Privacy policy
Whomwise · Last updated 2 October 2026
1. Who is responsible
Philipp Sommer, Dornierstraße 11, 88048 Friedrichshafen, Germany ("we") runs Whomwise. For questions about your data write to hello@whomwise.com. We are based in Germany and the service is for people in the United States, so both German and EU data protection law and US state privacy laws may apply.
2. What we store, and why
| What | Where it comes from | Why |
|---|---|---|
| Your account: name, email address, how you sign in (Google, Microsoft or an email link), time zone, when you last used the service | You, and Google or Microsoft when you sign in with them (only name and email address) | To give you an account and keep it safe |
| Your profile: your CV, your answers to the setup questions (target roles, places, work permission, pay expectations, hours a week, dealbreakers), stories you tell us, and what we work out from them (directions, your pitch, a description of your writing style with up to 3 short excerpts of your own messages) | You | To find employers that fit you and write in your voice |
| Your LinkedIn export, if you upload it: your connections (names, employers, positions), your own messages and your past applications | You | To show who you already know at an employer, to avoid suggesting jobs you applied to, and to learn how you write. It is never shown to anyone else (section 5). |
| Employers, the people we suggest you write to, addresses we found for them, your messages and drafts, notes, statuses, the history of what you did in the app | Public sources, our providers (section 4) and you | To run your search |
| Your mailbox, only if you connect it: for the threads about people you wrote to through the app, who wrote, when, what kind of message it was (reply, out of office, bounce…) and the first 200 characters; what you sent compared with our draft. Only if you turn on the separate switch for job alerts (off unless you do): from the job alert emails you get from Handshake, LinkedIn, Indeed, Glassdoor, USAJOBS and similar senders, the title, employer, place, date and link of each listing. We don't keep those emails, we never open their links, and what we keep is deleted when you turn the switch off, disconnect or delete everything. Nothing from any other email is kept. Your sent mail is read to learn your style and is not stored, apart from the excerpts above. | Your mailbox, read-only | To notice sends, replies and bounces for you |
| Your plan and payments: which plan you have, its dates, and Stripe's customer and subscription numbers. Not your card. | Stripe | To give you the plan you paid for |
| Notes you send with the Feedback button, and the page you were on | You | To improve the service |
| Waitlist: your email address and country, if you ask to be told when your country opens | You | To email you once when it opens |
| Technical data: a session cookie that keeps you signed in and protects forms, a protected version of your address to limit abuse, server logs | Your browser | Security and running the service |
The only cookie is the session cookie, which is needed to sign you in. There are no advertising or tracking cookies. We don't use analytics.
People who aren't our users. To suggest who you could write to, we look up people at employers in public sources (company pages, press, podcasts, news) and store their name, job title, the source and a possible work email address. We don't use LinkedIn or data brokers for this. If you're one of them and want your data removed, write to hello@whomwise.com and we delete it.
3. Legal bases (GDPR)
- Running your account and the service you asked for: performance of a contract (Art. 6(1)(b)).
- Connecting your mailbox and uploading your LinkedIn export: your consent (Art. 6(1)(a)), which you can withdraw at any time by disconnecting or deleting.
- Security, abuse prevention, and looking up business contacts at employers: our legitimate interests (Art. 6(1)(f)).
- Payment and tax records: legal obligation (Art. 6(1)(c)).
4. Who else handles your data
We use these providers as processors under data processing agreements.
