Privacy
Wispfield has no accounts, no telemetry, and no interest in your code. This page says exactly what is collected and by whom.
1. Who we are
Wispfield is a product of Loomfield Labs, LLC, a Florida limited liability company, which is the controller of the personal data described here.
2. What we collect when you buy
Buying a license collects one field about you: your email address. We store it with your license number, the class of license, the amount paid and the date, because that record is what lets us re-send a key you have lost and process a refund you ask for.
We never see your card. Payment is handled by Stripe, who process it as an independent controller under their own privacy policy. What reaches us is confirmation that a payment succeeded, and the email address you gave them.
There is no account to create and no password to store. What we hold is that record and your license key, which we keep for as long as your license exists, because a license with no record behind it cannot be supported or reissued. The key that signs licenses is not kept with them, so nothing in that record can be used to make a license.
3. What the app collects
Nothing goes on its own. There is no analytics SDK, no crash reporter and no usage telemetry in Wispfield. Your code, your prompts, your files and your voice do not reach us in the background, because there is no code in the product that would send them.
Three exceptions. Two are licensing, and the third is you pressing send. A license covers three computers, and the only way to hold it to three is for the app to say which computer it is. The trial asks us one question as well. The third is a report you write yourself, which goes nowhere until you send it. All three are described below, and together they are everything Wispfield sends us.
Activation, the one thing the app sends us
When you activate, and when the app renews that activation, it sends three things: your license key, an identifier for that installation, and the version of the app. That is the whole request.
That identifier is a random number generated on your computer, written once and then reused. It is not a hardware fingerprint, not a serial number, and not derived from anything about your machine or about you. Swapping a graphics card or a network adapter does not change it, and it means nothing anywhere outside Wispfield.
We store it against your license with the time we last heard from it, and that is what lets the app show you which computers are using your license when you want to release one. We do not learn what you are working on, when you work, or how much you use the app. Renewal happens on its own schedule and is not triggered by anything you do.
The trial asks one question, before you have bought anything
During the seven day trial the app asks us a single thing: when did you first see this installation? It sends the same random identifier and nothing else, and we answer with a date. If we have not seen it before we record the date and never change it afterwards.
That row holds two things: the random identifier, and a date. No email, no license key, no name, nothing that connects it to a person, because at that point you have not told us who you are and we have not asked. It exists so that the trial is seven days rather than seven days that can be reset by editing a file on your own computer.
It carries no consequence either way. If the request fails, or you are offline, or you block it, your trial is exactly the length it would have been.
A report goes when you send it, and not before
Wispfield can send us a report: a problem, a suggestion, a feature request or a question. You write it, in a sheet you opened, and it goes when you press send. Nothing about it happens on a schedule, and nothing is gathered in the background in case you might.
You see what is attached before it goes. The sheet lists every item and what it weighs, and it shows you the diagnostics themselves rather than a description of them: the bytes on the screen are the bytes that upload. Untick them and the report is your words and nothing else.
With everything left ticked, a report carries what you typed, the same random installation identifier described above, the app version, and whether you are on trial or licensed. To that it adds facts about your machine, the state of the field you were looking at, and the tail of the app’s own logs. The contents of a terminal are the one thing that is off by default, ticked for a single report and never remembered, because a terminal holds your source code.
Some things never go, whatever is ticked. Your provider credentials, your license key, the contents of your project files and the variables your machine runs with are excluded by the app itself. What is left is put through a filter that replaces your home directory, your workspace path, anything shaped like a license key and anything shaped like an API token. That happens before the preview is drawn, so what you are shown cannot disagree with what is sent.
Attachments are the files you attached and nothing else: a screenshot you pasted, a file you dropped. The email box is optional, it is there so we can reply, and leaving it empty does not stop the report being read.
Your voice is transcribed on your own machine
Speech recognition runs as a local process on your computer and is reached over loopback, the network interface that cannot leave the machine. Audio is transcribed where it is spoken. It is not uploaded, not to us and not to anyone else.
Your provider credentials stay on your machine
Wispfield reads the credentials your model providers have already stored on your computer so it can run their tools on your behalf. Those credentials are sent to the provider they belong to and nowhere else, in the request header only. They are never written to our servers, never included in an error message, and never logged.
What the app does talk to
- Your model providers. The agents you run are those providers’ own tools, and what you ask them goes to them under their terms and their privacy policy, exactly as it would if you ran the same tool in a terminal.
- Your providers’ usage endpoints, to show you what you have spent and how much of your plan is left. This uses your own credential and returns numbers about your account.
- Web pages you ask it to open. A browser loom is a real browser view, and it shares the one browser profile the app keeps on your own computer. So a site you sign into stays signed in between sessions, exactly as it would in any browser, and those cookies never leave your machine. What passes between you and a site you open is between you and that site.
Wispfield also checks for a new version. That request asks for one file describing the current release, and carries nothing about you or your installation with it.
There is no list of revoked licenses to download, and your license number is never sent anywhere to be checked against one. A license that has been revoked is refused at the next renewal, by the same request described above.
4. This website
wispfield.dev uses Vercel Analytics and Vercel Speed Insights. Both are first party: they report to this domain, set no cookies, and build no profile of you across sites. We use them to see which pages are read and how quickly they load.
The home page embeds the Wispfield film from YouTube. Playing it is a request to Google, who receive it on the same terms as if you had watched the film on youtube.com. Nothing else on this site reaches a third party.
5. Who else processes your data
Four services, each doing one thing:
- Stripe, for payment. They hold the card details we never see.
- Supabase, which hosts the database holding the license record described in §2, and any report you have sent, with its attachments.
- Resend, to email you your license key.
- Vercel, which hosts this site and serves the installer download.
We do not sell personal data, and we do not share it for advertising. There is no advertising.
6. Your rights
You can ask us what we hold about you, ask us to correct it, or ask us to delete it. If you are in the EEA or the UK, the GDPR gives you those rights explicitly, along with the right to complain to your supervisory authority; if you are in California, the CCPA gives you a comparable set. We honor all of them wherever you live, because with one email address per buyer there is no reason not to.
What deletion means here. We erase your email address, which is the only personal information in the record. What stays is the sale itself with nothing of yours attached: a license number, a date, an amount. Two reasons. A sale has to be accountable long after the person is forgotten, and a purchase that forgets it ever happened can be made to happen again from an old link, issuing a new license to somebody who asked us to stop holding their details.
After that we can no longer reissue your key or confirm the purchase was yours, because the thing that connected them is gone. That is the point, and it is not reversible. Ask us and we will tell you exactly what it affects before doing it.
A report is separate from a sale. Deleting one does not touch the other, so you can ask us to erase a report you sent and keep the license you bought, or the reverse. We keep reports for as long as they are useful to us and delete any of yours on request.
Write to support@wispfield.dev. We will answer within thirty days, and usually much sooner.
7. Children
Wispfield is a developer tool and is not directed at children. We do not knowingly collect personal data from anyone under 16.
8. Changes
If this policy changes in a way that affects what we collect, we will change the date at the top of this page. The application collecting nothing is not a default we intend to revisit.