Privacy Policy

Last updated: September 5, 2026

1. Scope of This Privacy Policy

Wott AI is a workspace platform provided by Wott Technologies. This Privacy Policy explains how Wott Technologies collects, uses, stores, protects, shares, and deletes information when you use Wott AI, including its website, applications, APIs, project collaboration features, notebook and file features, search functionality, authentication systems, and integrations with third-party applications and AI assistants.

This policy applies to information processed through https://wott.ai, through Wott AI's APIs and services, and through third-party applications that connect to Wott AI using supported integration mechanisms such as OAuth and the Model Context Protocol (MCP).

This policy specifically describes data handling when Wott AI is connected to AI applications such as ChatGPT and Claude. It also applies to future third-party MCP-compatible applications that connect to Wott AI, unless a separate privacy notice specifically applies to that integration.

This Privacy Policy describes Wott Technologies's processing of information. Third-party services such as OpenAI's ChatGPT and Anthropic's Claude may independently process information under their own privacy policies, terms, retention policies, and user controls.

2. Information We Collect

We collect information you provide when you create an account, authenticate with Wott AI, create or manage workspace content, communicate with us, or use features of the service.

Account information may include your name, email address, profile information, authentication identifiers, account creation information, account status, and other information required to create and maintain your account.

Workspace information may include project names, project descriptions, project identifiers, project settings, project visibility settings, project slugs, project metadata, project ownership information, project membership information, notebook names, notebook identifiers, notebook content, notebook metadata, folders, files, file metadata, paths, storage information, timestamps, and related workspace information.

Collaboration information may include project membership records, membership identifiers, user roles, permissions, invitations, membership status, ownership information, administrative actions, and records of changes to project access.

When you make a project public, Wott AI may process and store the information necessary to make the project available through its public sharing mechanism, including a public project identifier or public URL and the project's configured public content.

When you make a project private or unlist a previously public project, Wott AI processes the project visibility and sharing settings required to restrict access according to the configured permissions and membership rules.

Usage and technical information may include IP address, request timestamps, browser or device information, operating system information, authentication events, API requests, error information, security events, request identifiers, and server or application logs.

We may collect information contained in requests made through our APIs or MCP server. The information collected depends on the specific operation requested and may include project IDs, notebook IDs, search queries, names, descriptions, notebook content, metadata, visibility settings, and other operation parameters.

3. Project Ownership, Membership, and Roles

Wott AI supports collaborative projects with role-based access controls. Project access may be assigned using roles such as Owner, Admin, and Member.

The Owner role is associated with ownership and the highest level of project management permissions supported by the project. Admin permissions may allow authorized users to manage specified project settings, members, or other administrative functions. Member permissions are limited to the actions allowed by the project's configured role and permissions.

Wott AI stores role and membership information so that it can determine whether a user is authorized to view, modify, share, or manage project resources.

When a user is invited to or removed from a project, Wott AI processes the associated membership information, invitation information, role information, and authorization state necessary to apply the change.

Project authorization is enforced using the authenticated user's identity together with project membership, ownership, role, and applicable permissions. Knowing a project ID, notebook ID, or public identifier does not by itself grant private access to a resource.

Administrative and membership actions may be recorded in technical or audit records where necessary to provide security, authorization, troubleshooting, abuse prevention, or accountability features.

4. Project Visibility and Public Sharing

Wott AI allows eligible users to control the visibility of projects using the sharing options provided by the service.

A project configured as public may be accessible to people who are not members of the project through the public sharing mechanism provided by Wott AI. Information made public by the project owner may therefore be accessible to anyone who obtains or discovers the applicable public URL, identifier, or public listing.

When you make project content public, you are responsible for ensuring that you have the right to disclose the information and that the content does not contain information that you intend to keep private.

A project that is unlisted or configured for private sharing is not intended to be publicly accessible through the public sharing mechanism. Access to private projects is instead controlled through authentication, membership, roles, and applicable permissions.

Changing a project from public to private or unlisted changes the future access rules applied by Wott AI. It does not guarantee that information previously viewed, copied, downloaded, indexed, cached, or otherwise obtained by third parties will be removed from systems outside Wott AI's control.

