Privacy policy
What Webway holds about you and your requests, why, how long for, who else sees it, and how to have it deleted.
Last updated
Willow Global LLC (1309 Coffeen Avenue, Ste 1200, Sheridan, WY 82801, United States) is the controller of the personal data described here. This policy covers the Webway website, the dashboard and the gateway API.
What we hold
Your account
Your name, email address, whether the address is verified, and a profile image if you signed in with a provider that gave us one. If you signed in with Google or GitHub rather than a password, we hold the account identifier that provider returned — never your password with them. Passwords we hold ourselves are stored hashed.
Alongside it: which workspace you belong to and your role in it, invitations you sent or accepted, and a customer id issued by Stripe.
Your keys
For each API key: a hash of the key, its first few characters, the name you gave it, when it was made, when it was last used, and any limits set on it. The key itself is shown once and never stored, so we cannot recover it for you — or for anyone else who asks.
Provider keys you bring yourself are encrypted at rest with AES-256-GCM.
Your requests
Every request through the gateway writes a log entry: a request id, the workspace and key it came from, the model and provider, token counts, cost, status, latency, the IP address it came from, and the user agent. This is what the usage screens and the ledger are built from, and it is how a disputed charge gets answered.
Request and response bodies — your prompts and the model's replies — are retained with that entry by default, so that the dashboard can show you what a request actually was. A workspace can turn payload retention off, and can set a retention period after which log entries are deleted. Aggregated usage (tokens and cost per day, per model) is kept regardless, because it is what the balance is made of.
We do not train models on your prompts or responses, and we do not sell them.
Your payments
Card details never reach us: Stripe collects them and holds them, and we see a brand, a last four and an expiry so the dashboard can show you which card is on file. For stablecoin payments we hold the payment intent, the chain, the token and the addresses involved — which are public on the ledger by nature.
We keep the ledger of every top-up, spend, refund and adjustment. Accounting law requires most of it, for years, regardless of anything else on this page.
Cookies
One first-party session cookie, set when you sign in, which is what keeps you signed in. It is signed and short-lived, and it briefly caches the session so every page load does not hit the database. There are no advertising cookies, no third-party trackers and no analytics scripts on this site.
Why we hold it
| What | Why | Basis |
|---|---|---|
| Account and session | To let you in and keep the workspace separate from everyone else's | Performance of the contract |
| Request logs and usage | To meter, bill, show you your own usage, and answer disputes | Contract, and our legitimate interest in an auditable ledger |
| Request and response bodies | So you can see what a request was; off by workspace choice | Contract, and your instruction |
| Payment records | To take payment, refund it, and keep books | Contract, and legal obligation |
| IP address and user agent | To spot a compromised key, abuse, and fraud | Legitimate interest in securing the service |
| Identity checks | Sanctions, AML and know-your-customer duties | Legal obligation |
| Service email | Failed payments, suspensions, material changes to the terms | Contract |
Who else sees it
- The model provider you routed to. Your prompt is sent to them to be served, and their privacy terms govern what they then do with it. The provider is named on every model page — check theirs if it matters to you which.
- Stripe, for card payments and refunds.
- Our stablecoin payments partner, for crypto top-ups.
- Our email provider, for service email.
- Our hosting provider, which runs the machine the gateway and its database sit on.
- Authorities, where a valid legal demand requires it. We tell you unless we are forbidden to.
That is the whole list. We do not sell personal data, and we do not share it for anyone else's marketing.
Requests are routed to providers in other countries — including the United States — so serving your request means transferring it there. Where the law requires a transfer mechanism, we rely on the standard contractual clauses.
How long we keep it
- Account records: while the account exists, and up to 90 days after it closes.
- Request logs: for the retention period the workspace set. Where none is set, they are kept while the account is open; payload retention can be turned off separately, and turning it off stops new payloads being stored.
- Aggregated usage and the credit ledger: for as long as tax and accounting law requires, which is generally seven years.
- Payment records: the same.
Deletion
Ask at [email protected] from the address on the account and we will delete what we can and tell you what we cannot. Closing an account revokes its keys immediately; the records listed above that we are required to keep are kept, and nothing else is.
Your rights
Depending on where you live, you can ask us to give you a copy of your data, to correct it, to delete it, to restrict or object to what we do with it, or to send it to someone else in a portable form. Where we rely on consent, you can withdraw it.
Write to [email protected]. We answer within 30 days. If you are in the UK or the EU and we have not resolved it, you can complain to your data protection authority.
Security
Traffic is encrypted in transit. API keys are stored as hashes, and provider keys you bring are encrypted at rest. Access to production data is limited to the people who operate the service. No system is perfect: if a breach affects you, we will tell you and the relevant regulator as the law requires.
Children
The service is not for anyone under 18, and we do not knowingly collect data from anyone under 18. If you think we have, tell us and we will delete it.
Changes
The date at the top changes when this policy does. Material changes are emailed to account holders before they take effect.
Contact
Willow Global LLC, 1309 Coffeen Avenue, Ste 1200, Sheridan, WY 82801, United States. [email protected].