone under 18.

Changes

We will post any changes to this policy here and update the date above. Material changes will be communicated to account holders by email.