Public sharing may expose project names, descriptions, notebook content, files, or other information that the project owner intentionally makes available. The exact information exposed depends on the public sharing features and configuration applicable to the project.

5. Notebook, File, and Content Data

Wott AI stores notebook and file content so that users can create, edit, organize, search, and retrieve their workspace information.

Notebook data may include titles, names, Markdown or other supported content, frontmatter, metadata, folder relationships, paths, project relationships, timestamps, authorship information, and related indexing information.

File data may include file names, file types, MIME types, file sizes, storage paths, project relationships, metadata, and the file contents where the applicable feature stores the contents in Wott AI.

When content is updated, Wott AI processes the new content and associated metadata necessary to save the requested change and maintain the consistency of the workspace.

When content is permanently deleted, Wott AI may delete the corresponding metadata, stored content, descendants, indexes, and other associated records according to the deletion behavior of the applicable feature.

6. Search and Indexing

Wott AI may process notebook and project content to provide search functionality. Search processing can include creating and maintaining indexes or derived search representations of content stored in projects that the user is authorized to access.

When you perform a search, Wott AI processes the search query together with the project or workspace scope required to perform the search.

Search requests may include a project identifier, search query, result limit, filters, or other parameters supported by the search feature.

Search results are generated from information that the authenticated user is authorized to access. Search functionality does not grant access to private projects or content for which the user does not have permission.

Search indexes and derived representations are retained only as necessary to provide search and related workspace functionality and are subject to the deletion and retention rules applicable to the underlying content.

7. Model Context Protocol (MCP) Integrations

Wott AI provides a remote Model Context Protocol (MCP) server that allows compatible applications and AI assistants to interact with authorized Wott AI resources through structured tools.

MCP requests are processed only after the connecting application has established an authorized connection and Wott AI has authenticated the user or otherwise established the applicable authorization context.

Depending on the tool being called, an MCP request may contain a project ID, notebook or item ID, search query, result limit, project name, description, notebook name, notebook content, parent folder ID, metadata, or other parameters required to perform the requested operation.

The current Wott AI MCP functionality includes project discovery and management, notebook retrieval and management, notebook deletion, and project search. The available tools and parameters may change as the service evolves.

For each MCP request, Wott AI uses the authenticated identity and applicable project or resource permissions to determine whether the requested operation is allowed.

MCP tool results may contain project information, notebook metadata, notebook content, search results, operation results, identifiers, timestamps, or other information necessary to complete the user's requested operation.

Wott AI does not treat a connection to an MCP-compatible application as unrestricted access to the user's entire account. Tool access remains subject to the permissions enforced by Wott AI.

8. ChatGPT and OpenAI Integrations

Wott AI may be connected to ChatGPT through an OpenAI app or MCP-based integration. When you authorize the connection, ChatGPT may call Wott AI's MCP tools when you ask ChatGPT to perform an action involving your Wott AI workspace.

For example, if you ask ChatGPT to list your projects, Wott AI may receive an authenticated request to retrieve your accessible projects. If you ask ChatGPT to search a project, Wott AI may receive the relevant project identifier and search query. If you ask ChatGPT to create or update content, Wott AI may receive the parameters necessary to perform that operation.

Information transmitted from ChatGPT to Wott AI can therefore include the project, notebook, search, content, metadata, or other tool parameters required by the specific request.

Wott AI processes the information received from ChatGPT to authenticate the user, enforce permissions, perform the requested operation, and return the requested result to ChatGPT.

The information returned to ChatGPT may include project information, notebook content, search results, metadata, operation status, identifiers, and other information required to answer the user's request.

Wott Technologies does not control OpenAI's independent processing of information within ChatGPT. OpenAI may process conversation content, tool calls, tool results, account information, and other information under OpenAI's applicable terms and privacy policies.

This Privacy Policy governs Wott Technologies's processing of information that Wott AI receives through the ChatGPT integration. OpenAI's own privacy practices, retention policies, and user controls are governed by OpenAI's applicable documentation and policies.

9. Claude, Anthropic, and Other MCP Clients

Wott AI may be connected to Claude and other applications that support remote MCP servers. When you authorize Wott AI in a compatible application, that application may invoke Wott AI tools when you request actions involving your Wott AI workspace.

