wimmo
Privacy

Privacy policy

Last updated 7 October 2026

Wimmo is made by Nexar Labs, which is NEXARLABS LTD (company number 16703034), 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. This page says what the app collects, why it collects it, where it goes and how to get rid of it. It is written to be read, not to be skimmed past.

The short version

Signing in

You can use your first session without an account. After that, you sign in with Google. The sign-in runs through Amazon Cognito, Amazon's sign-in service: Google tells Cognito which Google account it is, and we file everything under a random number of our own linked to that sign-in. We do not keep your name and we do not keep your email address.

What is copied to our server when you are signed in

This is what lets your history come back on a new phone. It is stored under your account and nobody else can read it.

What stays on your phone

The three things sent to AI

Wimmo uses an AI model in exactly three places, and each one runs only when you tap for it. The text goes to Google's Vertex AI, through our own server, which checks your allowance and passes the request on. Under Google's terms for Vertex AI, what we send is not used to train their models. We use Google's global Vertex AI service, so Google may process the request in any of the locations it runs it from, including outside the UK and the EU. The part of our server that passes the request on does not store what is sent or what comes back; anything you keep, like a plan or a smaller step, is copied only as part of your history, as described above.

Planning a session The task you type, your answers to its follow-up questions, and — if you start from a saved task — the note and smaller step you kept for it. It comes back as a plan of steps. The plan is part of your history; your answers to the questions are not copied to our server.
Make it smaller The task and its current first step, when you tap “Make it smaller”. One smaller step comes back, and it is kept only if you choose to keep it.
Clear your head The text you wrote, when you submit it. A list of tasks comes back for you to check and save. For 24 hours our server keeps a one-way fingerprint of the text — never the text — so that a retry does not use up your free go twice.

What we keep for counting

Your free sessions and free uses

With an account, we keep how many of your three free sessions you have used and whether you have used the free “Clear your head”. For each session we keep when it started, whether it counted and whether it ended early — before sign-in too — so a session is never counted twice. For each plan the AI delivered we keep when, and whether you left it without starting; if that happens five times in a day, planning help pauses until the next day. These records hold ids, times and yes-or-no flags — nothing you wrote — and each is removed 6 months after it was made.

We also keep short-lived counters of how many AI requests you made today and in the last minute, which keep the service running for everyone. To stop one computer creating endless new phones or waitlist entries, a daily counter is kept under a one-way code made from your internet address with a secret key only our server has — never the address itself. All of these counters are deleted automatically within three days.

A code for your device, before you sign in

So that the free first session cannot be used again and again, the app sends an identifier your phone already has to our server once, over an encrypted connection. Our server turns it into a one-way code with a secret key only the server has, and keeps the code — never the identifier itself. Beside the code it keeps whether the free session and the free “Clear your head” were used on that phone, and when the app was first and last used there. If you later sign in, the code records that your account took over that phone's free use.

The code is pseudonymous, not anonymous: our server can recognise the same phone again, which is its whole purpose. It cannot be turned back into the phone's identifier, it proves nothing about you, and it is not used for anything else. It is removed 6 months after the app was last used on that phone. The pass our server gives the phone to use before sign-in expires after 30 days, and its record goes with it.

Daily totals

We count, per day, how many people used the app, how many sessions were completed, and how many people came back after a gap. To count each person once a day we keep a marker under your random account number for 40 days, or until you delete your account. The totals themselves are just numbers.

Crash reports

If the app hits an error, it can send a crash report to Sentry (Functional Software, Inc.), stored in Sentry's EU region (Germany). A report contains the type of error, where in the app's code it happened, the app version, and your phone's operating system name and version. It never contains what you type — tasks, notes or “Clear your head” entries — nor your name, email address, or account or device identifiers; these are removed on your phone before anything is sent. Sentry is set not to store the internet address a report arrives from, or a location worked out from it. Nothing is sent when the app works normally, and no usage or session data is collected. Reports are kept for up to 90 days, then deleted.

The waitlist

If you join the waitlist on our website, we keep the address you typed, the date, and that it came from the website, so we can tell you when the app is out. The waitlist is stored on its own, apart from app accounts, and is never linked to one. It is kept until the app launches and we have written to you, or until you ask us to take your address off.

