Privacy policy

Last updated: August 12, 2026

At Well App, Inc. (“Well”, “we”, “our”, or “us”), your privacy is important.

This Privacy Policy describes how we collect, use, disclose, and protect personal data when you use our platform, services, and APIs (collectively, the “Services”). Your use of the Services is also governed by our terms and conditions.

This policy applies to personal data that Well processes in its role as a data controller (e.g., account registration, support) and as a processor (e.g., when our customers use Well to extract or route data from their own users).

If you do not agree with this Privacy Policy, you should not access or use our Services.

1. Information we collect

1.1 Information you provide

  • Account info: Name, email address, organization name, job title, password
  • Billing info: Payment method, billing address (processed via secure third-party payment processors)
  • Communications: Emails, support requests, surveys, and product feedback
  • Integration data: Configuration details when connecting third-party services to Well

1.2 Information we collect automatically

  • Usage logs: Timestamps, API activity, IP address, browser headers
  • Device info: Device type, OS, browser version
  • Telemetry: Application performance, feature usage, error rates
  • Cookies and tracking: See Section 7

1.3 Information we process on behalf of customers

Our customers may upload or retrieve personal data from third-party platforms (e.g., portals, inboxes, or cloud storage) using our Services. In such cases, Well acts as a data processor and our Data Processing Agreement (DPA) applies.

2. Browser extension

The Well browser extension finds invoices and receipts on the supplier portals you already use, and sends them to your Well workspace. This section describes every category of data the extension collects, what we do with it, where it is stored and for how long, and who else sees it.

Everything the extension sends goes to Well’s own API. The extension contains no third-party analytics or telemetry software. There is no Sentry, PostHog, Google Analytics, Mixpanel, or Segment code in it. The only third-party service the extension contacts directly is Google Firebase, which handles sign-in.

2.1 Website browsing activity

  • Collected: The domain name of every site you visit while signed in to Well, except Well’s own domains and browser-internal pages, together with a visit count and the time of the last visit. We do not record full page addresses or page content. Which of those domains are supplier or invoice portals is worked out on our servers, not by the extension.
  • Used for: Working out which supplier portals you actually use, so Well can offer you the right providers to collect from instead of asking you to name them all.
  • Stored: On your device, in extension storage, for 30 days after the last visit. Once an hour the extension sends batches of up to 500 domains to the Well API, where they are kept with your workspace and deleted when the workspace is deleted.
  • Shared with: No one outside Well, apart from the infrastructure vendors described in Section 4.1.

2.2 Page content during a collection run

  • Collected: While a collection run is active on a tab, the extension takes a screenshot of that page and a summary of its structure and accessibility tree, together with the page address, the addresses visited during the run, the actions it has taken, and the elements it can act on. This happens only while a run is active on that tab.
  • Used for: Working out where the invoices are on that portal and how to download them. The Well API passes this material to the AI models that drive the automation.
  • Stored: With the record of that run, for as long as we need it to operate and improve invoice collection, then deleted.
  • Shared with: The AI model providers and infrastructure vendors we use as service providers under contract (Section 4.1).

2.3 Diagnostic capture when a run fails

  • Collected: When a collection run fails, and only then, the extension uploads the raw page markup at the moment of failure (up to 2 MB), a rolling snapshot of the page shortly before it (up to 1 MB), a record of which page elements it looked for, and its own log buffer. This is unedited page content. We do not remove or mask anything from it, so it can contain whatever that page was showing you at the time, including invoice details and account information. Nothing is captured when a run succeeds.
  • Used for: Repairing the automation. A supplier portal changes its pages and our automation stops working, and this capture is what tells our engineers why.
  • Stored: With the record of the failed run in Well’s systems, for as long as we need it to repair the automation. You can ask us to delete a capture at any time using the address in Section 15. The copy held on your device is dropped once it is more than 24 hours old.
  • Shared with: No one outside Well, apart from the infrastructure vendors described in Section 4.1.

2.4 What you send from the side panel

  • Collected: When you open the side panel conversation, the extension sends your message together with the page address, page title, domain, any text you have selected on the page (up to a length limit), and details read from the page such as company or person names, email addresses, phone numbers, and invoice line items. This happens on any page except Well’s own. It does not depend on whether we already recognize the domain as a supplier portal: an unrecognized domain is still scraped and sent, just without a known supplier attached to it.
  • Used for: Answering you and acting on what is on the page in front of you.
  • Stored: With your workspace conversation history, for as long as your workspace exists or until you delete the conversation.
  • Shared with: The AI model providers and infrastructure vendors we use as service providers under contract (Section 4.1).

