Back to home

Privacy

Weeka Privacy Policy.

This policy explains what information Weeka handles, why it uses it, and which choices are available to the people and organizations using the platform.

Regulatory status: Weeka does not currently claim HIPAA compliance and does not offer a verified Business Associate Agreement (BAA). Until those controls and agreements are confirmed in writing, do not use Weeka to store or transmit protected health information (PHI).

01

Account information

When an account is created or managed, we may handle a name, email address, Google identifier when that sign-in option is used, organization, job title, phone number, time zone, account type, and verification status. Passwords are stored as hashes, not readable text.

We also keep information needed for invitations, workspace memberships, roles, sessions, and operational preferences.

02

Content stored in Weeka

The service stores information that you or authorized workspace members choose to enter: agencies, clients, case codes, availability, scheduled services, notes, outcomes, next steps, rates, rules, templates, and data used to generate PDF reports.

The account or workspace administrator is responsible for having authority to enter, share, and export that information. Do not include data that is unnecessary for the account’s purpose.

03

Payments, communications, and technical data

Stripe processes checkout, payment methods, invoices, and subscriptions. Weeka keeps billing identifiers and status, but does not store full card numbers. Google may process sign-in when you choose that option. Verification and invitation messages may be delivered through Resend or a configured SMTP provider.

Delivery, hosting, and security infrastructure may log an IP address, browser, date, requested route, and technical events needed to operate the service, diagnose errors, and prevent abuse.

04

How information is used and shared

We use information to provide the platform, authenticate users, maintain workspace permissions, generate reports, process payments, send operational messages, respond to requests, and protect the service. We do not use account data for behavioral advertising or sell it.

Data is shared only with authorized workspace members, providers needed to operate Weeka, or when legally required. Current providers may include Railway for infrastructure, Cloudflare for delivery and security, Stripe for billing, Google for optional sign-in, and Resend or SMTP for email.

05

Public links and local storage

If you create a public note link, anyone holding that link can view its contents while it remains active. The link uses a token, can expire, and can be disabled; do not use it for information that should not be accessible to its recipient.

The browser stores preferences such as language and workspace selection. Sessions use an in-memory access token and an HttpOnly refresh cookie; Weeka does not use advertising cookies.

06

Retention, access, and requests

We retain data while an account or workspace is active and for a reasonable period needed for security, dispute resolution, billing, and legal obligations. Some payment records remain with Stripe, and backup copies may be removed according to provider cycles.

You can correct several details in your profile. To request access, export, correction, or deletion, use the official channels listed on the Contact page. We will verify identity and workspace authority before acting and respond under applicable law.

Official Weeka information

This page will be updated when the product’s practices, providers, or controls change.

Contact