Privacy Policy

Last updated 2026-08-19

What we collect

Account data:when you sign in with GitHub or Google we store the provider's account id, username or handle, display name, email address, and avatar URL. We never see your GitHub or Google password. Content data: items you submit, versions, votes, collections, and reports. Operational data: server logs (including IP addresses used for rate limiting and abuse prevention) and error reports.

What we don't do

We don't sell your data, run third-party advertising, or use tracking pixels. Anonymous abuse reports store no account identity (the client IP is used transiently for rate limiting).

Public information

Your username, published items (with version history and scan reports), public collections, and vote counts on items are public. Votes are not publicly attributed to your account.

Processors

We host on Vercel (web), Neon (database), Cloudflare R2 (file storage), and Railway (background worker); error monitoring uses Sentry. Each processes data only to provide the service.

Retention & deletion

Account data is kept while your account exists. To delete your account, email hello@waxmark.app. Published content may be retained (it is licensed openly) but is disassociated from the deleted account.