Privacy Policy
Last updated: 2026-05-21
Status: Beta. SilkHat is pre-launch software offered to a limited group of testers. This policy describes both what SilkHat is built to do (our target privacy architecture) and how it actually behaves during beta today — because, honestly, those are not yet the same thing. Please read the beta sections carefully. By using SilkHat during beta you accept the beta risks described below.
A note about beta — please read this first
We are building SilkHat to be the most private AI personal assistant we know how to make. The plan — the architecture SilkHat is being built around — is straightforward to state:
- Process your data on your own machine. SilkHat is designed to run locally, on the device you control, rather than on our servers.
- Scrub personal information before anything leaves your device. SilkHat is designed to remove or mask personal information before any content is sent to an external AI provider.
- Gate every external AI provider through compliance profiles. SilkHat is designed to decide which providers may receive which classes of your data, based on a compliance profile you select.
- Encrypt your data at rest. SilkHat is designed to keep the data it stores encrypted on your device.
That is the target. Here is the honest current state of play during beta:
- These protections are still being built and rolled out. They are not all in effect yet.
- During beta, your content — including content SilkHat accesses from your connected accounts (such as Gmail, Google Calendar, Outlook mail, and Microsoft 365 calendar) — may be sent directly to one or more external AI model providers (currently Anthropic; potentially OpenAI or Google as fallback providers) without first being scrubbed of personal information.
- During beta, conversation history and content SilkHat stores on your device may be kept in unencrypted form.
- During beta, WBC Works personnel may review data — including content accessed from your connected accounts — to diagnose problems and improve SilkHat before launch, subject to the specific consent and limits described in the Connected Accounts section below.
And here is the implication of failure, stated plainly:
- SilkHat is beta software. Some components — including the privacy features described above — may not work as designed. A privacy feature that is still being built can fail, be incomplete, or be absent. WBC Works takes all commercially reasonable measures to protect your privacy, but you acknowledge and assume the ultimate risk of using beta software. If you are not comfortable assuming that risk, please do not connect sensitive accounts to SilkHat during beta.
We are telling you all of this on purpose. We would rather you trust us because we were honest about the gap between the plan and today than discover the gap on your own. The rest of this policy gives the detail. As these protections come into effect, we will update this policy — and before SilkHat is offered for general (non-beta) public use, the beta conditions described here will be revisited and this policy revised accordingly.
1. Who we are
SilkHat is operated by WBC Works LLC ("WBC Works," "we," "us," or "our"), a Pennsylvania limited liability company based in United States. SilkHat is our AI personal assistant product; Friday is the in-product assistant personality you interact with.
For any privacy question, or to exercise the rights described in this policy, contact us at [email protected].
This policy covers both the SilkHat website (silkhat.ai) and the SilkHat beta application, including data accessed through accounts you connect to SilkHat. Where the website and the application are handled differently, we say so.
2. Information we collect
Information you give us. If you join our early-access list, send us a message, fill out a form, or sign up to test SilkHat, we collect the information you provide — for example your name, email address, and anything you choose to include in a message.
Information SilkHat processes when you use the beta application. When you use SilkHat, we (and the AI providers we rely on — see Section 5) process:
- The messages you send to Friday and Friday's responses (your conversation content).
- Content SilkHat retrieves from accounts you connect — see Section 6, Connected Accounts.
- Operational and diagnostic information about how the software is running (for example error logs, performance data, and records of which features were used), which during beta may include the content of your conversations and connected-account data when that content is needed to diagnose a problem (see Section 6).
Information collected automatically on the website. When you visit silkhat.ai we automatically collect technical information through server logs and cookies, such as your IP address, browser type, device information, and the date and time of your visit.
3. Cookies and similar technologies
On the SilkHat website we use:
- Essential cookies — required for the site to function.
- Analytics cookies — to understand how the site is used so we can improve it.
- Third-party / affiliate cookies — limited cookies set by services we work with.
You can manage or disable cookies through your browser settings; disabling some cookies may affect site functionality. The SilkHat application does not rely on advertising cookies.
4. How we use information
We use the information described above to:
- Operate, provide, maintain, and improve SilkHat and the website.
- Carry out the tasks you ask Friday to perform (including reading, composing, and sending messages, and reading and managing calendar events, on your instruction).
- Respond to your messages and provide support.
- Measure and improve performance and reliability.
- Diagnose problems and improve SilkHat during beta, including, where described and consented to in Section 6, review by WBC Works personnel of content needed to investigate a specific issue.
- Detect, prevent, and investigate fraud, abuse, and security incidents.
- Comply with legal obligations and enforce our terms.
We do not use your content to serve you advertising, and we do not sell your personal information.
5. How we share information — AI model providers and other recipients
To make Friday work, SilkHat sends content to external AI model providers and, where you ask Friday to take an action, to the relevant service (such as Google or Microsoft). This section explains who receives your data and why.
