wunel

Privacy policy

Last updated 19 September 2026

wunel is a shared markdown workspace where people and the AI assistants they connect edit the same pages. This policy explains what personal data we handle when you use wunel, why, who helps us, how long we keep it, and what you can ask of us.

1. Who we are

Upnorth AI AB (org.nr 559495-0882)
Klippvägen 19, 135 61 Tyresö, Sweden
support@wunel.com

Upnorth AI AB is the controller for the personal data described here. This policy covers the wunel web app at app.wunel.com, the agent server at mcp.wunel.com that your AI assistants connect to, the wunel iOS app (currently a TestFlight beta), and this website.

When you put other people’s personal data into your pages (a meeting note that names a colleague, say), you decide what goes in and who can see it. We store and serve that content for you so that the service works.

2. What we collect

Your account

What you and your assistants write

Files and images

Sharing

Connected assistants

Security and account activity

Product analytics

3. Your AI assistants

wunel does not run AI models on your content, and we do not send your content to AI providers.

You choose to connect an assistant, such as Claude or ChatGPT, over MCP. That assistant then reads and writes the pages and files you give it access to, on your behalf. What the assistant’s provider does with that content is governed by your agreement with that provider, not by this policy. You can see every connected assistant, and revoke its access, under Settings → Security.

4. Why we use data, and on what legal basis

PurposeLegal basis (GDPR art. 6)
Providing wunelContract (art. 6.1 b): creating your account, signing you in, storing and syncing your pages and files, attributing edits, sharing, connecting your assistants and sending service emails such as sign-in codes and invitations.
Keeping wunel secureLegitimate interests (art. 6.1 f): account activity logs, server logs, rate limiting and preventing abuse, protecting you, other users and the service.
Understanding useLegitimate interests (art. 6.1 f): learning which features are used and where people get stuck, so we can improve the product. See product analytics.
Legal requirementsLegal obligation (art. 6.1 c), where applicable, for example bookkeeping rules or a lawful request from an authority.

We do not sell personal data, and we do not use your content for advertising.

5. Product analytics

We use PostHog, hosted in PostHog’s EU cloud, to learn which features are used, where people get stuck and when something breaks. It is set up so that the content of your pages never reaches it:

If you prefer not to be tracked, content blockers that block PostHog stop the browser part of analytics from loading. wunel works normally without it. You can also object to this processing; see your rights.

In the iOS app PostHog records the same kind of events (screens opened, pages opened and edited, sync and offline periods, all without page text), linked to your account ID only. When something goes wrong it records the error type, which request failed and how, and, after a crash or a freeze, Apple’s crash report for it (MetricKit), never the data involved. There is no session recording in the app. To group events, the app keeps a random installation ID and a small event queue in its own storage on your device.

This website (wunel.com) does not load PostHog. Some events, such as signing in or an assistant writing to a page, are recorded by our servers, so they are counted whichever app you use.

6. Cookies and similar technologies

7. Who processes data for us

We use these providers (sub-processors) to run wunel. Each handles data only on our instructions and only for the purpose listed.

ProviderWhat forWhere
Hetzner Online GmbHServers, database and file storage for all wunel data, and our backupsHelsinki, Finland (EU)
WorkOS, Inc.Sign-in: issues and checks your one-time codes, and handles sign-in when you connect an assistant. Receives your email address and, at sign-in, your IP address and user agentUSA
ResendSending service emails such as sign-in codes, sign-in links and invitations. Receives your email address and the email’s contentEU region
PostHogProduct analytics in the web app (details)EU cloud
VercelHosts this website, wunel.com. It does not host the app or your dataGlobal edge network
AppleDistributes the iOS beta app through TestFlight, under Apple’s own termsUSA

8. Transfers outside the EU

Your pages, files and account data are stored in the EU. Some providers above are based in the USA (WorkOS for sign-in, and Apple for the TestFlight beta). Where personal data is transferred outside the EU/EEA, we rely on a recognised safeguard, such as the EU–US Data Privacy Framework where the recipient participates in it, or the European Commission’s standard contractual clauses. You can ask us for more information about these safeguards.

9. How long we keep data

10. Deleting your account

You can delete your account yourself in the web app under Settings → Security → Delete account. To protect you, we email you a one-time code first, and deletion only goes ahead with that code. Deleting your account permanently removes:

Text you wrote in pages that belong to other people’s workspaces stays in those pages, because it is part of their document, but it is no longer linked to your account. We keep a record that the account was deleted (the time, IP address and user agent) for security. Deleted data stays in backups until they roll off after 14 days. If you want written confirmation that files you uploaded have been erased from storage, email us.

11. Your rights

Under the GDPR you have the right to:

To use any of these rights, email support@wunel.com from the address on your account. We will answer within one month.

12. Changes and contact

If we change this policy, we will update the date at the top. For significant changes we will also tell account holders by email.

Questions about privacy: support@wunel.com, or write to Upnorth AI AB, Klippvägen 19, 135 61 Tyresö, Sweden.

How we protect your data is described on our security page.