Privacy Policy
Last updated: August 19, 2026
1. Introduction
Wren is operated by Vantage Ventures, LLC, a North Carolina limited liability company doing business as Wren (“we,” “our,” or “us”). Vantage Ventures, LLC is the data controller for the personal data described in this policy. We operate an AI-assisted writing platform that helps founders and executives create LinkedIn content (the “Service”). This Privacy Policy explains what information we collect, how we use and share it, the choices you have, and your rights under applicable privacy laws including the EU General Data Protection Regulation (“GDPR”), the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”), and other US state privacy statutes.
By accessing or using the Service you acknowledge that you have read this Privacy Policy. If you do not agree with our practices, please do not use the Service.
2. Information We Collect
2.1 Information You Provide
- Account information. When you create an account we collect your email address and password (hashed and salted before storage). If you sign in with Google, we receive your name and email address from Google's authentication service.
- Writing content. Post drafts, ideas, outlines, writing samples, voice-profile documents, style guides, and other context documents you create or upload within Wren.
- Chat messages. Conversations you have with Wren's AI writing agents during a writing session are stored so you can resume sessions.
- Media files. Images or other media you attach to posts are stored in our cloud infrastructure.
- LinkedIn data. If you connect your LinkedIn account, we may collect your LinkedIn profile URL, public profile information, and post performance metrics (impressions, reactions, comments, and reshares). We also store periodic snapshots of your profile analytics (follower count, profile views) to help you track growth. You can provide your LinkedIn profile URL manually without connecting your account.
- Telegram integration. If you connect Telegram, we store your Telegram chat ID and messages you send to Wren via Telegram for the purpose of capturing ideas.
- Settings & preferences. Writing schedule, category distribution targets, notification preferences, RSS feed URLs, and content topic preferences.
2.2 Information Collected Automatically
- Usage data. Pages visited, features used, actions taken within the app, and timestamps of those actions.
- Device & browser data. IP address, browser type and version, operating system, and device identifiers.
- Cookies & similar technologies. See Section 8 below.
- API usage metrics. We log the AI model used, token counts, and the endpoint called for each request to monitor costs and enforce usage limits. These logs do not contain the content of your prompts or responses.
2.3 Information from Third-Party Sources
- RSS feeds. We aggregate publicly available articles from RSS feeds you configure. Article titles, URLs, summaries, and publication dates are stored to power content inspiration features. We do not collect personal data from these feeds.
- Content you save with “Save to Wren”. When you click Save to Wren on a web page or a LinkedIn post, we store that item in your account so you can use it as source material. For a LinkedIn post this includes the post's text and its author's name — information about a person other than you, which you have chosen to save. Nothing is captured unless you click save, one item at a time, and we never collect this in the background or in bulk. Saved items are private to your account, are never published or shared by us, and you can delete any of them at any time.
3. How We Use Your Information
We use the information we collect for the following purposes:
- Provide the Service. Generate AI-assisted drafts, outlines, critiques, and content suggestions; store and manage your ideas, drafts, and writing sessions.
- Personalize your experience. Build your voice profile, tailor content recommendations, and curate your idea bank.
- Communicate with you. Send product updates, writing cadence reminders (via email or Telegram), and respond to support requests.
- Improve the Service. Analyze aggregate usage patterns, diagnose technical issues, and inform product development.
- Ensure security. Detect and prevent fraud, abuse, and unauthorized access.
- Comply with legal obligations. Respond to lawful requests and enforce our Terms of Service.
3.1 Lawful Bases for Processing (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we rely on the following lawful bases under GDPR Article 6:
- Performance of a contract — to provide the Service and fulfill our obligations to you.
- Legitimate interests — to improve the Service, ensure security, and send non-marketing communications, where those interests are not overridden by your rights.
- Consent — where you have opted in to marketing communications or optional data processing (e.g., Telegram integration). You may withdraw consent at any time.
- Legal obligation — where we are required to process data by applicable law.
4. AI Processing & Third-Party Services
The Service relies on third-party providers to function. We share only the minimum data necessary with each provider.
4.1 AI Service Providers
To power text generation (drafts, outlines, critiques, idea scoring) and image generation features, we send your content to third-party AI model providers. The data sent may include your writing content, voice-profile context, chat messages, and image prompts. AI providers process this data as sub-processors on our behalf and may retain inputs and outputs for a limited period for trust and safety purposes. Each one is named on our subprocessor list.