2.5 Invoices and other documents

  • Collected: The invoices, receipts, and similar documents the extension finds on a supplier portal during a run. It picks them up either from the portal’s own responses or from a browser download that it then cancels, so the file does not land on your disk.
  • Used for: Uploading the document to your Well workspace, reading the amounts and dates out of it, and matching it to your transactions.
  • Stored: In your workspace, alongside the documents you upload yourself, under the retention rules in Section 5.
  • Shared with: The document processing, AI model, and cloud storage providers we use as service providers under contract (Section 4.1).

2.6 Sign-in information

  • Collected: Four cookies, read only on Well’s own domain: your sign-in token, your refresh token, the email address you signed in with, and the page to open after you install the extension. The extension does not read cookies from supplier portals or from any other site.
  • Used for: Keeping you signed in, so the extension acts as you and puts documents in your workspace. The extension also writes and removes its own sign-in cookies on Well’s domain: it refreshes the sign-in cookie while you work, and it deletes the sign-in and refresh cookies when your session ends or is rejected.
  • Stored: The sign-in token is held in extension storage on your own device, along with your user ID, email address, display name, and profile photo URL from your account, until you sign out or remove the extension. The refresh token stays in the cookie on Well’s domain. The extension does not copy it into extension storage.
  • Shared with: Google Firebase, which issues and refreshes these tokens as our authentication provider.

2.7 What the extension does not do

  • It does not store your passwords or your supplier portal credentials.
  • It does not read cookies belonging to supplier portals or to any site other than Well.
  • It uses the Chrome debugger interface only while a collection run is active on that tab, and releases it when the run ends.
  • It does not sell your data, and it carries no advertising or tracking code.

3. How we use personal data

We use your information to:

  • Provide and maintain the Services
  • Authenticate users and secure access
  • Monitor usage and detect fraud or abuse
  • Improve and develop new features
  • Send updates, notices, and support messages
  • Bill and collect fees
  • Comply with legal obligations

We may also use anonymized or aggregated data for analytics, benchmarking, or product development. This data cannot be linked to any individual.

4. How we share personal data

We do not sell personal data. We only share personal data as follows:

4.1 Service providers

We share data with vendors who help operate our platform (e.g., cloud hosting, customer support tools, email services). These vendors are bound by contractual obligations to protect data. The vendors that process personal data on behalf of our customers are named in our sub-processor list.

4.2 AI model providers

Well uses large language models to read and structure your data. Depending on the task, content from your workspace is sent to a model provider, which processes it and returns a result. That content can include the text and page images of documents you upload or that we retrieve for you, the records the assistant reads to answer a question, transaction and counterparty details, and the messages you send in a conversation. The providers we use are:

  • Google (Gemini API): the default provider for document, transaction and reconciliation processing, including reading document page images
  • Anthropic: the in-product assistant and agent, extraction of documents other than invoices, and failover for background classification and matching
  • OpenAI: generating the field mapping for a newly connected tool, naming conversations, and failover for document classification and extraction
  • LlamaIndex (LlamaCloud): converting an uploaded document to text when our own parser cannot read it

We call each provider on its own commercial terms. We do not currently pin a processing region for any of them, and we do not state a retention or model-training position on their behalf.

If you connect Well to an AI client of your own through the Model Context Protocol, that client’s model provider receives whatever data you ask it to read. You choose that provider, not Well, and it is outside this policy.

4.3 Legal requirements

We may disclose data if required to comply with law, regulation, subpoena, or court order, or to protect Well’s legal rights, prevent harm, or enforce our agreements.

4.4 Business transfers

In connection with a merger, acquisition, or sale of assets, your data may be transferred as part of the transaction. We will require the receiving party to give your data equivalent protection, and we will notify you of any such change in control.

5. Data retention

We retain personal data only as long as necessary for the purposes described above, or as required by law. Retention periods vary based on data type and context.

When data is no longer needed, we will delete or anonymize it.

