Legal

Privacy Policy

Wedelia is provided by OLI & CECE INC, located at 6175 Spring Mountain Rd, Las Vegas, Nevada 89146-8845, United States. OLI & CECE INC is the controller of the personal information described in this Privacy Policy. "Wedelia," "we," "us," and "our" refer to OLI & CECE INC when you use the Wedelia mobile application, website, and related services (the "Service").

1. Information we collect

Information you provide

Information collected automatically

2. How we use information

We use information to:

We do not sell your personal information. We do not connect your account to an external service unless the integration is separately enabled and you explicitly authorize the requested access.

3. AI processing and service providers

Your prompts and relevant conversation context are processed by AI models so Wedelia can generate a response. The primary processor is Google Cloud: replies, images included with chat, structured canvas content, and Google Workspace tool results are generated by models served on Google Vertex AI, including Google's Gemini models and third-party models that Google hosts on Vertex AI. This path stays inside Google Cloud and does not use Google Search or Google Maps grounding, supervised tuning, fine-tuning, or customer data to train or improve a model. Vertex AI also generates requested images and the embeddings used to retrieve relevant account-scoped context. For accounts that have never connected Gmail, Google Calendar, or Google Drive, text replies may instead be generated by Zhipu AI, reached at open.bigmodel.cn and processed in mainland China. Zhipu AI receives the same prompt and conversation context as the Vertex AI path but never any Google Workspace data: an account that has connected a Google service at any time stays on Vertex AI for every chat reply, background processing (memory, mail alerts, morning briefs) never uses Zhipu AI, and images attached to chat are described by Vertex AI before any text model sees them. If a Zhipu AI request fails, the reply is generated on Vertex AI instead. The specific models we use change over time as providers release new versions; the providers and data locations above are what we commit to, and we update this section whenever a provider or processing location is added.

When you ask Wedelia to search the web, carry out a browser task, or use a custom connector, it may use relevant conversation, saved memories, profile information, and device context to prepare the request. This includes information from connected services, as described in Section 6. The sections below explain what is shared and with whom.

Browser tasks

When browser tasks are available to your account, you can ask Wedelia in chat to look up information, fill in a form, or make a reservation on a public website. Wedelia opens a separate browser for that task on Google Cloud and closes it when the task ends. Google Cloud processes the task goal, webpage screenshots from each step, and page URLs through Google Vertex AI to decide what to click or fill in next. This processing stays within Google Cloud.

Screenshots from each step are saved to your account so only you can retrieve them. They appear in the browser card in your chat and are deleted when you delete your account.

Wedelia does not enter passwords, verification codes, or bank card numbers. It pauses for you to handle sign-ins, verification, or payment yourself. Wedelia does not make payments and stops at payment pages. Before submitting a form, confirming a reservation, or sending a message, it asks you to confirm on the card and does not submit without your confirmation. It opens only public websites and does not access private network addresses. You can take over or cancel from the card. If notifications are enabled, you receive a push notification when a task needs confirmation or your help, finishes, or cannot be completed. The notification body contains no task content.

The task goal draws on the context described above. Information from it may be entered into the website you ask Wedelia to visit, where the site operator handles it under its own terms and in its own processing locations. Tasks begin at your request, and the confirmation requirements above still apply.

The interactive canvas feature, which builds a small running mini application such as a game, timer, or calculator, uses a separate code model: a Zhipu AI code model, reached at open.bigmodel.cn and processed in mainland China. That model receives only the text of the canvas request you type and, when you edit a mini application you already have, that page's own HTML. It does not receive your conversation history, your saved memories, your account context, your files, or any Google Workspace data. If your account has connected Gmail, Google Calendar, or Google Drive at any time, canvas requests are never sent to Zhipu AI and are handled on the Vertex AI path described above instead. Requests for ordinary canvas pages, such as a checklist, a data page, or a travel itinerary, are also handled on the Vertex AI path.

