Version 1.1, effective October 10, 2026
Wondara ("Wondara", "we", "us") is a research and education website for users in the United States. This policy explains what personal information we collect on wondara.org, why, who processes it for us, how long we keep it and the choices you have.
We do not sell your personal information, we do not share it for cross-context behavioral advertising, and we do not use advertising or tracking cookies.
1. Information we collect
- Watch requests: your email address, the topics you choose to Watch, the page where you asked, and a record of your consent (policy version, time, and whether you confirmed by email).
- Account and sign-in: your email address, whether it is verified, and an opaque session identifier stored in a strictly necessary cookie. Sign-in uses one-time email links; we store only a hash of each link token, and links expire after 30 minutes.
- Your activity on Wondara while signed in: topics you Watch or save, alert preferences, and the alerts we send you.
- Contact form: the email address, topic and message you submit. Please do not include sensitive health information.
- First-party analytics: pages viewed and interactions on Wondara, the referring page and campaign tags, linked to a random identifier stored in your browser (local storage "rp_anon_id" and session storage "rp_session_id") and, if you are signed in, to your account. We also run Umami, a self-hosted, cookie-free analytics tool that records aggregate page views, referrers, browser, device type and country.
- Technical data: IP address, browser user agent and request details in server and security logs, and email delivery events (delivered, bounced, spam complaint) reported by our email provider.
We do not ask for, and you should not send us, diagnoses, medications you take, or other health records. Which topics you Watch may reveal health-related interests; we treat that as sensitive and use it only to provide the service you asked for.
2. How we use information
- To send the emails you ask for: Watch confirmations, sign-in links and alerts when a Watched topic meaningfully changes.
- To run your account, keep it secure, prevent abuse and debug problems.
- To answer contact requests, corrections and privacy requests.
- To understand, in aggregate, which research pages are useful so we can improve them.
- To comply with law and enforce our Terms of Use.
Our internal operations system receives pseudonymous events about sign-ups, Watches and consent (for example "a Watch was confirmed") identified only by a one-way hash of your email address, never the address itself, sign-in links or message content.
3. Service providers (processors)
We share personal information only with providers that process it on our behalf under contract:
- Postmark (ActiveCampaign, LLC), USA: sends transactional email (confirmations, sign-in links, alerts) and reports delivery, bounce and complaint events.
- Microsoft 365 (Microsoft Corporation, provided through GoDaddy), USA: hosts our hello@wondara.org and privacy@wondara.org mailboxes.
- GoDaddy (GoDaddy Operating Company, LLC), USA: domain registration, DNS and inbound email security filtering (Proofpoint).
- Hetzner Online GmbH: hosts our servers and server snapshots in its Nuremberg, Germany data center.
- Backblaze, Inc., USA: stores our encrypted off-site database backups.
- If we add a content-delivery or security network (such as Cloudflare), we will list it here before it processes any traffic.
We may also disclose information if required by law, to protect the rights and safety of users or others, or as part of a merger or acquisition, in which case this policy continues to apply.
4. How long we keep information
- Unconfirmed Watch requests: deleted 30 days after the request.
- One-time sign-in and confirmation tokens: expire after 30 minutes; records are deleted after 30 days.
- Sessions: expire after 30 days of inactivity.
- Account, Watches and preferences: until you delete your account, or after 24 months with no sign-in and no opened alert, after a reminder email.
- Consent records: for as long as the consent is active plus 3 years, to show that we had permission.
- Do-not-email list: a one-way hash of addresses that unsubscribed, bounced or complained, kept so we never email them again.
- Contact messages: 24 months after the conversation ends.
- First-party analytics and Umami data: 13 months, then deleted or aggregated.
- Server and security logs: 14 days. Database backups: overwritten on a rolling 30-day cycle.
5. Your rights and choices
You can ask us to access, correct, delete or export your personal information, or to stop processing it, by emailing privacy@wondara.org from the address concerned. We verify requests by email and respond within 30 days (45 days where California law allows). You can unsubscribe from any alert with the link in the email or turn alerts off in your preferences. There is no charge, and we will not treat you differently for exercising your rights.
California (CCPA/CPRA): in the past 12 months we collected identifiers (email, IP address), internet activity (pages and interactions), and inferences limited to the topics you choose to Watch, for the purposes in section 2. We do not sell or share personal information and do not use sensitive personal information to infer characteristics. You have the right to know, delete, correct and limit, and you may use an authorized agent.
Where information is processed: Wondara is intended for users in the United States. Our servers are hosted by Hetzner in Germany and our encrypted backups are stored with Backblaze in the United States; our email and mailbox providers are in the United States. Wherever it is processed, this policy applies to your information and you can use the rights above.
Washington, Nevada and similar consumer health data laws: topic choices may be consumer health data. We collect it only to provide the Watch you requested, do not sell or share it, and you may access, delete or withdraw consent at privacy@wondara.org.
7. Security
We use HTTPS, hashed sign-in tokens, salted hashes in logs, access controls and encrypted backups. No system is perfectly secure; if a breach affects you, we will notify you as the law requires.
8. Children
Wondara is not directed to children and is intended for adults 18 and over. We do not knowingly collect information from children under 16. If you believe a child has given us information, contact privacy@wondara.org and we will delete it.
9. Changes to this policy
We will post changes here with a new version date. If a change materially affects how we use information you already gave us, we will email account holders before it takes effect.
10. Contact
Privacy requests: privacy@wondara.org. General questions: hello@wondara.org.
Wondara Team