W
WedgeAura

Privacy Policy

Effective: April 5, 2026 · WEDGE Method LLC

1. Who We Are

WedgeAura is a product of WEDGE Method LLC, a Utah limited liability company (EIN on file). We operate the WedgeAura platform, mobile applications, and related services. Contact: jacob@thewedgemethodai.com · 8977 S 1300 W #615, West Jordan, UT 84088.

2. Data We Collect

We collect only what is necessary to provide our services: • Account data: name, email address, username, profile photo • Location data: GPS coordinates, only when you have enabled sharing and only shared with your explicit circle members • Message content: encrypted in transit, stored to deliver messages • Payment data: transaction amounts, notes, counterparties. Card details processed by Stripe — we never store card numbers • Social media data: accessed via OAuth with your explicit permission. We cache posts for up to 24 hours only • Email data: accessed via OAuth read-only. We do not store email content — it is fetched on-demand and displayed only to authorized contacts you have approved • Device data: push notification tokens, device type for service delivery

3. Legal Basis for Processing (GDPR)

We process your data under the following legal bases: • Contractual necessity: to provide the services you signed up for • Legitimate interests: fraud prevention, service security • Consent: location sharing, social media integration, email glimpse — all require your explicit opt-in • Legal obligation: we comply with applicable laws and respond to lawful requests

4. Location Sharing

Location sharing is fully opt-in. You control who sees your location, when they can see it, and for how long. You can disable sharing at any time from Settings → Privacy. For Business Circles, location tracking operates only during configured work hours and requires explicit written employee consent.

5. Social Media & Email Integration

Connecting social accounts (Instagram, Twitter, Facebook, LinkedIn, TikTok) and email (Gmail, Outlook) requires OAuth authorization. We receive read-only access tokens scoped to the minimum necessary permissions. We do not post on your behalf. You can revoke access at any time from Settings → Connected Accounts.

6. Business Tracking (Employment Context)

For Business Circles: employees must provide explicit digital consent before any tracking begins. The consent form clearly identifies: what data is collected, when it is collected (work hours only), who can view it, and how long it is retained. Employees may revoke consent at any time. Employers receive an audit log of all data accessed.

7. Your Rights

Under GDPR, CCPA, and applicable law, you have the right to: • Access your personal data • Correct inaccurate data • Delete your account and all associated data • Export your data in a portable format • Object to processing • Withdraw consent at any time Exercise these rights at Settings → Privacy → Your Data, or email jacob@thewedgemethodai.com.

8. Data Retention

Account data is retained until you delete your account. Location data is retained for 7 days, then permanently deleted. Message data is retained for the duration of your account. Social post cache expires after 24 hours. Business tracking data is retained for 90 days, then permanently deleted.

9. Security

We use AES-256 encryption for data at rest, TLS 1.3 for data in transit, and row-level security in our database. We never sell your data. We never share your data with third parties except Stripe (payments), Supabase (infrastructure), and Daily.co (calls) — all bound by Data Processing Agreements.

10. Children

WedgeAura is not intended for users under 13. Users 13–17 require verifiable parental consent. We do not knowingly collect data from children under 13. If you believe a child has provided us personal information, contact jacob@thewedgemethodai.com immediately.

11. Contact

Privacy questions: jacob@thewedgemethodai.com WEDGE Method LLC · 8977 S 1300 W #615, West Jordan, UT 84088 We will respond to all privacy requests within 30 days.