Waterbear

Updated 9 September 2026

Privacy Policy

This privacy policy explains how Water Bear Strategy Oy processes personal data in the Waterbear consumer service.

Plain English: we process the data needed to run private AI agents, manage accounts, billing, support, security and service development. We do not sell your data.

1. Controller

Water Bear Strategy Oy, Finland. Privacy contact: jani@vallirinne.fi.

2. Data we process

Depending on your use of the service, we may process:

3. User-provided agent content

During use, you may provide conversations, notes, files or other information to your Waterbear. Waterbear content may be processed by the AI model provider and optional integrations that you enable, as described in this policy.

Important: share the minimum necessary. Do not enter unnecessary personal data. Never enter passwords, one-time login codes, private keys, payment card numbers or other secrets. Only provide sensitive personal data, such as health information, identity numbers, financial information, precise location, information about children or another person's information, when it is directly necessary for an appropriate Waterbear use case and you have the right to provide it. Do not paste another person's data without a lawful reason. If you accidentally share a password or other secret, change or revoke it immediately.

Suomeksi: Jaa vain tarpeelliset tiedot. Älä syötä tarpeettomia henkilötietoja. Älä koskaan syötä salasanoja, kertakäyttökoodeja, yksityisiä avaimia, maksukorttinumeroita tai muita salaisuuksia. Syötä arkaluonteisia tietoja, kuten terveystietoja, henkilötunnuksia, taloustietoja, tarkkaa sijaintia, lasten tietoja tai toisen henkilön tietoja vain, jos niitä tarvitaan suoraan sopivassa Waterbear-käyttötapauksessa ja sinulla on oikeus antaa ne.

4. Purposes

We use data to provide the service, create and manage agents, authenticate users, process payments, enforce fair use, maintain security, troubleshoot issues, provide support and improve the product.

5. Legal bases

Processing may be based on contract performance, legitimate interest, consent where requested, and legal obligations such as accounting requirements.

6. Service providers

Data may be processed by infrastructure providers, email providers, payment providers, AI model providers and optional integrations such as Telegram when needed to provide the service.

7. International transfers

Some providers may process data outside the EU/EEA. When this happens, we aim to use providers and safeguards appropriate under applicable data protection law.

8. Retention

We keep data only as long as needed for the purposes described here. Billing records may be retained for legal accounting periods. Technical logs are retained for limited operational and security needs. Cancelled agent data should be made exportable for a temporary period before deletion.

9. Security

We use technical and organizational safeguards such as access controls, isolated runtime environments, secret handling, backups and logs. Security practices will continue to develop with the service.

10. Your rights

You may have the right to access, correct, delete, restrict or object to processing of your personal data, request portability, or withdraw consent where processing is based on consent. Contact us at jani@vallirinne.fi.

11. Complaints

You may lodge a complaint with a data protection authority. In Finland, the supervisory authority is the Office of the Data Protection Ombudsman.

12. Cookies

The web app may use technically necessary cookies or similar technologies. If analytics or marketing cookies are introduced, they will be handled separately where required.