This policy explains which personal data Wingo UI processes, why, for how long and what rights you have. We collect as little as we can: no advertising, no tracking pixels and no third-party analytics.
1. Controller
The controller under the EU General Data Protection Regulation (GDPR) is:
- Company
- FREEVOX S.R.L.
- Address
- Str. Crăițelor nr. 2B, camera 2, 075100 Otopeni, jud. Ilfov, Romania
- support@wingo-ui.com
For any privacy question or request, write to support@wingo-ui.com.
2. What we process and why
Browsing the website. Our servers process your IP address, browser type, the page requested and the time, to deliver the site and protect it against abuse (legitimate interest, Art. 6(1)(f) GDPR). Server logs are deleted after 30 days.
Your account. Email address, optional name, language, email preferences and the date you signed up. We need them to provide your account (contract, Art. 6(1)(b) GDPR).
Signing in and security. One-time sign-in codes and links (valid for minutes), passkey public keys (we never receive your private key or biometrics), the two-factor secret and hashed backup codes if you turn on two-factor authentication, and active sessions with IP address and device type so you can review and end them. We keep a security log of important account events, such as a new passkey or API key (contract and legitimate interest in security).
API keys and usage. API keys are stored only as a hash. When the CLI or MCP server fetches a component, we record which component, version and channel were used, linked to your account, to enforce the license and rate limits and to understand which components matter (legitimate interest). We do not receive the contents of your projects.
Purchases. Plan, prices, payments, invoices, billing name, email, address and tax ID. Card and payment details are handled by Stripe and never reach us. We use the billing details to issue your invoice ourselves and email it to you. We need this data for the contract and must keep invoices for the period required by tax law (Art. 6(1)(b) and (c) GDPR).
Emails. We send sign-in codes, receipts and important account messages (contract). Release notes are sent only if you keep product updates switched on, and you can turn them off in one click. Promotional emails are sent only with your consent (Art. 6(1)(a) GDPR). We log which emails were sent and whether they were delivered.
Support. When you write to us, we use your message and email address to answer you.
4. Service providers
We use a few carefully chosen providers that process data on our behalf under data processing agreements:
- Stripe
- Payment processing (Stripe does not issue our invoices). Stripe Payments Europe, Ltd., Dublin, Ireland. Stripe may transfer data to the United States under the EU-U.S. Data Privacy Framework and standard contractual clauses. See stripe.com/privacy.
- SmartBill
- Invoicing. We write your invoice in the SmartBill invoicing service (Romania, EU) from your billing name, address, tax ID and email.
- PowerMail
- Delivery of our emails (sign-in codes, receipts, account messages). Operated by FREEVOX S.R.L. itself; emails are delivered through Amazon Web Services EMEA SARL (Amazon SES), 38 Avenue John F. Kennedy, L-1855 Luxembourg
- Hosting
- Servers for the website, the API and the database. OVH SAS, 2 rue Kellermann, 59100 Roubaix, France (servers in France)
We do not sell personal data and do not share it with anyone else unless the law requires us to.
5. How long we keep data
- Account data: while your account exists. When you delete your account, we delete or anonymize it within 30 days.
- Invoices and payment records: for the period required by tax and accounting law, typically up to 10 years.
- Sessions: until they expire or you sign out. Security log: 24 months. Email delivery log: 12 months. Server logs: 30 days.
- Component usage records: 24 months, then only in aggregated form.
6. Your rights
You have the right to access your data, to have it corrected or deleted, to restrict or object to processing, to data portability and to withdraw consent at any time with effect for the future. In your account settings you can export your data and delete your account yourself.
You can also lodge a complaint with a data protection supervisory authority, in particular in the EU country where you live or work, or where we have our registered office.
7. Security
All connections are encrypted with TLS. Sign-in is passwordless, API keys and backup codes are stored as hashes, and access to production systems is limited and protected with multi-factor authentication.
8. Children
Wingo UI is a tool for developers and is not directed at children under 16. We do not knowingly process their data.
9. Changes
We update this policy when our processing changes. The date at the top shows the latest version. We tell you about material changes by email.
Questions about this page? Write to support@wingo-ui.com.