Privacy policy
The short version: we hold your content so you can come back to it, we log every metered call so billing is auditable, prompt content reaches the model provider you selected, and we do not sell any of it.
Last updated 16 August 2026
1. What we collect
Account data: your name, email address, and the organisations you belong to along with your role in each. A password is stored only as a hash.
Content data: the documents you write, the PDFs you upload and the text extracted from them, the designs you generate and their canvas state, and the brand kit you configure.
Usage data: for every AI call, the app, tool, model, provider, input and output token counts, billed tokens, cost, duration and outcome. For every wallet movement, the amount, source, resulting balance and a description.
Billing data: plan, interval, payment status and gateway reference. Card details are handled by the payment gateway and never reach our servers.
2. Why we hold it
To deliver the service: your content is stored so you can come back to it, and indexed so retrieval-grounded answers can cite it.
To meter fairly: the usage log and wallet ledger are what let us bill on real consumption and let you audit every rupee of it.
To keep accounts secure: session and login records support rate limiting, session revocation and investigating account misuse.
3. Who else sees it
Model providers receive the prompt context of a call you initiate, which may include the document or PDF text you asked about. Only the content needed for that call is sent, and only when you run a tool.
The payment gateway receives what it needs to take a payment. Infrastructure providers hosting our database and file storage hold data at rest on our behalf.
Other members of your organisation see the organisation's content according to their role. We do not sell personal data or content to anyone.
4. Retention
Content is kept while your organisation exists. Deleting a document, PDF or design removes it from your workspace; usage log and ledger entries survive as an immutable billing record, but they hold metadata about the call rather than the content of it.
Closing an account removes your content within thirty days, except where we are required to retain billing records for tax or accounting purposes.
5. Your choices
You can update your profile, revoke individual sessions or sign out everywhere from account settings, and export your documents and designs at any time in the formats your plan allows.
To request a copy of your data or its deletion, email us and we will confirm the request against your account before acting on it.
6. Security
Access tokens are short-lived and refresh tokens are httpOnly. Sensitive endpoints are rate limited. Payment webhooks are verified against a signature over the raw request body. See the security page for the full picture, including what we do not claim.
To request a copy of your data or its deletion, email support@casperwasp.com from the address on the account. We confirm the request against the account before acting on it, which is why it has to come from that address.