Skip to content

Privacy notice

Last updated: August 4, 2026.

What data Wurz processes, why, who it’s sent to, and what you can do about it. It’s written to be read, not to discourage.

Who answers for your data

Ander Mitre de Jacobis, tax ID (RFC) MIJA040325272, with address at Roble 6, Fracc. Prado Largo, Ciudad López Mateos, Atizapán de Zaragoza, Estado de México, C.P. 52936, México, is the controller of your personal data. For any privacy matter, write to privacidad@wurz.app.

Wurz wears two different hats, and it’s worth telling them apart from the start, because they change who decides what:

  • With your account data —your name, your email, your billing— we are the controller: we decide what it’s used for, within what this notice says.
  • With the personal data of third parties inside the documents you upload —your clients, your employees, your suppliers— we are the processor. The controller is you: we process it on your instructions, to provide the service you signed up for, and for nothing else.

What data we process

  • Your account data. Your name, your email address, and the identifier our identity provider assigns you. That's how we let you in and know which workspaces you belong to.
  • Billing data. If you buy a paid plan: tax ID (RFC), legal name, postal code, and tax regime — the fields Mexico's tax authority requires to issue you an electronic invoice (CFDI). You enter them yourself.
  • What Wurz keeps from each document. A summary of the content, the references that appear in it (people, topics, dates, concepts), the tags you add, and minimal metadata: file name, when it was uploaded, who uploaded it, and the file's identifier inside your Google Drive.
  • Third parties' personal data inside your documents. An invoice carries names and tax IDs; a contract, addresses; a payroll, salaries. Wurz doesn't choose what you upload: it processes what you give it. With respect to that data we act on your instructions, not on our own behalf.
  • Your Google account credential. When you connect Google Drive, we store the permission you granted so we can read and write there within the scope you authorized. It's yours and no one else's in the workspace: not even an administrator can use it.
  • Workspace activity log. A record of who uploaded, deleted, tagged, invited, disconnected Drive, emptied the workspace, transferred ownership, or left — with its date. It never stores document contents, third-party emails, or amounts.
  • Technical operations data. Server logs to diagnose failures and count the work done: how many documents were read, how many model calls were made, how much text was processed. They enforce your plan's caps and keep the system from failing silently.
  • Temporary working copies. While the chat reads a document in depth, the extracted text is held in memory so it doesn't have to be fetched again on every question of the same conversation. That copy expires on its own after 4 hours.

About sensitive data. Wurz doesn’t ask you for sensitive data and doesn’t need it to work. But a document can carry it without either of us looking for it: a payroll with sick leaves, an HR file, a medical-expenses insurance policy. If you upload documents like that, understand that their content travels the same path as any other, including the providers in the transfers section, and that the decision to upload them is yours.

What Wurz keeps from your documents (and what it doesn’t)

Wurz is not a place to store files. When you upload a document, the original is published to Google Drive and Wurz keeps only:

  • A summary of the content.
  • The people, topics, dates, and other references that appear in the document.
  • Minimal metadata: file name, when it was uploaded, and who uploaded it.

Wurz does not keep a copy of the original file or a search index with its full content. When the chat needs to read beyond the summary, it opens the file directly from Google Drive and keeps a working copy —the extracted text— for up to 4 hours, so it doesn’t have to reopen it on every question of the same conversation; after that time it deletes itself.

Where your files end up

Every Wurz workspace has one owner. The files anyone uploads in that workspace are stored in that owner’s Google Drive, inside a folder named Wurz created right there — even when the person uploading the file is someone else in the workspace.

That’s why, in Google Drive’s history, the file will appear as uploaded by the owner’s account. Inside Wurz, however, who really uploaded it is recorded. And if a workspace doesn’t yet have an owner with Google Drive connected, nothing can be uploaded there until it does.

A consequence that’s often overlooked and works in your favor: Wurz is not the custodian of your tax documents. The obligation to preserve them with evidentiary value remains yours and is met where it always was — in your own Drive. If you cancel Wurz tomorrow, your files are still there.

