Privacy policy
Last updated 19 September 2026
wunel is a shared markdown workspace where people and the AI assistants they connect edit the same pages. This policy explains what personal data we handle when you use wunel, why, who helps us, how long we keep it, and what you can ask of us.
1. Who we are
Upnorth AI AB (org.nr 559495-0882)
Klippvägen 19, 135 61 Tyresö, Sweden
support@wunel.com
Upnorth AI AB is the controller for the personal data described here. This policy covers the wunel web app at app.wunel.com, the agent server at mcp.wunel.com that your AI assistants connect to, the wunel iOS app (currently a TestFlight beta), and this website.
When you put other people’s personal data into your pages (a meeting note that names a colleague, say), you decide what goes in and who can see it. We store and serve that content for you so that the service works.
2. What we collect
Your account
- Your email address and display name.
- The workspaces you belong to and your role in each (owner, editor or viewer), invitations you send or receive, and pages shared with you.
What you and your assistants write
- Pages, folders, comments and replies.
- Provenance: for every block of text, who wrote it (a person, or which assistant on whose behalf) and when. This is a core feature. It is what lets your team see and review who changed what.
- A history of changes to each page, so edits can be reviewed and reverted.
Files and images
- Files and images you or your assistants upload, with their file name, type, size and who uploaded them.
- Files are stored exactly as uploaded. We do not remove metadata such as EXIF data in photos, which can include the camera, the time the photo was taken and GPS location. Remove it before uploading if you do not want it stored and shown to people who can open the file.
- We extract text from some files so that you and your assistants can search and read them.
Sharing
- Share links you create and the access level you choose (view, comment or edit).
- People who open a share link without an account (“guests”) can give a display name. We store that name, what they write, and a guest cookie that recognises them on that browser (see cookies).
- Requests to access a page: who asked, for which page, and whether the request was approved or declined.
Connected assistants
- A record for each assistant you connect (its name and whose behalf it acts on) and the access keys issued to it. Keys are stored as hashes, with when they were created, when they were last used and when they expire.
Security and account activity
- Security-relevant events on your account, such as sign-ins, sign-in codes and links being sent, keys created or revoked, “sign out everywhere”, access requests and account deletion. For these we store the time, the IP address and the browser or app identifier (user agent). You can see this log yourself under Settings → Security.
- Our web server logs each request, including IP address, user agent, the address requested and the time. We use these logs to run and secure the service.
Product analytics
- How wunel is used, in the web app and by AI assistants you connect, without page content. See product analytics below for exactly what that includes.
3. Your AI assistants
wunel does not run AI models on your content, and we do not send your content to AI providers.
You choose to connect an assistant, such as Claude or ChatGPT, over MCP. That assistant then reads and writes the pages and files you give it access to, on your behalf. What the assistant’s provider does with that content is governed by your agreement with that provider, not by this policy. You can see every connected assistant, and revoke its access, under Settings → Security.
4. Why we use data, and on what legal basis
| Purpose | Legal basis (GDPR art. 6) |
|---|---|
| Providing wunel | Contract (art. 6.1 b): creating your account, signing you in, storing and syncing your pages and files, attributing edits, sharing, connecting your assistants and sending service emails such as sign-in codes and invitations. |
| Keeping wunel secure | Legitimate interests (art. 6.1 f): account activity logs, server logs, rate limiting and preventing abuse, protecting you, other users and the service. |
| Understanding use | Legitimate interests (art. 6.1 f): learning which features are used and where people get stuck, so we can improve the product. See product analytics. |
| Legal requirements | Legal obligation (art. 6.1 c), where applicable, for example bookkeeping rules or a lawful request from an authority. |
We do not sell personal data, and we do not use your content for advertising.
5. Product analytics
We use PostHog, hosted in PostHog’s EU cloud, to learn which features are used, where people get stuck and when something breaks. It is set up so that the content of your pages never reaches it:
- Events. Page views, clicks (without the text of what you clicked) and a small set of named events, such as “signed in”, “page created”, “agent connected” or “change kept”. For AI assistants we record which tool was used and how many blocks were written, never the text, file names, titles or search queries.
- Identity. When you are signed in, events are linked to your account ID only. Your email address and name are not sent.
- Session recordings, fully masked. For signed-in members we record how the app is used, with every piece of text replaced by placeholders, form input masked, and the editor, images and files blocked out entirely. Recordings never run on shared pages, guest views or pairing pages. They are kept by PostHog for 30 days.
- Errors. When something breaks we send a short, scrubbed error message and where in the code it happened, never the data involved.
- Not collected. Console messages, network traffic, performance data and heatmaps are switched off. Share-link tokens and pairing codes are stripped from addresses, IP addresses are discarded, and “Do Not Track” is respected.
