1. Scope and controller
This policy covers waitgraph.com, its public answer tools, private trackers, evidence workflows, correction intake, and operational messages. WaitGraph is the controller for personal data it decides to process. The service is operated independently and is not affiliated with the organizations whose timelines it describes.
2. Data we process
Depending on what you use, WaitGraph may process:
- transient waiting-time questions, normalized process interpretations, and privacy-safe demand signals; the operational database stores a keyed query hash and bounded normalized candidates, not the raw unsupported question;
- 30-day beta measurement events containing only the answer source, response status, answer type, and whether the request was a real or synthetic check; they contain no question, query hash, network or browser identifier, URL, region, or case content;
- private tracker facts such as organization, process, start, status, outcome, region, subtype, and consent choices;
- an essential HttpOnly browser owner cookie and its SHA-256 hash for private access; the opaque cookie stays in the browser and only the hash reaches the database;
- a verified account email only for legacy recovery or reminder flows; new browser-owned trackers do not collect an email address;
- private evidence files and review metadata when you deliberately upload proof;
- short-lived, rotating abuse-prevention identifiers derived from network or session signals; separate beta-measurement admission counters use daily HMACs for the network and browser-session signals and never copy those identifiers into the beta event;
- technical logs, error events, and aggregate usage counters designed to omit raw case content.
WaitGraph does not intentionally request passwords, payment data, identity documents, medical details, or complete private dashboards.
3. Why we use it
Data is used to answer a question, provide and secure a private tracker, send a requested legacy recovery or reminder message, prevent abuse, correct errors, operate the service, review evidence, and—only with the relevant consent—prepare anonymized statistics or research.
The legal basis depends on the context: providing a requested feature, consent, legitimate interests in security and reliable operation, and legal obligations where applicable. Consent can be withdrawn for future processing.
4. Service providers
WaitGraph uses service providers for hosting and delivery, database/authentication/private storage, sourced AI answers, transactional email when enabled, and error monitoring when configured. At launch these categories may include Vercel, Supabase, Perplexity, Resend, Cloudflare, and a monitored error service. The current beta funnel measurement is first-party and stored in the EU Supabase project. Providers process data under their own terms and the operator’s configuration.
Separately, free Cloudflare Web Analytics reports aggregate visits, page views, referrers, countries, device and browser types, and loading performance on approved public entry pages. Cloudflare states that it does not use cookies, local storage, or fingerprinting to identify visitors and does not log query strings. Private tracker, authentication, administrative, and API routes are excluded, and automatic single-page navigation tracking is disabled. Entering a private tracker starts a separate page document without that analytics script, and navigation referrers omit paths and queries. Public traffic is viewed in a private portfolio dashboard; it is not joined to questions, proof, tracker records, beta events, or cross-product identities.
Unsupported questions may be sent through Vercel AI Gateway to Perplexity Sonar only after local records and cache do not answer them. Sonar searches the public web and returns source URLs with its answer. Provider processing may occur in North America. Do not put personal or confidential information in a question. Raw proof, tracker rows, emails, and private tokens are not sent to the AI answer provider.
5. Cookies and local access
An essential HttpOnly cookie keeps a browser-owned tracker accessible and protects the service from abuse. WaitGraph does not require advertising cookies. Successful tracker access refreshes this cookie for one year. The browser may remove it sooner under its own privacy settings; clearing or blocking site data loses browser-owned access. The private link alone is not enough.
If you choose “Track this wait” after an answer, the page may place one signed, short-lived attribution token in session storage. It links only that answer event to the first tracker created with the same browser-session identifier, expires within 24 hours, is removed after successful tracker creation, and is never placed in the URL. The identifier is signed into the token but is not stored in the beta event. Tracker creation still works when storage is unavailable, the token is reused, or either value is invalid.
6. Retention and evidence
Data is retained only for its stated purpose and the defaults in the data policy. Pending or rejected proof is normally deleted after 30 days; accepted originals after 90 days unless a documented need applies; unsupported demand hashes and candidates after 30 days; and rotating abuse identifiers within 24–30 days. Beta-measurement admission counters are removed within about three days. Categorical beta answer events are deleted after 30 days, and their optional tracker-attribution link is then removed automatically. Non-identifying aggregate facts may last longer under consent. Raw unsupported question text is not retained in the WaitGraph database.
Deletion scrubs the case’s private endpoints and cohort fields, schedules proof deletion, and retains privacy-safe event, consent, and audit history only for integrity and recomputation. After the browser’s final non-deleted case is removed, its stored owner-key hash is replaced so future trackers cannot be linked through that key.
7. Your choices and rights
The private tracker offers data export and deletion. You can decline aggregation and research consent without losing the private tracking function. Depending on applicable law, you may also have rights to access, correct, erase, restrict, object, withdraw consent, and receive portable data.
Use the private tracker for case-specific export or deletion. Use the correction route for public-source or published-data errors without submitting personal data. If a verified account contact route is later required, WaitGraph will display it here before collecting identity details.
8. Security and transfers
WaitGraph uses access controls, row-level ownership rules, private storage, short-lived links, input validation, origin checks, secret separation, metadata stripping, and limited logs. New private tracker links keep their opaque token after the URL's #; browsers do not send that fragment in an HTTP request path, query, or referrer. Tracker data calls use the stable private endpoint with the token in an authorization header plus the separate browser owner cookie. Existing legacy token-path links remain temporarily compatible and migrate when opened, so historical and legacy-link provider-log exposure is not represented as erased. Application-authored logs omit tracker tokens, cookies, questions, case content, headers, and request bodies. No system can promise absolute security. Providers may process data outside your country; where required, appropriate contractual or legal safeguards apply.
9. Changes
Material changes will update the date at the top and, where practical, be surfaced before they affect an existing consent. The public correction page shows whether correction intake is currently available.