The information transmitted to Wott AI depends on the operation requested. It may include project identifiers, notebook identifiers, search queries, names, descriptions, notebook content, metadata, and other MCP tool parameters.

Wott AI uses received information to authenticate the connection, verify authorization, execute the requested operation, and return the requested result to the connected application.

Third-party AI providers may independently process prompts, conversations, tool calls, tool results, account information, and other information according to their own policies and retention practices.

For Claude specifically, Anthropic's own data handling and retention practices apply to information processed by Claude. Wott Technologies does not control Anthropic's independent processing of information within Claude.

The same principle applies to future MCP-compatible clients. Connecting a third-party application to Wott AI may cause information required for the requested operation to be transmitted between that application and Wott AI.

We will not intentionally require an MCP client to transmit unrelated conversation history to Wott AI when that information is not necessary for the requested Wott AI operation.

10. OAuth and Connected Application Authorization

Wott AI uses OAuth-based authorization for supported third-party integrations. OAuth allows a connected application to obtain authorization to call supported Wott AI resources without receiving the user's Wott AI password.

OAuth-related information may include OAuth client identifiers, redirect information, authorization requests, authorization codes, PKCE information, requested scopes, access tokens, token expiration information, authorization state, and related security information.

Authorization codes are designed to be short-lived and are invalidated after successful exchange or expiration. Access credentials are processed according to the security requirements of the integration.

The authenticated identity associated with an OAuth connection is used to determine which Wott AI projects, notebooks, and other resources the connected application may access.

OAuth authorization does not bypass Wott AI's project membership or role-based access controls. A connected application acting on behalf of a user is subject to the permissions available to that user.

You can revoke or disconnect an authorized integration through the controls made available by the applicable third-party application or Wott AI. Revoking authorization prevents future use of that authorization but does not automatically delete content previously stored in Wott AI.

11. How We Use Personal and Workspace Information

Wott Technologies uses information to provide the Wott AI service and the features you request.

We use account information to create and maintain accounts, authenticate users, communicate with users, protect accounts, and provide account-related functionality.

We use project and membership information to provide collaboration features, enforce ownership and role-based permissions, manage invitations, control project visibility, and protect private project data.

We use notebook, file, and content information to provide storage, organization, editing, retrieval, synchronization, search, and related workspace functionality.

We use MCP request information to authenticate connected applications, authorize requested operations, execute tool calls, return results, maintain security, and troubleshoot integration failures.

We use technical and security information to detect unauthorized access, prevent abuse, investigate security incidents, maintain reliability, diagnose failures, and protect the service and its users.

We may use aggregated or de-identified information for analytics and service improvement where the information is no longer reasonably capable of identifying an individual.

We do not use private workspace content for a purpose unrelated to operating, securing, maintaining, improving, or providing the features of Wott AI, unless we have a lawful basis to do so or obtain consent where required.

12. Data Recipients and Service Providers

We do not sell your personal information or private workspace content.

Wott Technologies may provide information to infrastructure and service providers that process information on our behalf. These providers may support authentication, databases, cloud hosting, object storage, search, monitoring, logging, communications, security, analytics, and other functions necessary to operate Wott AI.

Where a service provider processes personal information on behalf of Wott Technologies, access is limited to the information and processing activities necessary to provide the relevant service, subject to applicable contractual, security, and legal requirements.

When you connect Wott AI to ChatGPT, information necessary to perform the requested operation may be exchanged with OpenAI. When you connect Wott AI to Claude, information necessary to perform the requested operation may be exchanged with Anthropic. Other MCP-compatible applications may similarly receive or transmit information necessary to perform requested operations.

We may disclose information to professional advisers, auditors, insurers, legal advisers, regulators, law enforcement, or other parties where reasonably necessary to comply with legal obligations, protect rights and safety, investigate fraud or abuse, or establish, exercise, or defend legal claims.

If Wott Technologies is involved in a merger, acquisition, financing, restructuring, bankruptcy, sale of assets, or similar transaction, information may be transferred as part of that transaction subject to applicable law and contractual protections.

13. Data Stored by Third-Party AI Providers

When you use Wott AI through a third-party AI assistant, information may be processed and retained by that AI provider independently of Wott Technologies.

