Skip to content

You're trusting us with your customers

WhyLeft handles data about people who have already decided to leave you. Here is exactly how that data is stored, who processes it, and what the AI is and isn't allowed to see.

Everything automated

Tagging · follow-up questions · insights · recommendations

Reply text

Plan

Price

Tenure

Churn tags

Customer name

Email address

The model

Receives the five fields above. It has never been sent a name or an email address, and the block is enforced where the prompt is built — not by convention.

When you ask about one customer

Wylo Copilot · the one exception

  1. 1

    You ask, signed in

    An explicit question about a named customer, from an authenticated account owner.

  2. 2

    Your dashboard decides

    The same authorization boundary the rest of the app uses. The model cannot go around it.

  3. 3

    Identity, scoped to you

    Returned only inside your own Organization, and only when the question needs it.

The controls, in plain terms

Row-level isolation on every table

Row-level security is enabled on every table in the database without exception, and every query is additionally scoped to your Organization. Two customers' data cannot meet, and neither can two Organizations belonging to the same account.

Your customers' names never reach the AI

Automated AI processing — tagging, follow-up generation, insights, recommendations — receives the reply text and non-identifying metadata only: plan, price, dates, churn tags. Never a name, never an email address. This is enforced at the point the prompt is built, not by convention.

Secrets encrypted at rest

Provider credentials and API keys you give us are encrypted with AES-256-GCM before they're stored. Server-side keys are never exposed to the browser under any circumstances.

Read-only, narrowly scoped billing access

The billing-provider connection is used to detect cancellations and look up the cancelled customer's email address. WhyLeft never reads card data, never moves money, and never modifies anything in your account.

EU-incorporated, GDPR by design

WhyLeft is incorporated in Estonia and operates under GDPR. You are the Data Controller for your customers' data; we are the Processor. A DPA covering that relationship is available on request.

Deletion that actually deletes

You can export or permanently delete all customer data from Settings at any time. Deletion removes the data rather than hiding it behind a flag. Billing records are retained for seven years, as Estonian tax law requires.

The one deliberate exception

Anonymised data is the default everywhere in WhyLeft. There is exactly one place where a customer's identity can reach a model, and it exists because the alternative is a product that can't answer the question you asked.

When you — the authenticated account owner — explicitly ask Wylo Copilot about a specific customer, it can retrieve that customer's identity. Only within your own Organization, only through the same authorization checks the rest of your dashboard uses, and only when the question genuinely requires it. The model never bypasses that boundary and cannot reach another organization's data.

Everything automated — the tagging that runs on every reply, the follow-up questions, the insights, the recommendations — never gets identity at all.

Sub-processors

Everyone who touches data on our behalf, and why. Each operates under a GDPR-consistent data processing agreement.

WhyLeft sub-processors and their purpose
Sub-processorPurpose
VercelApplication hosting
SupabaseDatabase (Postgres, RLS on every table)
ClerkAuthentication
StripeBilling, and cancellation detection
PostmarkExit, follow-up and win-back email delivery
ResendTransactional email (welcome, billing alerts)
AnthropicAI processing, under Zero Data Retention
UpstashJob queue and rate limiting

Request the DPA at privacy@whyleft.com.

Security questions

Does my customers' personal data go to the AI?

No. Automated AI processing — tagging, follow-up generation, insights, recommendations — receives the reply text and non-identifying metadata only: plan, price, dates, churn tags. Never a name, never an email address.

The one exception is deliberate and founder-controlled: when you personally ask Wylo Copilot a question about a specific customer, it can retrieve that customer's identity — inside your own authenticated workspace only, through the same authorization boundary as your dashboard.

Does Anthropic train on my data?

No. Anthropic processes data as our sub-processor under a Data Processing Agreement with Zero Data Retention: prompts and outputs are not retained and are never used to train models.

What access does WhyLeft have to my Stripe account?

Read-only, and narrowly scoped. WhyLeft uses the connection to detect cancellations and look up the cancelled customer's email address. It never reads card data, never moves money, and never modifies anything in your account.

How is my data isolated from other customers'?

Row-level security is enabled on every table in the database without exception, and every query is scoped to your Organization. Secrets you give us — API keys, provider credentials — are encrypted at rest.

Is WhyLeft GDPR compliant?

WhyLeft is incorporated in Estonia and built for GDPR from the start. You are the Data Controller for your customers' data; we are the Processor, and a DPA covering that relationship is available on request.

Every email carries one-click unsubscribe, you can export or permanently delete all customer data from Settings at any time, and deletion is real deletion rather than a hidden flag.

See also the privacy policy and terms.

Your next cancellation is coming.

It can be another number on a chart, or the reason you build the right thing next quarter.

No credit card. Cancel in one click — we'd rather you tell us why.