We require that all AI providers we use do not use your data to train or improve their AI models. We enforce this through our commercial agreements and by selecting API tiers that contractually prohibit training on customer data. The specific AI models and providers we use may change over time as we improve the Service. Our current providers include Anthropic and OpenRouter. Each provider's own privacy policy governs their data handling practices.
4.2 Supabase
We use Supabase for user authentication (including Google OAuth) and as our primary database (PostgreSQL). Your account data, content, and application data are stored in Supabase's infrastructure. Data is encrypted at rest and in transit.
4.3 Railway
Our application is hosted on Railway's cloud infrastructure. Server logs may temporarily contain request metadata (IP addresses, timestamps, and endpoints) for operational purposes.
4.3a PostHog
We use PostHog for product analytics, hosted in the United States. It receives usage and interaction data — the events and pages that tell us how Wren is used — together with an identifier for your account and standard device and browser information. It does not receive the content you create or connect: your drafts, ideas, writing samples, voice profile, LinkedIn post text, or your LinkedIn analytics. See Section 8.
4.4 LinkedIn
If you connect your LinkedIn account, we use LinkedIn's official API for one thing only: publishing a post when you explicitly ask us to. We do not post to LinkedIn on your behalf without your explicit action.
Your post analytics do not come from an API. LinkedIn does not make per-post analytics available to us that way. If you install the optional Wren browser extension and turn on analytics capture, the extension reads those numbers from your own LinkedIn pages in your own browser — see Section 14, which describes exactly how that works and what it means for your LinkedIn account. If you do not install the extension, we have no analytics about your posts at all.
If LinkedIn grants us access to its member analytics API and you authorize it, we will retrieve your own post analytics through that API instead, and the commitments in this section apply to that data in the same way.
We use LinkedIn data solely to provide analytics and content performance features within the Service. Your LinkedIn data is subject to LinkedIn's Privacy Policy. Key commitments regarding your LinkedIn data:
- We do not use LinkedIn member data to train AI models or for any purpose other than providing the Service to you.
- We do not share your LinkedIn data with any third parties beyond what is necessary to operate the Service.
- If you disconnect your LinkedIn account or revoke access, we will delete your LinkedIn-sourced data (engagement metrics and profile snapshots) within a reasonable timeframe. Content you created using the Service (drafts, ideas) is yours and remains in your account.
4.5 Telegram Bot API
If you opt in to the Telegram integration, messages you send to our Telegram bot are relayed through Telegram's Bot API. Telegram's own privacy policy governs the processing of data on their platform. We store only the content necessary to save ideas from your messages.
4.6 Google OAuth
If you choose to sign in with Google, we use Google's OAuth 2.0 service. We receive your name and email address. We do not access your Google contacts, calendar, or other Google data.
5. Data Sharing & Disclosure
We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising. We disclose data only in the following circumstances:
- Service providers. With the third-party providers listed in Section 4, strictly as necessary to operate the Service.
- Legal requirements. When required by law, legal process, or governmental request, or to protect the rights, safety, or property of Wren, our users, or the public.
- Business transfers. In connection with a merger, acquisition, reorganization, or sale of assets, your data may be transferred to a successor entity. We will notify you before your data becomes subject to a different privacy policy.
- With your consent. We may share data for other purposes when you have given us explicit consent to do so.
6. Data Retention
We retain your data for as long as your account is active or as needed to provide the Service. Specific retention periods:
- Account data & content. Retained for as long as your account is active.
- Chat session history. Retained for the life of the associated writing session and account.
- API usage logs. Retained for a reasonable period for cost monitoring and then aggregated or deleted.
- Server logs. Retained for a limited period (typically no more than 90 days).
When you delete your account, we will delete or anonymize your personal data within a reasonable timeframe, except where retention is required by law or for legitimate business purposes (e.g., fraud prevention, legal compliance). Backups containing your data may persist for a limited period before being overwritten.
7. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- Encryption in transit (TLS/HTTPS for all connections) and at rest using industry-standard encryption.
- Password hashing using industry-standard algorithms.
- Access controls and the principle of least privilege for internal systems.
- Regular dependency updates and vulnerability monitoring.
No method of transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. If we become aware of a data breach that is likely to result in a risk to your rights and freedoms, we will notify affected users and relevant supervisory authorities in accordance with applicable law (within 72 hours under GDPR).
