Privacy Policy
This Policy explains the information Wave Vision collects through its analytics product, checkout, integrations, and optional measurement tools, and the choices available to you.
Effective 2026-08-12
1. Introduction and Scope
Wave Vision ("Wave Vision," "we," "us," or "our") provides social-media analytics, content analysis, Vision Score, planning, and related services. This Privacy Policy explains what information we collect, why we use it, when we disclose it, and the choices available to you when you use our websites, application, checkout, or support channels.
This version is effective 2026-08-12. It describes the product behavior currently supported by the application code and the configured services we have identified. If a vendor or feature is enabled only in a particular environment, the related disclosure applies only when that feature is enabled.
2. Information We Collect
Account and contact information
- Email address, username, name, password-related account data, and authentication identifiers.
- Support requests, messages, preferences, and communications you send us.
- Policy acceptance records, including the accepted document versions, time, signup flow, and limited request metadata used to preserve the acceptance record.
Connected platforms and content
- Connected social-media account identifiers and connection status.
- Public profile information, follower and engagement metrics, post metadata, performance data, transcripts, frames, uploaded media, and other content you authorize us to access or submit.
- Vision Scores, analyses, recommendations, content plans, storyboard data, chat history, and other outputs created while you use the service.
Device, usage, and attribution information
- IP address, browser and device information, operating system, approximate location inferred from an IP address, error data, and performance data.
- Page views, feature interactions, funnel events, and session information when optional analytics are enabled.
- Advertising and attribution identifiers such as Meta cookies or click identifiers when advertising measurement is enabled and permitted.
- Browser local storage and session storage used for authentication, cached product data, attribution, checkout recovery, and one-time flow markers.
Payment information
Stripe processes card and payment details for us. Wave Vision receives payment status, billing identifiers, subscription information, invoice information, and limited checkout metadata. We do not store full card numbers in our application database.
3. Sources and How We Use Information
Sources
- You, when you create an account, connect a platform, upload content, use features, contact support, or complete checkout.
- Connected platforms and their authorized APIs.
- Payment, authentication, hosting, analytics, advertising, error-monitoring, email, and customer-communication providers.
- Your browser and device when you visit or use the service.
Purposes
- Create and secure accounts, authenticate users, and provide the application.
- Fetch, normalize, store, and analyze authorized social data and submitted content.
- Generate Vision Scores, AI-assisted insights, recommendations, reports, plans, and related features.
- Process payments, manage subscriptions, prevent duplicate or fraudulent transactions, and provide billing support.
- Send service messages, onboarding or trial communications, support responses, and other communications you request or that are necessary to operate the service.
- Measure product performance and campaign effectiveness when optional analytics or advertising measurement is enabled.
- Protect the service, investigate abuse, troubleshoot failures, enforce our Terms, and comply with legal obligations.
4. Sharing, Service Providers, and Advertising
We do not sell your personal information for money. We may disclose information to providers that process it for the purposes described in this Policy, to connected platforms at your direction, to professional advisers, during a business transfer, when required for legal or safety reasons, or with your direction.
When optional advertising measurement is enabled, we may disclose online identifiers, device or browser information, event information, attribution identifiers, IP address, user-agent information, and conversion information to advertising providers such as Meta. California law may treat some disclosures for cross-context behavioral advertising as "sharing" even when no money is paid. Use the privacy choices control to decline future browser-based advertising measurement.
Provider categories currently supported by the codebase
| Category | Examples | Purpose |
|---|---|---|
| Infrastructure and database | Supabase, Railway or hosting providers | Authentication, storage, APIs, logs, and application operation. |
| Payments | Stripe | Checkout, billing, subscriptions, invoices, and fraud controls. |
| Social data | Authorized social APIs and InsightIQ/Phyllo where enabled | Account connection and analytics retrieval. |
| Analytics and measurement | Google Analytics, Meta Pixel/Conversions API, Vercel Analytics, PostHog where enabled | Usage analytics, performance, attribution, and advertising measurement. |
| Reliability and communication | Sentry, Loops, SMS or email providers where enabled | Error monitoring, transactional email, alerts, and support operations. |
| AI processing | AI providers configured by the backend | Analyze the content and analytics necessary to generate requested outputs. |
The exact vendor set depends on production configuration. We will not treat a provider as active merely because optional integration code exists.
5. Security
We use administrative, technical, and organizational safeguards intended to protect information, including authenticated access, encrypted network connections, access controls, logging, backups, and provider security features where configured. Security is not absolute, and no internet service or storage system can be guaranteed to be completely secure. We will not describe a control as end-to-end encryption, a completed audit, or a formal compliance certification unless that claim is verified for the relevant production system.
6. Your Privacy Rights and Choices
Available requests
- Know or access the categories and specific pieces of personal information we maintain, subject to applicable exceptions.
- Correct inaccurate personal information.
- Delete personal information, subject to legal, security, billing, backup, and other permitted exceptions.
- Export information in a reasonably usable format when applicable.
- Opt out of marketing communications and optional advertising measurement.
- Withdraw optional analytics or advertising consent for future browser activity.
How to submit a request
Email privacy@wavevision.com with the request type, the account email, and enough information for us to verify the request. We may ask for additional verification to protect an account. We will respond within the time required by applicable law and will explain if an exception applies. We do not discriminate against users for exercising applicable privacy rights.
Privacy choices
The privacy choices banner controls future browser-based optional analytics and advertising tools on this device. Browser controls, Global Privacy Control, and provider opt-out tools may also be available depending on the user's browser and location. Turning off optional tools does not undo processing that already occurred or disable necessary account, payment, security, or service operations.
8. Retention and Deletion
We retain information while it is needed to provide the service, maintain security, administer subscriptions, resolve disputes, meet tax or accounting obligations, enforce agreements, or comply with law. Account and product data is intended to be deleted when an account is deleted, subject to provider delays, backups, fraud-prevention records, billing records, and other lawful retention needs. Stripe, social-platform, analytics, email, and infrastructure providers may retain records under their own policies.
The current account-deletion endpoint cancels the subscription, attempts to disconnect connected social accounts, deletes the user profile, and deletes the authentication user. It does not guarantee immediate deletion from every third-party backup, analytics system, payment record, or browser cache. We will not promise more than the verified deletion workflow can deliver.
9. International Data Transfers
Wave Vision and its providers may process information in the United States and other locations where they operate. Where applicable law requires transfer safeguards, we intend to use appropriate contractual or other lawful mechanisms. Users outside the United States should understand that privacy protections may differ by location. We will add specific regional rights and transfer details before actively marketing the service in a jurisdiction that requires them.
10. Children's Privacy
The service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided information, contact us so we can investigate and take appropriate action. If a local law sets a higher age threshold, that law may apply.
11. Changes to This Policy
We may update this Policy when our practices, providers, product, or legal obligations change. We will change the fixed version and effective date, preserve prior versions where practical, and provide additional notice or request renewed consent when required for a material change. The date shown on this page is not updated automatically.
12. Contact Us
Questions, privacy requests, and corrections can be sent to:
Email: privacy@wavevision.com