Wren AI Cloud
Privacy Policy

Last modified: July 17, 2026

Privacy Policy

This Privacy Policy explains how Canner, Inc. ("Canner," "Wren AI," "we," "us," or "our") collects, uses, discloses, and protects personal data when you visit our websites, communicate with us, or use Wren AI Cloud and related services (collectively, the "Services").

"Personal data" means information that identifies, relates to, describes, or can reasonably be linked to an individual. It does not include information that has been de-identified so that it cannot reasonably be linked to an individual.

Our Role

Canner is the controller of personal data that we collect for our own purposes, such as website, account, billing, sales, marketing, support, security, and product-usage data.

When a customer submits or connects data to Wren AI Cloud, Canner generally processes that data on the customer's behalf as a processor or service provider. The customer determines what data is connected, why it is processed, and who may access it. Questions about personal data in a customer's project should normally be directed to that customer. Our processing of customer data is also governed by our agreement with the customer, including any applicable data processing agreement.

This Policy does not govern a self-hosted Wren AI deployment operated entirely by a customer or another third party, except for information sent to us for licensing, telemetry, support, security, or other Services that we provide.

Personal Data We Collect

Depending on how you interact with the Services, we may collect:

  • Account and contact information: Name, business email, telephone number, employer, job title, account identifiers, authentication information, and organization membership.
  • Commercial and transaction information: Subscription, order, billing, and payment-related information. Payment card information is generally processed for us by Stripe.
  • Communications: Messages, support requests, survey responses, feedback, event registrations, and other information you provide when communicating with us.
  • Device, log, and usage information: IP address, approximate location derived from IP address, browser and device type, operating system, access times, pages viewed, referring URLs, product features used, API activity, bandwidth usage, and system configuration information.
  • Customer data: Information that a customer or authorized user submits, queries, generates, or connects to Wren AI Cloud, which may include database schemas, SQL statements, prompts, query results, charts, data models, security-policy definitions, and data synchronized from connected SaaS tools.
  • Cookie and similar-technology data: Identifiers and activity data collected through cookies, pixels, local storage, and similar technologies used for authentication, security, analytics, marketing measurement, and referral attribution.

We collect this information:

  • directly from you;
  • from your employer, organization administrator, or another person who provides you access to the Services;
  • automatically when you use the Services;
  • from data sources and third-party services that you or your organization choose to connect;
  • from service providers, referral and promotional partners, and publicly available business sources; and
  • when a third-party AI client sends requests to Wren AI at your direction.

How We Use Personal Data

We use personal data to:

  • provide, operate, maintain, and support the Services;
  • create and administer accounts, authenticate users, and enforce access controls;
  • process transactions and manage subscriptions;
  • execute customer-directed queries, integrations, and workflows;
  • monitor performance, troubleshoot errors, and improve usability and reliability;
  • secure the Services, detect abuse or fraud, investigate incidents, and enforce our agreements;
  • respond to inquiries, provide support, and communicate service-related information;
  • send product, event, and marketing communications, subject to applicable law and your choices;
  • measure website, campaign, and referral performance;
  • comply with law and protect our rights, users, and third parties; and
  • establish, exercise, or defend legal claims.

Where the GDPR or UK GDPR applies, we rely on one or more of the following legal bases:

  • Contract: Processing needed to provide the Services or take steps you request before entering a contract.
  • Legitimate interests: Operating and improving our business and Services; securing the Services; supporting customers; measuring performance; and conducting proportionate business-to-business marketing. We balance these interests against your rights and expectations.
  • Consent: Processing for which we request your consent. You may withdraw consent at any time, without affecting processing that occurred before withdrawal.
  • Legal obligation: Processing needed to comply with applicable law, regulation, court process, or enforceable governmental request.

If we ask you to provide personal data required by law or contract, we will identify that requirement when appropriate. If you do not provide required information, we may be unable to create an account, complete a transaction, or provide the requested Service.

