Updated 9 September 2026
Privacy Policy
This privacy policy explains how Water Bear Strategy Oy processes personal data in the Waterbear consumer service.
1. Controller
Water Bear Strategy Oy, Finland. Privacy contact: jani@vallirinne.fi.
2. Data we process
Depending on your use of the service, we may process:
- name and email address,
- Google or Apple sign-in identifiers,
- user, runtime, tenant and agent identifiers,
- agent names, flavors and workspace metadata,
- billing, subscription and payment metadata,
- usage, cost and rate-limit metadata,
- technical logs, provisioning logs and error logs,
- support messages and email communication,
- optional Telegram connection data, such as bot token and Telegram user ID.
3. User-provided agent content
During use, you may provide conversations, notes, files or other information to your Waterbear. Waterbear content may be processed by the AI model provider and optional integrations that you enable, as described in this policy.
Suomeksi: Jaa vain tarpeelliset tiedot. Älä syötä tarpeettomia henkilötietoja. Älä koskaan syötä salasanoja, kertakäyttökoodeja, yksityisiä avaimia, maksukorttinumeroita tai muita salaisuuksia. Syötä arkaluonteisia tietoja, kuten terveystietoja, henkilötunnuksia, taloustietoja, tarkkaa sijaintia, lasten tietoja tai toisen henkilön tietoja vain, jos niitä tarvitaan suoraan sopivassa Waterbear-käyttötapauksessa ja sinulla on oikeus antaa ne.
4. Purposes
We use data to provide the service, create and manage agents, authenticate users, process payments, enforce fair use, maintain security, troubleshoot issues, provide support and improve the product.
5. Legal bases
Processing may be based on contract performance, legitimate interest, consent where requested, and legal obligations such as accounting requirements.
6. Service providers
Data may be processed by infrastructure providers, email providers, payment providers, AI model providers and optional integrations such as Telegram when needed to provide the service.
7. International transfers
Some providers may process data outside the EU/EEA. When this happens, we aim to use providers and safeguards appropriate under applicable data protection law.
8. Retention
We keep data only as long as needed for the purposes described here. Billing records may be retained for legal accounting periods. Technical logs are retained for limited operational and security needs. Cancelled agent data should be made exportable for a temporary period before deletion.
9. Security
We use technical and organizational safeguards such as access controls, isolated runtime environments, secret handling, backups and logs. Security practices will continue to develop with the service.
10. Your rights
You may have the right to access, correct, delete, restrict or object to processing of your personal data, request portability, or withdraw consent where processing is based on consent. Contact us at jani@vallirinne.fi.
11. Complaints
You may lodge a complaint with a data protection authority. In Finland, the supervisory authority is the Office of the Data Protection Ombudsman.
12. Cookies
The web app may use technically necessary cookies or similar technologies. If analytics or marketing cookies are introduced, they will be handled separately where required.