Privacy Policy
This Privacy Policy explains how Sad Coder, Inc. (Sad Coder, we, us, or our) handles personal data when you use wspc, including its web console, CLI, APIs, Drive features, and MCP server (collectively, the Service).
Sad Coder is the controller of personal data described in this policy unless we state otherwise. Our business and privacy contact details are:
Sad Coder, Inc., 5F., No. 50, Zhongyang 7th St., Xindian Dist., New Taipei City 231014, Taiwan — [email protected]
This policy does not govern a third party’s independent processing, including Paddle’s transaction processing or an integration you choose to connect.
1. Personal data we collect
Depending on how you use the Service, we collect:
- Account and workspace data: email address, user and workspace identifiers, workspace name, membership, role, invitations, and account creation and update times.
- Authentication and authorization data: one-time login-code records, hashed API keys, OAuth client and grant information, token-family and revocation records, authorized scopes, and security events. The web console stores access credentials and consistency bookmarks in your browser’s local storage so it can keep you signed in and provide consistent reads.
- Customer Content: todos, projects, comments, calendar events, email messages and addresses, attachments, aliases and domains, Drive libraries, files and versions, push-notification configuration, and other content you or an authorized client submits.
- Billing data: workspace plan, Paddle customer, subscription, transaction and product identifiers, subscription status and billing periods, plan changes, cancellation state, usage and quota records, and refund or support status. We do not receive or store full payment-card numbers.
- Usage and device data: feature actions, pseudonymous user identifiers, a masked email value, browser or device information, IP address and request metadata that infrastructure providers process, and local-storage or analytics identifiers.
- Diagnostics and support data: error and performance information, low-sensitivity operational diagnostics, security warnings, and information you include in support or privacy requests.
Customer Content may contain personal data about other people. The person or organization submitting that content is responsible for having an appropriate basis to do so.
2. Sources of personal data
We receive personal data:
- directly from you and other members or administrators of your workspace;
- from authorized clients, agents, OAuth applications, MCP hosts, and other integrations acting on your instructions;
- from senders, recipients, and mail systems when the Service sends or receives email;
- from Paddle when it reports transaction and subscription state; and
- automatically from your browser, device, and use of the Service.
3. Why we use personal data
We use personal data for the following purposes and legal bases where those bases are required:
| Purpose | Typical legal basis |
|---|---|
| Create accounts, operate workspaces, deliver email and files, run connected clients, and provide support | Performance of our contract with you |
| Authenticate users, prevent abuse, secure the Service, debug failures, and maintain reliable operations | Performance of our contract and our legitimate interests in security and service reliability |
| Administer plans, reconcile Paddle state, apply quotas, and keep transaction-related records | Performance of our contract and compliance with legal obligations |
| Understand feature use and improve the Service through product analytics | Our legitimate interests, or consent where applicable law requires it |
| Respond to legal requests, enforce our Terms, protect rights, and comply with tax, accounting, sanctions, and other laws | Compliance with legal obligations and our legitimate interests |
| Send service messages and respond to requests | Performance of our contract and our legitimate interests in communicating with users |
We do not use Customer Content to train machine-learning models, sell personal data for money, or use personal data for cross-context behavioral advertising.
4. How we disclose personal data
We disclose personal data only as needed for the purposes above:
- Workspace members and administrators: according to workspace roles and permissions. Administrators may manage members, access, billing, and shared workspace content.
- Processors and service providers: Cloudflare provides application, database, object-storage, network, and security infrastructure; Resend provides email delivery and receipt; PostHog provides product analytics and feature flags; and Sentry provides error and performance monitoring. Each receives the data needed for its service.
- Paddle as merchant of record: Paddle independently processes purchaser, payment, tax, invoice, fraud, refund, and transaction-support data under its Privacy Notice. Sad Coder and Paddle generally act as independent controllers for transaction data shared between them. We receive limited identifiers and transaction or subscription state needed to provide paid plans.
- Integrations and communications: we disclose data to an integration you authorize and to email recipients and their mail providers when you direct the Service to communicate with them.
- Legal and safety recipients: we may disclose data to authorities, advisers, or affected parties where reasonably necessary to comply with law, protect rights and safety, investigate abuse, or establish or defend legal claims.
- Corporate transactions: data may be disclosed to advisers and a successor in connection with a financing, merger, reorganization, or sale, subject to appropriate confidentiality and applicable law.
We do not control how an independent recipient or an integration you authorize uses data under its own terms.
5. Analytics, browser storage, and similar technologies
The web console uses browser local storage for authentication state and consistency bookmarks. Removing this storage or signing out may end your session or remove local account state.
Where configured, PostHog records product interactions and uses identifiers to associate activity with an account. Browser and infrastructure providers may also use cookies or similar technologies for security, routing, or service operation. Some jurisdictions require prior consent for non-essential analytics. You may use browser controls to restrict cookies or local storage, although essential features may stop working.
6. Retention and deletion
We keep personal data only as long as reasonably necessary for the purposes in this policy, including providing the Service, maintaining security and audit records, resolving disputes, and meeting legal obligations.
Current product-specific periods include:
- email and Drive items placed in trash are scheduled for permanent deletion after 30 days and may be permanently deleted sooner when an authorized user empties trash;
- Drive file-version retention is seven days for free workspaces; paid workspaces may select an available retention period, including indefinite retention;
- completed email and Drive export packages expire after seven days; and
- some bounded operational records have shorter or longer lifetimes based on their purpose, such as login codes, OAuth grants, email idempotency records, security events, and billing reconciliation records.
Other workspace records may be soft-deleted and remain until the applicable workspace or account cleanup process permanently removes them. Backup copies and records held by service providers may remain for their normal backup or legal-retention periods. Paddle independently retains transaction data under its own policy and legal obligations.
You should export data before terminating access. To request account deletion, contact [email protected]. We will verify the request and account for shared workspace rights, security, fraud prevention, legal holds, and records we must retain. Removing one member does not necessarily delete content controlled by the workspace or other members.
7. International data transfers
Sad Coder operates from Taiwan as a Delaware corporation, and our providers may process data in the United States, Taiwan, and other countries where they operate. Those countries may have different data-protection laws. Where law requires a transfer safeguard, we use an applicable contractual or legal mechanism and supplementary protections appropriate to the transfer.
8. Security
We use administrative, technical, and organizational measures designed to protect personal data, including encrypted transport, credential hashing, access controls, and filtering sensitive request headers and bodies from error reports. No system is completely secure. Keep your credentials and connected clients secure and report suspected compromise to [email protected].
9. Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal data; withdraw consent; opt out of certain processing; or appeal our response. You may also complain to your local data-protection authority.
You can edit or delete many records through the Service, revoke connected clients, and sign out to clear active access. For any other request, email [email protected]. We may verify your identity and authority before acting. If a request concerns data controlled by a workspace, its administrator, an integration, or Paddle, we may direct the request to the appropriate party.
These rights are subject to lawful exceptions. We will not discriminate against you for exercising a privacy right.
10. Minors
The Service is not intended for anyone who has not reached the age of majority where they live, and we do not knowingly collect personal data from minors. If you believe a minor has provided personal data, contact us so we can review and delete it where appropriate.
11. Changes to this policy
We may update this policy as the Service or law changes. We will post the new version and update the date above. Where required, we will give additional notice before a material change takes effect.
12. Contact
For privacy questions, requests, or complaints, contact [email protected] or write to Sad Coder at the address stated at the beginning of this policy.