Privacy

Effective Date: August 24, 2026

This Privacy Policy explains how Water AI, Inc., doing business as Water AI ("Water," "we," "us," or "our"), collects, uses, discloses, transfers, retains, and protects personal information when you use wwater.ai, Water applications, APIs, beta programs, connected-app features, and related services (collectively, the "Services").

Water is an AI-powered goal, memory, planning, collaboration, and action-execution service. Because the Services can remember context, connect to third-party applications, and perform user-authorized actions, privacy depends both on what you provide to Water and on the permissions you grant.

1. Who Controls Your Personal Information

For consumer and direct-user Services, the controller or business responsible for your personal information is:

Water AI, Inc.

Privacy contact: privacy@wwater.ai

If you use Water through an employer, business customer, developer, or other organization that has a separate agreement with us, that organization may be the controller and Water may act as its processor or service provider. In that situation, the organization's privacy notice and agreement with Water may govern the relevant processing.

2. Personal Information We Collect

The categories below describe the information Water may process depending on the features you use.

2.1 Account and Profile Information

  • Name, email address, account identifiers, authentication information, profile preferences, timezone, locale, language, and similar account settings.
  • Organization, company, team, role, or collaborator information if you use business or collaboration features.

2.2 Goals, Conversations, Plans, Tasks, and Memory

  • Goals, priorities, tasks, plans, decisions, blockers, reminders, notes, instructions, prompts, conversations, and AI responses.
  • Information you ask Water to remember or that Water stores to provide continuity and personalization.
  • Derived or inferred information, such as likely preferences, relationships between tasks, suggested priorities, goal progress, and contextual recommendations.

2.3 Connected-App Information

If you connect a third-party service, Water may receive information made available under the permissions you grant. Depending on the integration, this can include calendar events, email or message content, contacts, files, project records, tasks, CRM data, account metadata, and action results.

Water may also process OAuth tokens, authorization identifiers, scopes, connection status, and similar credentials needed to maintain the connection. We use these credentials to operate the connection, not as a substitute for your own login credentials.

2.4 Action and Execution Data

  • Requests to perform an action, approval state, permissions, tool or integration selected, action parameters, execution status, response, errors, retries, verification results, and timestamps.
  • Audit information reasonably necessary to show what Water attempted, what a third-party service returned, and whether an action was completed.

2.5 Collaboration Data

If you invite or collaborate with others, we may process collaborator names, email addresses, invitations, permissions, shared-goal content, messages, comments, actions, and activity relevant to the shared workspace.

2.6 Beta Application, Support, and Communications

  • Beta application information, including your name, email, company, goals, reasons for applying, blockers, and information about how you currently manage your work or goals.
  • Support requests, feedback, survey responses, bug reports, and correspondence with Water.
  • Marketing preferences and records of communications we send to you.

2.7 Device, Usage, and Security Information

  • IP address, device and browser type, operating system, app version, language, approximate location derived from IP, identifiers, timestamps, pages or features used, diagnostics, crash information, and logs.
  • Security signals, authentication events, suspected abuse indicators, rate-limit data, and similar information used to protect accounts and systems.

2.8 Payment Information

If you purchase paid Services, our payment provider may collect payment card, billing, tax, and transaction information. Water generally receives transaction status, billing identifiers, plan information, and limited payment metadata rather than full card details.

2.9 Sensitive Information

Your goals and conversations may reveal sensitive information, including health or wellness information, financial circumstances, precise location, religious or political interests, sexual orientation, citizenship status, or other information treated as sensitive under some laws. Do not provide sensitive information unless it is reasonably necessary for the feature you choose to use.

Where applicable law requires consent to process sensitive information, we will request consent or rely on another legally permitted basis before processing it for the relevant purpose.

3. Where We Get Information

We collect information:

  • directly from you when you create an account, communicate with Water, apply for beta, enter goals, upload content, or configure settings;
  • from Connected Services when you authorize access;
  • from collaborators when they invite you or add information to a shared goal or workspace;
  • automatically from your device and use of the Services; and
  • from service providers that help us operate payments, authentication, security, analytics, communications, or infrastructure.