Speech synthesis. To create a voice reply, Wedelia's cloud runtime sends the text to be spoken to a speech service. We use Alibaba Cloud Model Studio, provided by Alibaba Cloud (Singapore) Private Limited and processed in Singapore. If it is unavailable, we use a cloned-voice system running on hardware owned by the operator, and if that is also unavailable, ElevenLabs, provided by Eleven Labs Inc. in the United States. The request contains a reply written by Wedelia, which may repeat or paraphrase something you just said, together with a voice ID, voice settings, and sometimes cues for tone or for sounds such as a laugh. It does not include your user ID, conversation history, saved memories, profile information, device context, files, or any Google Workspace data. Each provider handles the request under its own terms. The returned audio is stored in Wedelia-controlled storage that only you can access.

Custom connectors

You can connect a third-party service of your choice and ask Wedelia to use it. You enter its API key on a secure connection page, not in chat. We store the key encrypted; chat shows only its ending characters. We use the key to authenticate requests to that service, and do not show the full key to the conversation model.

Wedelia uses a custom connector only when you ask it to work with that service. Requests may include relevant information from the context described above. The service you chose handles that information under its own terms and in its own processing locations.

Before a request that writes or changes data in the connected service, Wedelia shows a confirmation card. It sends that request only after you confirm it on the card.

If you connect your own Obsidian vault, Wedelia can search it while she answers you. Your notes stay on your own device: we do not upload them and we do not store them in our cloud. When a search matches, the matching excerpts travel with that one request and are processed by Google Vertex AI, the same as the rest of your message.

Safety review and crash reporting. Wedelia uses OpenAI's API modelomni-moderation-latest only to screen the current inbound user message, including user-supplied quoted text, and the final assistant reply for disallowed content. It does not generate Wedelia replies or perform Google Workspace features. OpenAI's endpoint-specific data-control table states that /v1/moderations data is not used for training and has no abuse-monitoring or application-state retention. If the app crashes, technical crash data — stack trace, device model, operating system version, and app version — is sent to Sentry (Functional Software, Inc., a US provider) so we can find and fix the problem. Crash reports never include your conversations, and we do not attach your identity to them. When you ask about the weather or places near you, your coordinates are sent to the weather and map providers serving your region — QWeather and Amap, providers based in China, or Google — to fulfil those requests. Separately from those requests, your precise coordinates and the place labels derived from them are synced to Wedelia's own servers and kept with your account, where they are used for your daily brief and as context in conversation. Section 4 describes that in full.

Self-hosted and offline model components. Wedelia runs Qwen3-TTS 0.6B for speech output, SenseVoice int8 ONNX through sherpa-onnx for realtime voice transcription, and InsightFace buffalo_l for the face matching described in Section 5 inside infrastructure controlled by OLI & CECE INC. These model components run locally within that controlled infrastructure and do not transmit text, audio, images, face measurements, or Google user data back to their model publishers for training or any secondary purpose.

Subscription processing. RevenueCat (RevenueCat, Inc., a US provider) helps Wedelia validate app-store purchases, restore subscriptions, and keep your Plus entitlement current. RevenueCat receives a pseudonymous Wedelia app-user identifier and purchase metadata such as the store, product, transaction identifier, purchase and expiration dates, and subscription status. We do not send RevenueCat your email, conversations, images, health information, or payment card details.

Email delivery. Loops, an email delivery provider, delivers Wedelia account emails and, if you separately opt in, product emails. For delivery and suppression, Loops receives your email address, a pseudonymous Wedelia user identifier, language, subscription status, and message-delivery events. For account email, Loops also receives the single-use verification or password-reset action link needed to deliver that message. If custom delivery is unavailable, or an older app version uses the legacy flow, Google Identity Platform/Firebase may deliver the account email instead. To make email-verification and password-reset delivery reliable and enforce rate limits, we may keep the normalized address briefly in a restricted delivery queue while the request is pending or retrying. The queue removes the address after delivery completes or permanently fails. Account verification and password-reset messages do not enroll you in product email. Product email is not enabled by registration or by accepting this Policy: you must turn it on separately in the app, and you can turn it off in Settings or use the unsubscribe link in any product email. We do not use Google Workspace data, conversation content, images, health information, or payment details for product email.

