Privacy Policy

Draft prepared for legal review. Replace everything in [ ] with your own details: legal entity, commercial registration, address, privacy mailbox. Do not publish before a qualified lawyer has reviewed it.

1. Who we are

Wateera is operated by [legal entity name], commercial registration [number], based in [city], Kingdom of Saudi Arabia ("we"). Wateera is a daily-performance product: a user plans their day, executes it, and closes it with a computed score, with the help of agents that work on their own data.

Privacy contact: [[email protected]].

2. What we process

Account data: name, email address, mobile number when you sign in with an OTP code, language preference, and an avatar if you upload one.

Your work content: the day's intention, the energy you state, tasks with their impact, effort and estimates, focus minutes, and review notes (what worked, blockers, tomorrow's task), plus any text you write in the product's screens.

Operational data: agent runs and their output, which engine answered (local engine or model), run duration, and metering records (runs, model tokens, GPU seconds when used) as well as the audit trail that records sensitive operations (closing a period, deleting an item, refused access attempts).

Technical data: session identifier, IP address, browser type and sign-in time — for account security and to detect unauthorised use.

Payment data: card details are processed by a licensed payment provider. We do not store card numbers or verification codes, only the transaction identifier, its status and the subscription amount.

Workspace data: workspace name, members and their roles, invitation history.

3. Legal basis

We process personal data under the Kingdom of Saudi Arabia's Personal Data Protection Law, on the following bases:

  • Performance of a contract: operating your account and workspace and providing the product.
  • Legitimate interest: service security, abuse prevention, the audit trail, performance work.
  • Legal obligation: invoicing and accounting retention.
  • Consent: marketing messages and non-essential analytics, withdrawable at any time.

4. AI and agent output

The product ships a deterministic local engine that runs without sending any data to any third party. When a model provider is enabled on your account, only the input fields the task needs (for example the intention text, the task list and the blocker) are sent to the model provider to produce the output, and the output is stored in your run history.

Our commitments:

  • We do not use your content to train any model, and we do not grant model providers the right to use it for training.
  • We do not send the provider more than the task requires (no passwords, no payment data, no other members' data).
  • Every run records who answered — the local engine or the model — and you can see that in your run history.

5. Sub-processors

We use providers to run the service, and they handle data only within what the service provides:

| Provider | Purpose | Data | | -------------------------------- | ------------------------------------ | -------------------------------------------- | | [hosting and database provider] | running the app and storing data | all product data | | [model provider, e.g. Anthropic] | generating agent output when enabled | the run's input fields | | [payment provider, e.g. Moyasar] | subscriptions and invoices | subscription data; card data stays with them | | [mail provider] | verification and notification email | email, name, message content | | [SMS provider] | mobile verification codes | mobile number, code content | | [object storage provider] | storing logos and images you upload | uploaded files |

6. Retention

  • Your days, tasks and reviews: while your account is active, then deleted within 30 days of a deletion request.
  • Audit trail: 12 months, because it is a security record.
  • Metering records: 24 months to meet accounting requirements.
  • Backups: a cycle shorter than 30 days, after which they are replaced automatically.

7. Your rights

You may access your data, correct it, request its deletion, restrict or object to processing, receive a portable copy, and withdraw consent at any time. We respond within 30 days of a request sent to [[email protected]]. You also have the right to complain to the competent authority in the Kingdom (the Saudi Data and AI Authority).

8. Cookies

We use cookies strictly necessary to operate the service (session, chosen language, cookie consent) and optional analytics cookies that do not run before you consent. You can change or withdraw your choice at any time from the site's cookie settings.

9. Security

  • Every workspace's data is isolated, and a member cannot read another member's data beyond what is disclosed (the team board shows score, focus minutes and the day's state only — never task titles or notes).
  • Encrypted transport, an ownership check on every request, and an audit trail for sensitive operations that includes refused access attempts.
  • Least privilege: production data access is limited to those who need it to operate the service.

10. Changes

We may update this policy and will publish the version in effect with its update date. Material changes are announced inside the product before they take effect.

11. Contact

[legal entity name] — [email] — [address].

Last updated: [date].