Last Updated: March 2026
Your work is sensitive. Waffl AI treats it that way.
Waffl AI is designed from day one to behave like a trusted executive assistant—not a data vacuum. Everything we build starts with a simple principle:
Your data is yours. Waffl AI only uses it to help you, and you stay fully in control.
Below is a clear overview of how Waffl AI keeps your information private, protected, and secured at every level of the system.
Waffl AI is architected so your information is always handled with the least access necessary. We never ingest more than we need, never store raw data unnecessarily, and never use your information to train public models.
You choose which accounts Waffl AI can see—email, Slack, Teams, Jira, calendar, and others. You can disconnect them anytime, and all associated data is deleted from our systems.
Waffl AI enforces strict access controls per user account. No shared embeddings, no shared vector stores, and no shared indexing pipelines. This reduces risk and ensures your information is never blended with anyone else's.
Waffl AI team members cannot see your messages, tasks, or account contents. Support interactions require explicit user approval and temporary access tokens—never unrestricted visibility.
We do not sell, rent, or share your data with third parties. We only use your data to provide your Waffl AI experience. Nothing more.
Waffl AI does not copy your entire inbox or Slack history. Instead, it ingests only the signals required to:
We avoid unnecessary retention by default.
All communication between Waffl AI and your connected tools uses TLS 1.2+ encryption.
All information stored by Waffl AI—including embeddings, metadata, and logs—is encrypted using industry-standard 256-bit AES.
Encryption keys are rotated regularly and never stored in plaintext.
Waffl AI uses official, secure APIs for all integrations:
These APIs enforce granular scopes. You approve exactly what Waffl AI can access—and nothing more.
AI processing happens within Waffl AI's secure environment, using your data store with strict access controls per user account and your private embeddings.
We do not send your identifiable work content to public, shared, or non-enterprise AI models.
Your data is never used to train global or public models. Your queries and summaries remain private to your account.
Removing access from Waffl AI immediately revokes all future data flow and schedules deletion of associated stored data.
You may request:
No delays. No questions. No hidden caches.
Waffl AI is built with a clear enterprise roadmap:
We know Waffl AI handles some of your most important work information. That's why we've built Waffl AI the same way we'd want it built for ourselves:
Private. Secure. Transparent. In your control.
If you'd like a deeper look at our security architecture or need enterprise documentation, reach out anytime at security@waffl.ai.