Legal

Privacy Policy

Version 1.0.0 Effective 2026-07-20 Last updated 2026-07-20

This policy describes what data Walling collects when you use our website, applications, and APIs (including the Model Context Protocol server), how we use that data, who we share it with, and the choices you have. We try to keep it short and in plain language. If anything is unclear, please contact us.

At a glance

We don’t sell your data

Walling has never sold and will never sell your personal information.

Not used to train shared AI

Workspace content sent to AI providers is processed under enterprise agreements that prohibit training on it.

AI features are opt-in

Nothing is sent to a model or external client until you trigger a feature or authorize a connection.

Revoke any time

Cut off any MCP connection or scheduled agent from Settings. Takes effect on the next call.

Who we are

Walling is operated by Walling Software Inc., a Delaware corporation. We provide a visual workspace for organizing ideas, content, tasks, and projects across web and mobile, with optional AI assistance and integrations.

For the purposes of the EU/UK GDPR, Walling Software Inc. is the controller of the personal data described in this policy. For questions about how we handle your data, contact privacy@walling.io.

Data we collect

Walling collects only what it needs to operate the service. Data falls into three categories:

Account information

Email, name, authentication credentials, and profile information you provide. If you sign in with Google, Apple, or workspace SSO, we receive the basic profile that provider returns.

Workspace content

The walls, sections, bricks, tags, files, comments, and other content you create, upload, or import — including content sent in via email pipelines and connected AI clients.

Usage and device data

Standard metadata such as IP address, browser/device type, pages visited, feature interactions, and timestamps. Used for security, troubleshooting, and product improvement.

How we use your data

We use your data to:

  • Provide and operate Walling — sync content, render your workspace, and deliver collaboration features.
  • Authenticate you and protect your account from unauthorized access.
  • Power AI features you choose to use (chat, generation, organization, MCP).
  • Support and improve the product — debug issues, measure feature usage in aggregate, plan improvements.
  • Send service emails (account notices, billing, security) and, where you opt in, product updates.
  • Comply with legal obligations and enforce our Terms.

What we never do. We do not sell your personal information, and we do not use the content of your workspace to train shared machine-learning models.

Legal basis (EU/UK users). We process your account and workspace data to perform our contract with you (GDPR Art. 6(1)(b)). We rely on legitimate interests (Art. 6(1)(f)) for security, fraud prevention, product improvement, and defending legal claims. Optional features — such as AI processing, MCP connections, and marketing email — rely on your consent (Art. 6(1)(a)), which you can withdraw at any time from Settings.

Your workspace content

Content you create in Walling belongs to you. We process it on your behalf to provide the service — to store it, sync it across your devices, render it in the app, share it with people you invite, and (where you choose) pass relevant excerpts to the AI features you activate.

  • Other members of a shared workspace can see content shared with them.
  • Public links you create are accessible to anyone who has the link.
  • You can delete content at any time; see Retention.

AI features and content processing

Walling integrates large language models (LLMs) and embedding models to power features like AI Chat, wall generation, the AI Wizard, inbox organization, and scheduled AI agents. When you use these features, relevant content from your workspace is sent to our model providers for processing.

  • We use providers under enterprise-grade agreements that prohibit using your content to train their models.
  • Content is sent only when you trigger an AI feature or when you authorize a scheduled agent to run on your behalf.
  • For search and retrieval, we generate vector embeddings of your content and store them in our own infrastructure. Embeddings are not human-readable but represent your content and are protected with the same access controls as the source.
  • You can see and revoke scheduled AI agents at any time from Settings → Agents.

Connecting external AI clients (MCP)

The Walling Model Context Protocol (MCP) server lets you connect external AI clients — such as Claude, Cursor, and ChatGPT — to your Walling workspace. This is an opt-in feature: nothing is sent until you authorize a connection. Here is what happens to your data once you do:

OAuth tokens

The connecting client receives an access token scoped to the permissions you granted and tied to a specific workspace. Tokens are stored by the client; Walling stores the corresponding grant record. Revoke from Settings → Connections at any time.

walling.read walling.write walling.execute walling.manage

Requests from the client

Each tool call is logged with metadata (tool name, timestamp, connection, result status). Tool arguments and return values are not stored beyond what is needed to operate the feature.

Content sent to the client

Read tools return content from your workspace to the connecting client (Claude, Cursor, ChatGPT, etc.) — each is a third party with its own privacy policy. Review the practices of any client you connect.

Write policy

By default, writes are queued as proposals in the Walling app for you to approve before any change is applied. You may grant walling.execute to apply writes directly — do this only with clients you trust.

Cross-workspace isolation

Each MCP connection is tied to a single workspace. An authorized connection cannot read or write to other workspaces you belong to.

Service providers (sub-processors)

Walling relies on a small number of vetted service providers to operate. They process data only on our behalf and under contractual data-protection commitments.