4. How We Use Personal Information

We use personal information to:

  • provide, personalize, and maintain the Services;
  • understand your goals, context, plans, and instructions;
  • generate AI outputs, recommendations, reminders, summaries, plans, and next-step suggestions;
  • maintain memory and continuity across sessions when enabled;
  • connect to and perform user-authorized actions through Connected Services;
  • support collaboration, invitations, permissions, and shared goals;
  • verify whether requested actions succeeded and diagnose failures;
  • process payments and administer subscriptions;
  • evaluate beta applications and communicate about access;
  • provide support and respond to requests;
  • secure accounts, prevent abuse, investigate incidents, and enforce our terms;
  • measure Service reliability, performance, and feature usage;
  • improve the Services using de-identified, aggregated, statistical, or otherwise lawfully processed information;
  • comply with legal obligations and protect rights, safety, and property; and
  • send marketing communications where permitted, subject to your choices.

5. AI Processing, Memory, and Model Improvement

Water uses AI models to interpret instructions, maintain context, generate plans and content, recommend actions, summarize information, and assist with execution. Information you provide may be sent to AI infrastructure or model providers acting as service providers or processors when needed to provide a feature.

Unless we provide a separate notice or obtain any consent required by law, Water does not use identifiable private User Content to train generalized AI models for unrelated customers. We may use de-identified or aggregated information that cannot reasonably be linked to you to improve reliability, safety, product design, and performance.

We configure and contract with model and infrastructure providers, where available, to limit use of Water data to providing the requested service. Before publication, Water should maintain and publish an up-to-date subprocessor list at [SUBPROCESSOR LIST URL].

Water may infer context from your data, such as suggested priorities, task relationships, reminders, or likely preferences. These inferences are used to provide the Services and may not always be correct. Where available, you can correct source information, delete content, reset memory, or provide new instructions.

6. Automated Decision-Making

Water may use automated processing to prioritize tasks, generate recommendations, detect patterns, select tools or models, and suggest or execute user-authorized actions. Water is not intended to make solely automated decisions that produce legal or similarly significant effects about you or another person, such as final decisions about employment, credit, insurance, housing, healthcare eligibility, or access to essential services.

If we introduce a feature that uses automated decision-making in a way that triggers additional legal rights, we will provide any required notice, explanation, consent, opt-out, human review, or appeal mechanism.

7. Legal Bases for EEA, UK, and Similar Jurisdictions

Where the GDPR, UK GDPR, or similar laws apply, our legal bases generally include:

  • Contract - processing necessary to provide the Services you request, maintain your account, generate outputs, connect applications, and perform authorized actions.
  • Legitimate interests - securing and improving the Services, preventing abuse, diagnosing failures, communicating about Service administration, and understanding product performance, where those interests are not overridden by your rights.
  • Consent - where you choose optional processing, where sensitive data requires consent, where required for certain cookies or marketing, or where another law requires affirmative permission.
  • Legal obligation - complying with tax, accounting, lawful requests, regulatory duties, and other legal requirements.

You may withdraw consent at any time where processing is based on consent. Withdrawal does not affect processing already lawfully completed.

8. How We Disclose Personal Information

We may disclose personal information to the following categories of recipients only as reasonably necessary for the purposes described above:

  • cloud hosting, storage, database, security, authentication, monitoring, and communications providers;
  • AI model and AI infrastructure providers;
  • integration and Connected Service providers when you request or authorize the connection or action;
  • payment processors and billing providers;
  • professional advisers such as lawyers, auditors, insurers, and accountants;
  • collaborators and workspace participants according to the permissions and sharing choices you make;
  • government authorities, regulators, courts, or other parties where disclosure is legally required or reasonably necessary to protect rights and safety; and
  • a buyer, successor, investor, or transaction adviser in connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to appropriate confidentiality and legal protections.

9. Sale, Targeted Advertising, and Cross-Context Behavioral Advertising

As of the effective date of this Policy, Water does not sell personal information for money and does not share personal information for cross-context behavioral advertising or process personal information for targeted advertising as those terms are defined by applicable U.S. state privacy laws.