Customer Names and Logos

We may display a business customer's name and logo to identify it as a Wren AI customer when permitted by our agreement with that customer or with its separate permission. A customer may ask us to stop future use by contacting privacy@cannerdata.com. This does not limit rights or obligations that apply under a separate contract.

Cookies and Similar Technologies

We use:

  • Essential technologies for authentication, security, network management, and core site functionality;
  • Analytics technologies, including Google Analytics, to understand site usage and improve our Services;
  • Marketing and customer-relationship technologies, including HubSpot, to manage forms, communications, and campaign measurement; and
  • Referral technologies, including Rewardful, to attribute referrals and administer our affiliate program.

These technologies may collect online identifiers, IP address, device and browser information, referring pages, pages viewed, interactions, and approximate location. Some providers may receive this information directly from your browser.

You can delete or block cookies using your browser settings. Where a cookie-preference tool is available on our site, you can also use it to change your choices. Blocking essential cookies may prevent parts of the Services from working. You may opt out of marketing communications using the unsubscribe link in an email or by contacting us.

Customer Data and AI Technologies

Certain features use generative AI and large language models. We do not use personal data or customer data to train general-purpose AI models. We may use SQL statements, schemas, or related usage patterns for product improvement or model training only after applying measures designed to de-identify the information so that it is not reasonably linkable to an individual or customer.

We do not attempt to re-identify data that we treat as de-identified. We apply technical and organizational safeguards intended to remove or generalize personal, confidential, and customer-specific elements before such use. Customers may opt out of this use by contacting privacy@cannerdata.com.

If information remains reasonably linkable to an individual or customer, we treat it as personal data or customer data and do not treat it as de-identified information.

Model Context Protocol Connections

When you connect a third-party AI client, such as Claude or ChatGPT, to Wren AI through the Model Context Protocol ("MCP"), Wren AI returns data requested through the tools you invoke to that client. Depending on the tool, this may include your data model and table schema, row-level and column-level security-policy definitions, generated SQL, natural-language summaries, query results, chart images, and functional query or conversation identifiers.

Data is returned only through a client connection that has been authenticated and authorized and only for projects exposed for MCP that the authorizing Wren AI account is permitted to access. Wren AI applies the applicable server-side row-level and column-level controls. A connected client cannot override those controls.

Anyone using a shared Wren AI account inherits that account's permissions. Use an individual account so that access controls apply to the correct person.

When you direct Wren AI to return information to a third-party AI client, that provider receives and processes the returned information under its own terms and privacy practices. Review the provider's settings and policies before connecting it. Wren AI remains responsible for the processing it performs before and during the authorized transfer; it does not control the third-party client's subsequent processing.

How We Disclose Personal Data

We may disclose personal data to:

  • Service providers and subprocessors that provide cloud hosting, authentication, AI functionality, product observability, analytics, customer support, marketing, payment processing, and related services;
  • Your organization and its administrators to administer accounts, permissions, security, and the customer relationship;
  • Services you direct us to connect with, including third-party AI clients and SaaS integrations;
  • Business and promotional partners when you request or express interest in a jointly offered service or promotion;
  • Professional advisers and authorities when reasonably necessary to comply with law, protect rights or safety, investigate misuse, or establish or defend legal claims; and
  • Parties to a corporate transaction, such as a merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality protections.

We require service providers that process personal data for us to use it only for contracted purposes and to protect it appropriately.

Material providers used in connection with our Services may include Google Cloud, Google Analytics, OpenAI, Anthropic, PostHog, Langfuse, Auth0/Okta, Stripe, HubSpot, and Rewardful. Their involvement depends on the Service and features you use.

Data Retention

We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, including to provide the Services, maintain security and business records, comply with legal and accounting obligations, resolve disputes, and enforce agreements.

Retention depends on the type of information and context in which it was collected. For example:

  • account and subscription records are generally retained while an account is active and for a reasonable period afterward for legal, audit, fraud-prevention, and dispute-resolution purposes;
  • marketing information is retained until you opt out or we determine it is no longer useful, subject to records needed to honor your opt-out;
  • security and technical logs are retained for periods appropriate to security, troubleshooting, and legal needs;
  • support and business communications are retained as needed to manage the relationship and maintain business records; and
  • customer data is retained according to the customer agreement, organization settings, deletion requests, and applicable backup schedules.

