Privacy Policy
Effective July 8, 2026
Waypoint (“Waypoint,” “we,” “us”) operates buildonwaypoint.com, a guided platform that helps you build and ship a Flutter iOS app. This policy explains what information we collect, how we use it, and the choices you have.
Information we collect
- Account information — when you sign in with Google or Apple, we receive your name, email address, and profile photo via Firebase Authentication. We never see or store your password.
- Content you provide — chat messages, screenshots you attach, and your project’s build progress are stored in our database (Firestore) so your work saves across sessions.
- Usage data — message counts and credit usage, so we can enforce plan limits fairly.
- Billing information — payments are processed entirely by Stripe. We never see or store your card number; we only keep your Stripe customer ID and the usage-based billing settings you choose (e.g., your spending cap).
How we use it
- To provide and operate the guided build experience, including generating AI responses and code.
- To save your progress and let you pick up where you left off.
- To enforce free-tier and subscription usage limits.
- To process subscription payments and opt-in overage billing.
- To respond to support requests.
Who we share it with
We rely on a small number of service providers to run Waypoint, each of which processes data on our behalf:
- Google Firebase — authentication and database hosting.
- Anthropic — the chat messages and screenshots you send are processed by Anthropic’s Claude models to generate guidance and code.
- Stripe — subscription and payment processing.
We don’t sell your personal information, and we don’t share it with anyone else for advertising purposes.
Google user data & the Limited Use policy
If you use Waypoint’s optional Firebase Auto-Setup feature, you’ll be asked to connect a Google account via OAuth. We request two scopes — firebase and cloud-platform — solely to create and configure the Google Cloud and Firebase project you choose (registering your iOS app, creating a Firestore database, and deploying security rules). We never use this access for any other purpose.
- How the connection is protected — your Google refresh token is encrypted (AES-256-GCM) and stored only in an httpOnly cookie in your own browser. Our servers never write your Google OAuth tokens to disk or to any database. The access token used to make setup calls is held in memory only for the duration of that request and then discarded.
- What we don’t do — we don’t read, copy, or retain the contents of any Google Cloud or Firebase project beyond the one-time setup actions you explicitly trigger. We don’t sell this data, use it for advertising, or use it to train AI models.
- You stay in control — every project Waypoint creates or configures is owned by your Google account, not ours. You can revoke Waypoint’s access at any time from myaccount.google.com/permissions, which immediately invalidates the stored refresh token.
Waypoint’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Data retention
We keep your account and project data for as long as your account is active. If you’d like your data deleted, email us and we’ll remove it, except where we’re required to keep records (e.g., billing history) for legal or tax purposes.
Your rights
You can request access to, correction of, or deletion of your personal information at any time by emailing us at support@buildonwaypoint.com.
International data transfer
Our service providers (Firebase, Anthropic, Stripe) may process and store data on servers located in the United States or other countries outside your own.
Children’s privacy
Waypoint is not directed at children under 13, and we don’t knowingly collect information from them.
Changes to this policy
If we make material changes to this policy, we’ll update the effective date above and, where appropriate, notify you directly.
Contact
Questions about this policy? Email support@buildonwaypoint.com.