logologo
Pricing
AppsPartnersAbout
Log inStart free trial

Privacy Policy

How WEXTL collects, uses, and protects information when you use our website and automation platform.

Effective July 10, 2026

This Privacy Policy describes how MAXMEL Tech ltd. ("we", "us") processes personal information when you visit our websites, create an account, or use WEXTL (the "Service").

This policy does not cover third-party services you connect to your workflows. Those providers have their own privacy practices.

We collect information in three broad categories:

  • Account & profile data — name, email address, organization name, authentication identifiers, and settings you provide.
  • Service data — workflows, run history, credentials metadata, audit events, and content you submit while using the product.
  • Technical data — device/browser type, IP address, log data, cookies, and usage analytics needed to operate and secure the Service.

We use personal information to:

  • Provide, maintain, and improve the Service.
  • Authenticate users, prevent fraud, and enforce our Terms.
  • Bill subscriptions, apply plan limits, and communicate about your account.
  • Respond to support requests and send product notices you cannot opt out of (e.g. security alerts).
  • Comply with legal obligations and protect our rights.

Where GDPR applies, we rely on contract performance (providing the Service), legitimate interests (security, product improvement, fraud prevention), consent (where required for marketing cookies), and legal obligation.

We do not sell your personal information. We share data only with:

  • Infrastructure and subprocessors that help us host, email, bill, or monitor the Service — under contractual confidentiality and security obligations.
  • Connected applications when you configure workflows to send data to them.
  • Authorities when required by law or to protect rights, safety, and security.
  • A successor entity in connection with a merger, acquisition, or asset sale, with notice where required.

When you connect a Google account to WEXTL — for example to use Google Sheets, Google Docs, Google Drive, Gmail, Google Calendar, or other Google products in your workflows — you authorize us through Google OAuth to access specific data in those Google services on your behalf so the automations you configure can run. This section explains how we access, use, store, and share Google user data, and applies in addition to the rest of this Policy.

WEXTL's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

  • What we access — only the scopes you approve on Google's consent screen when you connect an account. We request the minimum scopes needed for the features you enable, such as reading and writing spreadsheets (Google Sheets), reading and creating documents (Google Docs), listing, reading, uploading, and managing files (Google Drive), sending and reading messages (Gmail), or managing events (Google Calendar). The exact scopes are shown to you for approval before any access is granted, and you may connect only the products you intend to use.
  • How we use it — solely to provide the user-facing features you set up in your workflows (for example: read a row, append data, upload or download a file, send an email, create a calendar event) and to show the status of your connections. We do not use Google user data for advertising, and we do not sell it.
  • Artificial intelligence and machine learning — we do not use data obtained through Google Workspace APIs to develop, improve, or train generalized or non-personalized artificial intelligence and/or machine learning models. Google data is used only to run the specific automation you request.
  • How we store it — OAuth access and refresh tokens are encrypted at rest and are used only to make the API calls you initiate or schedule. Google user data passes through the Service to execute a workflow step; any output you choose to save (for example to run history or a downstream app) is stored according to your workflow configuration and retained as described in "Retention". You can delete a stored connection at any time.
  • How we share it — we do not transfer Google user data to third parties except: to the destinations you explicitly configure in your own workflows; to service providers and subprocessors strictly to host and operate the Service under confidentiality and security obligations; when required by law or to protect against imminent harm; or with your consent. Any such transfer is limited to providing or improving the user-facing feature, complying with applicable law, or protecting against security threats.
  • Human access — we do not allow humans to read your Google user data unless: you give explicit consent (for example, to troubleshoot a support issue you raise); it is necessary for security purposes (such as investigating abuse or a security incident); it is required to comply with applicable law; or the data has been aggregated and anonymized and is used only for internal operations.
  • Revoking access — you can disconnect WEXTL at any time from your Google Account permissions page (https://myaccount.google.com/permissions) or by deleting the connection in your WEXTL credential settings. Revoking access stops future API calls, and we delete the associated OAuth tokens.

We retain personal information for as long as your account is active and as needed to provide the Service, comply with law, resolve disputes, and enforce agreements.

Organization owners may export or request deletion of workspace data through in-product controls, subject to legal retention requirements and backup cycles.

We use administrative, technical, and organizational measures designed to protect personal information, including encryption in transit and access controls.

Data may be processed in the region you select for your organization where the product offers regional storage, and otherwise in facilities operated by our subprocessors.

Depending on your location, you may have rights to access, correct, delete, restrict, or port your personal information, and to object to certain processing.

EEA/UK users may lodge a complaint with a supervisory authority. To exercise rights, contact [email protected] or use the data controls in organization settings.

Cookies are small text files stored on your device when you visit our website or use the Service. We use cookies and similar technologies (such as localStorage mirrors) to keep the product secure, remember your preferences, and — only with your consent — understand how the Service is used.

When you first visit our marketing pages, a cookie banner lets you choose Essential only or Accept all. Essential cookies are always set because the Service cannot function without them. Analytics cookies are placed only if you choose Accept all or equivalent consent where required by law.

You can reopen the cookie banner at any time via the cookie icon at the bottom-left of the page to review or change your choice (unless you previously chose Accept all and dismissed the banner entirely).

  • Essential — session & authentication: Better Auth session cookies that keep you signed in across requests. Duration: session or as configured by your browser. Legal basis: contract / legitimate interest (security).
  • Essential — wextl-theme: remembers light or dark theme (wextl-theme cookie and matching localStorage). Duration: 1 year. Legal basis: legitimate interest (preference storage).
  • Essential — wextl-cookie-consent: records whether you chose essential-only or accept-all (wextl-cookie-consent cookie and matching localStorage). Duration: 1 year. Legal basis: legitimate interest (demonstrate consent).
  • Essential — blueprint intent: short-lived cookie used when deploying a workflow from a public share or library link after sign-up (wextl-blueprint-intent). Duration: until consumed or expired. Legal basis: contract (complete your requested action).
  • Analytics (optional): only if you select Accept all on the cookie banner. These help us measure aggregate product usage (e.g. page views, feature adoption). We do not use analytics cookies for advertising. You may withdraw consent by clearing site data or contacting [email protected].

In addition to the in-product cookie banner, most browsers let you block or delete cookies through their settings. Blocking essential cookies may prevent sign-in, break theme persistence, or cause the cookie notice to reappear.

To reset your choice, clear cookies for our domain or use the cookie preferences icon on our public pages, then make a new selection.

The Service is not directed to children under 16, and we do not knowingly collect their personal information.

We may update this policy from time to time. We will post changes on this page and update the effective date.

Questions: [email protected].