Voice and call processing. When you record a short voice input, the audio clip is sent securely to Wedelia and processed by Google Cloud Speech-to-Text so it can be converted into text. Wedelia does not save that raw clip to your account unless you turn on “Let Wedelia recognise your voice” in Settings (off by default). With it on, your voice inputs are stored to your account and used only to build a voice profile that tells your voice apart from other people and background sound during calls; turn it off at any time to stop, and the stored clips and profile are deleted. The resulting transcript is handled as conversation content. We keep operational metadata such as the request identifier, audio duration, subscription plan, and whether transcription succeeded for allowance and cost accounting. Live calls are audio-only: your microphone audio is transmitted in real time, encrypted, to Wedelia's own calling service on Google Cloud so Wedelia can respond. When your network does not allow a direct connection, the encrypted call stream may pass through the network relay service of Cloudflare, Inc. (United States). We do not record or store the live audio stream as a media file, though text produced during the call may become part of your conversation history. You can deny microphone permission; calls then cannot start, and the rest of the app keeps working.

Travel Interpreter photos. Wedelia uses your camera only when you choose Take a photo in Travel Interpreter, to translate a menu, sign, or other text in front of you. You can also pick a photo from your library instead. Where your phone can read the text itself, the photo stays on your phone and only the recognized text is sent for translation, which is handled by the AI service providers described above. If no text can be read on the phone, the photo is sent to Wedelia and translated by Google Vertex AI. Translation photos are not saved to your account.

Money tracking. When you tell Wedelia in chat that you spent or received money, or show her a receipt, and ask her to track it, she records an entry in your ledger: the date, whether it is income or an expense, a category, the merchant or payer if you give one, the amount and currency, receipt line items, and an optional note. If you have connected Gmail and ask her to, she can read a statement email and record each transaction on it. You can review your entries in the app. Wedelia does not connect to your bank. If you join a savings challenge, the other participants see only the nickname you choose for that challenge and your progress number, never your individual entries; a challenge invite link shows only the challenge title, rules, and dates. You can leave a challenge at any time.

Meal logs. When you describe a meal or send a photo of it and ask Wedelia to log it, she records the meal, the foods and estimated portions, and estimated calories, protein, fat, and carbohydrates, using a food-composition reference table together with the AI model's own estimate. Photos you send for a meal are kept in private storage linked to that meal so you can see them in the app. These estimates are for general tracking and are not medical or dietary advice.

Reading room. Books you import stay on your phone; we do not upload the book file. To keep your place across devices, the app sends each book's title, author, current chapter label, reading position, and progress, along with reading-activity events such as starting or ending a session, creating a highlight, or finishing a chapter or book. These events carry only positions, counts, and times, not the text of your book or highlights. When you ask for Wedelia's spoken after-chapter talk, the end of that chapter, your highlights, and your reading conversation are sent with that one request to write and voice it, processed by the AI and speech providers described above, and are not stored.

Meeting minutes. When you record a meeting under Minutes, that recording is uploaded to Wedelia's storage and transcribed by Google Cloud Speech-to-Text, which also separates the recording into speakers. A model then writes the minutes from the transcript. The recording itself is deleted as soon as transcription finishes, and in any case within 24 hours. The written minutes and the transcript are kept with your account for 30 days so you can reopen them, and are then deleted automatically. You can delete any set of minutes yourself at any time, which removes the transcript with it. We keep operational metadata such as the request identifier, audio duration, subscription plan, and whether transcription succeeded for allowance and cost accounting. Recording a meeting captures everyone who is speaking, so only record where you are permitted to.

AI output may be inaccurate or incomplete. Safety systems may review, block, or limit content before a response is returned.

4. Device context you choose to share

Wedelia can read context from your phone so she can write your daily brief and answer with the situation you are actually in. Each category below is read only after you grant the matching operating-system permission, and only from a phone where you granted it.

While you are using the app, your phone sends this snapshot to Wedelia about every 30 minutes, and again when you bring the app back to the foreground or send a message, so that something you just added to your calendar is not missing from her answer. Only the most recent snapshot is kept: each one replaces the last and is stored with your account. Its non-health fields can support the daily brief and serve as background context in conversation; health fields support only the Food screen's wellbeing overview and the private daily brief, as explained below. It is not on a separate deletion timer — it stays until you delete it by deleting your account. Your contacts are never part of this snapshot: if you turn on Contacts in the app's settings, your phone looks for the people you name in a message and sends only the matching entries (name, phone numbers, email addresses, and birthday) with that message so Wedelia can answer it; the rest of your address book stays on your phone, and the entries sent are not stored.

