Private by default · useful by consent

Data policy

WaitGraph separates the private record that helps you track a wait from the reviewed, anonymized facts that may improve a public answer.

The short version

Your tracker is private. Contribution is optional.

  • Starting a tracker does not publish your case.
  • Aggregation consent and research consent are separate and unticked by default.
  • Proof stays private and is reviewed manually.
  • Public statistics exclude direct identifiers and raw proof.
  • The private tracker provides its own export and deletion controls.

Case records

What a tracker stores

A case records the organization, exact process, start date and precision, registration mode, current status, any explicit outcome, optional cohort details, consent choices, evidence state, reminders, and an append-only update history. Duration is computed from endpoints; it is not accepted as an authoritative typed number.

An active case remains active until its owner records an outcome, withdraws it, marks the process wrong, or deletes it. Silence never becomes a made-up completion.

Private proof

Evidence is handled as sensitive input

WaitGraph accepts only bounded JPEG, PNG, or WebP uploads where evidence is enabled. Files are decoded, re-encoded, stripped of metadata, checked for size and dimensions, hashed for duplicate detection, stored at a random path in private storage, and placed in a manual review queue.

Do not upload passwords, payment information, identity documents, medical information, complete dashboards, booking references, or unrelated correspondence. Public use of an image requires separate consent and redaction; aggregation consent does not make the original public.

Deletion schedule

Retention defaults

Shorter retention wins where the data is no longer needed. Legal or security obligations may require a documented exception.

DataDefault
Pending or rejected proof originals30 days after review state, then scheduled deletion
Accepted proof originals90 days after review unless a clearly stated, necessary longer period applies
Derived non-identifying endpoint factsRetained while aggregation consent remains valid and the process record remains useful
Unsupported demand signalsRaw question text is not stored in the database; keyed hashes and bounded normalized candidates expire after 30 days
Rotating abuse identifiers24–30 days, never raw IP addresses
Completed private trackerUntil the owner deletes it or an operational retention rule expires
Browser owner keyThe cookie lasts one year after successful access and may be removed sooner by the browser; its database hash is unlinked after the browser’s final case is deleted

Aggregation

How a private case may become a public statistic

  1. The owner explicitly opts into anonymized aggregation.
  2. The case receives a real outcome and passes process and quality checks.
  3. Direct identifiers, raw notes, tokens, filenames, and proof are excluded.
  4. The case is grouped only with comparable process versions and cohorts.
  5. Publication gates, contributor diversity, evidence composition, and editorial review still apply.

Consent does not guarantee inclusion. Withdrawal or deletion is applied prospectively and to retained case-level data; already published aggregate snapshots may be retained when they cannot identify a person.

Your controls

Export or delete from the private tracker.

Keep the private browser link and the owner key stored in the creating browser. New links keep the tracker token after the URL’s #, so it is not sent in normal request paths or referrers. Together they provide a JSON export of the case, events, consents, and evidence metadata without proof URLs. Successful access refreshes the owner cookie for one year, but browser privacy settings may remove it sooner; clearing or blocking site data loses access. Deletion removes owner access, scrubs the retained case record, schedules private evidence for deletion, and unlinks the stored owner-key hash after that browser’s final case is deleted.