Waymark
Menu

Privacy Policy

This Privacy Policy (the “Policy”) outlines how Waymark (“we,” “us,” or “our”) collects, uses, and protects personal information obtained from users (“you” or “user”) of the Waymark website and services. We are committed to safeguarding your privacy and ensuring the confidentiality of your personal information in compliance with the General Data Protection Regulation (GDPR) and other applicable privacy laws.

Data Controller: Alex MacArthur, Waymark
Contact: macarthur.me/contact

Effective Date: May 24, 2026


1. Information We Collect

a. Personal Information

  • Account Information: When you create an account, we collect your name and email address. Account passwords are hashed using bcrypt and never stored in plaintext.
  • Authentication Data: If you sign in via Google OAuth, we receive your name, email address, and Google account identifier from Google. We do not receive your Google password.
  • Payment Information: Payment details are processed entirely by Stripe. We do not store, transmit, or have access to your credit card number or other payment instrument details. We store only a Stripe-issued customer identifier and your subscription status.
  • Communication Data: If you contact us for support, we collect your email address and the content of your message.

b. Content You Create

  • Questions & Conversations: Every question you ask and every answer generated by Waymark is stored as part of a conversation. This includes the full text of your questions and the AI-generated responses.
  • Shared Conversations: Conversations may be designated as public, making them accessible via a shareable URL and indexable by search engines. You are responsible for the content you choose to make public.

c. Information from Unauthenticated Users (Guests)

  • Questions & Conversations: Guests can ask questions without creating an account. These conversations are stored in our database with a random browser token (stored in your browser’s sessionStorage) rather than an email address.
  • IP Addresses: IP addresses are temporarily stored in our session database and in Redis for rate-limiting purposes (preventing abuse of our free question limits). These are automatically removed when sessions expire or the daily rate-limit window resets.
  • Browser Information: We store your browser’s user agent string as part of standard session management.

d. Usage Information

  • Analytics Data: We use Plausible Analytics, a privacy-focused analytics service that does not use cookies and does not store IP addresses or personally identifiable information. It collects anonymous usage data such as page views and interaction events.
  • Error & Performance Monitoring: We use error and performance monitoring services to diagnose issues and maintain application health. These are configured not to collect personally identifiable information by default. We also maintain self-hosted operational logs at the info level for diagnostic purposes.
  • Rate Limiting: We track the number of questions asked per user, guest token, and IP address on a rolling 24-hour basis solely to enforce our fair-use limits. These counters expire daily.

e. Cookies

Waymark uses only essential cookies necessary for the operation of the service:

  • Session Cookie (waymark-app-session) — Maintains your session state while using the application.
  • CSRF Token (XSRF-TOKEN) — Protects against cross-site request forgery attacks.
  • Remember-Me Token — Set only if you choose “Remember me” when logging in.

We do not use tracking cookies, advertising cookies, or any form of cross-site tracking.

f. Legal Basis for Processing (GDPR Article 6)

  • Consent: For non-essential communications and when you voluntarily submit information.
  • Contract Performance: For providing the theological Q&A services you request.
  • Legitimate Interests: For improving our services, preventing fraud and abuse, and ensuring the security of our systems.

2. How We Use Your Information

a. Service Provision

  • Processing your theological questions and generating responses grounded in our corpus
  • Managing your account and subscription
  • Providing customer support
  • Enforcing rate limits to ensure fair access for all users

b. Communication

  • Sending account-related notifications (password reset)
  • Responding to your inquiries and support requests
  • We do not send marketing emails or promotional communications

c. Service Improvement

  • Analyzing anonymous usage patterns to improve the accuracy and quality of responses
  • Monitoring system performance and diagnosing errors
  • Preventing abuse and maintaining the security of our platform

3. Data Sharing and Third-Party Services

We share your information only with the categories of service providers listed below, and only to the extent necessary for them to perform their function. We never sell your personal data.

