Privacy Policy
Last updated 20 August 2026
Draft — pending legal review
This document was written in-house to be reviewed and amended by a qualified lawyer before Weave opens to the public. Highlighted values still need to be supplied. It is not yet a binding agreement.
1. Who is responsible for your data
Weave is operated by [LEGAL ENTITY NAME], registered at [REGISTERED ADDRESS](“Weave”, “we”). You can reach us about anything in this policy at [CONTACT EMAIL].
Weave holds two different roles depending on which data is in question, and the distinction decides who answers a request about it.
- Weave is the controller of your account. Your email address, your public profile, your sign-in records and how you use the service are ours to justify, secure and delete. Sections 2 to 8 are about that data.
- You are the controller of your own address book. The private notes, tags, photos and records you keep about the people you have met are your material. You decide what to write, why, and how long to keep it. For that content Weave is your processor: we store it, secure it and act on your instructions, and we do not use it for our own purposes.
This matters most when someone who does not use Weave asks for their record to be removed. Because the record belongs to the user who created it, that request is answered against that user’scopy — we give you a direct way to make it (section 9) and we act on it, but the underlying decision to keep a record about someone is the user’s, and so is the responsibility for having a lawful reason to do so.
2. What we collect
Data you give us
- Account: your email address, and — if you sign in with Google — your Google account identifier, name and profile photo.
- Profile: your username, display name, photo, current city, hometown, profession, interests and date of birth, all optional beyond a username.
- Your network: the people you add, and the private notes, tags and photos you attach to them.
- Messages you send to other Weave users through the app.
Data we derive
- Approximate coordinates for the city you enter, so your pin can be placed on the map. These are the coordinates of a city, not of you: Weave does not collect device location, and never tracks you in real time.
- Your age, calculated from your date of birth. Other users see your age; they only see the full date if you have added them back.
Data collected automatically
- Aggregate page analytics — see section 10.
- Technical logs and error reports, which include an IP address and browser details, kept to keep the service running and secure.
3. Why we use it, and on what basis
- To provide the service — creating your account, showing your map, running your searches, delivering your messages. Basis: performance of our contract with you.
- To keep the service secure — sign-in protection, rate limiting, abuse and fraud prevention, error monitoring. Basis: our legitimate interest in a service that is not abused, and our legal obligation to secure personal data.
- To understand and improve the product — aggregate, non-identifying measurement of which features are used. Basis: our legitimate interest, balanced by the fact that we do not build profiles or track visitors across sites.
- To comply with the law, where we are required to retain or disclose information. Basis: legal obligation.
We do not sell personal data, we do not share it with advertisers, and we do not use your notes, messages or network to train any AI model.
4. AI search
When you run an AI search, the question you typed and the relevant part of your own network — names, public profile fields, and the private notes you wrote — are sent to our AI provider to produce the answer, and the answer is returned only to you.
- It happens only when you run a search. Nothing is sent in the background.
- The result is never shown to anyone else, including the people it names.
- The provider processes the request on our instructions and does not use it to train models.
5. Who else processes your data
We use a small number of providers, each under a data-processing agreement, each limited to what the service needs:
- Supabase — database and file storage. Photos are held in a private bucket and served only through short-lived, authenticated links.
- Vercel — hosting and cookieless page analytics.
- Google — sign-in, if you choose to use it.
- Resend — delivering sign-in codes by email.
- Anthropic — the AI search described in section 4.
- Sentry — error monitoring.
- OpenFreeMap — map tiles. Your browser requests these directly when the map loads, which discloses your IP address to that service, as it would to any website you visit.
Some of these providers operate outside the European Economic Area. Where that is the case, transfers rely on the European Commission’s Standard Contractual Clauses or an equivalent safeguard. Current hosting region: [HOSTING REGION].
6. Who can see what
- Private to you, always: your notes, your tags, the photos you add to a contact, and the records you keep about people who are not on Weave. Nobody else can read them — not the person they describe, and not other users.
- Visible to other users: your username, name, photo, city, hometown, profession, interests and age.
- Visible only to people you have added back: your full date of birth.
- Never public unless you turn it on: appearing in searches run by people outside your own network is off by default and shows only public profile fields.
7. How long we keep it
Your account data is kept for as long as your account exists. Content you created about other people is kept until you delete it or delete your account. Technical logs and error reports are kept for [LOG RETENTION PERIOD]. Where the law requires us to keep records — billing, for example — we keep those for the period the law sets.
When you delete your account, your personal data is removed. Notes, tags and photos that other users wrote about you are their own records and remain with them, stripped of the profile information that was yours — your photo, bio, username, city and coordinates.
8. Your rights
If you are in the EU or the UK you have the right to access your data, correct it, delete it, receive a copy in a portable format, restrict or object to certain processing, and withdraw consent where processing is based on it. Exporting your data and deleting your account are both available from within Weave, free, without asking us.
Write to [CONTACT EMAIL] for anything else. You also have the right to complain to your local data protection authority — in Italy, the Garante per la protezione dei dati personali.
9. If you do not use Weave
A Weave user can keep a private record about someone who has not signed up — the digital equivalent of a name in a paper address book. Such a record is visible only to the user who created it. It is not a profile, it is not public, it is not indexed by search engines, and no username is reserved.
If you have been sent a link to a record about you, that page lets you remove it directly. We then keep a one-way fingerprint of the contact detail involved for the sole purpose of preventing the same record from being recreated — nothing else about you is retained. You can still join Weave later and connect normally; that is your own decision to make.
For any other request concerning a record about you, write to [CONTACT EMAIL]. As explained in section 1 the user is the controller of their own address book, so we will act as processor and pass the request on where we cannot resolve it ourselves.
10. Cookies and analytics
The public pages set no cookies and store nothing on your device. Page analytics are aggregate and carry no identifier, no cookie and no fingerprint — we can see that a page was viewed, not who viewed it, and we cannot follow you to another site. Fonts are served from our own domain, and the promotional video loads nothing from YouTube until you press play. That is why you are not being asked to dismiss a consent banner.
Inside the app, we set a strictly necessary cookie to keep you signed in. It is not used for tracking and no consent is required for it.
Analytics still involve an IP address, which is personal data, so the processing is covered by section 3 above under our legitimate interest.
11. Security
Access to data is enforced on the server for every request: each user can read only their own records. Photos live in a private bucket reachable only through authenticated, short-lived links. Sensitive identifiers are encrypted. We test these rules automatically as part of our release process.
12. Children
Weave is not intended for anyone under [MINIMUM AGE]. We do not knowingly collect data from children below that age; if you believe we have, contact us and we will delete it.
13. Changes
We will update this policy as the product changes, and the date at the top always reflects the current version. If a change materially affects your rights, we will tell you in the app or by email before it takes effect.