Privacy
Privacy Policy
Last updated: July 17, 2026
This Privacy Policy describes how AI PRODUCTS LTDA, CNPJ 63.045.700/0001-12 (“Weft”, “we”, “us”), collects, uses, shares, and protects personal data when you use letsweft.com and the Weft applications (together, the “Service”). We are the data controller under the EU General Data Protection Regulation (“GDPR”), the business under the California Consumer Privacy Act / California Privacy Rights Act (“CCPA/CPRA”), and the controlador under the Brazilian Lei Geral de Proteção de Dados (“LGPD” — Law 13.709/2018).
1. Data We Collect
- Account data — your name, email address, and a salted password hash. We do not store your password in plain text.
- Content you create — tasks, sprints, columns, comments, attachments, board configuration, and any text you add through the web app or an AI client. If you join or create a shared workspace (Team plan), all members of that workspace can see and edit this content. Only the workspace owner is billed.
- Billing data — we store a Stripe customer ID and subscription metadata. Card details are entered directly on Stripe’s PCI-DSS-compliant infrastructure and are never stored on our servers.
- AI client / MCP metadata — when you connect an AI assistant (Claude, Cursor, Codex, ChatGPT, Gemini, etc.) via the MCP endpoint, we log the authorized client, OAuth tokens, and the tool calls made, so access can be audited and withdrawn on request.
- Usage & technical data — IP address, browser/device type, operating system, pages visited, cookie identifiers, and timestamps, used for security, analytics, advertising measurement, and debugging.
- Support data — the content of your messages when you email us.
2. How We Use It
- to provide, operate, and maintain the Service;
- to process payments and manage your subscription;
- to authenticate you and secure your account;
- to let you and your AI clients read and modify your board through the MCP endpoint;
- to respond to support requests;
- to send transactional messages (receipts, security alerts, policy updates) and, with your consent where required, product updates;
- to detect fraud and abuse, enforce our Terms, and comply with legal obligations;
- to fix bugs and improve the Service;
- to measure how visitors use letsweft.com and how our marketing campaigns perform, and to reach potential users with advertising — using analytics and advertising cookies only with your consent where required (see Section 12).
We do not sell your personal data, and we do not use your User Content to train shared or third-party AI models.
3. Legal Bases (GDPR & LGPD)
- Contract — to provide the Service you signed up for (account, billing, MCP access).
- Legitimate interests — to keep the Service secure, prevent fraud, and improve reliability; balanced against your rights.
- Legal obligation — to keep billing records and respond to lawful requests.
- Consent — for optional cookies, optional marketing emails, or any other processing that requires consent. You can withdraw consent at any time.
4. Who We Share Data With
We share personal data only with the parties below. Most are service providers (sub-processors) acting under written agreements that limit their use to our instructions; Google (analytics) and Meta (advertising measurement) also process some data for their own purposes as described in their privacy policies:
- Vercel, Inc. (United States) — application hosting, edge network, and serverless function execution for letsweft.com and our APIs.
- Neon, Inc. (United States) — managed PostgreSQL database storing account, content, and billing data.
- Upstash, Inc. (United States / EU) — managed Redis used for rate limiting and short-lived session/MCP state.
- Stripe, Inc. (United States) — payments, subscription billing, and customer portal for web purchases. Card data is entered directly on Stripe’s PCI-DSS-compliant infrastructure.
- Google LLC (United States) — two roles: (a) when you purchase or manage a Pro subscription on Android via Google Play Billing, Google processes the transaction under its own terms; (b) Google Analytics on letsweft.com helps us understand how visitors use the site (pages visited, device type, approximate location derived from IP). Analytics cookies are set only as described in Section 12.
- Meta Platforms, Inc. (United States) — advertising measurement via the Meta Pixel on letsweft.com. Where allowed under Section 12, Meta receives usage events (such as page views and sign-ups), cookie identifiers, and — when you sign up — a hashed (SHA-256) version of your email address and name, used to match conversions to Meta ads (“Advanced Matching”). Subject to the same Section 12 consent, we may also report the sign-up event to Meta from our servers (“Conversions API”), limited to the same hashed identifiers (email, account ID) and technical data (IP address, browser identifiers). We never send your board content, password, or billing details to Meta.
- Apple Inc. (United States) — when you purchase or manage a Pro subscription on iOS or macOS via Apple In-App Purchase, Apple processes the transaction under its own terms.
- Email delivery provider (United States / EU) — sends transactional messages (verification, password reset, billing receipts).
- AI clients you connect — if you authorize an AI client to access your board via MCP, that client’s provider receives whatever data you or your client chooses to transmit. Each provider processes that data under its own terms.
- Legal & safety — if required by law, court order, or to protect our or others’ rights, property, or safety.
- Successors — as part of a merger, acquisition, or asset sale, subject to equivalent protections.
