Privacy & Security

How WYASK protects your content and your recipients

WYASK is built on the principle that your documents are private by default. We do not read your content beyond what is needed to answer questions in an active session, and we never store, share, or use it for any other purpose.

We never train on your documents or conversations

Hallucinations minimised to near zero through document-grounded AI

All chat history permanently deleted when an envelope expires

Data minimised — we store only what is strictly necessary

We never train on your data

Documents you upload and conversations your recipients have are never used to train or fine-tune AI models — ours or anyone else's. Your content is used exclusively to answer questions within the active envelope session. It belongs to you.

Hallucinations minimised to near zero

WYASK answers are grounded strictly in the documents you provide. The AI is not allowed to speculate beyond the content of your envelope. If an answer is not in the document, recipients are told so — rather than being given a plausible but incorrect response.

Ephemeral envelopes — chat deleted at expiry

Envelopes are designed to be temporary. When an envelope expires or is deactivated, all associated chat history and session data are permanently and irreversibly deleted. No conversation is retained after the envelope lifecycle ends.

Data minimisation by design

We collect and store only what is strictly necessary to operate the service. We do not build profiles on recipients, we do not track behaviour beyond what you opt into via analytics, and we do not retain data longer than required.

Session isolation

Every recipient session is completely isolated. What one person asks cannot be seen by another. There is no shared chat history, no cross-user leakage, and no aggregation of individual sessions into a viewable log for anyone other than the envelope owner.

Access control you can trust

WYASK gives you granular control over who can open an envelope. Open Access, Verified Access, and Private Access each provide a different level of restriction. Combined with expiry dates and per-envelope query caps, you have full control over the lifecycle of every document you share.

Invite-only sharing

Private Access envelopes are restricted to email addresses you explicitly approve. Recipients who are not on the list cannot access the content, even if they have the link.

Expiry and deactivation

You can set a hard expiry date on any envelope, after which it automatically becomes inaccessible. You can also manually deactivate an envelope at any time. Once deactivated, neither the documents nor the AI assistant are reachable.

Encryption in transit and at rest

All data transmitted between recipients and WYASK is encrypted using TLS. Documents stored on WYASK infrastructure are encrypted at rest. Access to storage is strictly controlled and audited internally.