Wrelik legal
Privacy Policy
Effective August 4, 2026 · Last updated August 4, 2026
This policy explains how Wrelik Brands LLC handles Personal Information across its Services. The sporkd addendum below describes practices specific to the recipe app.
1. Scope
This Privacy Policy explains how Wrelik Brands LLC ("Wrelik," "we," "us," or "our") collects, uses, discloses, and protects Personal Information when you visit our websites or use our applications and related services, including sporkd, Klutr, and DRX / Deelrx CRM (each an "App" and together, the "Services"). "Personal Information" means information that identifies, relates to, describes, or can reasonably be linked with an individual.
The app-specific addendum presented with this Privacy Policy describes practices unique to the App you use. If an app-specific addendum conflicts with the general portions of this Privacy Policy, the addendum controls for that App.
For individual accounts and our websites, Wrelik generally determines why and how Personal Information is processed. For DRX business accounts, the subscribing business generally controls the business records and Personal Information entered by its authorized users. In that context, Wrelik processes the information on the business customer's instructions as its service provider or processor, except for account administration, security, billing, compliance, and other purposes for which Wrelik independently determines the means and purposes of processing.
2. Information we collect
Depending on the Service and the features you use, we may collect:
- Account and identity information: name, email address, profile details, authentication identifiers, organization membership, role, account settings, and login or security events.
- Content and workflow information: text, notes, links, files, images, audio, transcriptions, recipes, lists, business records, customer records, inventory records, sales records, and other information you choose to create, import, upload, or process through a Service.
- Transaction and subscription information: plan, subscription status, purchase history, billing contact, and limited payment-related records. Payment card information is handled by the applicable payment processor or app marketplace and is not stored in full by Wrelik.
- Device, network, and usage information: IP address, browser or device type, operating system, app version, language, pages or features used, timestamps, referring pages, session and interaction information, and similar technical information.
- Diagnostics and security information: crash reports, error logs, performance data, audit events, suspected fraud or abuse signals, and information needed to keep accounts and Services secure.
- Communications: support requests, feedback, survey responses, beta-program communications, and other messages you send to us.
- Information from integrations and third parties: information received when you use a sign-in provider, app marketplace, connected service, content source, or an integration you or your organization enables.
- We collect information directly from you, automatically from the device or browser you use, from the organization that provides your account, and from third parties you choose to connect with a Service.
3. How we use information
We use Personal Information to:
- provide, operate, maintain, sync, and support the Services;
- authenticate users, administer accounts and organizations, and enforce role-based access;
- process user-directed content and requests, including optional AI-assisted features;
- personalize settings and restore user or business data across supported devices;
- provide subscriptions, billing administration, transactional messages, and customer support;
- monitor reliability, measure feature use, diagnose errors, and improve usability and performance;
- protect users, organizations, Wrelik, and the public from fraud, abuse, security threats, and unlawful activity;
- comply with law, enforce our agreements, resolve disputes, and protect legal rights; and
- communicate about material Service, security, policy, or account changes.
- Where applicable law requires a legal basis, we rely on performance of a contract, legitimate interests such as security and service improvement, compliance with legal obligations, and consent where requested. You may withdraw consent for future processing when consent is the applicable basis.
4. AI-assisted processing
Some Services offer optional features that use machine learning or generative AI. When you direct an AI feature to process content, the relevant input, instructions, and necessary context may be sent to Wrelik's configured AI infrastructure and model providers to return the requested result. We limit this processing to providing, securing, and improving the feature as described in the applicable addendum and provider terms.
AI output may be incomplete, inaccurate, or inappropriate. Do not rely on AI output as professional, medical, legal, financial, tax, safety, or regulatory advice. Do not submit information to an AI feature unless you are authorized to use and disclose it for that purpose.
Wrelik does not use customer content to build advertising profiles or sell it. Any materially different use of customer content for model training would require updated notice and, where required, consent.
