Private by default · useful by consent
Data policy
This deployment is a read-only public record. The policy below documents the safeguards required before private tracking can be enabled.
The short version
Private tracking is not currently enabled.
- No tracker form is offered and no private case record is created.
- Broader answer demand is not collected while sourced answers are disabled.
- The reviewed public record and its evidence limits remain available.
Case records
What tracking would store if enabled
No private case is created on this deployment. If tracking is enabled later, a case will record exact endpoints, consent choices, evidence state, and an append-only update history under the safeguards described here.
Private proof
Evidence is handled as sensitive input
WaitGraph accepts only bounded JPEG, PNG, or WebP uploads where evidence is enabled. Files are decoded, re-encoded, stripped of metadata, checked for size and dimensions, hashed for duplicate detection, stored at a random path in private storage, and placed in a manual review queue.
Do not upload passwords, payment information, identity documents, medical information, complete dashboards, booking references, or unrelated correspondence. Public use of an image requires separate consent and redaction; aggregation consent does not make the original public.
Deletion schedule
Retention defaults
Shorter retention wins where the data is no longer needed. Legal or security obligations may require a documented exception.
| Data | Default |
|---|---|
| Pending or rejected proof originals | 30 days after review state, then scheduled deletion |
| Accepted proof originals | 90 days after review unless a clearly stated, necessary longer period applies |
| Derived non-identifying endpoint facts | Retained while aggregation consent remains valid and the process record remains useful |
| Rotating abuse identifiers | 24–30 days, never raw IP addresses |
Aggregation
How a private case may become a public statistic
- The owner explicitly opts into anonymized aggregation.
- The case receives a real outcome and passes process and quality checks.
- Direct identifiers, raw notes, tokens, filenames, and proof are excluded.
- The case is grouped only with comparable process versions and cohorts.
- Publication gates, contributor diversity, evidence composition, and editorial review still apply.
This describes the review path required if private contribution is enabled later. No new tracker contribution is accepted on this deployment.
Your controls
No tracker data is collected on this deployment.
No tracker control is offered because the storage-backed tracking capability is unavailable. The privacy policy still explains how public requests and operational data are handled.