For personal data we process on behalf of a customer, return or deletion on termination is at that customer’s choice and is governed by our data processing agreement.

6. Your rights

Depending on your location, you may have the following rights:

RightDescription
AccessRequest a copy of your personal data
CorrectionRequest updates to incomplete or inaccurate data
DeletionRequest we delete your data, subject to legal limits
RestrictionRequest limited use of your data under certain conditions
PortabilityRequest a structured copy of your data in machine-readable format
ObjectionObject to processing based on legitimate interests or direct marketing
Withdraw consentWithdraw consent where processing is based on it (e.g., marketing emails)

To exercise any of these rights, please contact us at privacy@wellapp.ai. We may verify your identity before fulfilling requests.

7. Cookies and tracking

We use cookies and similar technologies to:

  • Maintain login sessions
  • Measure usage and performance
  • Remember preferences
  • Support marketing and analytics

You can change the choice you made in our cookie banner at any time from , or manage cookies through your browser. If you disable cookies, some features of the Services may not function properly.

8. Security measures

We implement industry-standard security practices, including:

  • HTTPS and encryption at rest
  • Role-based access control
  • Regular vulnerability scanning and patching
  • Isolated data environments
  • Audit logging

No system is 100% secure, but we take reasonable steps to protect your data from unauthorized access, use, or disclosure.

9. Where your data is processed

Well App, Inc. is a United States company. Personal data you put into the Services is processed on our production infrastructure in the United States, and by the service providers and model providers described in Section 4 and listed in our sub-processor list, in the locations stated there, where Well has verified them. Where that list says the location is determined by the provider, Well has not verified it and does not state it here.

A contract governed by European law is not European hosting, and we do not claim European data residency. Transfers out of the EEA, UK and Switzerland rely on the European Commission’s standard contractual clauses and, for UK transfers, the UK International Data Transfer Addendum.

10. Children’s privacy

Our Services are intended for use by businesses. We do not knowingly collect personal data from children under 13. If we become aware of such data, we will delete it.

11. California privacy rights (CCPA)

If you are a California resident, you have the right to:

  • Know what categories of personal data we collect and how we use them
  • Request deletion of your personal data
  • Opt out of “sale” (we do not sell personal data)

To exercise your rights, email us at privacy@wellapp.ai or use our in-app privacy portal (when available). We will not discriminate against you for exercising your rights.

12. EEA / UK / Swiss users: GDPR compliance

If you are in the EEA, UK, or Switzerland, we process your data under the legal bases of:

  • Performance of a contract (e.g., providing services)
  • Legitimate interest (e.g., improving services, ensuring security)
  • Consent (e.g., marketing emails)

You may lodge a complaint with your local data protection authority if you believe we have violated your rights.

Where Well processes personal data on behalf of a customer, that processing is governed by our data processing agreement, and the providers involved are listed in our sub-processor list, in the locations stated there, where Well has verified them. Where that list says the location is determined by the provider, Well has not verified it and does not state it here.

13. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be announced via email or in-app notices. Your continued use of the Services after updates means you accept the revised policy.

14. Limited use of data

Our browser extension is published for a single, user-facing purpose: to collect your own supplier invoices and receipts from web portals and deliver them into your accounting stack. Our use of data received through the extension follows the Chrome Web Store User Data Policy, including its Limited Use requirements.

  • We use data collected through the extension only to provide or improve that single purpose.
  • We do not sell that data. We transfer it only as described in Section 4: to service providers who help us provide or improve that purpose, to comply with applicable law, or as part of a merger or acquisition in which the receiving party gives it equivalent protection.
  • We do not use or transfer that data for advertising or ad targeting, including personalized or interest-based advertising.
  • We do not use or transfer that data to determine creditworthiness or for lending purposes.
  • Humans do not read that data, except: with your affirmative consent; to fix a fault you reported to us, for example when a supplier portal changes, a collection run fails, and you ask us to repair the automation; for security purposes; to comply with applicable law; or where the data is aggregated and de-identified.

To repair a failed collection run, the extension may send us the content of the page it could not read. Our engineers review that content only to restore the automation you asked us to fix.

15. Contact us

If you have any questions or concerns about this Privacy Policy or your data:

Well App, Inc.
1111B S Governors Ave STE 29109
Dover, DE 19904
Email: privacy@wellapp.ai