Because Wedelia's replies are written by an AI model, this snapshot is part of the context sent to Google Vertex AI for the turn being answered, except your health metrics, which are never sent to an AI model provider. Your coordinates are also sent to Amap, a map provider based in China, as each snapshot arrives, so Wedelia can name the venue you appear to be at.

Health metrics are used only to show you your own numbers in the Food screen's daily wellbeing overview and in your private daily brief. The overview places your calorie intake beside permitted activity, sleep, and resting-heart-rate data so you can follow general wellness patterns; it is not a medical or diagnostic feature. Health metrics are processed only on Wedelia's own servers by fixed app logic, without any AI model involved, and they are not part of what Wedelia is given when she writes a reply to you. They are never used for advertising, never sold, and not shared with any third party.

Turning it off

Each category has its own switch under Settings > Phone data in the app — location, calendar and reminders, and health. Turning one off stops its automatic context from being collected or sent at all, even while the operating-system permission is still granted. Turning off location additionally stops Wedelia from using your location in replies, weather, and nearby search. You can also revoke the permission in your operating system's settings — Location, Calendars, Reminders, or Health — and Wedelia stops collecting that category straight away; the app reads nothing it has not been granted. Deleting your account, from Settings > Privacy in the app or through the account deletion instructions, removes the stored snapshot along with the rest of your data. Calendar actions that you explicitly request are handled on your phone and require the calendar permission; Wedelia does not keep a separate cloud copy of the event created by that action beyond the next context snapshot. On Android, turning off Health also asks Health Connect to revoke all Health permissions granted to Wedelia; the app provides a direct link to Health Connect if you want to inspect or change them yourself.

5. Face matching on people you save

Wedelia can help you identify people in photos you send, but only people you have chosen to save a photo for. Nothing happens here until you save a photo yourself.

What we store

How matching works

When you ask who is in a photo, we compute face measurements from that photo and from the photos you saved, compare them in memory, and discard the measurements immediately. They are never written to a face database, because we do not operate one. Matching happens only within your own account: your photos are never compared against another user's, and never against any outside database.

This is biometric processing

Not storing face measurements reduces risk, but it does not change what this is. Analysing a face to identify a person is biometric processing of sensitive personal information under laws including China's Personal Information Protection Law and the EU and UK GDPR. We rely on your consent, which you give by choosing to save a photo, and you can withdraw it at any time as described below.

Photos of other people

The people you save are usually not you. Before saving someone else's photo, you are responsible for having that person's permission and for telling them it will be used to recognise them in your photos. Please do not save photos of people who have not agreed, and do not save photos of children.

Turning it off

Delete the photo from the person's card. Recognition for that person stops immediately, because that photo is the only thing that made it possible. Deletion works even when face matching is otherwise unavailable. Deleting your account removes these photos along with the rest of your data.

Voice recognition

"Let Wedelia recognise your voice" is off unless you turn it on. The app asks once, when you first switch on always-listen mode ("一直听"), whether to enable it, with Yes and No choices. If you choose No, the app remembers that choice and collects nothing for voice recognition. If you turn it on, Wedelia keeps the recordings of your push-to-talk voice messages and derives a voiceprint from them.

The voiceprint is a numeric voice embedding: a vector averaged over samples of your own voice. It is not a recording and cannot be played back. We store it in your own account. Matching happens only within your own account: your voiceprint is compared only against your own voice, never against another user's, and never against any outside database.

We use the voiceprint only to check whether the person speaking is the account holder, so that a television or someone else talking in the room is not recorded as your own words. The check is one of several filters and can be wrong in either direction. We do not use the voiceprint to identify anyone else or for advertising, and we do not share it with third parties.

Analysing a voice to recognise a person is biometric processing of sensitive personal information under laws including China's Personal Information Protection Law and the EU and UK GDPR. We rely on your consent, which you give by choosing to turn the setting on, and you can withdraw it at any time by turning the setting off.

When always-listen mode is running, this check can happen on your device. The app downloads a voice-recognition model and compares the speech with your voiceprint locally. On that path, the audio does not leave your phone for this check.

Turning the setting off deletes both the voiceprint and the stored voice-sample recordings. They are on the same deletion path, and the derived voiceprint is not kept after the recordings are gone. Account deletion removes both by cascade.

