Wagglet

Share AI work, not AI accounts.

Last updated 23 September 2026

Privacy

Who is responsible

Rockbite LLC, trading as Rockbite Games, operates Wagglet. For account, security, service-operation and website data, Rockbite is the data controller. Contact us at [email protected].

A company or other organization that provides your Wagglet workspace normally decides why its members' workplace data is processed. For that workspace data, the organization is the controller and Rockbite processes the data to provide Wagglet on its instructions. Contact your workspace administrator first for requests about employer-controlled data; we will help the organization answer them.

What we collect and how

  • Account and profile — your name, email address and photo come from Google when you sign in. We also store a replacement photo, profile skills, preferences, account identifiers and workspace memberships that you or a workspace administrator provide.
  • Workspace content — tickets, stories, requests, comments, notes, delivery reports, reactions, recordings, transcripts, attachments and their history, including who did what and when. We collect these when you, another workspace member, or an authorized connected agent submits them.
  • Availability and employment data — work schedules, holidays, attendance balances, time-off dates and categories, optional reasons or documents, and approval history. A sick-leave entry or free-text reason may reveal health information. Your organization controls who can enter and see it.
  • Files, photos and audio — profile photos and files you choose to upload. Voice dictation sends audio only when you start it; meeting audio is stored only when you explicitly create or upload a recording.
  • App, device and notification data — mobile session records, an app installation identifier, device name, push token or browser subscription, notification preferences and delivery status. We receive these from the app, device and push provider when you sign in or enable notifications.
  • Optional usage telemetry — if you pair Scout or an administrator connects a provider report, Wagglet stores subscription headroom, token counts and bounded connection health. Scout pairing is optional, and sharing its figures with a team is controlled separately.
  • Connections and invitations — invitation email addresses; identifiers and metadata returned by services you connect; and encrypted credentials needed to operate an authorized GitHub, model, transcription or other workspace integration. Wagglet does not store your Google password.
  • Technical and support data — request, security and error information made available by your browser, device and hosting infrastructure, such as IP address, user agent, timestamps and the details you send when asking for support.

Why we use it and our legal bases

  • Provide the service — authenticate you, show authorized workspace content, save submissions, synchronize clients, deliver notifications and support users. This is necessary to perform our contract with you or your organization.
  • Keep Wagglet secure and reliable — prevent abuse, troubleshoot failures, keep audit history and protect accounts and workspaces. We rely on our legitimate interests in operating a secure service and, where applicable, the legitimate interests of your organization.
  • Run optional features — process dictation, recordings, connected integrations, telemetry and push notifications when you or your organization enables them. Depending on the feature and who controls the workspace, this is based on contract, legitimate interests or consent.
  • Meet legal obligations — preserve or disclose limited records when applicable law requires it and respond to valid legal requests.

Name, email, an account identifier and session data are required to sign in and use an authorized workspace. Without them we cannot provide an account. Profile details, notifications, Scout, voice features and most content submissions are optional. We do not use personal data to make solely automated decisions that produce legal or similarly significant effects.

The iPhone and Android apps

The mobile apps use the same account and workspace data as the website. Data sent by the app is linked to your account and used for app functionality: contact information for sign-in, user-generated content, optional photos and audio, account and installation identifiers, notification data, and availability data. The app does not collect precise location, contacts, an advertising identifier or payment information, and contains no advertising or cross-app tracking SDK.

The app keeps sign-in credentials in device-protected storage. It may also keep recovery copies of unsent text and some preferences only on your device; unsent text expires after 24 hours and is cleared for the account when you sign out. Device-only data is not collected by Wagglet unless you submit it.

Microphone access is optional and requested when you start dictation or recording. Dictation audio goes through Wagglet to the transcription service configured for the workspace, currently OpenRouter; Wagglet does not retain the dictation audio after the transcription request. Editable text becomes workspace content only when you submit it. Meeting recordings are different: when you explicitly save one, its audio and transcript are stored with the note and may be processed by OpenRouter or ElevenLabs, depending on workspace settings.

If you enable notifications, Apple Push Notification service, Firebase Cloud Messaging, or the browser push service receives the device token and information needed to deliver the notification. Preview settings control whether a title appears. You can disable notifications in Wagglet or device settings and revoke a registered device in Wagglet.

Where data is stored and who receives it

Application records are stored in PostgreSQL and files in an S3-compatible object store, hosted on Railway. Rockbite staff may access them when necessary for operations, security or support. A workspace's members see data according to current membership and permissions; workspace administrators can manage membership and broad workspace access.