Wott Technologies cannot determine or control the retention period, model-improvement settings, conversation storage, account settings, or other processing performed by a third-party AI provider under that provider's own policies.

Before connecting Wott AI to a third-party AI application, you should review the privacy, data retention, security, and connected-application policies of that provider.

For clarity, this Privacy Policy does not promise that information transmitted to ChatGPT, Claude, or another third-party application will be deleted when information is deleted from Wott AI. Deletion from Wott AI and deletion from a third-party provider are separate processes governed by the respective provider's systems and policies.

14. Public Projects and Information Shared by Users

Information you intentionally publish through Wott AI's public sharing features should be treated as public information.

Publicly shared projects may be accessible to people who are not members of the project. Public content may be copied, downloaded, indexed, cached, referenced, or redistributed by third parties outside Wott Technologies's control.

Changing a project from public to private or unlisted prevents future access according to the updated Wott AI access rules, but it cannot guarantee removal of copies that third parties may have already obtained.

You are responsible for determining whether information is appropriate to publish publicly and for ensuring that you have the necessary rights and permissions to share it.

15. Security and Access Controls

Wott Technologies uses technical and organizational safeguards intended to protect personal information and workspace content against unauthorized access, disclosure, alteration, loss, and destruction.

Wott AI's authorization model uses authenticated user identity together with project ownership, membership, role, and applicable permissions to control access to protected resources.

Project Owners, Admins, and Members may have different capabilities. The specific actions available to each role depend on the permissions implemented by the relevant project and feature.

MCP requests are processed using the authenticated identity associated with the connection. Resource identifiers such as project IDs and notebook IDs are not intended to act as authorization credentials.

Access tokens, authentication credentials, and other security-sensitive information are protected using security controls appropriate to their function.

No internet transmission or storage system can be guaranteed to be completely secure. We continuously evaluate and improve security controls appropriate to the nature of the information processed by Wott AI.

16. Data Retention

We retain account information for as long as the account remains active or for as long as necessary to provide the requested services, comply with legal obligations, resolve disputes, enforce agreements, prevent abuse, and maintain necessary security records.

Project, notebook, file, membership, and collaboration information is retained while it is required to provide the workspace and collaboration features, unless you delete the information or request account deletion, subject to applicable legal, security, backup, and operational requirements.

Publicly shared project information remains available according to the project's public sharing configuration until the project is made private, unlisted, deleted, or otherwise removed according to the applicable feature behavior.

Membership and authorization records may be retained after a membership change when necessary to maintain security, enforce historical authorization decisions, investigate abuse, maintain audit records, resolve disputes, or comply with legal obligations.

OAuth authorization information is retained only for as long as reasonably necessary to establish, maintain, secure, and audit the authorized connection. Short-lived authorization codes are invalidated after use or expiration.

Search indexes and derived search data are retained while necessary to provide search functionality and are subject to deletion or rebuilding when the underlying content is modified or deleted.

Operational logs and security records are retained according to the retention periods configured for the relevant system. These periods should be documented in our internal retention schedule and may differ by log type.

When information is no longer required for the purposes described in this policy, Wott Technologies takes reasonable steps to delete, anonymize, or securely dispose of it, subject to applicable legal, backup, security, and operational requirements.

17. Deletion and User Controls

You can manage your workspace information using the controls provided by Wott AI. Depending on the feature and your role, you may create, edit, move, share, unlist, archive, or delete projects, notebooks, files, and other workspace resources.

Project Owners and users with appropriate administrative permissions can manage project membership and access according to the role and permission model applicable to the project.

When you remove a member from a project, that member's future access is restricted according to the updated membership and permission state. Removing membership does not necessarily delete content that the member previously viewed, copied, downloaded, or otherwise obtained.

When you permanently delete a notebook or folder, Wott AI may permanently remove the item, descendants, stored content, associated metadata, indexes, and related records according to the deletion behavior of the applicable feature.

When you change a project from public to private or unlisted, future access is controlled according to the new visibility configuration. Previously obtained copies outside Wott AI are not automatically deleted.

You may request deletion of your account and associated personal information by contacting [email protected]. Account deletion may be subject to identity verification, legal obligations, fraud prevention, security requirements, outstanding disputes, and backup retention procedures.