6. Google, Apple, Telegram and other connected accounts

Signing in

If you choose Sign in with Google, we receive identity information needed to authenticate you: your Google account identifier, email address, and, when Google returns it, your display name. The display name prefills the editable name field during onboarding; you can change it before continuing. Wedelia does not receive your Google password, and signing in does not give Wedelia access to Gmail, Google Calendar, or Google Drive.

If you choose Sign in with Apple, we receive an Apple account identifier and an email address, plus your name if you choose to share it on the first sign-in. Apple lets you hide your real address; if you do, we receive a private relay address ending in privaterelay.appleid.com and never see the address behind it. Wedelia does not receive your Apple password. Signing in with Apple gives us no access to iCloud, Apple Health, or anything else in your Apple account.

Optional Google Workspace connection

Separately from Sign in with Google, you can choose Connect Google after confirming that you are 18 or older during onboarding, or later under Profile > Connections & integrations. Immediately before Google's consent screen, the app explains the data requested and requires you to tap Continue. You can connect or disconnect Gmail, Google Calendar, and Google Drive separately. Each connection asks Google only for access to that product; the profile access described below is included with the first product you connect. Connecting during onboarding asks for all three at once. Disconnecting one product stops Wedelia from using it while your other connected products keep working. To withdraw the Google grant completely, remove Wedelia from your Google Account's third-party apps. Depending on the products you connect, Wedelia can:

The candidate Google display name and original profile-photo URL are kept in encrypted, account-isolated connector storage only while the Google connection remains active. If you have no custom account avatar, the Wedelia app downloads the candidate photo, resizes and re-encodes it, and uploads a separate copy to Wedelia's self-avatar storage. The app does not overwrite an existing avatar or use the original Google URL to display the copied avatar. A Google display name becomes your Wedelia display name only when you choose to use and save it. A saved display name can be included in the account context sent to Google Vertex AI as described in Section 3.

We use this Google Workspace data to provide the visible features you request or enable, including the user-initiated external requests described in Section 3. Relevant data is encrypted in transit to Wedelia's servers and is processed by Google Vertex AI to produce the answer or important-mail alert you requested or enabled. The generative AI path for Google-connected chat turns, mail monitoring, and stored chat history that can contain Google-derived information is Vertex AI, and a connected account's canvas requests are handled there too. On these AI processing paths, raw or derived Google Workspace data is not sent to DeepSeek, Zhipu AI, or any AI provider that uses it to create, train, or improve a foundational or generalized AI or machine-learning model. The current inbound user message, including user-supplied quoted text, and the final assistant reply may be sent to OpenAI's omni-moderation-latest API only for the safety screening described in Section 3. Only when Memory learning is enabled for the account, Wedelia's background mail monitoring may use only the sender, subject, and snippet to derive short, durable facts about the account holder and save them to that account's personal memory. Message bodies are never fetched for memory and never leave the mailbox as part of this process. We save the derived fact, not the message: no copy of the message and no quoted text are saved. We save only facts about the account holder, not facts about the sender or the sender's business. Verification codes, credentials, account numbers, card numbers, and invoice or order specifics are explicitly excluded and never saved. Google Vertex AI performs this derivation inside the same Vertex AI boundary described above. This memory-generation process does not send raw or derived Workspace data to Zhipu AI, DeepSeek, or any provider that would use it to train a generalized model. Each saved fact is labeled with its source on the in-app memory page, where you can read it and delete it individually. With Memory learning enabled, Wedelia may derive the same kind of short, durable facts about the account holder from calendar events the phone uploads as part of device context; this snapshot may include events from accounts you sync on the device. Only an event's title and time are used for memory. Event descriptions, notes, and attendee addresses are never used for memory. The calendar derivation uses the same Vertex AI boundary, Memory learning setting, source label, and individual deletion controls on the memory page. Turning Memory learning off stops both mail- and calendar-derived memory capture. If Memory learning is enabled, a Google-derived fact that appears in a user-visible chat reply may be processed by Vertex AI and written into personal memory through the same Vertex AI boundary. If mail alerts and notification previews are enabled, the resulting short alert can also pass through Expo and the applicable Apple or Google push-notification service for delivery to your device.

