Private by default · useful by consent
Data policy
WaitGraph separates the private record that helps you track a wait from the reviewed, anonymized facts that may improve a public answer.
The short version
Your tracker is private. Contribution is optional.
- Starting a tracker does not publish your case.
- Aggregation consent and research consent are separate and unticked by default.
- Proof stays private and is reviewed manually.
- Public statistics exclude direct identifiers and raw proof.
- The private tracker provides its own export and deletion controls.
Case records
What a tracker stores
A case records the organization, exact process, start date and precision, registration mode, current status, any explicit outcome, optional cohort details, consent choices, evidence state, reminders, and an append-only update history. Duration is computed from endpoints; it is not accepted as an authoritative typed number.
An active case remains active until its owner records an outcome, withdraws it, marks the process wrong, or deletes it. Silence never becomes a made-up completion.
Private proof
Evidence is handled as sensitive input
WaitGraph accepts only bounded JPEG, PNG, or WebP uploads where evidence is enabled. Files are decoded, re-encoded, stripped of metadata, checked for size and dimensions, hashed for duplicate detection, stored at a random path in private storage, and placed in a manual review queue.
Do not upload passwords, payment information, identity documents, medical information, complete dashboards, booking references, or unrelated correspondence. Public use of an image requires separate consent and redaction; aggregation consent does not make the original public.
Deletion schedule
Retention defaults
Shorter retention wins where the data is no longer needed. Legal or security obligations may require a documented exception.
| Data | Default |
|---|---|
| Pending or rejected proof originals | 30 days after review state, then scheduled deletion |
| Accepted proof originals | 90 days after review unless a clearly stated, necessary longer period applies |
| Derived non-identifying endpoint facts | Retained while aggregation consent remains valid and the process record remains useful |
| Unsupported demand signals | Raw question text is not stored in the database; keyed hashes and bounded normalized candidates expire after 30 days |
| Rotating abuse identifiers | 24–30 days, never raw IP addresses |
| Completed private tracker | Until the owner deletes it or an operational retention rule expires |
| Browser owner key | The cookie lasts one year after successful access and may be removed sooner by the browser; its database hash is unlinked after the browser’s final case is deleted |
Aggregation
How a private case may become a public statistic
- The owner explicitly opts into anonymized aggregation.
- The case receives a real outcome and passes process and quality checks.
- Direct identifiers, raw notes, tokens, filenames, and proof are excluded.
- The case is grouped only with comparable process versions and cohorts.
- Publication gates, contributor diversity, evidence composition, and editorial review still apply.
Consent does not guarantee inclusion. Withdrawal or deletion is applied prospectively and to retained case-level data; already published aggregate snapshots may be retained when they cannot identify a person.
Your controls
Export or delete from the private tracker.
Keep the private browser link and the owner key stored in the creating browser. New links keep the tracker token after the URL’s #, so it is not sent in normal request paths or referrers. Together they provide a JSON export of the case, events, consents, and evidence metadata without proof URLs. Successful access refreshes the owner cookie for one year, but browser privacy settings may remove it sooner; clearing or blocking site data loses access. Deletion removes owner access, scrubs the retained case record, schedules private evidence for deletion, and unlinks the stored owner-key hash after that browser’s final case is deleted.
