Private by default · useful by consent

Data policy

This deployment is a read-only public record. The policy below documents the safeguards required before private tracking can be enabled.

The short version

Private tracking is not currently enabled.

  • No tracker form is offered and no private case record is created.
  • Broader answer demand is not collected while sourced answers are disabled.
  • The reviewed public record and its evidence limits remain available.

Case records

What tracking would store if enabled

No private case is created on this deployment. If tracking is enabled later, a case will record exact endpoints, consent choices, evidence state, and an append-only update history under the safeguards described here.

Private proof

Evidence is handled as sensitive input

WaitGraph accepts only bounded JPEG, PNG, or WebP uploads where evidence is enabled. Files are decoded, re-encoded, stripped of metadata, checked for size and dimensions, hashed for duplicate detection, stored at a random path in private storage, and placed in a manual review queue.

Do not upload passwords, payment information, identity documents, medical information, complete dashboards, booking references, or unrelated correspondence. Public use of an image requires separate consent and redaction; aggregation consent does not make the original public.

Deletion schedule

Retention defaults

Shorter retention wins where the data is no longer needed. Legal or security obligations may require a documented exception.

DataDefault
Pending or rejected proof originals30 days after review state, then scheduled deletion
Accepted proof originals90 days after review unless a clearly stated, necessary longer period applies
Derived non-identifying endpoint factsRetained while aggregation consent remains valid and the process record remains useful
Rotating abuse identifiers24–30 days, never raw IP addresses

Aggregation

How a private case may become a public statistic

  1. The owner explicitly opts into anonymized aggregation.
  2. The case receives a real outcome and passes process and quality checks.
  3. Direct identifiers, raw notes, tokens, filenames, and proof are excluded.
  4. The case is grouped only with comparable process versions and cohorts.
  5. Publication gates, contributor diversity, evidence composition, and editorial review still apply.

This describes the review path required if private contribution is enabled later. No new tracker contribution is accepted on this deployment.

Your controls

No tracker data is collected on this deployment.

No tracker control is offered because the storage-backed tracking capability is unavailable. The privacy policy still explains how public requests and operational data are handled.