This Privacy Policy explains how Sternwheel Labs LLC, which operates Wake ("Wake", "we", "us"), collects, uses, shares and protects information when you visit trywake.io, use the Wake application at app.trywake.io, or view a report or dashboard shared through Wake (together, the "Service").
Wake is a business tool for media buyers and agencies. It connects to advertising platforms ("DSPs"), brings their reporting into one workspace, and, when an authorized user permits it, makes changes to campaigns on those platforms. It is not intended for consumers or for anyone under 18.
1. Our two roles
- Controller of account data. We decide how to handle the information we need to run your account: who you are, how you sign in, and how you use the Service.
- Processor of customer data. We handle the advertising data you or your organization connect to Wake on your organization's behalf and under its instructions. This includes campaign structure, spend, delivery and performance data, creatives, and the notes, reports and dashboards you build from them. Your organization (our "Customer") is the controller of that data. If you have a question about it, contact your organization first. Customers who need a Data Processing Addendum can ask us for one at hello@sternwheellabs.com.
2. Information we collect
Information you provide
- Account information: your name, email address and username, and the organization you belong to, along with your role and permissions in it. If you set a password or an optional PIN, we store it only in hashed form; Wake staff never see it.
- Invitations: when an administrator invites you, we receive your name and email address from them.
- Content you create: messages you send to Wake's AI assistant ("Alex") and its replies, commands typed into the command deck, notes, tickets, tasks and rules, report and dashboard configurations, saved views, and feedback such as thumbs-up or thumbs-down ratings.
- Settings: your time zone, notification and email preferences, quiet hours, and interface preferences.
- Report recipients: email addresses you add to a scheduled report, including people outside your organization, and the addresses of anyone who unsubscribes from those reports.
Information from our website and waitlist
- Waitlist sign-ups: when you join the waitlist on our website, we collect your email address and, if you choose to give them, your name, company, role, the advertising platforms you use and the approximate monthly media spend you manage. We use this only to run the waitlist, decide onboarding order and contact you about Wake. It is stored in Google Forms and Google Sheets.
- Website hosting: our website is hosted on GitHub Pages and loads fonts from Google Fonts. Those providers receive your IP address and browser information when your browser requests the site. The website sets no cookies and uses no analytics.
Information from advertising platforms you connect
When your organization connects The Trade Desk, StackAdapt, Google Display & Video 360, Google Ads or Meta, either through that platform's sign-in or with an API key, we receive:
- Credentials: access tokens, refresh tokens, API keys or service-account keys. We encrypt these before storing them (see Section 7).
- Account and campaign data: advertisers, campaigns, insertion orders, line items, ad groups, creatives, deals, budgets, bids, pacing, and reporting such as spend, impressions, clicks, conversions, reach, frequency, and geography, device and site breakdowns.
- Basic sign-in identity: for Google, the email address of the account that authorized the connection.
We do not collect from these platforms search-term reports, audience lists or other personal data about the people who see your ads, or user-level click logs. The reporting we sync is aggregated by the platform.
Information collected automatically
- Product usage events: which panels you open, close or focus, and which features you use (for example, editing a bid). Each event is stamped with your user and organization, a random per-tab session ID, your time-zone offset and the app version. We use these events only to operate and improve Wake. They are not sent to any third-party analytics provider.
- Audit records: a record of actions taken in Wake, such as changes sent to an advertising platform, approvals, and administrative changes. Each record shows who or what (for example, the AI assistant or an automated task) took the action and when.
- AI usage records: for each AI request, the model used, the token counts and the cost. We also keep the prompt text and the page context it was asked from, for troubleshooting and for enforcing your organization's AI budget.
- Shared dashboard metrics: for dashboards shared by link, the number of views and the time of the most recent view.
- Network information: your IP address is used briefly to rate-limit sign-in, dashboard and onboarding-link requests. We do not store it in our application database. Our hosting and authentication providers may log IP addresses and browser information as part of their own security operations.
3. Cookies and browser storage
Wake does not use advertising cookies, cross-site tracking or third-party analytics.
- Sign-in session: our authentication provider (Supabase) keeps your signed-in session in your browser's local storage.
- Dashboard unlock cookie: when you open a password-protected shared dashboard, we set one signed, HTTP-only, secure cookie that lasts 12 hours.
- Preferences and caches: we use local storage and session storage to remember your layout, panel widths, the last page you viewed, saved filters, report drafts and a local copy of recent assistant messages. Clearing your browser's storage removes them.
- Third-party content: the app loads fonts from Google Fonts and map tiles from CARTO. Those providers receive your IP address and browser information when your browser requests them.
4. How we use information
- To provide the Service: syncing and showing your advertising data, building reports and dashboards, sending email, and carrying out actions you or your organization authorize.
- To make changes on advertising platforms. Where your organization has turned it on, Wake can change bids, budgets and line-item status on supported platforms (currently The Trade Desk, StackAdapt and Display & Video 360). It does so only when an authorized user sends the change or sets up an automated task or rule that sends it, and only within the permissions and limits your organization configures. Wake does not currently write changes to Google Ads or Meta.
- To provide AI features (see Section 5).
- To secure the Service: authentication, rate limiting, abuse prevention and audit logging.
- To support you, troubleshoot problems, and communicate with you about the Service.
- To improve the Service using usage events and feedback.
- To meet legal obligations and enforce our Terms of Service.
We do not sell personal information. We do not share it for cross-context behavioral advertising. We do not use one Customer's data to benefit another Customer.
5. AI features
Wake uses large language models to answer questions, summarize performance, draft report commentary, propose changes, classify publishers, and interpret commands.
- What is sent: your message and the context needed to answer it. This can include campaign and performance data from your organization's workspace, and occasionally your name or the page you are on.
