WIPJar Privacy Policy
Effective: August 13, 2026
WIPJar is a product of Kiwi Bar, Inc. ("WIPJar," "we," "us"), 29 West 36th Street, New York, NY 10018. This policy describes what we collect, why, and what we never do. Questions: support@wipjar.com.
What WIPJar does
WIPJar builds a shared map of your organization's working relationships from the message headers of connected work mailboxes — who corresponded with whom, and when. It does not read the content of your email.
Information we collect
Account information. Your name, work email address, and organization membership. We use passwordless sign-in; we never collect or store a password.
Mailbox metadata. When you connect a work mailbox, we request read access to message headers only: sender, recipients, timestamps, and thread identifiers. We do not access, receive, or store message bodies or attachments. Subject lines are neither stored nor displayed. For Google accounts we request the gmail.metadata scope; for Microsoft accounts, the equivalent minimum permission.
Derived relationship data. From mailbox metadata we compute aggregate signals per contact (for example: message counts, thread counts, first and last activity) and relationship classifications. These aggregates are the product; underlying per-message records are transient and purged on a rolling basis.
Information you send us. If you submit a request to speak with WIPJar about paid services, we collect the name, work email, organization, and message you provide.
Service logs. Server-side operational events (sign-ins, sync runs, errors) as counts and identifiers. We do not use third-party analytics or advertising trackers. Cookies are limited to authentication and session management.
How we use information
To operate the service: build and display your organization's relationship map, run mailbox syncs, send transactional email (sign-in links, invitations, notifications), provide support, and maintain security. We do not use your data to train machine-learning models. We do not sell or rent your data. We never send mail from your mailbox.
Google user data — Limited Use
WIPJar's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide and improve the user-facing features described here, is never transferred to third parties except as necessary to provide those features, with consent, or for security or legal compliance, is never used for advertising, and is never read by humans except with your explicit consent, for security purposes, or to comply with law. Microsoft user data is handled under the same restrictions.
Visibility inside your organization
Your organization's relationship map is shared: every member of your WIPJar organization can see the full organization graph, including relationships derived from other members' connected mailboxes. We disclose this at signup and again when you connect a mailbox.
When someone leaves
The graph belongs to the organization. If a member departs or is removed, their connected mailbox stops feeding the graph, and the organization retains the relationship data already derived.
Service providers
We share data only with the providers we use to operate WIPJar, only as needed: Supabase (database and authentication), Railway (application hosting), Cloudflare (DNS and static site hosting), and Resend (transactional email). Data is stored in the United States. Google and Microsoft are not subprocessors; they are providers you connect to WIPJar under your own consent, governed by your agreements with them.
Retention and deletion
Connected-mailbox analysis covers a rolling recent window. If you disconnect a mailbox, we stop ingestion immediately and delete the data derived from that mailbox within 30 days. You can export your organization's data and delete your account at any time; account deletion removes your personal data on the same 30-day schedule, subject to legal retention requirements.
Security
Data is encrypted in transit and at rest. Mailbox access credentials are stored encrypted, and access is limited to what the service requires.
Children
WIPJar is a business tool for work email and is not directed at anyone under 18.
Changes
We will post any changes to this policy here and update the date above. Material changes will be communicated to account holders by email.