5. How we disclose information
We may disclose Personal Information:
- To service providers and processors: that provide cloud hosting, databases, storage, authentication, analytics, error monitoring, communications, customer support, app distribution, payment processing, content processing, and AI infrastructure. Depending on the App and feature, these providers may include Apple, Google, Expo, Vercel, Convex, Neon, Supabase, Clerk or another configured authentication provider, PostHog, Sentry, Resend, Help Scout for customer support, and configured AI model providers.
- At your or your organization's direction: including to integrations, content sources, collaborators, or other users with authorized access.
- For legal and safety reasons: when reasonably necessary to comply with law or valid legal process; protect rights, safety, and security; investigate fraud or abuse; or enforce our agreements.
- In a business transaction: such as a financing, merger, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality and notice where required.
- With professional advisers and affiliates: that need the information to provide legal, accounting, insurance, security, or operational support and are required to protect it.
- We do not sell Personal Information for money. We do not use or disclose Personal Information for cross-context behavioral advertising. We have not sold Personal Information or shared it for cross-context behavioral advertising during the preceding 12 months. If these practices change, we will update this Policy and provide legally required choices before the change applies.
- Service providers may process information only to perform services for us or as otherwise permitted by their agreements and applicable law. We require providers that receive user data to apply protections appropriate to the information and their role.
6. Cookies, local storage, analytics, and preferences
Our websites and web applications may use cookies, local storage, and similar technologies for authentication, security, preferences, feature operation, analytics, and performance. Required technologies are used to deliver the Service. Where required, we request consent before enabling optional analytics or similar technologies. Browser settings can limit some technologies, but doing so may prevent parts of a Service from working.
We honor legally required opt-out signals where they apply to our practices. Because we do not currently sell Personal Information or use it for cross-context behavioral advertising, there is no sale or targeted-advertising activity to opt out of.
7. Retention and deletion
We retain Personal Information only as long as reasonably necessary for the purposes described in this Policy, including while an account or customer relationship is active; to provide user-requested retention, synchronization, or recovery; to meet contractual, tax, accounting, audit, and legal obligations; to resolve disputes; and to protect the Services.
When an account, workspace, or item is deleted, we remove or de-identify the information from active systems after verifying the request and completing the deletion workflow, unless retention is required or permitted by law or needed to protect the rights and security of users or the Service. Limited copies may remain temporarily in encrypted backups, logs, fraud-prevention records, or records subject to legal holds until those records are rotated or no longer required. De-identified information that cannot reasonably identify an individual may be retained for analytics, security, and Service improvement.
For an organization-managed DRX account, the organization controls ordinary retention, export, correction, and deletion requests for business data. Individuals should first contact that organization; Wrelik will assist the organization as required by contract and law.
8. Security
We use administrative, technical, and organizational measures designed to protect Personal Information, including access controls, authentication safeguards, encrypted network transport, service-provider controls, logging, and environment separation where appropriate. No system is completely secure, and we cannot guarantee that unauthorized access, loss, or misuse will never occur. You are responsible for using unique credentials, protecting your devices, and promptly reporting suspected unauthorized access.
9. Your privacy rights and choices
Depending on where you live and how Wrelik processes your information, you may have the right to:
- know or access the Personal Information we hold about you;
- correct inaccurate Personal Information;
- request deletion;
- receive a portable copy of information you provided;
- restrict or object to certain processing;
- withdraw consent for future processing;
- opt out of sale, targeted advertising, or qualifying profiling where applicable; and
- appeal a denied privacy request or complain to a data protection authority.
- We will not discriminate against you for exercising a privacy right. To submit a request, email legal@wrelik.com with the subject "Privacy Request" and identify the App and account involved. We may need to verify your identity and authority before completing a request. An authorized agent may submit a request where permitted by law, subject to verification.
- If an organization controls your DRX account, send business-data requests to that organization. You may also contact us, and we will route or assist with the request as appropriate.
10. U.S. state disclosures
During the preceding 12 months, we may have collected the categories described in Section 2: identifiers; customer-record information; commercial or subscription information; internet or electronic-network activity; approximate geolocation derived from IP address; audio, visual, or other content you submit; professional or employment-related information for business accounts; and inferences limited to providing or improving requested features. We collect these categories from the sources described in Section 2, use them for the purposes in Section 3, and disclose them to the categories of recipients in Section 5.
