whatatake

Privacy

What we keep about you, what anyone can see, and which services handle it.

Updated 14 Sept 2026

What we keep

Your email address
We use it to sign you in and to send the emails described below. No one else on whatatake sees it.
Your name and handle
The display name you choose, and your handle. If you sign in with Google, Google also sends us your name and profile picture, and we suggest that name as your display name.
Your takes
Each take's words, whose take it is, its date or condition, and its reach. With it, anything you add: a friend's name, a link to a post and our copy of that post, a screenshot, a verdict and its evidence, or a stake's terms.
Groups and follows
The groups you start or join, and the takes you follow.

We keep your account and your takes for as long as whatatake runs, unless you ask us to delete them.

What anyone can see

Your display name and handle are on your profile, which anyone can open. Members of your groups also see your display name.

Each take's reach decides who can read it: only you, a group, anyone with the link, or everyone. Whoever can read a take sees your display name on it. Public takes are also listed on Explore and on your profile, and search engines can find them.

A take's words and its reach can't be changed once it's logged.

Emails

We email you when a take of yours is due, and when a take you follow gets its verdict. Every email has a link to stop them, and you can turn them all off in Settings. We keep a record of each email we send.

Sign-in links come by email too.

What we measure

We count visits to a take's page, Explore and source pages. For each visit, we record the page, the site that sent you, and any campaign tags in the link.

We also record what happens on your account: signing up, logging a take, following one, recording a verdict, starting or joining a group, and each email we send you. Each record names your account or your browser by an ID. It never includes your email address or the words of a take.

Cookies

Sign-in cookies
They keep you signed in. Supabase sets them.
wat_vid
A random ID for your browser, so we don't count a return visit as a new visitor. When you sign in, we link that browser's earlier visits to your account. It lasts a year.
wat_att
Where your first visit came from: the site that sent you, the first page you opened, and any campaign tags. It lasts a year.

We don't use advertising cookies, and we don't sell your data.

Services that handle your data

Supabase
Signs you in, and stores the database and uploaded images on servers in Ireland.
Vercel
Hosts whatatake. Our code runs in Dublin.
PostHog
Stores our records of visits and activity, in the EU.
Resend
Sends our emails, so it receives your email address and each email.
Google Gemini
Drafts a take from what you write. It receives the words you type, or the text of the post you link, and never a screenshot or your account details. Google may use that text to improve its products, and its reviewers may read it.
Bluesky and X
When you paste a link to a post, we fetch that post from its site.
Sentry
Receives a report when our code fails on the server. A report can include the address of the page.
Google
Signs you in, when you choose to sign in with Google.

Several of these companies are based in the United States, and your data might be processed there.

Your choices

Change your display name in Settings. Your handle is permanent.

Stop emails in Settings, or with the link in any email.

You can't edit or delete a take yourself. To get a copy of your data, correct it, or delete your account and your takes, email privacy@whatatake.com.

If you're in the EU or the UK, you can also complain to your data protection authority.

Contact

whatatake is an independent project. Email privacy@whatatake.com about anything on this page.