Skip to content

What we collect, what we never store, and who can see it.

This page describes how the product actually behaves. Where a rule is enforced in code, we say so.

What is collected

  • Daily mood: one of five values, an optional reason, an optional comment with personal details scrubbed before it is saved.
  • Monthly PSS-10: ten answers and a score.
  • Surveys: answers, stored against a one-way respondent hash when the survey is anonymous.
  • Calendar, with your permission: start time, end time and attendee count of events, 35 days back. Read-only access. Titles, descriptions, locations and attendee identities are never stored.
  • Voice reports: category, severity, target department. The reporter is a one-way hash.
  • Safe Space conversations: stored so you can return to them. Readable only by you.
  • Account data: name, work email, department, role, and the roster fields your admin imports.

Who can see what

  • Members see their own data and nothing team-level.
  • Department heads see aggregates for their own department.
  • Admins see aggregates for every department.
  • Nobody sees an individual’s mood, stress, chats or expert bookings. The request is refused by the server.
  • Wanderfly’s own staff can reach account and billing data and aggregate counts. They cannot reach mood, stress, chat or practice history.

Anonymity floors

Aggregates need five or more people, and calendar signals need three or more connected calendars. Departments smaller than five are pooled into the company view. This is enforced on the server, including in PDF reports, share links and exports, and share links re-check it every time they are opened.

Retention and deletion

Anyone can delete their own account. The record is soft-deleted immediately and purged after 30 days, including moods, stress records, calendar data, practice history and conversations. Calendar events older than 35 days are pruned continuously, and everything from a calendar is deleted when it is disconnected. When an admin removes someone from a team, what remains is an anonymous exit record with no link back to the person.

Encryption and access

All traffic is encrypted in transit. Voice reports and calendar tokens are encrypted at rest at the application level. Passwords are hashed with scrypt. Login is by email and password or Google. Login, signup, password reset and Voice submission are rate-limited.

Third parties

  • Slack, for check-ins and alerts. Wanderfly never reads channel messages; it sends prompts and receives answers.
  • Google and Microsoft, for read-only calendar access. Scopes: calendar.readonly (Google); Calendars.Read, User.Read, offline_access (Microsoft).
  • AI model providers (Groq, OpenRouter, Google) receive Safe Space messages to generate replies. They are not sent your identity.
  • Serene, Wanderfly’s expert network, receives a person’s name and work email only after that person consents, and reports back booking counts without identity.
  • Razorpay for billing. Resend for transactional email.

Regulatory

Wanderfly is an Indian company, Wanderfly Travel Private Limited, and handles personal data in line with the Digital Personal Data Protection Act, 2023. Our privacy policy sets out the roles we and your employer play, the grievance officer, and how to exercise your rights.

Privacy policy