whoosin ← Back to whoosin
BETA

Privacy Policy

Effective June 18, 2026 · whoosin, LLC (“whoosin,” “we,” “us”)

The short version

The full detail is below. whoosin is currently in beta; see our Terms of Service.

1. Who we are

whoosin is operated by whoosin, LLC, a Connecticut limited liability company, USA. Questions about this policy or your data: hello@whoosin.app.

2. The information we access from Google

When you connect your Google account, you authorize whoosin through Google OAuth. You sign in on Google’s own page, and we never receive your password. whoosin requests two permissions:

Your Gmail is read in your browser, communicating directly with Google’s API. Through this automatic reading, full message bodies and the subjects of replies are not transmitted to or stored on our servers. The one exception is a message you choose to paste yourself when reporting a misclassification (a reply, or your own invitation — see section 5) — nothing is ever captured from your mail without that deliberate action.

Google Limited Use disclosure

whoosin’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we:

3. How AI classification works

To turn replies into a tally, a short snippet of each reply (up to roughly 800 characters) is sent transiently to our classification service and our AI provider (Anthropic) to determine whether it means yes, no, maybe, or no clear answer. These snippets are processed in the moment and then discarded — they are not stored, not logged, and not used to train any model. Only the resulting verdict (a status plus a short generated note, e.g. “in unless it rains”) is saved, so your list stays consistent. If the AI reads a reply wrong, you can report it — and optionally paste that reply — to help us improve accuracy; see section 5.

4. What we store — and what we don’t

We store only the metadata needed to run your dashboard:

We do not store the content of invitees’ replies, full message bodies, or attachments — with one exception you control: a message you choose to paste (a reply, or your own invitation) when reporting a misclassification (see section 5). Your Google OAuth access token is held only in your browser’s memory and is never written to our database or logs.

5. Other information we collect

6. How we use information

To provide and operate whoosin, classify replies into your attendance list, create follow-up drafts at your request, process billing, send you a welcome message and service reminders about your own events (these are on by default — every email has a one-click unsubscribe, and you can turn them off in Settings; for EEA/UK users this rests on our legitimate interest in helping you run the events you set up), maintain security, and comply with law. Genuinely promotional email, if we ever send it, is separate and opt-in where local law requires. We do not sell personal information and do not use Google user data for advertising or marketing.

7. Service providers (subprocessors)

We share data only with providers who help us run the service, under their own terms:

8. Data retention & deletion

Because we store only metadata — never message content, aside from a message you explicitly choose to paste (a reply or your invitation) when reporting a misread — the most sensitive information stays out of our hands by default.

9. Your choices & rights

You can disconnect whoosin at any time from your Google Account permissions, and you can delete your account and all associated data from within the app.

We do not sell or “share” your personal information for advertising, and we never use Google data for marketing. Depending on where you live — for example, California, or the EEA/UK — you may have rights to access, correct, delete, or port your personal information, or to object to certain processing. You can do most of this yourself in the app; to make any other request, email hello@whoosin.app and we’ll respond within the time your local law requires. We won’t discriminate against you for exercising these rights.

10. Security

We rely on Google’s infrastructure, transport encryption (HTTPS), and a design that minimizes message content on our servers. No method of transmission or storage is 100% secure, but minimizing what we hold is our primary safeguard.

11. Children

whoosin is not directed to children under 13 and is intended for adults organizing events. We do not knowingly collect personal information from children under 13.

12. Changes to this policy

We may update this policy as the product evolves. Material changes will be reflected by a new effective date, and where appropriate we will notify you.

13. Contact

Questions or requests: hello@whoosin.app.