Privacy Policy
1. Controller and scope
FiveToClose (“we,” “us,” or “our”) operates the website wheretheyask.com and the WhereTheyAsk software service (collectively, the “Services”). This Privacy Policy describes how we collect, use, disclose, retain, and protect personal information in connection with the Services. By accessing or using the Services, you acknowledge that you have read this Policy. Seller of record is FiveToClose.
2. Categories of information we collect
We may collect and process:
- Identity and contact data — name and email address obtained when you sign in with Google, and any name displayed on your Google profile.
- Account and authentication data — Google account identifier, session cookies, and sign-in timestamps. We do not receive or store your Google password.
- Offer and workspace data — offer URLs, audience descriptions, voice samples you paste, generated drafts, daily moves, and room/thread suggestions associated with your account.
- Transactional data — subscription plan, purchase dates, paid-through dates, Stripe customer and subscription identifiers, and amounts paid. Full payment card numbers are processed by Stripe and are not stored on our servers.
- Technical and usage data — IP address, browser type, device characteristics, pages viewed, and diagnostic logs used to operate, secure, and improve the Services.
- Communications data — messages you send to support and related metadata.
3. Purposes of processing
We process personal information to:
- Create and authenticate your account;
- Generate drafts, daily moves, and suggested public-thread replies for your workspace;
- Process subscription payments, prevent fraud, and maintain accounting records;
- Provide customer support and service announcements;
- Secure the Services, debug faults, and improve product quality;
- Comply with legal obligations and enforce our Terms of Service.
4. Legal bases (where applicable)
Where data-protection laws require a legal basis, we rely on: (a) performance of a contract (providing the subscribed service); (b) legitimate interests (security, product improvement, limited service communications); (c) consent (where required, including certain optional cookies); and (d) legal compliance.
5. Google sign-in
Sign-in uses Google OAuth. Google authenticates you and returns a verified email address, name, and a stable account identifier. We use that information solely to create or recognize your WhereTheyAsk account. Your use of Google is governed by Google’s terms and privacy policy. We do not post to Google, Gmail, YouTube, or any other Google product on your behalf.
6. What we do not do
We do not post to your Reddit, X (Twitter), email provider, or other social accounts. Drafts are generated for you to copy and publish yourself. We do not sell personal information for monetary consideration. We do not use customer workspace content to train public foundation models.
7. Service providers and disclosures
We may disclose information to:
- Payment processors (Stripe) for checkout, invoicing, refunds, and fraud prevention;
- Authentication providers (Google) for sign-in;
- Infrastructure and AI providers necessary to host the Services and generate drafts (including xAI / SpaceXAI as the model provider);
- Professional advisers and authorities when required by law or to protect rights, safety, and integrity of the Services.
Providers are instructed to process data only as needed to perform services on our behalf.
8. Cookies and similar technologies
We use a first-party session cookie (wta) to keep you signed in, and a short-lived cookie during Google sign-in (wta_oauth). These cookies are necessary for the Service to function. You may control cookies in your browser; disabling the session cookie will sign you out.
9. Retention
We retain account, workspace, and transaction records for as long as your account is active and thereafter as reasonably necessary for billing disputes, legal compliance, security, and legitimate archival needs, unless a longer period is required or permitted by law. You may request deletion as described below.
10. Security
We implement administrative, technical, and organizational measures designed to protect personal information, including encrypted transport (HTTPS), access-restricted servers, and hashed session tokens. No method of transmission or storage is completely secure. You use the Services at your own residual risk.
11. International transfers
Our infrastructure and service providers may process data in the United States and other jurisdictions. Where required, we take steps reasonably designed to ensure that transfers receive an adequate level of protection under applicable law.
12. Your rights
Depending on your location, you may have rights to access, correct, delete, or restrict certain processing of your personal information, to object to processing, or to data portability. To exercise rights, email support@fivetoclose.cloud. We may need to verify your identity before fulfilling a request. Internal operator accounts used to run the Service are not customer records.
13. Children
The Services are not directed to individuals under 18. We do not knowingly collect personal information from children. If you believe we have done so, contact us and we will take appropriate steps to delete such information.
14. Changes to this Policy
We may revise this Privacy Policy from time to time. The “Effective date” above will be updated when material changes are posted. Continued use of the Services after the effective date constitutes acceptance of the revised Policy, except where applicable law requires additional consent.
15. Contact
Privacy inquiries: support@fivetoclose.cloud. Please check spam and promotions folders for replies.
© 2026 FiveToClose. All rights reserved. Questions: support@fivetoclose.cloud.