Privacy Policy
Last updated: July 18, 2026 · Applies to the WingHUD closed beta (winghud.com and the WingHUD Windows application)
WingHUD is currently an invite-only closed beta, free of charge, limited to testers in the EU. This policy explains what we collect during the beta, why, who we share it with, and the rights you have over it.
1. Who is responsible for your data (Controller)
WingHUD is currently operated by Guy Almog as an individual developer, pre-incorporation - there is not yet a registered company behind the product while it's in closed beta. You can reach the controller directly at guy@winghud.com for any privacy question or request. If WingHUD is later operated by a registered business entity, this policy will be updated to reflect that and you'll be notified via the email on file.
2. What we collect, and why (Purposes)
| Data | Collected when | Purpose |
|---|---|---|
| Name, email, country, favorite games | You submit the closed-beta signup form on this site | To review and curate invitations to the beta, and to understand tester interest by title/region |
| Email, first/last name, username, password (stored hashed by our auth provider) | You register an account inside the WingHUD desktop app after being invited | To create and authenticate your account |
| Your chat messages, screenshots/area captures, and voice recordings | You use WingHUD's assistant while playing | To generate the AI response you asked for - sent to our AI providers (OpenAI, and for voice, primarily Deepgram) per-request to answer your question |
| Short rolling buffer of recent gameplay screenshots ("Have You Seen That?") | Automatically, only if you've turned on this optional, off-by-default feature, while a known game is running | Lets you ask about a moment that just happened - kept only in memory on your own PC until you actually trigger a question (only those frames are sent to our AI provider); the rest are discarded automatically |
| Detected game name (from running processes on your PC) | Automatically, while WingHUD is running, if the setting is on | To tailor responses to the game you're currently playing |
| Player memory/profile (playstyle, preferences, per-game notes accumulated over time) | Built up automatically from your conversations with WingHUD | To personalize future answers without you re-explaining context every session |
| Chat history | Every conversation you have with WingHUD | So you can revisit past answers - stored locally on your own PC, not centrally on our servers |
| Usage/cost telemetry (token counts, estimated cost, feature used, model used, timestamps) | Every request you make | To operate the beta responsibly - monitor real per-user cost, enforce session limits, and detect abuse |
| Basic product analytics events, error reports | While using the app or this website | To find and fix bugs, and understand which features are actually used |
| Standard web data (IP address, browser, approximate location, pages visited) via Google Analytics | Browsing this website | To understand traffic to the marketing site - see "Analytics & cookies" below |
3. Who we share data with (Sub-processors)
We don't sell your data. It's shared only with the following service providers, strictly to run WingHUD:
- Supabase - hosts our database, authentication, and backend functions. Our project runs in the EU (West Europe) region.
- OpenAI - processes the text/image content of your chat requests to generate WingHUD's replies, including performing a live web search when useful to answer your question. Also used for voice transcription/replies in some configurations. We hold the API key server-side; it never ships inside the app.
- Deepgram - the primary processor for voice audio (speech-to-text and text-to-speech, used by Voice Wingman and Open Mic).
- Purelymail - sends transactional email (beta invitations, password resets, account confirmations) from noreply@winghud.com.
- Firebase (Google) - hosts this static marketing website.
- Google Analytics - basic website traffic analytics (see below).
OpenAI, Deepgram, and Purelymail are US companies, so using them involves transferring your data outside the EU. This is done under their Standard Contractual Clauses, the standard EU-approved safeguard for this kind of transfer.
Each of these providers processes data only as needed to perform their specific function for us, under their own data processing terms. We do not use your conversations to train AI models beyond what our providers' own standard API terms specify (as of this writing, API traffic is excluded from training under OpenAI's and Deepgram's API terms - check their current terms for the latest details, since this policy can't guarantee changes on their end).
4. Legal basis for processing
During this closed beta, everything described in this policy is processed based on your consent to participate as an invited tester - you were personally invited, and you actively agreed to these terms before your account was created. A more detailed, per-category legal basis will be added before any future paid launch.
5. Analytics & cookies
This website uses Google Analytics (gtag.js) to understand visits and traffic sources. This may set cookies and share standard web analytics data (e.g. approximate location, device/browser type, pages viewed) with Google. The WingHUD desktop application itself does not use advertising cookies or third-party trackers.
6. How long we keep your data (Retention)
- Beta signup form submissions not yet invited are kept while the beta is being staffed, and reviewed periodically.
- Account data is kept for as long as your account exists. You can delete your account and its associated data at any time from Settings > Account > Delete Account inside the app - this triggers a real, immediate deletion on our servers.
- Local data (chat history, local logs, cached memory) lives only on your own PC and is removed if you uninstall WingHUD or clear it yourself.
- If the beta ends (see our Terms of Service), we will give you a way to request deletion of any remaining server-side data even if you no longer have the app installed - email us at the address above.
7. Your rights
Since the beta is EU-only, you have rights under the GDPR, including the right to:
- Access the data we hold about you.
- Rectify inaccurate data.
- Erase your data (self-serve for account data via in-app deletion, or by request for anything else).
- Restrict or object to certain processing.
- Port your data to another service in a structured format, on request.
- Withdraw consent at any time where processing is based on consent (e.g. the beta signup form).
- Lodge a complaint with your local data protection supervisory authority.
To exercise any of these, email guy@winghud.com.
8. Security
We take reasonable technical measures to protect your data - for example, your local session token is encrypted at rest on your PC, and our database access is locked down with row-level security so only your own account can read your own data. No online service can guarantee perfect security, but we treat this seriously, especially while handling account credentials and chat content.
9. Children
WingHUD is not intended for anyone under 16, and account registration requires agreeing to our Terms of Service. If you believe a child has provided us data without appropriate consent, contact us and we will remove it.
10. Changes to this policy
We may update this policy as the product evolves, especially moving from the free closed beta into a later paid phase. Material changes will be reflected here with an updated "Last updated" date, and where appropriate we'll also notify you by email.
11. Contact
Questions about this policy or your data: guy@winghud.com.