1. Scope and controller
This policy covers waitgraph.com, its public answer tools, private trackers, evidence workflows, correction intake, and operational messages. WaitGraph is the controller for personal data it decides to process. The service is operated independently and is not affiliated with the organizations whose timelines it describes.
2. Data we process
Depending on what you use, WaitGraph may process:
- transient waiting-time questions, normalized process interpretations, and privacy-safe demand signals; the operational database stores a keyed query hash and bounded normalized candidates, not the raw unsupported question;
- private tracker facts such as organization, process, start, status, outcome, region, subtype, and consent choices;
- an anonymous authentication identifier or a securely stored hash representing private access;
- an optional email address when recovery or reminders are enabled;
- private evidence files and review metadata when you deliberately upload proof;
- short-lived, rotating abuse-prevention identifiers derived from network or session signals;
- technical logs, error events, and aggregate usage counters designed to omit raw case content.
WaitGraph does not intentionally request passwords, payment data, identity documents, medical details, or complete private dashboards.
3. Why we use it
Data is used to answer a question, provide and secure a private tracker, send a requested recovery or reminder message, prevent abuse, correct errors, operate the service, review evidence, and—only with the relevant consent—prepare anonymized statistics or research.
The legal basis depends on the context: providing a requested feature, consent, legitimate interests in security and reliable operation, and legal obligations where applicable. Consent can be withdrawn for future processing.
4. Service providers
WaitGraph uses service providers for hosting and delivery, database/authentication/private storage, sourced AI answers, transactional email when enabled, and error or privacy-safe product measurement when configured. At launch these categories may include Vercel, Supabase, Google Gemini, Resend, and a monitored error service. They process data under their own terms and the operator’s configuration.
Unsupported questions may be sent to Gemini only after local records and cache do not answer them. On the unbilled free tier, Google says submitted content may be used to improve its products. Do not put personal or confidential information in a question. Raw proof, tracker rows, emails, and private tokens are not sent to the AI answer provider.
5. Cookies and local access
Essential cookies or browser storage may keep a private tracker accessible and protect the service from abuse. WaitGraph does not require advertising cookies. Clearing browser data may remove anonymous tracker access until a recovery method is configured.
6. Retention and evidence
Data is retained only for its stated purpose and the defaults in the data policy. Pending or rejected proof is normally deleted after 30 days; accepted originals after 90 days unless a documented need applies; unsupported demand hashes and candidates after 30 days; and rotating abuse identifiers within 24–30 days. Non-identifying aggregate facts may last longer under consent. Raw unsupported question text is not retained in the WaitGraph database.
7. Your choices and rights
The private tracker offers data export and deletion. You can decline aggregation and research consent without losing the private tracking function. Depending on applicable law, you may also have rights to access, correct, erase, restrict, object, withdraw consent, and receive portable data.
Private tracking is disabled on this deployment, so no case-specific data is being collected. The correction page records the current read-only intake status and policy. If a verified account contact route is later required, WaitGraph will display it here before collecting identity details.
8. Security and transfers
WaitGraph uses access controls, row-level ownership rules, private storage, short-lived links, input validation, origin checks, secret separation, metadata stripping, and limited logs. No system can promise absolute security. Providers may process data outside your country; where required, appropriate contractual or legal safeguards apply.
9. Changes
Material changes will update the date at the top and, where practical, be surfaced before they affect an existing consent. The public correction page shows whether correction intake is currently available.