Category Purpose Data Shared Location
AI service providers Generating answers, creating search embeddings, and reranking results for relevance Your questions and relevant corpus text passages. No conversation history, account details, or personal identifiers are included. United States
Stripe Payment processing and subscription management Customer ID, subscription metadata. Payment card details are handled entirely by Stripe. United States
Email delivery service Transactional email delivery (password reset, account notifications) Email address and message content. United States
Plausible Analytics Privacy-focused website analytics (self-hosted) Anonymous page views and interaction events. No cookies, no IP addresses, no personal data. European Union (self-hosted)
Error & performance monitoring Diagnosing errors and tracking application health Exception data and performance traces. Configured not to collect personally identifiable information. United States
Google OAuth Social login Your name, email, and Google account ID (only when you choose to sign in with Google). United States

All third-party providers are contractually bound to protect your information and use it only for the specified purposes. We have reviewed each provider’s privacy practices and selected them for their commitment to data protection. A complete list of named sub-processors is available upon request.

International Data Transfers

Some of our service providers are located outside the European Economic Area (EEA). Where such transfers occur, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) and other legally recognized transfer mechanisms.

Legal Disclosures

We may disclose your information if required by law or in response to valid legal requests from public authorities.


4. Data Retention

  • Account Data: Retained for as long as your account is active. When you delete your account (via your Account page), your user record and all associated conversations are permanently deleted.
  • Conversations & Messages: Stored indefinitely while your account is active. Guest conversations (no linked account) are also stored indefinitely unless you contact us to request deletion.
  • IP Addresses: Transient — stored in session records only for the duration of the session, and in Redis rate-limit counters only until the daily window expires (maximum 24 hours).
  • Usage Analytics: Anonymous analytics data is retained indefinitely for service improvement purposes.
  • Payment Records: Retained as required by applicable tax and accounting laws.

When data is no longer needed for its original purpose and there is no legal obligation to retain it, we securely delete or anonymize it.


5. Your Rights Under GDPR

If you are a resident of the European Union, you have the following rights regarding your personal data:

  • Right of Access: You can request information about the personal data we hold about you and receive a copy of that data.
  • Right to Rectification: You can request correction of inaccurate or incomplete personal data.
  • Right to Erasure (‘Right to be Forgotten’): You can request deletion of your personal data under certain circumstances. You may also delete your account directly from your Account page at any time.
  • Right to Restrict Processing: You can request that we limit how we use your personal data in certain situations.
  • Right to Data Portability: You can request a copy of your personal data in a structured, machine-readable format.
  • Right to Object: You can object to processing of your personal data based on legitimate interests or for direct marketing purposes.
  • Right to Withdraw Consent: Where processing is based on consent, you can withdraw your consent at any time.
  • Right to Lodge a Complaint: You can file a complaint with your local data protection authority if you believe we have violated your privacy rights.

To exercise these rights, contact us at macarthur.me/contact. We will respond to your request within 30 days.


6. Security Measures

We implement appropriate technical and organizational measures to protect your personal information, including:

  • Encryption of data in transit (HTTPS/TLS) and at rest
  • Password hashing using bcrypt with a cost factor of 12
  • CSRF protection on all state-changing requests
  • Rate limiting to prevent brute-force attacks and abuse
  • Regular security updates to our dependencies and infrastructure
  • Access controls and authentication procedures

However, no data transmission over the internet or electronic storage method is completely secure, and we cannot guarantee absolute security.

Data Breach Notification

In the event of a data breach that poses a high risk to your rights and freedoms, we will notify you within 72 hours as required by GDPR.


7. Children’s Privacy

Waymark’s services are not intended for use by individuals under the age of 16 (or the applicable age of digital consent in their jurisdiction). We do not knowingly collect personal information from children under this age. If we become aware that we have inadvertently collected personal information from a child under the applicable age, we will take prompt steps to delete the information from our systems.


8. Public Conversations

Waymark supports public conversations that are accessible via a shareable URL and indexable by search engines. You are solely responsible for the content you choose to make public. We recommend not including personally identifiable information in conversations you intend to share publicly.


9. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal obligations, or service offerings. When we make material changes, we will update the effective date at the top of this policy and post a notice on our website. For significant changes affecting your rights, we may require your renewed consent. We encourage you to review this Privacy Policy periodically.


10. Contact Information

If you have any questions, concerns, or requests related to this Privacy Policy or wish to exercise your data protection rights, please contact us at:

Alex MacArthur, Waymark
macarthur.me/contact

If you are in the EU and believe we have violated your privacy rights, you also have the right to lodge a complaint with your local data protection supervisory authority.

We will respond to your privacy-related requests within 30 days. If we require additional time, we will inform you and explain the reason for the delay.


Thank you for using Waymark.

Alex MacArthur, Waymark
Last Updated: May 24, 2026