We disclose only the data needed to these categories of recipient:

  • hosting, object-storage, backup and transactional-email providers;
  • Google for sign-in, and Apple, Google or browser services for optional push delivery;
  • OpenRouter, ElevenLabs or another workspace-configured model provider when an authorized person uses transcription or a model-backed feature;
  • services such as GitHub or Slack when an administrator or user enables the relevant integration;
  • professional advisers, authorities or another party when law requires it or a valid corporate transaction makes it necessary.

Service providers may process data only to supply their contracted service and must apply protections no less protective than those described here and required by applicable law. We do not sell personal data or workspace content, share workspace content with advertisers, or use it to train models.

International transfers

Wagglet and its providers may process data outside the country where you live, including outside the European Economic Area. Where data protection law requires a transfer safeguard, we use an applicable adequacy decision, approved standard contractual clauses, or another lawful mechanism. Contact us for information about the safeguard relevant to your data.

Advertising measurement on the website

This does not occur in the mobile app. With your permission, the public website loads the OpenAI Pixel to measure ad visits and registrations that create a company workspace. OpenAI receives browser and network information, the page URL, an ad click reference when available, and a conversion event identifier. Its pixel stores the click reference in a first-party cookie. If automatic advanced matching is enabled for our pixel, it may also detect contact information on the page, normalize it and send SHA-256 hashes for attribution.

Wagglet does not put tickets, notes, workspace names or email addresses in its event payloads. Events opt out of future user-level personalization. You may allow or reject measurement and change your choice using Cookie preferences. Rejecting or withdrawing consent does not affect sign-in.

How long we keep data

  • Account and workspace content remains while the account or workspace is active, unless an authorized user deletes it sooner. Shared work and necessary audit history may remain after a member leaves the workspace.
  • Dictation audio is not retained by Wagglet after processing. Saved meeting recordings and transcripts remain with their note until they or the workspace are deleted.
  • Scout quota readings and connection heartbeats are kept for 7 days; Scout daily usage totals for 90 days; and provider-reported daily totals for up to 400 days.
  • Mobile sessions expire after 30 days. Expired mobile sessions, delivery jobs and replay-protection records are removed on bounded cleanup schedules.
  • Website advertising consent lasts 180 days and a pending registration-measurement receipt expires after 24 hours. You can withdraw consent sooner.
  • Invitations, security records and backups remain only as long as needed for their purpose, legal obligations and the backup lifecycle.

Your privacy choices and rights

Depending on where you live and the legal basis involved, you may ask to access, correct, export or delete your personal data; restrict or object to processing; and withdraw consent at any time. Withdrawal does not affect processing already carried out lawfully. You can also disable optional notifications and microphone access in device settings, disconnect integrations, revoke paired devices, and change website cookie consent.

Email [email protected] from your account address and describe the request. We may need to verify your identity. For workspace-controlled data we may refer the request to the organization that controls it. We will respond within the time required by applicable law and explain if a lawful exception applies. We do not discriminate against anyone for exercising a privacy right.

If you are in the EEA or United Kingdom, you may also complain to the data protection authority where you live or work, or where you believe an infringement occurred. We would appreciate the opportunity to address the concern first.

Request account or data deletion

In the mobile app, open Settings → Account & sign out and choose Request account deletion. This submits the request directly while you are signed in. If you cannot sign in, email [email protected] with the subject “Wagglet account deletion”. Send an email request from your account email address, or identify that address so we can verify ownership. You may also request deletion of specific data or a workspace you own. You do not need the app installed to use the email fallback.

Account deletion includes the profile and uploaded avatar, sign-in and mobile sessions, notification devices, and personal connections. Shared work, employer-controlled data and records required for security, legal compliance or workspace audit history may need to remain. We confirm the scope, explain any retention that applies, and delete or de-identify eligible data and files from active systems; residual backup copies age out on the backup schedule.

Security

Wagglet uses encrypted network connections, access controls, workspace-scoped queries, protected device storage and hashed or encrypted credentials where appropriate. No system is perfectly secure. Report a suspected exposure to [email protected] without placing credentials or private workspace content in ordinary email.

Children and changes to this notice

Wagglet is a workplace service and is not directed to children under 16. We do not knowingly create accounts for them. Contact us if you believe a child has provided data so we can investigate and delete it where required.

We update this notice when Wagglet's practices or legal obligations change and show the latest date above. If a change materially affects how we use personal data, we will give additional notice where appropriate.