Privacy
Privacy Policy
Last updated: August 4, 2026
1. Who is responsible for your data?
WhyBecause.io is an independent software project operated by Benjamin Lavi, an individual, and is currently offered as a beta. Benjamin Lavi is the data controller for the waitlist, user accounts, service operations, security and product communications.
Privacy contact: privacy@whybecause.io.
No Data Protection Officer has been appointed at this stage.
2. Our role for workspace content
When an organization uploads a transcript, it determines why that content is processed and must have the necessary rights to do so. It will generally act as controller for personal data contained in its meetings. WhyBecause processes that content to provide the requested service and on the instructions of authorized workspace users.
3. Data we process
- Waitlist data: email, first name, role, team size, use case, language and consent evidence.
- Account data: identity, email, authentication information, profile and preferences.
- Workspace data: organization, members, roles, invitations and permissions.
- Meeting data: transcripts, speakers, summaries, decisions, actions, open topics, risks, quotes and review corrections.
- AI feature data: questions, conversations, sources, results and AI Credits usage.
- Billing data: plan, subscription status, Stripe identifiers, invoices and usage history. WhyBecause does not store full payment-card numbers.
- Technical data: IP address, security logs, browser, device, errors and events required to operate the service.
- Optional analytics: product navigation and usage only after consent to Pendo.
4. Purposes and legal bases
- Consent: managing the beta waitlist and loading optional Pendo analytics.
- Pre-contractual steps and service performance: creating accounts, operating workspaces, analyzing meetings, providing AI Search and administering subscriptions.
- Legal obligations: retaining billing records and responding to legally binding requests.
- Legitimate interests: securing the service, preventing abuse, diagnosing errors and improving reliability, without using workspace content for advertising.
5. Required and optional information
Email, waitlist consent and authentication data are required for their respective journeys. Fields marked optional may be left blank. Transcripts are processed only when you choose to use a meeting feature.
6. Recipients and service providers
Data is available only to authorized workspace users and, where necessary, to Benjamin Laviand technical providers operating the service:
- Supabase for database, authentication and backend services;
- configured AI providers for requested analyses and searches;
- Stripe for payments, subscriptions and invoices;
- Resend for transactional emails and waitlist communications;
- Pendo for analytics and guides, only after consent;
- hosting, security and operational providers where strictly necessary.
Data is not sold or used for targeted advertising.
7. International transfers
Some providers may process data outside the European Economic Area. Where required, those transfers rely on an applicable mechanism such as an adequacy decision or standard contractual clauses, depending on the provider and service involved.
8. Retention periods
- Unconfirmed waitlist requests: 30 days.
- Confirmed waitlist records: for beta selection, up to 24 months without further interaction.
- Transcripts: 7 days on Free, 30 days on Starter, and while the service is used for plans with no predefined transcript-retention limit.
- Structured meeting memory and AI conversations: until deletion by an authorized user, workspace closure or the selected retention period where available.
- Accounts and workspaces: while in use, then for the time needed to complete deletion and comply with applicable obligations.
- Billing records: for the period required by accounting and tax obligations.
- Security logs: for a period proportionate to detecting and resolving incidents.
9. Security
WhyBecause applies measures designed to prevent unauthorized access, including workspace access controls, encrypted communications, application-level encryption for stored transcripts and audit logs. No service can guarantee zero risk.
10. Cookies and analytics
Mechanisms strictly required for authentication, security and product preferences operate without analytics consent. Pendo loads in the authenticated application only after explicit consent, which can be changed in Settings. WhyBecause does not use advertising trackers.
11. Your rights
Depending on your situation, you may request access, correction, erasure, restriction or portability, object to processing based on legitimate interests and withdraw consent at any time without affecting prior processing.
Send requests to privacy@whybecause.io. Reasonable identity verification may be requested. You may also lodge a complaint with the CNIL.
12. Automated decisions and policy changes
Meeting analyses produce suggestions for review and do not independently make decisions that have legal effects on individuals. This notice may evolve during the beta. Material changes will be communicated by an appropriate method and the date above will be updated.
Notice version: 2026-08-04.