5.1 External AI model providers (the most important disclosure)
Friday is powered by large language models operated by third-party AI providers. To answer your requests and take the actions you ask for, SilkHat sends the relevant content — which may include the contents of your conversations and of your connected accounts — to one or more of these providers.
- During beta, your content may be sent to these providers without first being scrubbed of personal information, because the personal-information scrubbing described in the beta note above is still being built and is not yet in effect by default.
- Our current primary AI provider is Anthropic. We may also use OpenAI or Google as fallback providers. The set of providers we use may change as we develop SilkHat; we will keep the Subprocessors list in Section 14 current.
About these providers' commitments. The AI providers we use represent that they do not use data submitted through their APIs to train their models. We rely on those representations. However, WBC Works does not control these providers and cannot guarantee their compliance — their handling of data submitted to them is governed by their own terms and is ultimately outside our control. We choose providers whose stated commitments align with this policy, and we will act on credible information that a provider is not honoring them, but you should understand that this is a matter of the provider's compliance, not something WBC Works can warrant.
5.2 Other recipients
- Connected-account providers (Google, Microsoft). When you ask Friday to take an action in a connected account (for example, send an email or create a calendar event), SilkHat sends the necessary content to that provider to perform the action.
- Messaging interface (Telegram). If you interact with SilkHat through Telegram, your messages pass through Telegram's systems and are subject to Telegram's own privacy policy.
- Service providers for the website and our operations. We use providers for website hosting, transactional email, and website analytics.
- Legal and safety. We may disclose information where required by law, to comply with legal process, or to protect the rights, safety, and security of users, the public, or WBC Works.
- Business transfers. If WBC Works is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this policy.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
6. Connected Accounts — Google & Microsoft User Data
This section governs data SilkHat accesses from accounts you connect to it, and applies in addition to the rest of this policy. If anything in this section conflicts with another section, this section controls for connected-account data.
When you connect a Google account (Gmail, Google Calendar), a Microsoft account (Outlook mail, Microsoft 365 calendar), or a future supported integration, you authorize SilkHat to access specific data from that account so Friday can carry out the tasks you ask it to perform. SilkHat requests the narrowest permissions that support these features.
6.1 What we access, and why
- Gmail / Outlook mail — to search and read the messages you ask the assistant about, and to compose, reply to, and send messages on your explicit instruction. SilkHat does not label, organize, archive, or delete your mailbox.
- Google / Microsoft Calendar — to list your events and to create or update events on your explicit instruction.
- Future integrations — when SilkHat adds support for additional services, we will access data from those services for the same kind of purpose: to perform the tasks you ask Friday to perform, under that provider's user-data rules, and we will update this section accordingly.
We use connected-account data only to provide and improve the user-facing features of SilkHat that you are using it for. We do not sell connected-account data, we do not use it for advertising or to build advertising profiles, and we do not transfer it to others except to provide or improve these features for you, or as disclosed in this policy (see Where your connected-account data goes during beta below) or with your consent.
6.2 Where your connected-account data goes during beta
To answer your requests, SilkHat sends the relevant connected-account content to our external AI model provider(s) (Section 5.1) to generate the response or perform the action you asked for, and to Google or Microsoft as needed to carry out the action itself.
During beta, the privacy protections described in the beta note above (local-only processing, personal-information scrubbing, compliance-profile gating, and encryption at rest) are still being built and may not be in effect. As a result, during beta your connected-account content may be sent to an external AI provider without first being scrubbed of personal information, and content SilkHat stores on your device may be stored without encryption. This is a beta condition we expect to close before launch; we are disclosing it now so your consent is informed.
6.3 Human review of connected-account data during beta — your explicit consent
We want to be precise here, because it matters and because Google's rules (Section 6.5) require it.
Routine, automatic operation. In normal use, no WBC Works person reads the contents of your mailbox or calendar. Friday processes your connected-account data automatically to do what you asked.
Review of system behavior is always allowed. WBC Works personnel may review system logs, behavior, performance data, and audit records to operate, debug, and improve SilkHat. This does not include reading the bodies of your messages or the contents of your calendar events.
Review of your connected-account content — only with your explicit, specific consent. During beta, diagnosing certain problems may require a WBC Works person to look at the actual content of a specific message or calendar item involved in a failure, in order to provide or improve the feature you were using. We will do this only when one of the following applies:
- You have given your explicit, specific, informed consent to our reviewing that specific item (or a specific, identified set of items) for the purpose of providing or improving the SilkHat feature you are using. Your consent is affirmative (you opt in; we do not infer it from your use of the beta), specific (it identifies what we may look at), and revocable (you can withdraw it at any time for future review). We will not review the content of your connected-account data for product improvement or debugging without this consent; or
- it is necessary for security purposes — for example, investigating a bug, abuse, or a security incident; or
- it is necessary to comply with applicable law; or
- the data has been aggregated or de-identified so that it no longer identifies you and is used for internal operations in accordance with applicable privacy law.