8. Cookies & Tracking Technologies
We use essential cookies for authentication and session management. These are strictly necessary for the Service to function and cannot be opted out of.
We also use analytics cookies and similar technologies through PostHog, our product-analytics provider, to understand how Wren is used so we can improve it. On our public marketing pages this includes an identifier stored on your device so we can recognise a returning visit. Inside the product, analytics are recorded on our servers against your account, not through anything stored on your device.
We do not record session replays or screen recordings of your use of Wren, and we do not use PostHog’s autocapture — the events we record are the specific ones we have chosen and documented, not everything you click.
What we never send to our analytics provider is the content you create or connect: your drafts, ideas, outlines, writing samples, voice profile, LinkedIn post text, or your LinkedIn analytics.
We do not use advertising cookies, advertising pixels, or third-party ad networks, we do not track you across other websites, and we do not sell or share your personal information with advertisers or data brokers.
We honor Global Privacy Control (GPC) and Do Not Track (DNT) signals. We do not sell or share personal information, and we do not engage in cross-site tracking or cross-context behavioral advertising — so there is nothing for these signals to switch off. They do not disable the product analytics described above, which we use only to operate and improve Wren.
9. International Data Transfers
Our Service is operated from the United States. If you are located outside the United States, your data will be transferred to and processed in the United States and potentially other countries where our service providers operate.
For transfers from the EEA, UK, or Switzerland, we and our sub-processors rely on applicable lawful transfer mechanisms, which may include Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework. You may contact us for more information about the safeguards in place for international transfers.
10. Your Privacy Rights
10.1 Rights for All Users
Regardless of where you are located, you may:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your account and all associated data.
- Export your content (drafts, ideas, context documents) upon request.
- Withdraw consent for optional processing at any time (e.g., Telegram integration, marketing emails).
10.2 Additional Rights — EEA, UK & Switzerland (GDPR)
If you are located in the EEA, UK, or Switzerland you also have the right to:
- Restrict processing of your personal data in certain circumstances.
- Data portability — receive your personal data in a structured, commonly used, machine-readable format.
- Object to processing based on legitimate interests, including profiling.
- Lodge a complaint with your local data protection supervisory authority.
10.3 Additional Rights — California (CCPA/CPRA)
If you are a California resident, you have the following additional rights under the CCPA/CPRA:
- Right to know — request the categories and specific pieces of personal information we have collected, the sources, the business purposes, and the categories of third parties with whom we share it.
- Right to delete — request deletion of your personal information, subject to certain exceptions.
- Right to correct — request correction of inaccurate personal information.
- Right to opt out of sale/sharing — we do not sell or share your personal information for cross-context behavioral advertising.
- Right to limit use of sensitive personal information — we only use sensitive personal information (account credentials) as necessary to provide the Service.
- Right to non-discrimination — we will not discriminate against you for exercising your CCPA/CPRA rights.
To exercise any of these rights, contact us at legal@writewithwren.com. We will respond to verifiable requests in accordance with applicable law — generally within 30 days for GDPR requests and 45 days for CCPA/CPRA requests, with extensions permitted where reasonably necessary. We will not charge a fee for responding to your request unless it is manifestly unfounded or excessive.
10.4 Additional US State Privacy Rights
Residents of other US states with comprehensive privacy laws may have similar rights, including the right to access, correct, delete, and port personal data, and to opt out of targeted advertising and profiling. To exercise these rights, contact us using the information in Section 15.
11. AI-Specific Disclosures
Wren uses artificial intelligence to generate content suggestions, drafts, outlines, critiques, and idea recommendations. Key facts about our AI processing:
- AI-generated outputs are produced by third-party AI models. Your content is processed by these models in real time and is not used for AI model training (see Section 4.1).
- We do not make any fully automated decisions with legal or similarly significant effects on you. All AI outputs are presented as suggestions for your review and approval.
- We use AI to score and prioritize ideas and content (relevance scoring, critic scoring). These scores are advisory and you retain full control over your content.
- We are committed to complying with applicable AI transparency requirements, including the EU AI Act, as they come into effect.
12. Children's Privacy
The Service is not directed to individuals under the age of 16 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If you believe we have inadvertently collected data from a child, please contact us immediately and we will promptly delete it.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
- Update the “Last updated” date at the top of this page.
- Provide reasonable advance notice via email or an in-app notification before the changes take effect.
- Where required by law, obtain your consent before applying material changes.