We do not use sensitive Personal Information to infer characteristics about individuals. We do not knowingly sell or share the Personal Information of people under 16. Rights provided by California, Colorado, Connecticut, Virginia, and other state laws apply only when the relevant law covers Wrelik's processing and the request.
11. International data transfers
Wrelik is based in the United States, and our providers may process information in the United States and other countries. Those locations may have data-protection laws different from those where you live. Where required, we use contractual and other safeguards intended to provide an appropriate level of protection for international transfers.
12. Children
The Services are not directed to children under 13, and we do not knowingly collect Personal Information from a child under 13. If you believe a child has provided Personal Information in violation of this section, contact legal@wrelik.com so we can investigate and take appropriate action. A Service or customer organization may impose a higher minimum age.
13. Third-party services and content
The Services may link to or interact with third-party websites, content, authentication providers, app marketplaces, or integrations. Their privacy practices are governed by their own notices. Wrelik does not control independent third parties and is not responsible for their practices.
14. Changes to this Policy
We may update this Policy to reflect changes in the Services, law, or our practices. We will post the updated version and revise the "Last updated" date. If a change materially expands how previously collected Personal Information is used, we will provide additional notice and obtain consent where required.
15. Contact
Questions and privacy requests may be sent to:
Wrelik Brands LLC Attn: Privacy 1700 Northside Drive Atlanta, GA 30318, United States legal@wrelik.com
Privacy Addendum — sporkd
This addendum applies when you use sporkd.
- Recipe and source content: sporkd lets you submit recipe links, captions, transcripts, and other source information for extraction and organization. We process the link, source metadata, recipe text, ingredients, instructions, grocery selections, and your edits to provide the requested features. The source website or content platform may receive your device or network request and applies its own privacy policy.
- AI-assisted extraction: When you ask sporkd to parse or organize a recipe, the submitted source information and necessary instructions may be processed through Convex, Wrelik's configured ingestion services, and OpenAI or another configured AI model provider to produce structured recipe data. Do not submit private, confidential, or unlawfully obtained material.
- Device-scoped identity: Some current beta builds use a randomly generated device identifier instead of a name-and-email account. That identifier can separate recipes, extraction jobs, and grocery selections associated with the device, but it is not account-grade authentication and may not follow you if the identifier is reset or the app is reinstalled.
- Saved content and requests: Depending on the version and sign-in state, recipes, preferences, timer information, and grocery lists may be stored on your device or in Convex. The native app's Delete All My Data control removes active device-scoped recipes, extraction jobs, grocery selections, device registrations, associated AI threads, local recipes, timers, selections, preferences, and the device identifier. Limited backup, security, or legally required records may remain as described in Section 7. Privacy rights and verified deletion requests may also be submitted to legal@wrelik.com.
- Public image URLs: sporkd may display recipe, source, or illustrative images from public URLs. Requesting an image can disclose network information such as your IP address to the image host, and public or source-hosted image URLs should not be treated as private storage. An image may remain available from its original host or cache after a recipe is removed from sporkd.
- Microphone and speech: If you enable hands-free cooking commands, the native app requests microphone and speech-recognition permission. Audio and recognized speech are processed only while listening is active; depending on your device and settings, speech may be processed by Apple. sporkd uses recognized commands such as next, back, and stop to operate cook mode.
- Notifications: If you allow notifications, sporkd schedules local cooking-timer alerts through your device. Timer labels and end times may be retained locally so active timers can continue after the app leaves the foreground.
- Analytics and diagnostics: Where an analytics-enabled build is configured, sporkd may process app version, device information, typed usage events, and limited crash or error details to maintain reliability. Analytics are configured to avoid recipe text, ingredients, transcripts, source URLs, grocery-list content, and other free-form user content as event properties, except when you intentionally provide information in a support request.
- No advertising use: sporkd does not use recipe content or grocery lists for targeted advertising and does not sell them.