Privacy
Last updated September 30, 2026
wack runs cloud boxes for your AI agents. This page says, in plain words, what we keep to do that and what we don't do with it.
Who is responsible
The operator of wack is responsible for the personal data described here. For anything about your data, email hello@wack.sh.
What we store
- Your account: your email address, and the name and profile picture your sign-in provides. You can change your name and time zone in Settings.
- Your boxes: their names, sizes, setups and state, when they were awake (to count your awake hours), which agents connected, and an activity history: the commands your agents ran with their exit codes, and the paths and sizes of files moved in and out.
- Your files: everything you and your agents put in a box stays on that box's disk until you reset or delete the box. A saved image is a copy of a box's disk and stays until you delete it.
- Automations and cloud sessions: your prompts and scripts, schedules, webhook payloads, and the output of each run or session (up to 5,000 lines each), so you can read them later.
- Secrets: tokens and keys you add in Toolhouse, and the agent sign-ins that apps you connect upload, encrypted with AES-256-GCM. API keys, connect URLs and webhook URLs are stored hashed.
- Billing: your plan, subscription status and the customer id from our payment processor. We never see or store your card number.
- Request logs: one line per API request with the time, method, path, status and your user id. Secrets in URLs are masked, and request bodies, command output and file contents are not logged.
A box's live screen is sent to your browser while you watch it. We don't record it.
How we use it
Only to run wack: to operate your boxes, run your automations, count usage against your plan, bill you, send the emails you'd expect (run results you asked for, trial and usage notices, billing problems), answer support requests and keep the service secure.
We don't sell your data, we don't show ads, and we don't use your files, prompts or output to train AI models. We don't read the contents of your boxes, except when you ask us for help with one or when we must to investigate abuse or follow the law.
Where the law asks for a legal basis: we process your data to provide the service you signed up for, to meet our legal obligations (such as keeping billing records), and for our legitimate interest in keeping wack secure and free of abuse.
Who helps us run wack
These providers process data on our behalf, only for the role listed:
- Sign-in: Auth0 handles accounts and passwords. We never see your password.
- Payments: Stripe processes subscriptions and card details.
- Email: Resend delivers the emails wack sends you.
- Cloud compute: cloud providers run the virtual machines your boxes live on, including their disks and saved images.
- Hosting: our infrastructure providers host the website, the API and the database.
Email hello@wack.sh for the current list of providers. We share data with others only when the law requires it, or if wack changes hands, in which case this page keeps applying to your data.
Your AI agents and apps are yours, not ours: what they send to their own model providers is governed by your agreements with those providers.
Where data is processed
wack and its providers process data in the United States and in other countries where they operate. When personal data leaves your country, it is covered by the safeguards the law requires, such as standard contractual clauses.
Cookies
We use one session cookie to keep you signed in, and your browser remembers your light or dark theme choice. While you sign in, our sign-in provider sets the cookies it needs to do that. There are no advertising or tracking cookies.
Keeping and deleting data
- We keep your account and its data while your account exists.
- Deleting a box destroys it along with its files, activity, runs and sessions. Records of when it was awake stay with your account, because your usage is counted from them.
- Deleting your account in Settings removes all of it, including your images, secrets and keys, and cancels your subscription.
- After that we keep one thing: a scrambled, one-way fingerprint of your sign-in and email address, so a trial can't be claimed twice. It can't be turned back into your email.
- Request logs and backups are deleted as they expire. Our payment processor keeps the billing records it is required to keep, and our sign-in provider keeps your sign-in until you ask us to remove it.
Your rights
You can see and download your data from the dashboard at any time. You can also ask us for a copy of anything else we hold about you, to correct it, to delete it, to stop or limit a use of it, or to send it to another service. Email hello@wack.sh and we'll answer within 30 days. We won't treat you differently for asking.
Depending on where you live, laws such as the GDPR, the UK GDPR or the CCPA give you these rights, and the right to complain to your data protection authority. We don't sell or share personal information as those laws define it.
Children
wack is for people aged 18 and over. We don't knowingly collect data from children. If you believe a child has an account, email hello@wack.sh and we'll delete it.
Security
Security describes how secrets, keys and connect URLs are protected. If a breach affects your data, we'll tell you without undue delay, and the authorities where the law requires it.
Changes and contact
When our practices change, we update this page and the date above, and we email you about significant changes. Questions go to hello@wack.sh.