When you ask Wedelia to search the web, read a page, carry out a browser task, or use a custom connector, relevant information from Gmail, Calendar, and Drive may be shared with the providers or websites involved, as described in Section 3. This includes saved memories and replies based on that information. Sharing takes place for requests you initiate; browser submissions and connector requests that write data still require your confirmation on a card.

We store the OAuth refresh credential in an encrypted, account-isolated vault. We fetch Calendar, Gmail and Drive data only when needed for these features and do not build a separate copy of your mailbox, calendars or Drive. An answer or alert may include information from that data and is retained as part of your Wedelia chat history under Section 9. We do not allow employees or contractors to read raw Google user data except with your specific consent, when necessary for security, or when required by law.

You can disconnect Google at any time under Connections & integrations. Disconnecting immediately disables the stored credential and stops new access, and deletes the connector's candidate Google name and original profile-photo URL. A display name you chose to save and a profile photo already copied into Wedelia remain as Wedelia account data after disconnection; you can edit the name or replace the avatar, and deleting your Wedelia account removes both. Disconnecting Google, including Gmail, stops all further mail-derived memory capture. Facts already derived remain in personal memory because they are facts about you, not copies of mail. You can delete them individually at any time on the memory page or request deletion of your account data as described in Section 9. You can also revoke Wedelia in your Google Account settings. Account deletion also removes the encrypted credential and Google-derived chat history with the rest of your account data. See the account deletion instructions.

If you turn on "Require unlock to open" in the app, your face or fingerprint is checked entirely by your phone. Wedelia only learns whether the check passed — no biometric data of any kind reaches the app, our servers, or anyone else.

Optional Telegram connection

Under Profile > Connections & integrations you can connect Telegram to talk with Wedelia from the Telegram app. Connecting opens Telegram with a one-time link that expires after ten minutes. When you tap Start, Wedelia stores a keyed one-way hash of your Telegram user identifier, your Telegram chat identifier, and the first name Telegram shows for you, so that messages you send to the Wedelia bot can be matched to your account and replies can be delivered to you. We do not receive your Telegram phone number, your contacts, or any message you send to anyone other than the Wedelia bot.

Messages you send to the Wedelia bot are treated exactly like messages sent in the app: they become part of your conversation history, are processed by the same AI service providers described in Section 3, and count toward the same daily allowance. Telegram also processes these messages under Telegram's own privacy policy. Only text is exchanged over Telegram; voice, images and every other feature remain in the app. The Telegram connection is available only after you confirm that you are 18 or older.

You can disconnect at any time from the same screen or by sending /disconnect to the bot. Disconnecting stops delivery immediately and revokes the stored Telegram identifiers. Conversation history stays in your account and is covered by Section 9. Deleting your account deletes the Telegram link together with everything else.

Optional LINE and Discord connections

Under Profile > Connections & integrations you can also connect LINE or Discord to talk with Wedelia from those apps. For LINE, Wedelia stores a keyed one-way hash of your LINE user identifier and the LINE user identifier needed to deliver replies to you; it does not store your LINE display name. For Discord, you sign in on Discord's own consent screen, which shares your Discord user identifier and name and adds Wedelia's chat commands to your Discord account; Wedelia stores a keyed one-way hash of that identifier, the identifier needed to deliver replies, and the name Discord shows for you. We do not receive your LINE or Discord password, contacts, friends, servers, or any message you send to anyone other than Wedelia.

As with Telegram, only text is exchanged. Messages you send to Wedelia become part of your conversation history, are processed by the AI service providers described in Section 3, count toward the same daily allowance, and are also processed by LINE (LY Corporation) or Discord (Discord Inc.) under their own privacy policies. You can disconnect from the same screen in the app, or by sending /disconnect. Disconnecting stops delivery and revokes the stored identifiers. Conversation history stays in your account under Section 9, and deleting your account deletes these links.

Optional WhatsApp connection

You can also connect WhatsApp under Connections & integrations. Connecting opens WhatsApp with a one-time message addressed to Wedelia's WhatsApp business number; the link is made only when you send it. WhatsApp then shares your WhatsApp phone number and the profile name you set in WhatsApp with us. Wedelia stores a keyed one-way hash of that phone number and the profile name. Your phone number is used to deliver each reply and is not kept in our database. We do not receive your contacts, groups, or any message you send to anyone other than Wedelia, and Wedelia does not start conversations with you on WhatsApp.