| Provider | What they do | What they get |
|---|---|---|
| Amazon Web Services, Inc. (Amazon Lightsail) (United States (Ohio)) | Hosts the service and its database, and keeps our encrypted backup copies | Everything we store, encrypted in transit; mailbox tokens are additionally encrypted in the database, and the backup copies are encrypted before they leave the server |
| OpenRouter, and the AI model companies behind it | Write and check text: your directions, your pitch, your messages, what postings require | The parts of your profile a step needs (for example your CV for reading it, or your background for a message). We only use routes for these steps that don't keep your data or train on it, and the app refuses routes that might. |
| Exa, Brave Search, Firecrawl | Search the web and read public pages about employers and people | Company names, places, fields and public people's names. Not your CV and not your contact details. |
| Hunter, MillionVerifier, NeverBounce | Find and check work email addresses | A public person's name, a company's domain and candidate addresses. Nothing about you. |
| Google, Microsoft | Sign-in, and reading your mailbox if you connect it | They tell us your name and address; if you connect, we read mail with read-only access |
| Stripe | Takes payments | What you enter on Stripe's page (card details go to Stripe only). We get the plan and dates. |
| Resend | Sends our emails (sign-in links, new roles, reminders about your plan) | Your email address and the email's content |
We don't sell your data and don't share it for advertising. Your data is stored in the United States: the service and its database run on servers there, and the encrypted copies of our backups are kept in another US data center. Most of the providers above are in the United States too. Because we are based in Germany, we rely on the EU Standard Contractual Clauses or the EU-US Data Privacy Framework where EU law requires it.
5. Your data is separate from everyone else's
- Every account is its own. Every page, background job, export and email works for one account only, and another account's records can't be opened, even by guessing an address.
- What is shared between users is research about employers from public sources (what a company does, its open roles, which lists name it). None of it is personal to you.
- Your LinkedIn data is never shared. It's never shown to other users, never used to improve results for others, and never sent to search or email-finding services. Only anonymous counts (for example how many people kept an employer that a kind of source listed) are pooled, and they contain nothing that can be tied to a person.
- Mailbox content is used only for your own account.
6. How long we keep it, and deleting it
- We keep your data while you have an account. You can download everything and delete everything under You → More → Your data. Deleting removes your profile, everything we found and wrote for you, your mailbox access, your sign-in, and your account, and cancels a monthly subscription so nobody is charged afterwards. Your plan ending never removes anything you have.
- Backups: we back up the database every day and keep each backup 30 days. Deleted data is gone from the backups within 30 days.
- Payment and invoice records are kept by Stripe and by us as long as tax and commercial law require.
- Sign-in links stop working after 15 minutes. If you leave the demo, its made-up account is deleted within about an hour.
- A waitlist entry is deleted when you use the link in its email.
7. Your rights
You have the right to access, correct, delete, restrict and export your data, to object to processing based on our legitimate interests, and to withdraw consent. Download and delete are buttons in the app; for anything else write to hello@whomwise.com. You can complain to a data protection authority, for example Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg. If you live in California or another US state with a privacy law, you have similar rights to know, correct, delete and to opt out of sale or sharing; we don't sell or share your data.
8. Security
Connections use HTTPS. Sign-in uses Google, Microsoft or a one-time link; sessions can be ended; forms are protected against forgery. Mailbox access tokens are encrypted in the database. Access to operator tools is limited to named administrators. No system is perfectly secure, and we'll tell you and the authorities if something goes wrong as the law requires.
9. Children
The service is for adults.
10. Data from your Google account
If you sign in with Google, we receive your name, email address and profile picture (scopes openid, email, profile) and use them only to create your account and sign you in.
If you choose to connect Gmail, we ask for read-only access (gmail.readonly). We use it only to detect, for the people you wrote to through Whomwise, whether they replied, whether an address bounced, and, if you turn on that switch, which job alert emails you got. What we keep from it is listed in section 2. We never send, change or delete anything in your mailbox. You can disconnect at any time under You → Connected accounts, or remove access in your Google account at myaccount.google.com/permissions; disconnecting deletes the access and everything we kept from your mailbox.
Whomwise's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular: we use Gmail data only to provide the features you see in the app; we don't transfer it to others except as needed to provide those features (the hosting provider, and the AI step in section 4 that reads a message to tell a reply from an out-of-office or a bounce, through routes that don't keep it or train on it), to comply with the law, or as part of a merger or sale with your notice; we don't use it for advertising; we don't sell it; and no person reads it unless you ask us to for support, it's needed for security or the law requires it. Neither we nor those providers use Gmail data to train AI models.
11. Changes
If we change this policy in a way that matters, we'll tell you in the app or by email before it applies.