Who can see your documents

Only the people who belong to the workspace, according to their role:

  • Reader. Can view documents, download the original, and ask the chat about them. Can also narrow the scope of their own search with filters. Uploads and deletes nothing.
  • Editor. Everything a Reader can do, plus uploading documents, deleting them, organizing them with tags, and connecting their own Google Drive account to sync their folders.
  • Administrator. Everything an Editor can do, plus inviting or removing people from the workspace and managing the workspace's Google Drive connections — managing them, not using someone else's credential.
  • Owner. Everything an Administrator can do. Also the only person who can delete the whole workspace or transfer it to someone else — and their Google Drive is where the workspace's files are stored.

What we use your data for

Necessary purposes. Without these there is no service: if you don’t accept one of them, Wurz cannot work.

  • Create your account, identify you at sign-in, and know which workspaces you belong to.
  • Publish the original file you upload to the Google Drive of the workspace owner.
  • Process each document: extract its text, split it into chunks, and generate its summary and references with AI providers.
  • Answer your questions in the chat citing the exact excerpt each statement comes from, opening from your Drive only the documents within the scope you authorized.
  • Build the reports you request in Cowork mode and make them available for download.
  • Enforce roles, permissions, and the separation between workspaces, so no one sees what isn't theirs.
  • Enforce your plan's limits, charge you, and issue the corresponding invoice.
  • Assist you when you write to support and notify you about the service: invitations, failures, important changes.
  • Maintain the audit log, prevent abuse, and respond to security incidents.
  • Comply with legal obligations and respond to requests from competent authorities.

Optional purposes. These are not needed to provide the service. Declining costs you nothing: the price doesn’t change and the product isn’t cut back.

  • Tell you by email what changed in Wurz: new features, improvements, and product content.
  • Invite you to interviews, surveys, or tests of new features to improve the product.

If you don’t want the optional ones, tell us at privacidad@wurz.app or use the unsubscribe link at the bottom of every email.

Who we send your data to, and to which country

Wurz does not sell or rent your data, and shares it with no one for advertising. It does transfer it to the providers that make the service work, and several of them are outside Mexico. Naming them, country included, is the only honest way to do it: if a client of yours asks where their data ended up, you have to be able to answer with this page in hand.

The artificial intelligence provider

To turn a document into a queryable summary and to answer your questions, the content of your documents is sent to:

  • OpenAI, L.L.C. (United States). Reads each document and writes its summary and references, generates the chat's answers, and plans and writes Cowork reports. Chunks of the document's text, up to 30 thousand characters each (the full text split across several readers when you request an in-depth read), your question, the summaries of the documents within scope, and the literal citations already verified against their source excerpt. Never the complete original files.

OpenAI does not receive your credentials, and never receives the complete original files: it receives the documents' text split into chunks in order to read them, and to answer your questions it receives summaries and citations that Python already checked, letter by letter, against the excerpt they came from.

Wurz does not train artificial intelligence models: we have none of our own. When we send content to these providers, we do it for the specific task you requested and nothing else. OpenAI, for its part, does not use the content we send through its API to train its models: that is its current default policy for API traffic, without us having to request or enable it.

The other providers

The rest —who stores your files, who manages your account, who hosts the servers, who delivers the emails— is in the full list of providers and subprocessors, with what each one does, what data it receives, and which country it operates from. That list is part of this notice.

When we ask for your consent

These transfers are necessary to provide the service you signed up for: without them there is no summary, no answer, and nowhere to store the file. We do not make them for any purpose of our own beyond that. Whenever you want us to stop making them, the way is to stop uploading documents, delete the ones you already uploaded, or cancel your account; you can also write to us and we will process it as one of the requests described further below.

Use of Google data

Wurz connects to your Google Drive because that's where your files live: Wurz is not a place to store them. When you connect your account, Google shows you a single permission:

  • Create and manage only the files Wurz itself uploads, plus the ones you explicitly choose with Google's official picker. With this permission we create the folder named Wurz, store the files there, and read the documents you selected.