Infrastructure

  • Supabase

    Primary database, authentication, and file storage (US)

  • Cloudflare

    CDN, DDoS protection, email ingress, and edge workers (Global)

  • Railway

    Application hosting for API, workers, and services (US)

AI providers

  • Anthropic

    Language models for AI features (US)

  • OpenAI

    Language and embedding models (US)

Notifications & email

  • Loops

    Transactional and product email delivery (US)

  • Knock

    In-app and cross-channel notification orchestration (US)

Product & support

  • PostHog

    Privacy-respecting product analytics (US, EU-region hosting available)

  • Gleap

    In-app help center and support chat (EU)

Payments & mobile

  • Paddle

    Payment processing and Merchant of Record for web plans (US/UK)

  • RevenueCat

    In-app purchase and subscription management for mobile (US)

  • Expo

    Mobile push-notification delivery and over-the-air updates (US)

Observability

  • Sentry

    Error and crash reporting (US)

  • Grafana Cloud

    Metrics and application log aggregation (US)

  • Better Stack

    Uptime monitoring and incident routing (EU) — being replaced by UptimeRobot

  • UptimeRobot

    Uptime monitoring and status pages (US)

We may also use email delivery providers for transactional and notification email. We update this list as our infrastructure evolves; material changes are reflected here with an updated effective date.

When we share data

We share your data only in the following limited circumstances:

  • With service providers listed above, strictly to operate the service.
  • With other members of a workspace, as required to power collaboration.
  • With AI clients you authorize via MCP, scoped to the permissions you grant.
  • When required by law, in response to valid legal process, or to protect rights and safety.
  • In connection with a business transaction (merger, acquisition, etc.) — subject to commitments equivalent to this policy.

Security

We protect your data with industry-standard technical and organizational measures:

  • Encryption in transit (TLS) and encryption at rest in our primary database.
  • Scoped access controls, including row-level security on tenant data.
  • Audited infrastructure and OAuth-based API access.
  • Routine secret rotation and least-privilege service accounts.

No system is perfectly secure. We maintain an incident-response process and will notify affected users in line with applicable laws.

Retention

We keep your workspace content for as long as your account is active. When you delete content, it goes to a recycle bin you can restore from; items in the recycle bin are permanently deleted after a grace period. You can request deletion of your account at any time — see Your rights.

Typical retention windows are:

  • Workspace content — kept for the life of the account. Deleted items in the recycle bin are purged after 30 days.
  • Account records — deleted within 30 days of account deletion, except where we are required to retain records (e.g. tax and billing history) for a longer period.
  • Operational logs (request metadata, errors, security events) — retained for up to 90 days for security, debugging, and abuse prevention.
  • Aggregated, de-identified analytics — may be kept indefinitely.
  • Backups — encrypted database backups roll off within 30 days of deletion.

Your rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to withdraw consent. You can exercise most of these directly in the app:

Access and export

Export your content from Walling in standard formats. Request a copy of the personal data we hold about you by emailing privacy@walling.io.

Correct and delete

Update your profile in Settings → Account, or delete bricks, walls, or your entire account. Account deletion is irreversible after the grace period.

Revoke AI access

Cut off any MCP connection or scheduled agent from Settings → Connections / Agents. Effective immediately.

Opt out of marketing

Unsubscribe from any product email with a single click. Service and security notices continue as required to operate the account.

EU, UK, and Swiss users

Under the GDPR and equivalent UK/Swiss laws, you have the right to access, rectify, erase, restrict, and port your personal data, to object to processing based on our legitimate interests, and to withdraw consent where processing is based on it. Automated decisions with legal or similarly significant effects are not made about you in Walling. You have the right to lodge a complaint with your local supervisory authority, though we hope you'll contact us first.

United States — state privacy rights

If you are a resident of a US state with a comprehensive privacy law — including California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), and Texas (TDPSA) — you have the right to (i) know what personal information we collect and how we use it, (ii) access a copy of it, (iii) correct inaccuracies, (iv) delete it, and (v) opt out of "sales" and targeted advertising. Walling does not sell personal information and does not engage in targeted advertising, so there is no opt-out link to publish. California residents also have the right to non-discrimination for exercising these rights and can designate an authorized agent to submit requests.

To exercise any of these rights, email privacy@walling.io. We will verify your identity against your account and respond within the timeframe required by applicable law (typically 45 days). If we deny a request, you may appeal by replying to our decision.

Cookies and similar technologies

We use cookies and local storage to keep you signed in, remember your preferences, and measure product usage. We do not use third-party advertising cookies. Where required by law, we will ask for your consent before non-essential cookies are set.

Children

Walling is not intended for and is not directed to children under 16 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal data from children, and we do not create accounts for children. If you believe a child has provided us personal data, please contact privacy@walling.io and we will delete the account and associated data.

International transfers

Walling is hosted and operated primarily in the United States. If you access Walling from the European Economic Area, the United Kingdom, Switzerland, or another jurisdiction outside the United States, your data will be transferred to and processed in the United States and in other countries where our service providers operate.

For transfers from the EEA, UK, and Switzerland, we rely on the European Commission's Standard Contractual Clauses (SCCs), Module 2 (controller-to-processor), together with the UK International Data Transfer Addendum where applicable. We put these clauses in place with each sub-processor that receives EU/UK/Swiss personal data. We also apply supplementary measures (encryption in transit and at rest, access controls, and a documented incident-response process) to protect your data during and after transfer.

Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify you in the app or by email. Continued use of Walling after the effective date constitutes acceptance of the revised policy.

Contact us

Copyright-infringement notices are handled separately — see our Copyright & DMCA Policy.