Privacy
Widdershins is run by Hagale Technologies. If you have a question about your data, email privacy@widdershins.watch and a human will answer.
What we collect
The minimum we need to run your account: your email address, your timezone, the watches and wears you log, and any photos you upload. If you turn on the daily wear-log reminder, we also store the push subscription your browser gives us for it — a delivery address and device credentials, not something you type in — so we know where to send that one reminder. That’s the whole list: no name, no address, no payment details.
Analytics
We use Cloudflare Web Analytics to count page visits. It’s the cookieless kind: no fingerprinting, no cross-site tracking, no profile of you being assembled anywhere. It tells us roughly how many people visited and which pages, and that’s all it tells us. There are no ad pixels, no session recorders, and no data brokers here.
Who handles your data
A short list of companies process data on our behalf. Cloudflare hosts everything on its global network: the app, the database, and your photos, and runs the bot check on the sign-in form, which sees your IP address. Resend, a US company, delivers the sign-in email, so it sees your email address and your sign-in link. GitHub stores the daily disaster-recovery database snapshot described below — see “Retention and deletion” — as a private, access-restricted build artifact for up to 45 days; that snapshot excludes sign-in links, but otherwise contains the same production data Cloudflare already hosts. None of these gets to use your data for anything except running Widdershins.
If you turn on the daily wear-log reminder, delivering it involves one more party: your own browser’s push service — run by whichever company makes your browser (Google, Mozilla, Microsoft, or Apple) — which your browser chose, not us. All we send it is an empty delivery request with no content and nothing about you attached; it never receives your email, your collection, or anything else in this list.
Short-lived operational data
To slow down abuse, we keep tiny rate-limiting records: your IP address for a few minutes (between one and fifteen, depending on the endpoint) and, when you request a sign-in link, your email address for fifteen minutes. They expire on their own. Sign-in links themselves also expire after fifteen minutes.
Cookies
Only the functional cookies needed to sign you in: your session, a one-time sixty-second prompt right after login, and whatever the bot check needs to pass its challenge. Your session is a random token stored in a cookie; we only keep its cryptographic hash, not the token itself, so a database leak alone can’t be used to sign in as you. No advertising or cross-site cookies, ever.
Photos
Every photo you upload is re-encoded on our servers before it’s stored, which strips embedded metadata (including GPS location) along the way. Data export covers your watches, wears, and account details, and the ZIP archive download includes every photo you’ve uploaded.
Retention and deletion
We keep your account data for as long as you have an account. Delete it and your watches, wears, photos, and account details go with it: removed immediately from the live app, not just hidden. There’s no in-app recovery window because there’s no soft delete to recover from.
We do keep a disaster-recovery backup behind the scenes, for one purpose only: recovering from our own bugs, not from your decisions. A daily job copies photos to a second, access-restricted storage bucket and exports a database snapshot, each retained for up to 45 days and then automatically deleted. If a bug on our end were to wrongly delete something, that backup is how we’d put it back; it isn’t browsable, isn’t used for anything else, and a deletion you asked for still fully disappears from it within that 45-day window.
The legal bits
We process your data because you asked us to: the lawful basis is performing our contract with you, providing the service. Because Cloudflare’s network is global and Resend and GitHub are both US companies, your data can be processed outside your own country.
Widdershins is not directed at children under 16.
We don’t sell, rent, or share your data. We don’t have an ad business to fund with it.