Privacy notice

Document version: 2026-09-21

Who is responsible

Dalya Abed, a sole trader trading as Wireona, is the controller responsible for the personal information described here. Contact info.wireona@gmail.com about privacy or write to the business correspondence address below. This notice covers the application, website, Academy, subscriptions and support.

Information used

The service processes account details, optional profile/contact details and photos, authentication and device records, access/subscription records, saved projects, course enrolments, progress, submissions and support messages. Local projects may remain on your device; cloud features send the relevant data to the service.

Why it is used

Account, project and course information is used to provide the service you request (contract). Necessary security logs and abuse prevention support legitimate interests, subject to your rights. Records required by law are handled under legal obligation. Where optional processing requires consent, it must be requested separately and can be withdrawn.

Providers and overseas processing

Supabase provides authentication, database and storage; our database region is Singapore. Vercel hosts the website/API, Google/Gmail handles support mail, Stripe handles payments and subscriptions, and YouTube receives connection data when embedded lessons load. Encrypted recovery copies are stored locally and in a private GitHub repository. Wireona stores payment/subscription identifiers and status, not full card numbers. Providers and subprocessors may process information outside the UK. Singapore is not treated here as covered by UK adequacy. Supabase’s published DPA incorporates EU Standard Contractual Clauses with a UK Addendum; Vercel also publishes contractual transfer safeguards. Restricted transfers without applicable UK adequacy require a valid UK IDTA or UK Addendum and the relevant transfer assessment. Encryption, access limits and data minimisation supplement rather than replace that legal mechanism. Contact us for the safeguards applicable to your data; publication of provider documents alone is not independent certification of every transfer.

Cookies and local storage

Sign-in uses authentication storage/cookies. The interface stores preferences such as language and appearance locally. Embedded YouTube content communicates with Google and may use its own storage. Any non-essential tracking requiring consent must remain disabled until an appropriate consent mechanism is verified.

Optional product analytics

If enabled, optional analytics starts only after you select Allow in the privacy controls. It records page categories, download and checkout-start events, coarse country, device type and referral source, using random visitor/session identifiers. It does not include your email, account ID, project content, full referring URL or IP address in the analytics event records. Your browser stores the random identifier and consent choice; a session renews after 30 minutes of inactivity. You can decline or withdraw using Privacy choices without losing product access. Events are retained for the configured reporting period (7–365 days, normally 90), then removed by daily cleanup. Visitor totals reflect consenting browsers, not every person. Aggregate account and verified billing statistics are separate operational records with the retention rules below.

Account, projects and learning retention

Account details, cloud projects and Academy progress are retained while your account is open so that a downgrade does not destroy your work. When you delete content or make a verified erasure request, we remove or anonymise the relevant live data unless a specific legal, dispute or security exception applies. We explain the exception and its duration. Inactivity alone does not authorise erasing your projects without notice. Your own local files and exports are not remotely erased.

Support, financial and security records

Support correspondence is retained while a matter is open and normally for two years after resolution. Necessary contract, invoice, refund and dispute records are retained for accounting/tax obligations and legal claims, normally up to six years after the relevant transaction or resolution; a specific legal duty or unresolved claim may require longer. Routine security and device records are reviewed for deletion when no longer needed for active sessions, abuse prevention, incident investigation or legal claims. Longer retention is limited to necessary records and reviewed when the reason ends. A minimal erasure record is kept to prevent recovery from recreating erased accounts.

Backup expiry and recovery

Account-data backups follow a rolling maximum of 90 days, except a specifically documented legal hold. Encrypted backups are restricted to recovery, not ordinary account use. Live erasure may not immediately remove data from every snapshot; it expires with that backup. Before a restore returns to use, the erasure record must be reapplied. Signing-key recovery material without customer account data follows its security recovery lifetime, not this account-data schedule. Provider-managed backup/deletion schedules also apply; we explain applicable exceptions in our response to an erasure request.

Your rights

You may request access, correction, erasure, restriction or portability, and object where applicable. Email support without sending passwords or unnecessary identity documents. Requests should be handled without undue delay, normally within one month, with any lawful extension explained. You may complain to the UK Information Commissioner’s Office at ico.org.uk.

Support ticketsinfo.wireona@gmail.com

Wireona

Business correspondence address

WireonaOffice 21381182–184 High Street NorthEast HamLondonE6 2JAUnited Kingdom

Virtual-office correspondence address only; we are not physically based at this location.