If you prefer not to be tracked, content blockers that block PostHog stop the browser part of analytics from loading. wunel works normally without it. You can also object to this processing; see your rights.
In the iOS app PostHog records the same kind of events (screens opened, pages opened and edited, sync and offline periods, all without page text), linked to your account ID only. When something goes wrong it records the error type, which request failed and how, and, after a crash or a freeze, Apple’s crash report for it (MetricKit), never the data involved. There is no session recording in the app. To group events, the app keeps a random installation ID and a small event queue in its own storage on your device.
This website (wunel.com) does not load PostHog. Some events, such as signing in or an assistant writing to a page, are recorded by our servers, so they are counted whichever app you use.
6. Cookies and similar technologies
wunel_session: keeps you signed in to the web app. It lasts up to one year, is marked HttpOnly (page scripts cannot read it) and is only sent over HTTPS. Strictly necessary.wunel_guest: recognises a guest who opened a share link, so their name and their edits stay theirs. It lasts up to 90 days. Strictly necessary for guest editing.- PostHog stores nothing in your browser: no cookie and no local storage. Its identifier lives in memory and is gone when you close the tab. (The iOS app keeps a random installation ID in its own storage; see product analytics.)
- The web app also keeps some preferences in your browser’s local storage. They stay on your device.
7. Who processes data for us
We use these providers (sub-processors) to run wunel. Each handles data only on our instructions and only for the purpose listed.
| Provider | What for | Where |
|---|---|---|
| Hetzner Online GmbH | Servers, database and file storage for all wunel data, and our backups | Helsinki, Finland (EU) |
| WorkOS, Inc. | Sign-in: issues and checks your one-time codes, and handles sign-in when you connect an assistant. Receives your email address and, at sign-in, your IP address and user agent | USA |
| Resend | Sending service emails such as sign-in codes, sign-in links and invitations. Receives your email address and the email’s content | EU region |
| PostHog | Product analytics in the web app (details) | EU cloud |
| Vercel | Hosts this website, wunel.com. It does not host the app or your data | Global edge network |
| Apple | Distributes the iOS beta app through TestFlight, under Apple’s own terms | USA |
8. Transfers outside the EU
Your pages, files and account data are stored in the EU. Some providers above are based in the USA (WorkOS for sign-in, and Apple for the TestFlight beta). Where personal data is transferred outside the EU/EEA, we rely on a recognised safeguard, such as the EU–US Data Privacy Framework where the recipient participates in it, or the European Commission’s standard contractual clauses. You can ask us for more information about these safeguards.
9. How long we keep data
- Account data and content: as long as your account exists, or until you delete it. Pages and files in a workspace stay until they are deleted or the workspace is deleted.
- Backups: we take nightly backups and keep them for 14 days. Deleted data disappears from backups as they roll off.
- Assistant keys expire one year after they are issued, unless you revoke them sooner.
- Session recordings are kept by PostHog for 30 days.
- Server logs are kept for a limited period for operations and security.
10. Deleting your account
You can delete your account yourself in the web app under Settings → Security → Delete account. To protect you, we email you a one-time code first, and deletion only goes ahead with that code. Deleting your account permanently removes:
- your account and your sign-in identity at WorkOS;
- the workspaces you own, with their pages, folders, comments, page history and share links, and the other members’ access to them;
- your comments, and the authorship records linking blocks to you, everywhere;
- your connected assistants and all their keys;
- your memberships in other people’s workspaces, your access requests, and your account activity log.
Text you wrote in pages that belong to other people’s workspaces stays in those pages, because it is part of their document, but it is no longer linked to your account. We keep a record that the account was deleted (the time, IP address and user agent) for security. Deleted data stays in backups until they roll off after 14 days. If you want written confirmation that files you uploaded have been erased from storage, email us.
11. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you, and get a copy.
- Rectification: have inaccurate data corrected. You can also edit your pages directly.
- Erasure: have your data deleted. You can do most of this yourself (see deleting your account).
- Portability: get your content in a usable format. Any page can be downloaded as Markdown (.md) or exported as Word (.docx) or PDF from the page menu in the web app.
- Object to processing based on legitimate interests, including product analytics.
- Restriction of processing in certain situations.
- Complain to a supervisory authority. In Sweden that is Integritetsskyddsmyndigheten (IMY), imy.se.
To use any of these rights, email support@wunel.com from the address on your account. We will answer within one month.
12. Changes and contact
If we change this policy, we will update the date at the top. For significant changes we will also tell account holders by email.
Questions about privacy: support@wunel.com, or write to Upnorth AI AB, Klippvägen 19, 135 61 Tyresö, Sweden.
How we protect your data is described on our security page.