Wurz cannot read your Drive. That is not a promise of good behavior: Google does not grant it that access. When you open the picker, the one browsing your Drive is you, inside a Google window running with your own session; Wurz afterwards receives nothing but the files you selected. A document you didn't choose is not visible to it.

This changed in August 2026. Before, Wurz also asked for read permission over your whole Drive, so it could pull in an entire folder at once. We removed it: it granted far more than the product needs. The cost is convenience —now you enter your folder and select the files, instead of choosing the folder and done— and the gain is that the permission you grant describes exactly what happens.

What we do with what we read is what you see inside Wurz and nothing more: extract the text, generate the summary and its references, and answer your questions with citations. That content passes through the artificial intelligence providers described above for those specific tasks. We don't use it for advertising, we don't sell it, and we don't train models with it — neither our own nor anyone else's.

Limited Use disclosure

The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements.

Your Google account is yours

Each person connects their own Google account when needed. Wurz never hands another member of the workspace access to your personal Google Drive — not even the workspace administrator. Managing a connection —marking it as primary, disconnecting it, syncing it— is different from using your credential: the former can be done by an administrator; the latter, only by you. The reason is simple: that permission is not scoped to the Wurz workspace, so lending it would grant access to your Google account outside the product.

How to disconnect Google Drive, and what happens after

From Settings › Database you can disconnect your Google account whenever you want, without asking anyone's permission. You can also revoke access from your own Google account's security settings. Upon disconnecting:

  • Wurz can no longer read from or write to that Google account.
  • The files already uploaded are not deleted from your Google Drive: they stay exactly where they were.
  • The documents Wurz already processed —their summary and references— remain available inside Wurz. What stops working is opening the full document from Drive and keeping that account in sync.
  • If the person disconnecting is the workspace owner, no one will be able to upload new files there until they reconnect or the workspace has another owner with Drive connected.

How we protect what we process

These are mechanisms that exist in the code, not promises of outcomes. We list them this way on purpose:

  • Traffic between your browser, Wurz, and its providers is encrypted in transit.
  • Workspaces are isolated from each other: the workspace each request belongs to comes from your already-validated session, never from what the browser claims to be.
  • Permissions come from a single, closed roles table: a role that isn’t in it inherits nothing. The same table is consulted by the interface, the API, and the chat’s tools, so there is no back door with different rules.
  • Every action that modifies something —uploading, deleting, tagging, inviting, disconnecting Drive, transferring ownership— leaves a record in the same operation that executes it. If the action is undone, so is the record.
  • When you narrow the scope with filters, what falls outside is not read: that is enforced in the code, not merely requested in the assistant’s instructions.
  • Minimal retention by design: what doesn’t need to be kept, isn’t.

What we do not have: security certifications such as SOC 2 or ISO 27001. We don’t advertise them because we don’t have them, and a seal without an audit behind it would be exactly the kind of claim you wouldn’t want to hire us over. If your firm needs its own vendor questionnaire answered, write to us at hola@wurz.app and we’ll answer what we can actually stand behind.

How long we keep things

What is defined today:

  • The file’s bytes while it waits its turn in the processing queue: discarded as soon as processing ends.
  • The working copy of the extracted text: 4 hours.
  • The reports generated by Cowork mode: 4 hours, to allow retries.
  • The Excel files you export: deleted after the first download.
  • A document’s summary, references, and metadata: for as long as the document exists in your workspace. When you delete it, they go with it.

The periods not yet defined —what happens to the audit log and account data after you leave— are below, among the pending items, instead of invented here.

Minors

Wurz is a work tool for accounting firms and teams. It is not directed at minors and we do not knowingly collect their data. If we detect an account belonging to a minor, we close it.

How to limit the use of your data

Before any formal request: almost everything can be done from the application itself, in one click and without writing to anyone.

  • Don't connect Google Drive: without a connection, Wurz neither reads nor writes anything in your Drive.
  • Choose what you upload. A document you don't upload isn't processed, isn't summarized, and doesn't travel to any provider.
  • Delete a document from Wurz: its summary and its references go with it.
  • Narrow the scope with filters: whatever falls outside the filter isn't read in that chat turn — and that's enforced in code, not just requested in the assistant's instructions.
  • Leave the chat's retrieval in confirmation mode, so no document is opened in depth without your approval.
  • Adjust the roles of the people in your workspace, or remove them.
  • Disconnect your Google account from Settings › Database.
  • Unsubscribe from product emails via the link at the bottom of each one.

