What we collect, what we don't, and what you can ask us to do about it.
This is Wren's privacy policy written the way we'd want to read one: plain English, no dark patterns, no invented certifications. It reflects how the product actually works today. For the security architecture behind these promises, see Security & privacy.
What we collect
- Your account: email address, name, and a hashed password (or Google identifier if you sign in with Google).
- Signature details you enter or import: name, job title, phone, links, address.
- Images you upload: logo, profile photo, banner artwork.
- Banner click counts: the anonymous number of times a banner was clicked, per campaign, per day.
What we never collect
- Email content — bodies, subjects, drafts, attachments.
- Your contact list or address book.
- Message metadata (senders, recipients, timestamps).
- Per-recipient identity for banner clicks — click counts are aggregate, not per-person.
We can't collect these because Wren never connects to your mailbox in the first place — no admin console, no OAuth into your inbox, no SMTP relay.
Legal basis (GDPR)
We process the data above on two grounds: contract — we need it to deliver the service you signed up for — and legitimate interest in running and improving the product. We follow the minimal-data principle: we only ask for and keep what the product actually needs to work.
Where your data lives
Wren's database and file storage run on managed infrastructure in the European Union. All data is encrypted in transit (TLS 1.2+) and at rest (AES-256 on managed volumes). Backups use the same encryption standard and are retained on a rolling basis for disaster recovery.
Retention and deletion
We keep your data for as long as your account is active. When you cancel, your installed signatures keep working in inboxes (the HTML is already pasted there), and your account data is removed from our systems on request. Email us any time to ask for an export of everything we hold on you, or full deletion — we act on those requests within a reasonable window.
Who we share it with
We share data only with the infrastructure subprocessors that make the product run — our hosting and managed-database providers, and the transactional-email provider that sends things like invite links and password resets. That's it.
We do not sell your data. We do not share it with ad networks or data brokers. There are no third-party tracking pixels, no advertising tags, no cross-site analytics plugged into the app.
Cookies
We use only essential cookies — the ones needed to keep you signed in and to remember your session. No advertising cookies, no third-party tracking cookies, no consent-banner theatre because there's nothing to consent to.
Your rights
You can ask us at any time to:
- Access or export the data we hold on you.
- Correct anything that's wrong.
- Delete your account and everything associated with it.
Email hello@flywithwren.com and we'll take care of it.
Contact
Operated by Wren. For any privacy question, email hello@flywithwren.com.