We do not use third-party analytics SDKs, advertising SDKs, or attribution SDKs in the mobile app.
5. International Transfers
We are headquartered in Brazil, and our service providers operate in multiple regions, including the United States and the European Union. When we transfer personal data out of your region, we rely on lawful transfer mechanisms such as Standard Contractual Clauses (GDPR), adequacy decisions, or equivalent safeguards under the LGPD.
6. Data Retention
We keep account and content data for as long as your account is active. When you delete your account, we delete or anonymize personal data within 30 days, except where we must keep records for legal, tax, accounting, or fraud-prevention purposes (typically up to 5 years under Brazilian tax law).
7. Security
We use industry-standard technical and organizational measures to protect your data, including TLS encryption in transit, encrypted password hashing, access controls, and audit logging. No method of transmission or storage is 100% secure; we cannot guarantee absolute security.
8. Your Rights
8.1 Everyone
You can at any time:
- access the data in your account through the Service;
- correct inaccurate data;
- export your data (tasks, sprints, comments) in a machine-readable format on request;
- delete your account from the account deletion page, from the settings screen in the Weft mobile app, or by emailing us — this also deletes the related personal data.
8.2 Brazil (LGPD)
You have the rights in Art. 18 of the LGPD, including confirmation of processing, access, correction, anonymization/blocking/deletion of unnecessary data, portability, information about sharing, and to revoke consent. The Brazilian data protection authority is ANPD — gov.br/anpd.
8.3 European Economic Area & UK (GDPR)
You have the rights of access, rectification, erasure, restriction, portability, and objection (including to processing based on legitimate interests). You have the right to lodge a complaint with a supervisory authority in your country of residence.
8.4 California (CCPA/CPRA)
California residents have the right to know what personal information we collect and how we use it, to request deletion, to correct inaccurate information, to limit the use of sensitive personal information, and to opt out of the “sale” or “sharing” of personal information. We do not sell your personal information. Our use of advertising cookies (the Meta Pixel) may constitute “sharing” (cross-context behavioral advertising) as defined by the CCPA/CPRA. You can opt out at any time by choosing “Essential only” in our cookie banner or via the “Cookie settings” link in the site footer; we also honor the Global Privacy Control (GPC) browser signal as a valid opt-out request. We will not discriminate against you for exercising your rights.
8.5 How to exercise your rights
To delete your account, use the self-service deletion page (web) or the Settings screen in the Weft mobile app. For any other request (access, correction, export, objection), email support@letsweft.com. We will respond within the timeframe required by applicable law (typically 15 days under LGPD, 30 days under GDPR, 45 days under CCPA/CPRA).
9. Mobile App Permissions
The Weft Android and iOS apps request the minimum permissions required to function. Specifically, the Android app declares only the INTERNET permission, which lets the app reach our API at letsweft.com to sync your board.
Weft does not request or use any of the following on Android: precise or approximate location, contacts, calendar, SMS or call logs, microphone, camera, background location, body sensors, nearby devices, external storage, or the advertising ID. The iOS app does not request location, contacts, calendar, microphone, camera, photos, motion, health, or tracking permissions.
10. AI Features
Weft does not generate content with AI. The product does not call any large-language model on its own, does not include a built-in chatbot, and does not transmit your board data to any AI provider.
What Weft does do is expose a Model Context Protocol (MCP) endpoint that you can authorize external AI clients (Claude Desktop, Cursor, ChatGPT Codex, Gemini CLI, etc.) to use. Each AI client connects directly to our MCP endpoint with an OAuth token you grant; the data exchanged is whatever you or your authorized client chooses to read or write. Weft is not the operator of those AI clients and does not send your data to them — you do, by connecting them.
11. Children
The Service is not directed to children under 13 (or the equivalent minimum age in your country), and we do not knowingly collect their data. If you believe a child has provided personal data, contact us and we will delete it.
12. Cookies & Similar Technologies
We use strictly necessary cookies to keep you signed in, remember your preferences, and secure the Service. These are always on.
We also use non-essential cookies for analytics and advertising measurement: Google Analytics (_ga, _ga_*) and the Meta Pixel (_fbp, _fbc). Visitors from the EEA, the United Kingdom, and Switzerland see a consent banner, and these cookies are set only after they choose “Accept all”. Browsers that send the Global Privacy Control signal are opted out automatically. You can change your choice at any time via the “Cookie settings” link in the site footer, and you can also manage or delete cookies in your browser.
13. Changes to This Policy
We may update this Privacy Policy. Material changes will be notified by email or in-product at least 15 days before they take effect. The “Last updated” date at the top reflects the latest version.
14. Contact & Data Protection Officer
- Data controller: AI PRODUCTS LTDA — CNPJ 63.045.700/0001-12.
- Privacy contact / DPO: support@letsweft.com