Your ARCO rights and how to exercise them

Over your personal data you hold four rights, and exercising them is free:

  • Access. Know what data of yours we hold, where it came from, and what we use it for.
  • Rectification. Have it corrected when it's wrong or incomplete.
  • Cancellation. Ask us to delete it, except what the law requires us to keep — for example, the tax receipts for what you paid us.
  • Opposition. Ask us to stop using it for a specific purpose, when you have a legitimate reason to.

To exercise them, write to privacidad@wurz.app with the following:

  1. Your name and an email or address where you want to receive the answer.
  2. A copy of your official ID; if you act on someone else's behalf, the document that proves it.
  3. Which right you want to exercise and over which data, clearly enough for us to locate it.
  4. Anything that helps us find it: your Wurz account email, the workspace name, the document name.
  5. If it's a rectification: what the correct data is and which document supports it.

We answer whether your request proceeds or not within 20 business days of receiving it, and if it proceeds we carry it out within 15 business days after that answer. Those periods may be extended once, for an equal period, when the circumstances justify it — and in that case we tell you so and tell you why. We don't charge for handling the request; if you ask for copies in a format that involves reproduction or shipping costs, we tell you what they cost before doing anything.

A clarification that matters if you are a firm. The personal data inside the documents you upload is neither yours nor ours: it belongs to your clients, your employees, or your suppliers, and toward them the data controller is you. If one of those people exercises their rights, handling the request falls to you. If it reaches us, we route it to you and help with what is in our hands — deleting a document, for example — but we don't decide on your behalf about data we don't administer.

How to revoke your consent

You can revoke the consent you gave us at any time, through the same email above and at no cost. Two consequences worth knowing beforehand: the revocation doesn't reach what was already done while the consent was in force, and if you revoke what sustains the necessary purposes, we won't be able to keep providing the service — we will tell you so in those words instead of leaving the account half-working.

For the optional purposes —product emails, interview invitations— revocation is independent: you unsubscribe from them and everything else keeps working the same.

Cookies and storage in your browser

Wurz stores a few things in your browser so your session isn't lost and your preferences are remembered. We use no advertising cookies, no third-party analytics, and no cross-site tracking. The key-by-key detail, and how to delete them, is on the cookies page.

How we notify you if this notice changes

This notice can change because the law, the product, or one of the providers on the list changes. When that happens we publish the new version at this same address with its update date at the top, which is how you know whether what you are reading is current. If the change is substantial —a new purpose, a new provider receiving content from your documents— we notify you by email to your account address before it takes effect.

If you believe we are not complying

Tell us first at privacidad@wurz.app: almost everything is resolved faster that way. If we don't leave you satisfied, you can file a complaint with Mexico's Secretaría Anticorrupción y Buen Gobierno, the authority that since 2025 oversees personal data protection in the private sector, after the INAI was dissolved.

Pending definition

Everything above describes what Wurz does today. What follows hasn't been decided yet, and that's why it doesn't appear above: we'd rather show you the gap than plug it with something we couldn't honor.

  • Retention periods: how long we keep the summary, the references, the audit log, and your account data after you delete a document, a workspace, or your whole account.
  • The contractual confirmation, provider by provider, that none of them uses your content to train their models. We don’t do it and don’t authorize it; we still need it in writing from each one.
  • The Data Processing Agreement a firm signs with us, with the express authorization that we subcontract the AI providers on the list.
  • Verifying this notice’s periods and articles against the published text of the 2025 law, whose regulations haven’t come out yet.
  • The status of Google’s verification for the Drive read permission, including the annual security assessment Google requires of applications with that permission.
  • How and within what period we notify you if there is a security incident affecting your data.
  • In which specific region each infrastructure provider hosts the data it receives.
  • What happens to a workspace’s data if Wurz ceases to operate.