We encourage you to review this page periodically. Your continued use of the Service after changes become effective constitutes acceptance of the revised policy.
14. Analytics Browser Extension
Wren offers an optional Chrome browser extension (“Wren LinkedIn Analytics”) that you install yourself and connect to your own Wren account. The extension is entirely opt-in: it does nothing until you install it and enter your personal Wren analytics-ingest token. This section describes exactly what the extension does, the data it handles, and why it requests each permission. We describe the mechanism candidly so you can make an informed choice.
14.1 What It Does
The extension works in two modes, and you choose them separately. When you install it, it can do a one-time read of your own profile and recent posts to set up your account faster. Keeping your analytics up to date on an ongoing basis is a separate step you turn on deliberately, and can turn off at any time — it is off until you choose it.
The extension reads your own LinkedIn post analytics — the impression, reaction, comment, and reshare metrics that LinkedIn shows you for posts on your own account, on the LinkedIn analytics and recent-activity pages you are already logged in to. It then sends those metrics to your Wren account so your content performance is available inside Wren. It only ever reads the analytics of the logged-in LinkedIn account using the browser; it does not access other members' private data.
So that it does not interrupt what you are doing, the extension opens those pages in a small background window rather than in the tab you are using. Browsers pause rendering for windows that are not on screen, so the extension signals to the page that it is visible — otherwise your own analytics would never load there and there would be nothing to read. That signalling is limited to LinkedIn analytics pages and affects only whether the page draws its contents in that background window.
Versions of the extension released before August 2026 also opened the audience-demographics breakdown on each post and recorded it. Current versions no longer collect that, and Wren links you to LinkedIn's own page for it instead. If you have an older version installed, it will continue to collect demographics until it updates.
14.2 Where Your Data Goes
The captured analytics are sent only to your own Wren account, over HTTPS, to Wren's analytics-ingest endpoint on app.writewithwren.com (or, for local development, a localhost endpoint you configure yourself). The data is authenticated with the personal ingest token you enter in the extension's options. We do not share this data with any third party, and we do not sell it. Once in your Wren account it is handled under this Privacy Policy like any other LinkedIn analytics data (see Section 4.4).
14.3 Permissions and Why They Are Needed
These are every permission the published extension requests, and why. If a future version needs another one, it appears here.
- storage. Stores your extension settings (Wren API base URL, your ingest token, your LinkedIn profile URL) and its sync progress locally in the browser.
- alarms. Schedules the periodic, rate-limited background sync so capture runs on a timer rather than continuously.
- tabs. Opens and manages the background window that loads your LinkedIn analytics pages for capture, and closes it when capture is done.
- contextMenus. Adds the right-click “Save to Wren” option so you can save a page or a post from the context menu.
- notifications. Shows the occasional desktop notification about capture — for example when a background sync starts, or when the capture window needed to give itself back to you. You can turn these off.
- activeTab. Lets the extension read the page you are currently on — and only at the moment you click Save to Wren, never in the background.
- scripting. Runs the small script that reads a page when you save it, and that reads your own analytics in the capture window.
- power. Keeps the computer from sleeping during the one-time initial capture, so a long first sync is not left half-finished. It never keeps the display awake, and it is not held during ordinary background syncing.
- idle. Detects when you are away from the computer so capture can prefer those moments and stay out of your way.
- Host access to linkedin.com. Lets the extension load and read your own analytics on LinkedIn’s analytics and recent-activity pages — the pages the metrics come from — and save a post when you ask it to.
- Host access to app.writewithwren.com. Lets the extension send what it captured to your Wren account’s ingest endpoint, and lets the Wren web app connect the extension for you.
14.4 Your Control
The extension runs only while it is installed and configured with your token. You can pause it, clear its token, or uninstall it at any time from Chrome's extensions page, which immediately stops all capture. Uninstalling removes its locally stored settings. To remove the analytics already synced to your Wren account, see your LinkedIn data rights in Section 4.4 and your general rights in Section 10.
15. Contact Us
If you have questions, concerns, or requests related to this Privacy Policy or your personal data, please contact us:
- Email: legal@writewithwren.com
- Mailing address: Vantage Ventures, LLC, 4030 Wake Forest Rd, Ste 349, Raleigh, NC 27609, United States
If you are located in the EEA and believe we have not adequately addressed your concern, you have the right to lodge a complaint with your local data protection supervisory authority.