Whyzr Privacy Policy
Last updated
1 Who we are and what this policy covers
This policy explains how StartupEdge LLC, a Puerto Rico limited liability company doing business as Whyzr (“Whyzr”, “we”, “us”), handles personal data. It covers the Whyzr app at app.whyzr.com, our MCP server and API, our emails and our website at whyzr.com.
Data we are responsible for. We decide how to use some personal data for our own purposes: the account and sign-in details of everyone who uses Whyzr, billing contacts, support messages, product emails, website visits, Usage Data and the de-identified benchmarks described in section 4. For this data we are the “controller”, and this policy applies in full.
Data we handle for our customers. Firms and companies put their financial data into Whyzr, and that data names people: their customers, vendors, employees and contractors. We process it on the customer’s behalf under our Terms of Service (whyzr.com/legal/terms) and Data Processing Addendum (whyzr.com/legal/dpa). The firm or company decides how it is used, and its own privacy notice applies. If you are a client of a firm that uses Whyzr, or your name appears in a company’s books, please contact that firm or company first. We will help them respond.
Whyzr is a business tool. It is not meant for consumers or for anyone under 18.
2 What we collect
| Category | Examples | Where it comes from |
|---|---|---|
| Account and sign-in | Name, email, role, workspace memberships, sign-in and session records, optional profile image, two-step sign-in settings, email preferences | You, or the person who invited you |
| Business financial data | Ledger details, financial statements, invoices and bills, recurring revenue, forecasts and assumptions, commentary, uploaded files | Uploads, and services you connect such as QuickBooks |
| People named in the books | Names of a company’s customers, vendors, employees and contractors in transactions and memos; pay shown on payroll lines | The company’s own records |
| AI chats | Questions, answers, the AI’s reasoning, tool results, charts, the page you were on, ratings and notes, chat titles, token counts and cost | You, and our AI provider |
| Audit trail | Who (a person, an agent or our staff) changed or read what, and when, values before and after a change, an agent’s stated reasoning, sign-ins and sign-outs | Created by the Service |
| Agents and API keys | Agent names, permissions, the first characters of each key (the full key is stored only as a hash), last-used time | Workspace admins |
| Billing | Billing contact, plan, trial dates. Polar handles card details; we do not receive full card numbers | You and Polar |
| Support and help requests | Messages to our support team, requests for help from StartupEdge | You |
| Technical data | Usage Data (features used, pages viewed in the app, errors, response times, AI cost per action), error reports, server logs, share-link view counts, browser type | Created by the Service |
We limit technical data on purpose. Error reports exclude IP-related headers, request bodies and AI inputs and outputs. Server logs carry record ids and counts, never financial figures, email addresses or message text.
Cookies. We use cookies to sign you in and keep your session secure, and your browser remembers whether the AI panel is open. We also use PostHog to measure how the app is used. PostHog stores a random identifier in your browser to tell visits apart, identifies you by an internal id rather than your name or email, and is set up not to record financial figures or text you type. We do not use advertising cookies.
3 How we use it
To run Whyzr. We use your data to sign you in, build and publish reports and forecasts, import from services you connect, answer AI questions, send notifications and keep an audit trail.
To run the AI. Whyzr’s AI uses models from Anthropic. When you or an agent use an AI feature, we send Anthropic our instructions, the conversation and the business data the AI reads to answer, which can include names in a company’s books. Under Anthropic’s commercial terms, Anthropic may not train its models on this data. Anthropic currently deletes it within 30 days, and keeps it longer only if its safety systems flag a possible policy violation or the law requires it. We do not have a zero-data-retention arrangement with Anthropic. AI suggestions are approved by a person before they take effect, and we do not use AI to make decisions with legal or similar effects on individuals.
To contact you. We send service emails: sign-in links, invitations, publication notices, security alerts and billing messages. You get these while you have an account. We also send product emails, such as trial reminders and tips. If you use Whyzr for your own business rather than through a firm, we may also tell you about StartupEdge’s advisory services. You can unsubscribe from these at any time.
To help you get started. We record onboarding milestones, such as signing up, opening the demo company or connecting QuickBooks. These records contain no financial figures. We copy them, with your name, email and company, into our customer-relationship system to follow up and help you.
To keep Whyzr safe. We use audit logs, sign-in records and technical data to detect abuse, investigate incidents and protect customers.
To improve Whyzr. See section 4.
To bill you. Polar, our reseller, processes payments and taxes.
To connect you with StartupEdge. If you ask for help from StartupEdge’s advisory practice, we pass on your request and the data you choose to share.
To meet legal duties. We use data where needed to comply with law, enforce our terms and defend legal claims.
Legal bases (EEA, UK and Switzerland). We rely on performing our contract with you or your organization; our legitimate interests in running, securing and improving Whyzr; your consent, where the law requires it for product emails; and our legal obligations.
4 How we improve Whyzr, and what we never do
| We never | We do |
|---|---|
| Train or fine-tune AI models on your data, or let our AI providers do so | Use Usage Data (features used, errors, response times, AI cost) to make Whyzr faster and more useful |
| Sell personal data, or share it for advertising | Read an AI answer and the question behind it when someone rates it with a thumbs up or down |
| Show one company’s figures to another customer | Test the AI against fixed questions built on demo or invented data |
| Let StartupEdge’s advisory practice see another firm’s data or clients | Keep lessons learned from your edits inside your own workspace |
| Read your financial data or chats without a reason | Read them only for support you ask for, to investigate a problem, for security, or when the law requires it, and record each read through the app in your audit log |
Benchmarks. Like other financial platforms, we combine data across customers into statistics such as growth rates or margins by industry and size. Before data goes into a benchmark we remove names, memos and other text. Each statistic combines at least 10 companies, and we never publish a single company’s figures. A benchmark cannot reasonably be used to identify a company or a person, and we forbid anyone we share benchmarks with from trying. A workspace Owner or Admin can opt a company, or the whole workspace, out of benchmarks in settings at any time.