- Providers: requests are routed through the Vercel AI Gateway to model providers including Anthropic and OpenAI, plus a specialized model for interpreting deck commands. If your organization supplies its own Anthropic API key, requests may go to Anthropic directly under that key.
- No training: we configure these requests so providers may not use them to train their models. Providers may keep request data for a limited period for abuse monitoring and safety, under their own terms. We do not currently use zero-data-retention arrangements with every provider.
- Stored history: we keep your conversations with the assistant and a daily summary of them, so the assistant can keep context over time. You can clear your chat history from inside the assistant.
- Your judgment still matters: AI output can be wrong. Proposed changes to campaigns are subject to the permissions and approval controls your organization configures.
6. How we share information
We share information only as described here:
- Within your organization: other members of your organization can see shared workspace content, tickets, actions and audit records, according to their roles.
With people you choose:
- Shared dashboards: anyone with the link (and the password, if one is set) can view live data for the campaigns included. You can expire, disable or password-protect a link at any time.
- Scheduled reports: these are emailed to the recipients you list.
- Onboarding links: these let your client connect their own advertising accounts to your organization.
- With advertising platforms: when Wake carries out a change you authorized, it sends that change to the platform.
With service providers (subprocessors) that host or operate parts of the Service under contract:
Provider Purpose Supabase Database, authentication, backups Vercel Application hosting, scheduled jobs, AI Gateway Anthropic, OpenAI and other providers reached through the Vercel AI Gateway AI features (Section 5) Resend Sending email (invitations, alerts, reports) GitHub Website hosting (GitHub Pages) Google (Forms, Sheets) Waitlist sign-ups Google (Fonts, Cloud Storage, YouTube Data API, favicon service, News RSS) Fonts; Display & Video 360 report downloads; publisher and channel metadata; logos; news headlines CARTO Map tiles logo.dev Publisher logos (domain names only) Open-Meteo Weather for the in-app clock (location only)
- For legal reasons: when required by law or legal process, or to protect the rights, safety or security of Wake, our Customers or others.
- In a business transfer: as part of a merger, acquisition, financing or sale of assets, in which case this policy continues to apply to the information transferred.
Access by Wake staff
A small number of Wake staff can access Customer workspaces to provide support, onboarding, troubleshooting and operations. Administrative changes made by staff are recorded in an append-only audit log. Staff access is limited to what is needed to operate and support the Service.
7. Security
We use administrative, technical and physical safeguards appropriate to the data we handle. They include:
- encryption in transit (TLS);
- application-level AES-256-GCM encryption of advertising-platform credentials;
- organization-level isolation of all Customer data;
- hashed passwords, PINs and dashboard passwords;
- signed, time-limited links and cookies;
- rate limiting;
- append-only audit logs;
- emergency switches that can stop syncs or writes to any advertising platform.
No system is perfectly secure. If we learn of a security incident affecting your personal information, we will notify affected Customers and individuals as the law requires.
8. Retention and deletion
- Account and workspace data is kept while your organization's account is active. When an organization's account ends, we archive it. We delete or de-identify its data within 90 days of the end of the agreement, or within 30 days of a verified deletion request, unless the law requires us to keep it longer.
- Hourly advertising data is kept for 180 days. Daily and summary reporting is kept for the life of the account, so you can report historically.
- Audit records of changes made to advertising platforms and of administrative actions are kept for as long as the account exists, and may be kept afterward for security, legal and dispute-resolution purposes.
- Waitlist information is kept until you ask us to remove it, or until we no longer need it to run the waitlist.
- Backups are held by our database provider and are overwritten on its rolling schedule.
- Disconnecting a platform: you can disconnect an advertising platform at any time, or revoke Wake's access from that platform's own settings (for Google, myaccount.google.com/permissions; for Meta, Business Settings > Integrations). We then stop syncing, and we delete the stored credentials when you ask.
To request deletion of your waitlist entry, your account or your organization's data, including data received from Google or Meta, email hello@sternwheellabs.com from the account's email address. We will confirm when the deletion is complete.
9. Google API Services disclosure
Wake's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- We use Google Ads and Display & Video 360 data only to provide and improve the user-facing features of Wake for the organization that connected it.
- We do not sell this data, use it for advertising, or let humans read it except with your consent, for security, to comply with law, or for internal operations.
- We do not transfer this data to third parties except as needed to provide the Service (for example, to our hosting and AI subprocessors under no-training terms), to comply with law, or in a business transfer.
- We do not use this data to train generalized AI or machine-learning models.
10. Your rights
Depending on where you live, you may have the right to access, correct, delete or export your personal information. You may also have the right to object to or restrict certain processing, and to withdraw consent. To exercise these rights, email hello@sternwheellabs.com. We will verify your request and respond within the time the law requires. If your request concerns data we process for a Customer, we will forward it to that Customer and help them respond.
- California residents: we do not sell or share personal information as the CCPA defines those terms, and we will not discriminate against you for exercising your rights.
EEA, UK and Swiss residents: we process account data:
- to perform our contract with you or your organization;
- for our legitimate interests in operating, securing and improving the Service;
- and to comply with legal obligations.
You may complain to your local data protection authority.
11. International transfers
Wake is operated from the United States, and our providers may process data in the United States and other countries. Where the law requires it, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses, for transfers out of the EEA, UK or Switzerland.
12. Children
The Service is for business use. It is not directed to children under 18, and we do not knowingly collect their personal information.
13. Changes
We may update this policy. If a change is material, we will notify account administrators by email or in the app before it takes effect. The "Last updated" date shows when this policy last changed.
14. Contact
Sternwheel Labs LLC
178 East Hanover Ave, 103-114
Cedar Knolls, NJ 07927
Email: hello@sternwheellabs.com