These are the only circumstances under which a human at WBC Works will read the content of your connected-account data. Outside them, your message bodies and calendar contents are not read by our personnel.
6.4 Retention and disconnection
You can disconnect a connected account at any time. Disconnecting deletes the stored access credential for that account and ends SilkHat's access to it. Content SilkHat has already retrieved is held only as long as needed to complete your requests and to provide SilkHat's ongoing features to you, and is then deleted or de-identified. To request deletion of connected-account content SilkHat has retained, contact [email protected].
Beta note: SilkHat's automatic retention-and-deletion controls are still being built, so some deletion during beta may be handled manually on request. We will honor disconnection and deletion requests; the mechanism is maturing.
6.5 Google API Services — Limited Use
SilkHat's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, with respect to data obtained through Google API scopes:
- We use Google user data only to provide and improve the user-facing features of SilkHat for which you granted access.
- We do not transfer Google user data to others, except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to you.
- We do not use Google user data for serving advertisements.
- We do not sell Google user data.
- We do not allow humans to read Google user data, except in the circumstances set out in Section 6.3 above (your explicit prior consent to view specific items; security; to comply with law; or aggregated/de-identified internal operations), which mirror the Google Limited Use human-access exceptions.
Microsoft account data (Outlook mail and Microsoft 365 calendar) is handled on the same basis: used only to provide and improve the features you connect it for, never sold, never used for advertising, and read by a human only under the same conditions in Section 6.3.
7. Your rights and choices
Depending on where you live, you may have rights over your personal information.
- EEA / UK (GDPR / UK GDPR). You may have the right to access, correct, delete, restrict, or object to processing of your personal data, to data portability, and to withdraw consent where processing is based on consent. Our legal bases for processing include performing the service you request, our legitimate interests in operating and improving SilkHat, your consent (including the beta consent in Section 6.3), and compliance with law.
- California (CCPA / CPRA). You may have the right to know what personal information we collect and how we use and share it, to request deletion or correction, and to opt out of "sale" or "sharing." We do not sell your personal information and do not share it for cross-context behavioral advertising. We will not discriminate against you for exercising your rights.
To exercise any of these rights, contact [email protected]. We will verify your request as required by law before acting on it.
8. Data retention
We keep personal information only as long as necessary for the purposes described in this policy or as required by law, after which we delete or de-identify it. Connected-account retention and deletion are described in Section 6.4. Website and contact information is retained as long as needed to operate the site and respond to you.
Beta note: As noted in Section 6.4, automatic retention-and-deletion tooling is still being built; during beta some deletion is handled on request.
9. Security
We take all commercially reasonable measures to protect your information, including encrypted storage of account credentials on your device. However, SilkHat is beta software, and some protective measures — including encryption of stored conversation and connected-account content, local-only processing, and personal-information scrubbing — are still being built and may not yet be in effect (see the beta note above and Section 6.2). No method of transmission or storage is completely secure, and during beta you should assume that the full security architecture SilkHat is being built around is not yet in place. As described in the beta note, you acknowledge and assume the ultimate risk of using beta software.
10. Children's privacy
SilkHat is not directed to children under 16, and we do not knowingly collect personal information from children under 16. During beta, SilkHat is offered to adults only. If you believe a child has provided us personal information, contact [email protected] and we will delete it.
11. International visitors
WBC Works operates in the United States. If you access SilkHat from outside the United States, your information will be processed in the United States and other countries that may have data protection laws different from those in your country. Our external AI providers and service providers may also process data outside your country. Where required, we rely on appropriate safeguards for international transfers.
12. Links to other sites
SilkHat and the website may link to third-party sites and services we do not control. This policy does not apply to them; please review their privacy policies.
13. Changes to this policy
We may update this policy as SilkHat evolves — and we expect to, as the beta privacy protections described above come into effect. When we make material changes we will update the "Last updated" date and, where appropriate, notify beta testers. Because the gap between our target architecture and the beta reality is central to this policy, we will revise the beta sections as those protections actually ship.
14. Subprocessors
We use the following third parties to provide SilkHat. We keep this list current.
| Subprocessor | Role | Data involved |
|---|---|---|
| Anthropic | AI model provider (current primary) | Conversation and connected-account content sent to generate responses/actions |
| OpenAI | AI model provider (potential fallback) | Same as above, when used as a fallback |
| AI model provider (potential fallback); connected-account provider | As a model provider: same as above, when used as a fallback. As a connected-account provider: Gmail/Calendar data you connect | |
| Microsoft | Connected-account provider | Outlook mail / Microsoft 365 calendar data you connect |
| Telegram | Messaging interface | Messages exchanged with SilkHat via Telegram |
| Resend | Transactional email | Email address and message content for early-access and support email |
| Website hosting provider | Hosts silkhat.ai | Website technical/log data |
| Website analytics provider | Website usage analytics | Website usage and technical data |
15. Contact us
Questions about this policy, or requests to exercise your rights, go to:
WBC Works LLC
United States
[email protected]
