Waismo is operated by S7 Business Solutions under SIGMA7 BUSINESS CONSULTANCY SERVICES. For privacy questions, contact admin@waismo.com. This notice covers the Waismo website, supported Android and iOS app builds, and Waismo social-page and community activities.
1. What Waismo does
The website helps people compare credit products, explore promos, and read financial information. Mobile builds can support manual tracking of selected cards, balances, limits, income, loans and debts, payment obligations, and plans. Waismo does not automatically connect to a bank, read bank transactions, monitor purchases, or make payments.
Features depend on the app build and provider configuration available to you. Waismo does not currently submit credit-card or loan applications to banks or lenders. The website's application-readiness screen is a local preview, not a submission service.
Do not enter bank passwords, one-time codes, full card numbers, CVVs, government ID numbers, or financial application documents into support messages, reports, or Ask Waismo.
2. Accounts and sign-in
Account-enabled builds use Supabase Auth. Depending on the build, you may sign in using email/password, Apple, Google, or Facebook. Supabase handles the account identifier, credential verification, provider identity response, and session. Waismo does not receive your Apple, Google, or Facebook password.
Account data can include a Supabase user ID; email address; display name; the identity provider and its stable account identifier; returned profile metadata such as an avatar or email-verification status; and authentication/session records. Apple may supply a name and email only on the first authorization, and you may choose Apple's private email relay. Google sign-in uses the returned subject identifier, name, and email. Waismo requests basic sign-in identity information, not Gmail, Drive, contacts, calendars, or Google payment data.
We use account data to recognize you, maintain sign-in, support verification and recovery, isolate account-scoped local storage, and control access to account-enabled services. Session credentials are stored using the mobile platform's protected app storage. Signing in does not automatically upload or restore your private financial tracker.
3. On-device financial records and preferences
Supported mobile builds store financial-tracking data in app-private local storage. This can include selected products; optional last four card digits; manually entered balances, limits, rates and due dates; debts and loans; income and assets; payment records and notes; payoff strategies; budgets; reminders; saved promos; and planning or sharing drafts.
Local records can be separated by guest or signed-in account scope on the device. They are not automatically synchronized to a cloud wallet, sent to banks, or attached to Ask Waismo. Public catalogs and artwork are separate downloads. This does not mean everything stays on the device: authentication, online Ask Waismo, correction reports, support messages, public-content requests, and information you deliberately export or share follow the separate flows below.
4. Deal search, public downloads, and correction reports
Deal Finder search and semantic ranking use downloaded public catalog and index files on the device. Private tracker values and account profile information are not sent to Waismo for that local search. Catalog and artwork requests expose ordinary connection information to the serving service, such as IP address, device or browser information, requested URL, time, and errors.
A correction report sends the public offer identifier, report type, and note to Supabase for review with status and timestamps. Avoid private financial or account details because free-text reports are not guaranteed to be automatically redacted.
5. Ask Waismo and third-party AI processing
Some builds answer locally. When online Ask Waismo is available, it requires a signed-in account and a separate consent. An online request sends your typed message and up to six prior online conversation turns to Waismo's authenticated Supabase service. Relevant excerpts from Waismo's public knowledge sources may be added to support the answer.
Before an online model request, the service applies automated filtering intended to remove numbers and currency amounts, email addresses, phone-like strings, URLs, and credential-like text. Filtering can miss sensitive information, so do not include secrets or private financial details. Private wallet rows, uploaded documents, account nicknames, and local tracker records are not automatically attached.
The online service routes requests through OpenCode to an allowlisted DeepSeek or OpenAI model. The app does not let a user select the provider. The reviewed OpenAI route sends store: false, but Waismo does not promise universal zero retention: OpenCode, DeepSeek, OpenAI, Supabase, and infrastructure providers may process request or security logs under their own terms and configured practices.
Waismo's reviewed application tables do not intentionally store the online prompt or generated answer as a cloud chat history. Conversation turns are session data on the device and are cleared when the session or account context ends. Waismo does store account-linked consent, usage-attempt, quota, and abuse-report records, including timestamps, status, selected provider/model metadata, and report reason or receipt. No automatic expiry schedule was identified for those records.