Subscriptions

Wimmo does not sell subscriptions yet, and nothing in the app takes a payment today. When subscriptions go on sale, they will be sold through Google Play, which takes the payment; we will never see your card details. The app will then use RevenueCat (RevenueCat, Inc.) to check with Google Play whether your subscription is active. RevenueCat will receive a random identifier from us — not your name or email address — your purchase and subscription history from Google Play, and your phone's locale and currency. We will update this page before subscriptions go on sale.

When you delete your Wimmo account, we also ask RevenueCat to delete its customer record for you — the random identifier and the purchase history it keeps for us. Google Play keeps its own record of what you bought; that is between you and Google. Deleting your account does not cancel a subscription — see “Deleting things” below.

Where it goes

Amazon Web Services, Ireland Our server, its database and the sign-in service (Amazon Cognito) run on Amazon Web Services in the EU (Ireland) region. The database is backed up continuously and we can restore it to any moment in the last 7 days, so a fault does not take your history with it. Backups are kept for 7 days and no longer.
Google Vertex AI The text for the three AI uses above, and nothing else.
Google sign-in Google confirms who you are when you sign in. It learns that you signed in to Wimmo; we learn which Google account it was.
Sentry, Germany Crash reports, as described above, and nothing else.
Google Play and RevenueCat Not yet. Only once subscriptions go on sale, as described above.

That is the whole list. Nobody else receives anything.

What we do not do

Deleting things

On the Account screen there are two choices, and our delete page does the second one without the app.

Deleting your account does not cancel a subscription. The store holds it, so it keeps renewing until you cancel it there — in the Play Store under Payments and subscriptions. You do not have to cancel first: you can delete your account either way, and the app shows a link to the store's subscription page next to the delete button.

If a deletion cannot finish in one go — for example RevenueCat cannot be reached — nothing is reported as deleted until every part is. Our server keeps a note of what is left, under your random account number and the same one-way code described below, and removes it the moment the deletion finishes. Trying again carries on from where it stopped, even after the sign-in itself has been deleted: sign in again with the same Google account, in the app or on the delete page.

One small record stays for 6 months after you delete your account, and it is fair that you know why. Without it, deleting an account and signing up again with the same Google account would hand back the free sessions and the free “Clear your head” use, over and over.

It holds a one-way code made from your Google account's identifier with a secret key only our server has, how many free sessions you used (0 to 3), and whether you used the free “Clear your head”. No content, no email address, no name, no device identifier. It is pseudonymous, not anonymous: if you sign in again with the same Google account within 6 months, our server recognises it and carries those numbers over, once. After 6 months it is removed — the removal can take a few days — and backups can hold it for up to 7 days more. Any phone's device code loses its link to your account and is removed 6 months after the app was last used on it.

For 2 days after the deletion our server also keeps a note that your sign-in was deleted — the sign-in's identifier and the time, with no account number and no content — so a sign-in still open on another phone cannot bring the account back.

Deleting the app takes everything on the phone with it, but leaves what is stored under your account — so delete your account too if you want both gone.

How long we keep things

Your rights

You can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Deleting works in the app or on the delete page straight away; for the others, write to us and we will answer within a month. Because we do not keep your email address, we may ask you to sign in so we can find your account.

If you think we have handled your data badly, you can complain to the UK's data protection regulator, the Information Commissioner's Office, at ico.org.uk. We would rather you told us first so we can put it right, but you do not have to.

Age

Wimmo is for people aged 16 and over. We do not knowingly collect anything from anyone younger. If you believe a child has given us their details, write to us and we will remove them.

Security

Everything stored under your account is filed under your account's number, and our server only ever reads and writes under the number of whoever is signed in — it never takes an account number from the app. Traffic between the app and our servers is encrypted. No system is perfect, and we will not claim otherwise — but nothing is stored that we could avoid storing, which is the part that helps most.

Not medical care

Wimmo is not treatment and not a substitute for medical care. It is a productivity tool, and nothing in it is health advice.

Changes to this page

If what the app does changes, this page changes with it, and the date at the top changes too. If a change matters to you — something new collected, or something going somewhere new — we will say so in the app rather than quietly editing this page.

Contact

NEXARLABS LTD (Nexar Labs), 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. Write to contact@nexarapps.com about anything on this page — a copy of your data, a correction, a deletion, or a question.