You may disconnect a SaaS integration at any time. When an authorized customer deletes a project or organization, or requests deletion, we generally delete the relevant active customer data within 30 days unless continued retention is required by law, necessary for security or dispute resolution, or permitted by the customer agreement. Residual copies may remain in protected backups until they are overwritten under our backup schedule.

We may retain de-identified information that cannot reasonably be linked to an individual or customer.

Security

We use administrative, technical, and physical safeguards designed to protect personal data. These include encryption in transit and at rest, access controls, least-privilege practices, and security reviews. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Your Privacy Rights

Depending on where you live and subject to legal exceptions, you may have the right to:

  • access and obtain a copy of your personal data;
  • correct inaccurate personal data;
  • delete personal data;
  • restrict or object to processing;
  • receive certain personal data in a portable format;
  • withdraw consent at any time;
  • opt out of direct marketing; and
  • appeal our decision regarding a privacy request, where applicable.

The right to object to processing for direct marketing is unconditional. Other rights may depend on the legal basis and circumstances of processing.

To exercise a right, email privacy@cannerdata.com with the subject line "Privacy Rights Request" and describe your request. We may ask for information reasonably necessary to verify your identity, authority, and the personal data involved. We will respond within the period required by applicable law. Authorized agents may submit requests where permitted by law, but we may require proof of authorization and verification of the consumer's identity.

If we process personal data on behalf of a customer, we may refer your request to that customer or assist it in responding.

Where applicable, you may also have the right to lodge a complaint with your local data-protection authority. We welcome the opportunity to address your concerns directly.

California Privacy Notice

This section applies to California residents to the extent the California Consumer Privacy Act, as amended ("CCPA"), applies to Canner.

During the preceding 12 months, we may have collected the following CCPA categories: identifiers; customer-record information; commercial information; internet or other electronic-network activity; approximate geolocation; professional or employment-related information; and inferences derived from the foregoing. Customer data may contain other categories at the direction of a business customer.

We collect these categories from the sources described in Personal Data We Collect and use them for the business and commercial purposes described in How We Use Personal Data. We may disclose each applicable category to the recipients described in How We Disclose Personal Data, depending on why the information was collected and which Services are used.

We do not sell personal information for money. Our use of certain analytics, marketing-measurement, and referral technologies may be considered "sharing" under California law because those providers may receive identifiers and internet or electronic-network activity from your browser. California residents may request to opt out of sale or sharing by contacting privacy@cannerdata.com. We do not knowingly sell or share the personal information of individuals under 16.

We do not use or disclose sensitive personal information to infer characteristics about California residents. We use sensitive personal information, if any, only for purposes permitted by law, such as providing requested Services, authentication, security, fraud prevention, and legal compliance.

California residents may request to know, access, delete, or correct personal information and may opt out of its sale or sharing. They may also use an authorized agent. We will not discriminate against you for exercising CCPA rights, although a valid request may affect our ability to provide a Service that requires the information.

Children's Privacy

The Services are not directed to children, and Canner does not knowingly collect personal data from individuals under 18. If you believe a child has provided personal data to us, contact privacy@cannerdata.com, and we will take appropriate steps to investigate and delete it.

Changes to This Policy

We may update this Policy to reflect changes to our Services, practices, or legal obligations. We will post the updated Policy on this page and revise the "Last modified" date. If changes materially affect how we use personal data, we will provide additional notice or request consent when required by law.

Contact Us

For questions, concerns, or privacy requests, contact:

Canner, Inc., 16192 Coastal Highway, Lewes, Delaware 19958, United States Email: privacy@cannerdata.com

Provider Privacy Information

The following links provide additional information about the privacy practices of providers that may be involved depending on the Services and features used. These provider policies do not replace our obligations to you or the contractual data-protection terms governing providers that process data for us.