Legal

Privacy Policy

Last updated 25 March 2026

01

What we collect

Things you give us

  • Account details: username, display name, email, and a hashed password
  • Profile details: bio, avatar, banner, and any links you add
  • Files and media you upload
  • Memes you create
  • Anything you write to support

Things collected as you use the site

  • IP address, and a rough location from it, so city or country level
  • Browser, version, and operating system
  • Pages visited and features used, with timestamps
  • Your session token, held in our database rather than in a cookie
  • User-agent string
02

What we use it for

  • Running and improving the service
  • Signing you in and keeping the session alive
  • Serving your files from our CDN
  • Spotting abuse, spam and security incidents
  • Sending transactional mail: verification, password resets
  • Looking at aggregate usage to decide what to work on
  • Answering your support messages

We do not use any of it for advertising, and we do not sell it.

03

Who else sees it

We do not sell personal information. It leaves our systems only here:

  • The infrastructure provider hosting our servers
  • The mail service that delivers transactional email
  • Law enforcement, where the law or a valid order requires it
  • Publicly, for anything you deliberately made public
04

Where it lives, and how it is kept

  • Account data sits in PostgreSQL, in a schema of its own
  • Uploads sit on our own CDN server, identified by SHA-256 hash
  • Sessions live in ba_sessions and expire after 7 days idle
  • Passwords are never stored as text. BetterAuth scrypt-hashes them

CSRF protection, HTTPS, a content security policy and automated content scanning are all on. None of that makes anything sent over the internet perfectly safe, and we will not pretend otherwise.

05

Cookies

There are three, and none of them are for advertising:

  • Session: weggle.sid, keeps you signed in
  • CSRF: stops other sites submitting forms as you
  • Maintenance bypass: weggle.maintenance_bypass, only if you used a bypass key

Full detail is in the Cookie Policy.

06

Your rights

  • Access: ask what we hold about you
  • Correct: fix anything wrong, mostly from settings
  • Delete: remove the account and everything attached, see the deletion policy
  • Export: ask for a copy of your data
  • Object: to particular processing, write to us
  • Withdraw consent: at any time, where consent is the basis

Write to support@weggle.xyz. We answer within 30 days.

07

Children

Weggle is not built for, or aimed at, anyone under 13, and we do not knowingly hold data about them. Accounts found to belong to under-13s are deleted along with their data. If you believe a child has given us information, write to supex@weggle.xyz.

08

Where the servers are

All of them are in the European Union. Using the site from outside the EU means your information is transferred there and processed there. It is handled the same way regardless of where you are reading this from.

09

Changes to this policy

This gets updated from time to time, and the date at the top changes when it does. Anything significant comes with an email or a banner on the site.

10

Contact

Privacy questions and requests: support@weggle.xyz

Everything else: supex@weggle.xyz

Questions about this document go to supex@weggle.xyz. Put LEGAL: at the front of the subject line and it gets read sooner.