Security & privacy

What we touch, what we don't, and where it lives.

This page is maintained by the Wren team as our honest answer to "what happens to our data if we use you?" — written in plain English, no certifications theatre. It reflects how the product actually works today.

We never touch your mailbox

Wren has zero access to your mail server. No admin console, no OAuth into your inbox, no SMTP relay, no MX changes. Signatures are pasted into Gmail, Outlook or Apple Mail by each teammate themselves. The banner under the signature is a hosted image we serve — your mail client fetches it the same way it fetches any other image in the message.

The practical consequence: your emails, drafts, contacts and message history stay entirely inside your own mail provider. There is no path by which Wren could read them, because we never connect to your mailbox in the first place.

What we store

We keep the smallest data set that makes the product work:

  • Your account: email address, name, and a hashed password (or Google identifier if you sign in with Google).
  • Signature details you enter or import: name, job title, phone, links, address.
  • Images you upload: logo, profile photo, banner artwork.
  • Banner click counts: the anonymous number of times a banner was clicked, per campaign, per day. No per-recipient tracking.

And, deliberately, what we don't store:

  • Email content — bodies, subjects, drafts, attachments.
  • Your contact list or address book.
  • Message metadata (senders, recipients, timestamps).
  • Individual recipient identities for banner clicks.

Where it lives

Wren's database and file storage run on managed infrastructure in the European Union. All data is encrypted in transit (TLS 1.2+) and at rest (AES-256 on managed volumes). Backups are encrypted with the same standard and retained on a rolling basis for disaster recovery.

Access to production data is limited to a small number of Wren engineers, gated by strong authentication, and used only to debug specific issues you raise with us.

GDPR

We follow the minimal-data principle: we only ask for and keep what the product actually needs. You can request an export of everything we hold on your account, or full deletion, by emailing us — we treat those requests seriously and act within a reasonable window.

When you cancel, your signatures keep working in installed inboxes (the HTML is already pasted there), and your account data is removed from our systems on request.

Report a concern

Found something that looks like a security or privacy issue? Please email hello@flywithwren.com with as much detail as you can share. We read every message and respond quickly.

We don't currently hold third-party certifications like SOC 2 or ISO 27001 — we'd rather be honest about that than claim badges we haven't earned. What we can promise is the architecture above: no mailbox access, minimal data, encrypted storage, EU-hosted, deleted on request.