You're trusting us with your customers
WhyLeft handles data about people who have already decided to leave you. Here is exactly how that data is stored, who processes it, and what the AI is and isn't allowed to see.
Everything automated
Tagging · follow-up questions · insights · recommendations
Reply text
Plan
Price
Tenure
Churn tags
Customer name
Email address
The model
Receives the five fields above. It has never been sent a name or an email address, and the block is enforced where the prompt is built — not by convention.
When you ask about one customer
Wylo Copilot · the one exception
- 1
You ask, signed in
An explicit question about a named customer, from an authenticated account owner.
- 2
Your dashboard decides
The same authorization boundary the rest of the app uses. The model cannot go around it.
- 3
Identity, scoped to you
Returned only inside your own Organization, and only when the question needs it.
The controls, in plain terms
Row-level isolation on every table
Row-level security is enabled on every table in the database without exception, and every query is additionally scoped to your Organization. Two customers' data cannot meet, and neither can two Organizations belonging to the same account.
Your customers' names never reach the AI
Automated AI processing — tagging, follow-up generation, insights, recommendations — receives the reply text and non-identifying metadata only: plan, price, dates, churn tags. Never a name, never an email address. This is enforced at the point the prompt is built, not by convention.
Secrets encrypted at rest
Provider credentials and API keys you give us are encrypted with AES-256-GCM before they're stored. Server-side keys are never exposed to the browser under any circumstances.
Read-only, narrowly scoped billing access
The billing-provider connection is used to detect cancellations and look up the cancelled customer's email address. WhyLeft never reads card data, never moves money, and never modifies anything in your account.
EU-incorporated, GDPR by design
WhyLeft is incorporated in Estonia and operates under GDPR. You are the Data Controller for your customers' data; we are the Processor. A DPA covering that relationship is available on request.
Deletion that actually deletes
You can export or permanently delete all customer data from Settings at any time. Deletion removes the data rather than hiding it behind a flag. Billing records are retained for seven years, as Estonian tax law requires.
The one deliberate exception
Anonymised data is the default everywhere in WhyLeft. There is exactly one place where a customer's identity can reach a model, and it exists because the alternative is a product that can't answer the question you asked.
When you — the authenticated account owner — explicitly ask Wylo Copilot about a specific customer, it can retrieve that customer's identity. Only within your own Organization, only through the same authorization checks the rest of your dashboard uses, and only when the question genuinely requires it. The model never bypasses that boundary and cannot reach another organization's data.
Everything automated — the tagging that runs on every reply, the follow-up questions, the insights, the recommendations — never gets identity at all.
Sub-processors
Everyone who touches data on our behalf, and why. Each operates under a GDPR-consistent data processing agreement.
| Sub-processor | Purpose |
|---|---|
| Vercel | Application hosting |
| Supabase | Database (Postgres, RLS on every table) |
| Clerk | Authentication |
| Stripe | Billing, and cancellation detection |
| Postmark | Exit, follow-up and win-back email delivery |
| Resend | Transactional email (welcome, billing alerts) |
| Anthropic | AI processing, under Zero Data Retention |
| Upstash | Job queue and rate limiting |
Request the DPA at privacy@whyleft.com.
Security questions
Does my customers' personal data go to the AI?
No. Automated AI processing — tagging, follow-up generation, insights, recommendations — receives the reply text and non-identifying metadata only: plan, price, dates, churn tags. Never a name, never an email address.
The one exception is deliberate and founder-controlled: when you personally ask Wylo Copilot a question about a specific customer, it can retrieve that customer's identity — inside your own authenticated workspace only, through the same authorization boundary as your dashboard.
Does Anthropic train on my data?
No. Anthropic processes data as our sub-processor under a Data Processing Agreement with Zero Data Retention: prompts and outputs are not retained and are never used to train models.
What access does WhyLeft have to my Stripe account?
Read-only, and narrowly scoped. WhyLeft uses the connection to detect cancellations and look up the cancelled customer's email address. It never reads card data, never moves money, and never modifies anything in your account.
How is my data isolated from other customers'?
Row-level security is enabled on every table in the database without exception, and every query is scoped to your Organization. Secrets you give us — API keys, provider credentials — are encrypted at rest.
Is WhyLeft GDPR compliant?
WhyLeft is incorporated in Estonia and built for GDPR from the start. You are the Data Controller for your customers' data; we are the Processor, and a DPA covering that relationship is available on request.
Every email carries one-click unsubscribe, you can export or permanently delete all customer data from Settings at any time, and deletion is real deletion rather than a hidden flag.
See also the privacy policy and terms.
Your next cancellation is coming.
It can be another number on a chart, or the reason you build the right thing next quarter.
No credit card. Cancel in one click — we'd rather you tell us why.