Disconnecting an AI integration or revoking OAuth authorization prevents future authorized access through that connection. It does not automatically delete projects, notebooks, or other content already stored in your Wott AI account.

18. Privacy Rights and Requests

Depending on your location and applicable law, you may have rights to access, correct, delete, restrict, object to, or obtain a copy of certain personal information processed by Wott Technologies. You may also have rights relating to portability, consent withdrawal, or automated decision-making where applicable.

To submit a privacy request, contact [email protected]. You may also use the contact information available at https://wott.ai/contact.

We may request information necessary to verify your identity before completing a privacy request. This verification is intended to prevent unauthorized disclosure, modification, or deletion of personal information.

We will process valid privacy requests within the time required by applicable law. Where a request cannot be completed, we will explain the applicable reason to the extent permitted by law.

If you believe your privacy rights have been violated, you may have the right to contact the applicable data protection authority or regulator in your jurisdiction.

19. Cookies, Sessions, and Similar Technologies

Wott AI may use cookies, session storage, local storage, and similar technologies required to authenticate users, maintain sessions, remember preferences, protect accounts, prevent abuse, and provide core functionality.

Authentication and security technologies may store identifiers or session information on your device so that Wott AI can recognize an authenticated session and protect access to your account.

Where optional analytics or similar technologies are used, Wott Technologies will provide applicable notices and controls where required by law.

Disabling required cookies or browser storage may prevent some Wott AI features from functioning correctly.

20. Children's Privacy

Wott AI is not intended for individuals who are below the minimum age required to use the service under applicable law.

We do not knowingly collect personal information from children in violation of applicable law. If you believe that a child has provided personal information to Wott AI without appropriate authorization, please contact [email protected].

21. International Data Processing

Wott Technologies and its service providers may process information in countries other than the country in which you live.

Where applicable law requires safeguards for international transfers, Wott Technologies will use appropriate mechanisms and contractual or organizational safeguards for those transfers.

The location of processing may vary depending on the infrastructure, service provider, feature, and third-party integration being used.

22. Legal Bases for Processing

Where applicable law requires a legal basis for processing personal information, Wott Technologies may rely on contractual necessity to provide the services you request, legitimate interests to operate and secure the service, legal obligations, consent where required, and other lawful bases recognized by applicable law.

For example, processing account information is necessary to provide an account, processing project membership information is necessary to enforce collaboration permissions, processing notebook content is necessary to provide notebook functionality, and processing MCP requests is necessary to perform operations explicitly requested through a connected application.

Where processing relies on consent, you may withdraw consent where permitted by applicable law. Withdrawal does not affect processing that occurred before withdrawal or processing based on another lawful basis.

23. Security Incident and Breach Response

Wott Technologies maintains security procedures intended to detect, investigate, contain, and respond to unauthorized access and other security incidents.

If Wott Technologies determines that a security incident requires notification under applicable law, we will provide notifications to affected users, regulators, or other parties as required by law.

If you discover a suspected security vulnerability involving Wott AI, please report it to [email protected] rather than publicly disclosing sensitive vulnerability details before we have had an opportunity to investigate.

24. Third-Party Links and Services

Wott AI may contain links to third-party websites, applications, services, or documentation. Third-party services operate independently from Wott Technologies and may have their own privacy policies and terms.

This Privacy Policy does not govern information collected directly by third-party websites or services. You should review the privacy practices of those services before providing information to them.

25. Changes to This Privacy Policy

We may update this Privacy Policy when Wott AI's features, integrations, data practices, service providers, or legal obligations change.

If we make material changes to the way we process personal information, we may provide additional notice where required by applicable law.

The current version of this Privacy Policy will be published at https://wott.ai/privacy and will include an updated effective or revision date.

Your continued use of Wott AI after an updated policy becomes effective constitutes acknowledgment of the updated policy to the extent permitted by applicable law.

26. Contact and Privacy Requests

For general support, contact [email protected].

For privacy questions, privacy rights requests, data access requests, correction requests, deletion requests, or questions about how personal information is processed, contact [email protected].

For security vulnerabilities or security incidents, contact [email protected].

For general contact and support options, visit https://wott.ai/contact.

For the Wott AI terms governing use of the service, visit https://wott.ai/terms.

Website: https://wott.ai