Privacy Policy
Last updated: August 11, 2026
Wakestow is built on a single promise: the person standing somewhere can read what someone else left there. Nothing else flows. This policy describes exactly what data we handle to make that work — and what we will never do.
What we collect
Anonymous account (no name, no address)
The first time you open the app we create an anonymous account for you — no email, no name, nothing you had to type. Your browser holds the session for it, and that session is the only thing tying your memories to you. Add a recovery email in Settings if you want to get back in on another device or after reinstalling; without one, clearing your browser data means the account and its memories are gone for good. Settings → Delete everything erases both immediately.
Location (used, not stored)
When you leave a memory, your GPS coordinates are sent to our server to record the location. When you try to read a memory, your coordinates are compared with the memory's location server-side. We do not store a history of your coordinates. The only location datum we persist is the coordinates of a memory you intentionally left — never your movement pattern.
Memory text
The text of a memory you leave is stored in our database (Supabase, EU region), encrypted at rest. It is readable only to someone physically present at the location and only after any reveal condition you set is met. The text is associated with your anonymous account — not with your name, email, or IP address.
Email address (optional, recovery only)
If you choose to set up Recovery (Settings → Recovery), you provide an email address. We use it exclusively to send a magic link that signs you back into your anonymous account on another device. We do not use it for marketing, newsletters, or any purpose other than that one delivery. Your address is stored in our authentication system and linked to that account — not in any profile or third-party CRM. It is permanently deleted when you use Delete everything.
Analytics (four events)
We use PostHog (EU region) to record four events that tell us whether the product is working:
meaningful_discovery— a memory was successfully revealedmemory_discovery_empty— a sensing attempt found nothing nearbymemory_left— a memory was writtenmemory_reported— a memory was flagged for moderation
None of these events contain memory text, precise coordinates, or any personal data. There is no pageview tracking, no session recording, no heatmaps, and no scroll or click telemetry.
Error reporting
We use Sentry to capture technical errors. Error reports may contain a stack trace and the URL at which the error occurred. They do not contain memory text or location data. Error reports are retained for 30 days.
What we do not collect
- Your name
- Your phone number
- Your location history or movement patterns
- Who reads a memory you left
- Any data that would identify you to another user
- Advertising identifiers of any kind
There are no social graphs. There are no profiles. There is no feed. No one can follow you, find your memories on a map, or see where you have been.
How we share data
We do not sell your data. We do not share it with advertising networks. We use a small number of infrastructure providers (Supabase, Cloudflare, Resend, PostHog, Sentry) — all operating under data processing agreements — to run the service. Each receives only the data it needs for its function.
Data residency
Our primary database and analytics infrastructure are hosted in the EU. Error reporting (Sentry) may involve temporary data transfer to servers outside the EU under standard contractual clauses.
Your rights
You have the right to delete all data we hold about your account. The Delete everything feature in Settings performs a permanent, irreversible deletion of your memories, your recovery email (if any), and the anonymous account itself. This operation is immediate and cannot be undone. There is no backup that survives it.
If you have questions about your data or want to exercise any rights under GDPR or applicable privacy law, contact us at support@wakestow.com.
Cookies
We do not use cookies for tracking or advertising. We use a single httpOnly session cookie when you authenticate via magic link (recovery flow). This cookie expires when the session ends. No third-party cookies are set.
Children
This service is not directed at children under 13. We do not knowingly collect data from anyone under 13. If you believe a child under 13 has used the service and left data, contact us and we will delete it.
Changes to this policy
If we make material changes, we will update the date at the top of this page and — if we have your recovery email — send a notification. Using the service after a change is published constitutes acceptance of the updated policy.