If our practices change, we will update this Policy and provide legally required opt-out mechanisms before beginning covered sale, sharing, or targeted-advertising activity. Where applicable, we will recognize valid universal opt-out signals, such as Global Privacy Control, for processing to which those signals legally apply.

10. Cookies and Similar Technologies

Water may use cookies, local storage, SDKs, pixels, or similar technologies that are necessary for authentication, security, preferences, Service operation, and analytics. Where required by law, non-essential cookies or similar technologies will be used only after required consent.

Before publication, Water should maintain a current cookie inventory and ensure any consent banner accurately reflects the technologies actually deployed.

11. Data Retention

We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, to provide the Services, maintain security and auditability, comply with law, resolve disputes, and enforce agreements. The following is the proposed operational retention schedule for this draft and must match actual system behavior before publication.

  • Beta applications not converted to active accounts: generally 12 months after the last meaningful contact, unless you ask us to delete sooner or we need a shorter or longer period for a documented legal reason.
  • Account and profile information: while the account is active, then generally deleted or de-identified from active systems within 30 days after account closure, subject to legal obligations and backups.
  • Goals, conversations, tasks, plans, memory, and user-created content: until you delete the content or close the account; after deletion, generally removed from active systems within 30 days.
  • Connected Service access tokens and active authorization data: until you disconnect the service, the authorization expires, or the account closes; revoked credentials should no longer be used after revocation is processed.
  • Action, reliability, security, and audit logs: generally 12 to 24 months, depending on security, fraud-prevention, troubleshooting, and accountability needs. Logs should be minimized and should not retain full content when metadata is sufficient.
  • Support communications: generally 24 months after the support matter is closed, unless a longer period is reasonably needed for dispute resolution or legal obligations.
  • Billing, tax, and transaction records: generally 7 years or the period required by applicable tax, accounting, and financial laws.
  • Marketing contact and consent records: until you opt out, plus a limited suppression record needed to honor your opt-out and demonstrate compliance.
  • Backups: deleted information may remain in encrypted backups for up to 90 days before routine overwrite, unless a shorter period is technically feasible or longer retention is required by law.

We may retain de-identified information that cannot reasonably be linked to you. We may also retain information longer when required by law, subject to a legal hold, necessary to investigate fraud or security incidents, or needed to establish, exercise, or defend legal claims.

12. Your Privacy Rights

Depending on where you live and the law that applies, you may have the right to:

  • know whether we process your personal information and access a copy;
  • correct inaccurate personal information;
  • delete personal information, subject to lawful exceptions;
  • receive certain information in a portable, machine-readable format;
  • restrict or object to certain processing;
  • withdraw consent where processing is based on consent;
  • opt out of sale, targeted advertising, or certain profiling where applicable;
  • limit certain uses of sensitive personal information where applicable;
  • appeal a refusal of a privacy request where applicable;
  • receive information about certain automated decision-making; and
  • complain to a data protection or privacy regulator.

To exercise a privacy right, email privacy@wwater.ai or use [PRIVACY REQUEST FORM URL]. We may verify your identity before fulfilling a request. You may use an authorized agent where permitted by law. We will not discriminate against you for exercising applicable privacy rights.

13. EEA, UK, and Switzerland Rights

If the GDPR, UK GDPR, or comparable European law applies, you may have rights of access, rectification, erasure, restriction, portability, objection, and withdrawal of consent, as well as rights relating to certain solely automated decisions. You may also lodge a complaint with your local supervisory authority.

If we rely on legitimate interests, you may object where the law gives you that right. You may always object to direct marketing.

14. U.S. State Privacy Rights

Residents of certain U.S. states, including California and Colorado, may have rights to access, correct, delete, and obtain a portable copy of personal information and to opt out of certain sale, targeted advertising, sharing, or profiling. Some states also provide rights relating to sensitive data and an appeal process.

California residents may additionally request information about categories and specific pieces of personal information collected, sources, purposes, and categories of recipients, and may exercise rights concerning sale or sharing and sensitive personal information where applicable. Water does not currently sell or share personal information for cross-context behavioral advertising.

If Water becomes subject to a law requiring recognition of a universal opt-out mechanism, Water will process qualifying signals in accordance with applicable law.