5 Who we share it with
Service providers. These companies process data for us under contracts that limit their use of it to the services they provide.
| Provider | What they do for us | What they receive | Where |
|---|---|---|---|
| Vercel | Hosting and file storage | All data in the Service | US |
| Neon | Database | All data in the Service | US |
| Anthropic | AI models | Instructions, conversations and the business data the AI reads | US |
| Resend | Email delivery | Names, email addresses and email content | US |
| Sentry | Error monitoring | Error details and user ids; no IP headers, request bodies or AI content | US |
| Google Workspace | Our staff email | Support and business emails | US |
| Unified.to | Connections to QuickBooks and other services (when you connect one) | Access credentials; your data passes through without being stored there | US |
| Inngest | Background jobs | Record ids and counts only | US |
| Polar | Billing, as reseller and merchant of record | Billing contact, plan and payment details | US |
| ClickUp | Our customer records | Name, email, company and onboarding milestones | US |
| PostHog | Product usage analytics | Internal user and workspace ids, features used and pages viewed; set up not to receive names, emails, IP addresses, financial figures or text you type | US |
We will keep a current list at whyzr.com/legal/subprocessors and give customers notice before adding a provider that processes their business data. That page, not this table, is the current list.
Others we share with:
- People in your workspace. Other users see what their roles allow, and workspace admins can see your activity in the audit log.
- People you share with. Anyone holding a share link you create can view what it opens.
- Tools you connect. AI tools and apps you connect through our MCP server or API receive the data they read, under your agreement with them.
- Services you connect. QuickBooks and other connected services exchange data with us under your authorization.
- StartupEdge’s advisory practice, only if you ask it for help, and only the data you choose to share.
- Authorities, where the law requires it. We will push back on overbroad requests and tell the customer first where allowed.
- A buyer or successor, if the Whyzr business is sold, reorganized or moved into a separate company. This policy continues to apply to your data.
We do not sell personal data, and we do not share it for cross-context behavioural advertising.
6 How long we keep it
Most data stays until you delete it. Whyzr keeps a permanent record of what was published and changed, because firms and their clients rely on that history.
| Data | How long we keep it |
|---|---|
| Account and profile | While your account is active; deleted with your workspace |
| Business financial data, published reports, forecast history and uploads | Until you delete the Company or workspace, or 90 days after your last plan or trial ends |
| Copies synced from QuickBooks | The latest 7 nightly copies, weekly copies for 13 weeks and monthly copies for 24 months, plus any copy a report or forecast uses |
| Spreadsheet models imported during a trial | Deleted 30 days after the trial ends, unless you subscribe to the Forecast tier |
| AI chats | Until the Company or workspace is deleted |
| Audit log | Up to 7 years; after deletion, only who did what and when, with figures and text removed |
| Database backups | Point-in-time recovery for 7 days; nightly backups for 30 days |
| Data sent to Anthropic | Up to 30 days, longer only if flagged for a policy review or required by law |
| Billing records | As long as tax law requires, typically 7 years |
| Product email opt-outs | Kept so we keep honouring them |
Deleting data yourself. In settings, an Owner or Admin can delete a Company, and an Owner can delete the whole workspace. Owners and Admins can export data first. Deleted data leaves our live systems within 30 days and our backups within 30 days after that. You can also email legal@whyzr.com.
7 Your rights and other information
Your rights. Depending on where you live, including the EEA, UK and some US states such as California, you may have the right to:
- access the personal data we hold about you, or get a copy to take elsewhere;
- correct it, or have it deleted;
- object to or restrict some uses, and withdraw consent you gave; and
- appeal our decision on your request, or complain to your data protection authority.
You can do much of this yourself in settings: update your profile, export data, or delete companies or your workspace. Otherwise, email legal@whyzr.com. We will verify your identity and respond within the time the law requires. If your request is about data we process for a firm or company, we will pass it to them and help them respond. We will not treat you differently for using these rights.
Security. We separate each customer’s data on every query and test that separation automatically. We encrypt data in transit, use single-use sign-in links that expire in 15 minutes, store API keys only as hashes, keep an audit trail that users and agents cannot edit and protect our admin accounts with hardware security keys. No system is perfectly secure, and we will notify affected customers of a breach as the law and our contracts require.
Where data is processed. We are based in Puerto Rico, a US territory, and our providers store and process data in the United States. Our staff and contractors may access it from other countries for support and operations, under confidentiality and security obligations. When we receive personal data from the EEA, UK or Switzerland, we rely on the EU Standard Contractual Clauses and the UK Addendum.
Children. Whyzr is not directed at anyone under 18, and we do not knowingly collect their data.
Changes to this policy. We will post updates here and change the date below. For a material change, we will tell account owners by email or in the app at least 30 days before it applies. Before we start using a new kind of data, such as payroll records or client email, we will update this policy first.
Contact. StartupEdge LLC, doing business as Whyzr, 954 Ave Ponce De Leon, Suite 205, San Juan, PR 00907. Email legal@whyzr.com.