Privacy Policy
Effective: August 1, 2026
This policy explains how Whack, Inc. (doing business as Renza) handles personal data when you use renza.io, the Renza API, the CLI, and related services. We collect the information needed to operate and secure the service. We do not sell personal data or use advertising trackers.
What we collect
- Account data — your name and email address, provided through our authentication service.
- Content — the documents you import, the settings you apply, and comments or replies you submit.
- Review information — on a review link, an unsigned-in viewer supplies a display name before opening the document. Renza records that name with visit and comment activity. The name is self-reported and is not identity verification.
- Usage data — pages visited, features used, product events, and API client/version information. We use PostHog's EU service to understand reliability and improve the product.
- Technical logs — IP address, user agent, timestamps, and request details used for security, abuse prevention, and debugging.
- Billing data — subscription and transaction details from Stripe. Renza does not receive or store complete card numbers.
Cookies and local storage
We use cookies for sign-in sessions, share-link access, and the active workspace. Local storage is used for preferences such as an unsigned-in reviewer's display name. We do not use advertising cookies or cross-site ad tracking.
Sharing and viewer information
Documents remain private unless you grant access or create a share link. Anyone who has an active share link may be able to open it, subject to any passcode or expiry you set.
Renza offers two share modes:
- Public shares do not ask viewers for a name. Their views are reported to the workspace in aggregate.
- Review links ask unsigned-in viewers for a display name. The workspace can see that supplied name, visit count, last visit, comments, and live presence where those features are enabled.
Renza does not use browser fingerprinting to identify viewers. Standard technical logs may still contain an IP address and user agent for security and abuse prevention.
Documents published without an account through a try link expire after seven days unless they
are claimed into an account.
Subprocessors
| Provider | Purpose |
|---|---|
| Vercel | Application hosting, serverless functions, object storage, and content delivery |
| Neon | Postgres database |
| Cloudflare | Realtime collaboration infrastructure |
| WorkOS | Authentication and sign-in |
| Stripe | Payments and subscription billing |
| Resend | Transactional and inbound email |
| PostHog (EU) | Product analytics and error reporting |
Retention and deletion
We retain account content while the account is active. Deleting a document removes it from normal serving immediately; associated stored data is deleted within a commercially reasonable period. Operational backups may retain deleted data temporarily until they expire.
To request account deletion, email hello@renza.io. We aim to complete verified requests within 30 days, except where we must retain information to comply with law, resolve disputes, or protect the service.
Your rights
Depending on where you live, you may have rights to access, correct, export, or delete personal data, or to object to or restrict certain processing. Email hello@renza.io to make a request.
Children
Renza is not directed to children under 16, and we do not knowingly collect their personal data.
Changes
We may update this policy as the service changes. We will provide notice before a material change takes effect and update the effective date above.
Contact
Whack, Inc. (d/b/a Renza)
9450 Southwest Gemini Drive, Beaverton, OR 97008, USA
hello@renza.io