You may withdraw Ask Waismo consent in the app to stop future online requests. Withdrawal does not itself delete existing consent history, usage/report records, or provider logs. See Data Deletion for the current request process.
6. Website, social pages, and technical information
Website filters, comparisons, recommendations, and application-readiness inputs are processed by the page code to show a local result. The preview does not send an application to Waismo, a bank, or an affiliate. Your browser may retain entries, history, or downloads under its settings.
Hosting, authentication, content, email, and AI services process technical information needed to deliver, secure, and troubleshoot their services. Waismo does not claim that infrastructure providers keep no logs.
Social-page and community interactions may involve your public name/profile, comments, messages, and interaction metadata for replies, education, and moderation. Authorized page-management operations may process page identifiers, post/comment metadata, permissions, and access tokens. Page-admin permissions are separate from mobile sign-in.
7. Service providers and sharing
Reviewed services use Cloudflare for website hosting and delivery; Supabase for authentication, databases, public catalog delivery, Edge Functions, consent/usage/report records, and correction reports; Apple, Google, and Meta/Facebook for chosen identity or social features; and the configured Zoho email service for account email. Online Ask Waismo can involve OpenCode, DeepSeek, and OpenAI. Website assets may load from jsDelivr and official issuer/content hosts.
Authorized Waismo operators may access account, support, moderation, consent, usage, and report information to operate and protect the service. Disclosure may also be required by law or a valid legal request. Provider processing may occur outside the Philippines.
Waismo does not sell personal data. The current website and tracker do not transmit application payloads or private finances to bank partners. Future referrals, application submission, or financial-data sharing require a separate explanation and appropriate authorization. Using Waismo is not blanket consent to share your finances.
8. User controls, exports, and backup
You can edit or remove supported local records, saved promos, and reminders. Platform settings control notification visibility and identity-provider connections. Revoking Apple, Google, or Facebook access stops that connection but does not automatically delete Supabase or Waismo records.
An export or share action can pass financial records or planning information to the receiving app you choose. That app may store or transmit the copy. Later deletion in Waismo cannot recall copies already exported or shared.
Waismo does not currently promise cloud backup or cross-device recovery for the local tracker. Platform backup behavior can depend on the app build and device settings; keep exports only in a place you control.
9. Retention, sign-out, and deletion
Signing out is not deletion. It clears or invalidates the local authentication session as supported, but does not by itself erase local tracker scopes, the Supabase account, correction reports, support messages, consent/usage/report records, or provider logs.
Local delete controls remove the records handled by that control from the active device scope. Uninstalling or clearing app storage removes local app data but does not delete cloud accounts or server-held records. Public caches, model files, exports, and shared copies are separate.
Current mobile builds do not provide a verified end-to-end server-account deletion action. Contact admin@waismo.com to request deletion of an account or specified server-held data. We may need proportionate verification. Do not send passwords, verification codes, full card numbers, or identity documents in the initial request.
Waismo has not published fixed retention periods for every account, consent, usage, report, support, or provider log. Requests are assessed against the records held and necessary legal, fraud-prevention, security, and backup constraints. We will not promise immediate deletion from systems or provider logs outside our control.
10. Privacy rights and contact
Subject to applicable law, you may request access, correction, erasure or blocking, object to processing, and exercise applicable portability rights. The Philippine National Privacy Commission explains rights and complaint options on its data-subject rights page.
Contact admin@waismo.com with enough information to identify the relevant account or interaction, while avoiding unnecessary financial details. See Support and the Data Deletion instructions.
11. Security and policy changes
The reviewed implementation uses platform-protected or app-private local storage, authenticated service calls where required, HTTPS endpoints, and scoped data access. These measures are not a guarantee of absolute security or a legal certification. Protect your device, credentials, and exports.
We will revise this notice when data handling changes and update the date above. A planned feature is not described as live until its relevant flow is implemented and available.