15. Consumer Health Data - Washington and Similar Laws

Some goals or connected information can reveal health or wellness information. For example, a user might ask Water to help with an exercise goal, schedule medical appointments, manage reminders related to health, or process information that can reasonably indicate a physical or mental health status. Where laws such as Washington's My Health My Data Act apply, this section is intended to provide the additional disclosures required for consumer health data.

Categories of consumer health data we may collect: information you provide about physical or mental health, wellness, symptoms, treatments, medications, exercise, health-related appointments, health-related goals, and other information that a law defines as consumer health data; information from a Connected Service that you authorize; and inferences that are reasonably linkable to your health status.

Sources: directly from you; from Connected Services you authorize; and, where relevant to a shared feature, from collaborators who lawfully provide the information.

Purposes: to provide the feature you request, maintain relevant context or memory, generate reminders or recommendations, perform user-authorized actions, maintain security, and comply with law.

Sharing: we may share consumer health data with service providers or processors needed to provide the requested feature, with a Connected Service at your direction, or with a collaborator when you intentionally share it. We do not sell consumer health data.

Where applicable law requires separate consent for collection or sharing, we will obtain that consent before the covered processing unless the processing is otherwise permitted because it is necessary to provide a product or service you requested.

You may request access to or deletion of covered consumer health data, withdraw consent for future collection or sharing where applicable, and exercise other rights provided by applicable law by contacting privacy@wwater.ai.

Operational note before publication: if Water intentionally processes consumer health data for Washington residents, counsel should confirm whether this section should also be presented through a separately and prominently linked Consumer Health Data Privacy Policy page or URL.

16. International Data Transfers

Water and its service providers may process information in the United States and other countries. Those countries may have data-protection laws different from the laws where you live.

Where required, we use legally recognized transfer mechanisms, such as adequacy decisions, Standard Contractual Clauses approved by the European Commission, the UK International Data Transfer Addendum or other approved UK mechanisms, and supplementary safeguards appropriate to the transfer.

17. Security

We use reasonable administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, loss, misuse, alteration, and disclosure. These safeguards may include access controls, encryption in transit and at rest where appropriate, secrets management, audit logging, least-privilege permissions, environment separation, incident response, and vendor security review.

No system is completely secure. You are responsible for protecting your account credentials and for selecting appropriate permissions for Connected Services and collaborators.

18. Children

The Services are not directed to children under 18, and we do not knowingly permit individuals under 18 to create consumer accounts. If we learn that we collected personal information from a child in violation of applicable law, we will take appropriate steps to delete it.

19. Business and Developer Customers

When a business, developer, or other organization uses Water to process personal information on its behalf, Water may act as a processor or service provider and process information under the customer's instructions and applicable data processing agreement. In that context, the customer is generally responsible for providing required notices, establishing a lawful basis, responding to end-user rights, and configuring the Service appropriately.

20. Data About Other People

Water may process information about another person if you include it in a goal, message, contact, file, collaboration, or Connected Service. You are responsible for ensuring you have a lawful basis and any required permission to provide that information. Do not use Water to secretly profile, monitor, or make high-impact decisions about other people in violation of law.

21. Legal Requests and Safety

We may preserve or disclose information when we reasonably believe it is necessary to comply with law, respond to valid legal process, protect users or others from serious harm, investigate fraud or security incidents, enforce agreements, or defend legal claims. We assess government requests and may challenge requests that appear unlawful, overbroad, or inconsistent with applicable protections.

22. Changes to This Privacy Policy

We may update this Policy as the Services, laws, vendors, or practices change. If a change materially affects how we use personal information, we will provide notice appropriate to the change and obtain consent where required by law. The effective date at the top will show when the current version became effective.

23. Contact Us

Privacy questions and rights requests: privacy@wwater.ai

Water AI, Inc.

Privacy request form: [PRIVACY REQUEST FORM URL]

Publication checklist: confirm the legal entity and address; actual subprocessors and model providers; cookie/analytics stack; Connected Service scopes; whether identifiable content is used for any model training; deletion and backup timing; health-data flows; age gate; international transfer mechanism; business/processor roles; and all state-specific opt-out or appeal mechanisms before publishing.