Only text is exchanged; photos, voice notes and other media you send there are ignored. Messages you send to Wedelia become part of your conversation history, are processed by the AI service providers described in Section 3, count toward the same daily allowance, and are also processed by WhatsApp (Meta) under its own privacy policy. You can disconnect from the same screen in the app, or by sending /disconnect. Disconnecting stops delivery and revokes the stored identifiers. Conversation history stays in your account under Section 9, and deleting your account deletes this link.

Optional Notion connection

You can connect Notion under Connections & integrations. Notion's own consent screen lets you choose which pages Wedelia may access. Wedelia stores an encrypted Notion access token and your workspace name and identifier. When you ask about your notes, Wedelia searches and reads the pages you shared at that moment; it does not create or change anything in Notion, and it does not keep a copy of your pages. Matching excerpts travel with that one request and are processed by the AI service providers described in Section 3, the same as the rest of your message. Disconnecting deletes the stored token; you can also remove Wedelia's access in Notion's settings. Deleting your account deletes the connection.

Optional Apple Music connection

Where the app offers it, you can connect Apple Music. Wedelia stores an encrypted Apple Music user token and, from time to time, reads a summary of your listening, such as top artists, songs on repeat, and recently played tracks. That summary is kept with your account and used to pick music for your radio and to keep one fact about your taste on your memory page, where you can delete it. Disconnecting deletes the token and the listening summary; the memory fact stays until you delete it. Deleting your account deletes all of it.

7. Optional public website analytics

The public website may use Google Analytics 4, but only after you choose "Accept analytics." It helps us understand referral and campaign sources, pages viewed, and interactions with beta, enterprise, language, and support links. We do not send Wedelia account IDs, email addresses, or conversation content to website analytics.

Google Analytics may process the page URL, referrer and UTM campaign details, browser and device information, coarse location, and the interaction events described above. Google signals and advertising personalization are disabled. Google states that GA4 uses IP addresses at collection time to derive location and discards them before they are logged.

Choosing "Necessary only" prevents the Google Analytics tag from loading. You can reopen "Analytics settings" at any time to change your choice. Withdrawing consent stops future analytics events and removes Wedelia analytics cookies available to this site; Google may retain information already collected according to its policies.

8. Data location and international transfers

The Service is offered to users outside mainland China. Data may be stored or processed in Singapore, the United States, mainland China, or other countries where our providers operate. When you request weather or nearby-place features, or when location context is synchronized as described in Sections 3 and 4, QWeather or Amap may process your coordinates in mainland China. When you use the interactive canvas feature, Zhipu AI processes that request in mainland China as described in Section 3. Privacy laws in those locations may differ from those where you live. We use appropriate contractual and technical safeguards where required.

9. Retention

We retain account and conversation data while your account is active and as needed to provide the Service. We may retain limited security, transaction, consent, and legal records for longer where necessary to prevent abuse, resolve disputes, comply with law, or enforce agreements. We retain product-email consent and unsubscribe or suppression records as needed to honor your choice and prevent further delivery. The device snapshot described in Section 4 is kept as a single most-recent copy that each sync replaces, with no separate expiry, and is removed when you delete your account. Money entries, meal logs and their photos, and reading progress are kept while your account is active and are deleted when you delete your account. Backup copies are removed on their normal rotation schedule.

10. Your choices and rights

Depending on where you live, you may have rights to access, correct, export, delete, restrict, or object to certain processing of your personal information. You may also withdraw consent where processing is based on consent.

You can export your data or permanently delete your account from Settings > Privacy in the app. You can also follow the account deletion instructions to start a verified request by emailing jack@wed.chat from the address associated with your account.

11. Security

We use access controls, encryption in transit, account-scoped data boundaries, monitoring, and other safeguards appropriate to the Service. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.

12. Changes to this policy

We may update this policy as the Service evolves. We will post the new version and effective date here and provide additional notice when required. Material changes may require you to accept the updated policy before continuing.

13. Contact

OLI & CECE INC
6175 Spring Mountain Rd
Las Vegas, Nevada 89146-8845
United States
Privacy questions and requests: jack@wed.chat.