Privacy policy · Last updated September 7, 2026
What we do with your data. And who else sees it.
Wishfleet coordinates listing preparation on your behalf. It holds your client work, and it sends messages to your crew on your instruction. This policy says what we collect, what we do with it, who else can see it, and what you can ask us to do about it.
What we collect, and why
You can create a Wishfleet account with an email address and a password, or by signing in with Google. Either way we store your name and your email address, and that is what the account is.
If you sign in with Google, Google tells us your name, your email address, and the account identifier it uses for you. We also store the access token and refresh token Google issues, because that is what keeps the sign-in working. Nothing in Wishfleet spends those tokens. No feature reads your calendar, your contacts or your mail; they are held because the sign-in library stores them. If we build something that uses them, Google will ask you for that permission separately, and this page will say so before it happens.
If you use a password instead, we store a one-way hash of it. We never hold the password itself, and nobody here can read it or tell you what it was.
The rest is business data: what you put into Wishfleet, and what Wishfleet went and got because you asked it to.
Properties. The address, the listing details, the scope of work, and the notes you write about the job, including access details such as a lockbox code or an alarm instruction. If you record the seller, we hold their name, email address and phone number.
Your crew. For each vendor and worker on your roster: a name, the company they work for, the trade they do, an email address and a phone number. These are people you added, and the roster stays yours.
The coordination itself. Every message sent and received on a job, the quotes that came back, the bookings, the schedule, and a record of the decisions the coordinator made and why. That record is what lets you see how a job got where it is.
Public property data. When you add a property, we look the address up against public property records and keep what comes back, such as the year built and the square footage, so you are not retyping it. That lookup sends the address and nothing else: no name, no account and no session goes with it.
What we do with it
Wishfleet's job is to talk to your vendors and workers for you, so real email leaves this system and reaches real people outside your business. Those messages carry what the job requires: the scope of work, the property address, the schedule, and the instructions a vendor needs to get in and do the work.
You decide when. A new account starts on “Review all messages”, which holds every outbound message until you approve it, so nothing goes out until you say so. You can move the account to “Review only key messages”, which lets the coordinator answer routine replies on its own and still brings you anything touching price, timing, the plan, or access.
Access details are held tighter than the rest. Lockbox codes and entry instructions are withheld from a vendor who is only quoting, and go out only to the vendor you actually book. Every outbound message is checked against that rule before it is sent, not after.
Who else can see it
Wishfleet runs on other companies' services, and each of them touches some part of your data to do its job. Described here are the ones you would not otherwise assume.
Session recording. Sessions are recorded for usability research through FullStory, a third-party service provider. It shows us where Wishfleet is confusing and where people give up.
Anthropic. Runs the coordinator. To draft a message or judge what a reply meant, we send the relevant part of the job to Anthropic's API: the scope of work, the conversation so far, the schedule. Anthropic's commercial API terms say that content is not used to train their models.
Google Analytics. Counts page views, and sets its own cookies in your browser to do it. Inside the product it is told a placeholder form of the page address instead of the real one, and the title it reports is derived from that same placeholder, so neither can carry a property's identifier or your account's reference.
The machinery. Everything else is what a web application runs on: the servers that host it, the network that delivers its pages, the database that stores everything above, the queue that moves work between our own processes, and the service that sends our email and receives the replies. Those companies hold your data because they run the equipment it sits on. We describe them as a class rather than name them one by one, because a list of vendors goes out of date and this description does not.
We do not sell your data, and we do not share it with anyone for their own advertising or marketing.
Cookies
One cookie keeps you signed in for a year. One remembers this browser for up to ten years, so a listing you start on the welcome pages before you have an account is still there when you come back. Others carry a confirmation line, or a form you had part-filled when a submission was refused, across a single page change and expire within a minute. None of ours can be read by scripts in your browser. Google Analytics and FullStory set their own.
Getting a copy of your data, or having it deleted
There is no button for this yet, and we would rather tell you that than pretend otherwise. Email [email protected] from the address on your account and say what you want. A person reads it and runs the request by hand.
To get a copy, we assemble what we hold on your account, meaning your properties, your crew and your coordination history, and send it to you.
To delete it, we have tooling that removes an account's properties, workflows, crew records and coordination history, and we confirm by email when it has run. Two things survive it, and you should know both: an email we already delivered is in someone else's inbox and we cannot take it back, and the companies described above keep their own recordings, delivery logs and backups on their own schedules.
We keep your data for as long as your account is open. Wishfleet is early and has no automatic retention schedule yet; when it gets one, this page will say what it is.
Changes to this policy, and how to reach us
Wishfleet is in active development, and this policy describes a system that is still moving. When what we collect or who handles it changes, we change this page and the date at the top of it.
If there is anything here you want explained, or anything that does not match what you are seeing, write to [email protected] and a person will answer. The terms of service cover the rest of the arrangement.
Adapted from the 37signals open-source policies, used under a Creative Commons Attribution 4.0 licence.