WirefoldBack to Wirefold

Your work. Your information.

Privacy policy

Effective October 2, 2026

This policy explains how Wirefold handles information on wirefold.app and in its desktop coding workbench. Wirefold is operated by Jesus Mendoza. For privacy questions or requests, contact contact@wirefold.app.

Account information

When you create or use an account, our hosted service stores your name, email address, verification status, account identifiers and timestamps. Email/password accounts store a password hash, not your plaintext password. We also process session credentials, expiration times, browser or device information, IP addresses where available, and abuse-prevention records.

We use this information to sign you in, protect and manage your account, verify your email, reset your password, and support account access from the desktop app. Signing in does not start a coding Run or apply project changes.

Google sign-in

If you choose Google sign-in, Wirefold requests only the basic identity scopes: email, profile and OpenID. Google provides your account identifier, name, email address, email-verification status and, when available, profile picture. Our authentication service may store the associated OAuth tokens; stored OAuth tokens are encrypted.

We use Google information to authenticate you and manage your Wirefold account. We do not request access to Gmail messages, Google Drive files, contacts or calendars. Google sign-in information is not used for advertising or AI model training, and account session credentials are not sent as coding-model context.

Wirefold’s use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. You can unlink Google in account settings when another usable sign-in method remains, or revoke Wirefold’s access through your Google Account. Revocation does not itself delete your Wirefold account.

Local projects and model providers

Repositories, session sandboxes, contracts, conversations and execution artifacts are managed locally on your computer. The hosted account service does not store your repositories, Review snapshots or coding-provider API keys.

Local-first does not mean local-only processing. Your chosen model provider receives the prompts, code and tool results included in task context. Screenshots, page observations, selected field values, logs and other captured application data can contain private information. That data can be saved in local artifacts and transmitted when included in model context. Wirefold does not automatically scan or redact application data or mask screenshots.

Choose the projects, connected services, credentials and data that are appropriate for your task. A sandbox isolates source changes; it does not isolate every connected database or external effect. Your selected provider’s privacy, processing and retention terms apply to the context it receives. Wirefold does not promise that provider copies are ephemeral.

Service providers and sharing

Vercel hosts the website and account APIs. Railway hosts the account database. Resend processes recipients, subjects and message content for account verification and password-reset emails, as well as delivery information. Cloudflare manages domain DNS and forwards messages sent to our public contact address to the operator’s inbox. We process your email address and the information you include to respond to support and privacy requests. Google processes the sign-in flow when you choose it and receives forwarded contact emails through Gmail. Your selected coding-model provider processes the task context described above.

These providers process information to deliver their respective services and may process it in countries other than yours. We may also disclose information when required by law or when necessary to address fraud, protect account security or respond to your request. We do not sell Google sign-in information or use it for advertising.

Cookies, logs and email

Authentication uses secure cookies and related session records to keep you signed in and protect login flows. Browser sessions expire after seven days without automatic renewal. Verification and password-reset links expire after 30 minutes. Blocking necessary cookies can prevent sign-in.

Hosting services may process technical request information, such as IP address, browser information, requested page, timestamps and errors, to operate and protect the service. Wirefold’s account emails do not enable Resend open or click tracking. Account recovery links and session credentials should be kept private.

Retention and security

We retain account information while it is needed to provide your account and address security, support or legal requirements. Sessions and recovery credentials stop being usable when they expire or are revoked; expiration is not a promise that every associated database record, provider log or backup is immediately erased. Local project records remain on your computer until you remove them.

We use HTTPS, certificate-verified database connections, password hashing, encrypted stored OAuth tokens and restricted server credentials. No storage or transmission method is completely secure.

Your choices and requests

You can sign out, revoke other sessions and manage linked login methods from your account. To request access, correction or deletion of hosted account information, email contact@wirefold.app. We may need to verify your identity before acting. We handle requests subject to applicable law and any records that must be retained for security or legal obligations.

Deleting a hosted account does not delete project files, sandboxes or artifacts on your computer, or copies already held by your selected model provider. Direct requests about that provider’s copies to the provider.

Changes to this policy

We will update this page and its effective date when our practices change. We will provide an additional notice or obtain consent where required before using information for a materially different purpose. New paid services or additional hosted AI processing require their own disclosures before activation.