Privacy Policy
Last updated: August 9, 2026
This policy explains how Whydeck — the website at whydeck.com, the Whydeck application, and the embeddable feedback widget (together, the “Service”), operated by Daiari Mayoe HB, a company registered in Sweden (“we”, “us”, “our”) — collects, uses, and protects personal data.
1. Two roles: our customers and their respondents
Whydeck handles two kinds of people’s data, and our role is different for each.
For account holders — people who sign up for Whydeck and visitors to whydeck.com — we decide how and why data is processed, and this policy describes that processing. For respondents — people who answer a study through the widget on a customer’s website — we process the responses on that customer’s behalf and on their instructions. The customer is responsible for the legal basis for collecting responses and for informing their respondents. If you answered a survey on someone’s website, your relationship is with that website; contact them first, and we will assist them with any request about your data.
2. What we collect
Account data. Your email address, name, optional avatar, and a securely hashed password — or, if you sign in with Google, the name, email, and profile picture Google shares with us. Your organization’s name and its membership.
Content. The studies you create and their settings, and the responses collected through them — ratings, chat transcripts, and the AI analyses generated from them.
Technical data. Standard server logs (IP address, browser type, pages requested, timestamps), used for security and debugging.
Usage data. We use PostHog, a product-analytics service hosted in the European Union (PostHog EU Cloud), to understand how the website and app are used — pages viewed and product actions such as creating a study. For account holders this is linked to your account; for visitors it is not tied to any identity. We do not record your screen or sessions. Respondents answering a study through the widget are not tracked by any analytics script — we only count, on our servers, that a response happened.
We do not run advertising trackers, and we do not sell personal data to anyone.
3. How we use data
We use data to provide the Service: operating your account, running AI-led interviews, generating analyses, showing you your results, and sending service emails such as sign-in codes and invitations. We also use it to secure, debug, and improve the Service, and to comply with legal obligations. Where the GDPR applies, we rely on performance of a contract, our legitimate interests in running and securing the Service, and consent where the law requires it.
4. AI processing
Interviews and analyses are generated by AI models operated by our AI providers (currently Google). Study content and responses are sent to those providers to produce interview questions and analyses. We use provider offerings under terms that restrict them from using this data for their own purposes, and we do not use your data to train AI models.
5. Service providers
We share data only with the providers we need to run the Service: hosting and content delivery (Vercel), database, authentication, and file storage (Supabase), AI models and sign-in (Google), and product analytics (PostHog, hosted in the EU). They process data on our behalf under data-processing agreements. We may also disclose data if the law requires it, or as part of a merger, acquisition, or sale of assets.
6. Cookies and local storage
On whydeck.com, the app uses essential cookies — the ones that keep you signed in — and browser storage for the analytics described above, used only to measure how the Service is used. There are no advertising or cross-site tracking cookies. The embeddable widget stores a small technical cache of its appearance settings in the visitor’s browser so it can render instantly; it does not use cookies to identify or track visitors across sites, and it carries no analytics.
7. Retention and deletion
We keep personal data for as long as your account exists or as needed to provide the Service. If you delete your account, or a customer deletes a study or their account, the associated data is deleted within a reasonable period, allowing for residual copies in backups that expire on their own schedule. We may retain minimal records where the law requires it.
8. International transfers
Our providers may process data outside the EU/EEA. Where they do, transfers are protected by recognized safeguards such as adequacy decisions or the European Commission’s Standard Contractual Clauses.
9. Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal data, to restrict or object to its processing, and to withdraw consent. You can exercise most of these directly in the app — your profile and studies are editable and deletable — or by emailing us. If you are in the EU/EEA, you can also complain to a supervisory authority; in Sweden that is the Swedish Authority for Privacy Protection (IMY).
10. Security
Data is encrypted in transit, passwords are stored only as secure hashes, and access to production data is limited to what is needed to operate the Service. No system is perfectly secure, but we take reasonable technical and organizational measures to protect your data and will notify you of a breach where the law requires it.
11. Children
The Service is not directed at children, and account holders must be at least 18. We do not knowingly collect personal data from children; if you believe a child has provided us personal data, contact us and we will delete it.
12. Changes to this policy
We may update this policy from time to time. If a change is material, we will give notice — for example on this page, in the app, or by email — before it takes effect. The “Last updated” date above always reflects the current version.
13. Contact
Questions about privacy, or a request about your data? Reach us through the support page.