This page is WeSearch's full privacy stance, written for humans. We try to keep the inventory small enough to fit on one page, because if you can't read your privacy policy in five minutes, the platform is doing too much. The structure of this page is: what we collect, what we don't, what we share, how long things live, and how to delete it.
What we collect
Identity (anonymous)
The first time you tap a reaction or post a comment, your browser generates a 32-byte random API key and a stable display handle ("Plain Loom 638") derived deterministically from that key. The key is transmitted over HTTPS in the Authorization header when an authenticated feature needs it. We store a hash of the key on our server so we can verify your reactions are yours; we cannot reverse that hash to recover the original key.
Reactions and comments
Reactions you post (👍 ❤️ 🔥 😂 🤔) are stored against the hash of your API key, the URL of the story, and the timestamp. Comments are stored similarly: the comment body, the parent comment id (for threading), the hashed key, and the timestamp. Comments are public by default.
Story view counts
Each /s/<slug> page increments an aggregate view counter on the server. The counter is a single integer per story; it is not associated with any specific reader.
Server logs
Standard HTTP access logs: IP address, user-agent string, request path, response status, timing. Logs rotate within 30 days. We use them for operational debugging, security, traffic management, and service reliability.
Operational analytics
Public pages use Google Analytics for limited audience measurement such as page views and basic technical context including browser/device, approximate geography, and referrer. We review these results in aggregate to operate and improve the service. We do not use them to personalize the news feed, target advertising, or sell reader data.
Push subscriptions
If you opt in to push notifications, the browser hands us a Web Push subscription endpoint (a URL on the browser vendor's push server) and a public key. We store these against your hashed API key. If you opt out or revoke browser permission, the entry is deleted.
Donations
If you donate via Stripe, Stripe collects payment information. We never see your card. We receive a Stripe customer id and a charge confirmation; that's it. If you provide an email at donation, it's stored only against the donation record, not the API key.
Optional email-recovery
If you choose to set up cross-device recovery, you provide an email address; we store a hash of (your email + a server salt) along with a hash of your key. The plaintext email is never stored. Recovery sends a single-use link to that email.
What we do not collect
- Real names, addresses, phone numbers. Not asked, not stored.
- A WeSearch reading-history profile. We do not build a story-by-story profile tied to your local reader key or use past reading to rank the home feed. Operational analytics can still receive page-view and interaction data as described above.
- Behavior used for personalization. We do not use scroll, mouse, dwell, or hover behavior to personalize news or target ads.
- A purchased cross-site profile. We do not buy, combine, or sell cross-site browsing data, and we do not install ad-retargeting pixels.
- Device fingerprints. We use a hashed API key, which you control. We don't compute or store browser fingerprints.
- BYOK credentials. AI keys you provide for in-browser features (Tenor, OpenAI) are forwarded to the upstream provider per request and never persisted server-side.
- Email addresses by default. Email is strictly optional and only used for recovery.
- Advertising-network profiles. We do not run Meta Pixel, programmatic-ad tags, or retargeting audiences.
Cookies and storage
WeSearch uses localStorage on your device — not cookies — for:
- Your API key (the only thing that persists across sessions on your device)
- The preferred-feed-category you last picked
- BYOK keys you've entered (browser-only, never sent to our server)
- Tour-completed flag
- Your "Mine" feed list
- Bookmarks and friends list (also synced server-side under your hashed key)
- OG-image cache (a tiny in-memory map of slug → cached image URL)
Most of this stays on your device. A value is sent when the feature requires it—for example, the API key in an Authorization header, a selected feed used to fetch stories, or a BYOK credential forwarded to the provider you chose. WeSearch does not use browser storage for ad targeting. Delivery, analytics, translation, and feature providers may use their own cookies or similar identifiers under their policies.
Third parties
WeSearch is an aggregator, which means we proxy your requests to upstream providers in some cases. The third parties we talk to are limited to:
- Cloudflare sits in front of our origin server as a CDN + DDoS shield. Every request to wesearch.press hits a Cloudflare edge first. Cloudflare receives your IP, user-agent, requested path, and timing data for delivery, security, and traffic management.
- Google Analytics provides operational audience measurement on public pages. Google receives the browser and request data needed to provide that service. We use the results in aggregate, not for personalized news ranking or advertising.
- Google Translate is loaded on the homepage to provide language translation. Loading or using it can send your IP address, browser information, page URL, and page content to Google under Google's terms.
- Open-Meteo for weather (your latitude/longitude is forwarded only when you query weather).
- Original publisher CDNs for OG images on story pages (the publisher's image URL is fetched server-side and cached).
- Stripe for donation processing.
- VAPID push servers (Mozilla, Google, Apple) for delivering Web Push notifications.
- Optional BYOK providers (Tenor, OpenAI, Anthropic) when you explicitly use a feature requiring your own key.
We do not pass these providers a real-name WeSearch profile because we do not require one. Direct browser services such as Cloudflare, Google Analytics, Google Translate, Stripe, and push gateways still receive the technical or transaction data needed to provide their service, under their own policies.
How long things live
- API key hash: forever, until you reset.
- Reactions and comments: forever, unless you delete them. You can delete any comment you posted.
- Server access logs: 30 days, then rotated.
- Push subscription: until you opt out or revoke.
- Email-recovery hash: until you opt out.
- Donation records: kept for accounting purposes per applicable law.
How to delete your data
You can:
- Reset your local API key to start fresh. Old comments stay public under their old handle but no longer link to you. Settings → Identity → Reset key.
- Delete individual comments at any time from the comment row.
- Opt out of push from Settings → Notifications.
- Opt out of email recovery from Settings → Identity.
- Request full deletion via /support. We will delete every record tied to your hashed key (including comments, reactions, push subscription, and any email-recovery hash) within 7 days and confirm by email if you provide one.
Government requests
If WeSearch receives a lawful subpoena, we will respond per applicable law. The information we have is limited: hashed API keys, public comments tied to those hashes, push subscription endpoints, operational analytics, and short-rotation IP logs. We do not have email addresses by default, do not require real names, and do not build a reading-history profile tied to your reader key.
Children
WeSearch is not designed for children under 13. We do not knowingly collect any data from anyone under 13. If you believe a child is using WeSearch and want their data deleted, contact /support.
Changes to this policy
We post a dated changelog at the bottom of this page when the privacy stance changes. We don't email you about changes because we don't have your email by default; check this page when you next visit if it matters to you.
Frequently asked
Do you sell my data?
No. We do not sell reader data, create ad-targeting audiences, or use operational analytics to personalize news ranking.
How do I delete everything tied to my account?
Email /support requesting full deletion. We delete every record tied to your hashed API key (comments, reactions, push subscription, optional email-recovery hash) within 7 days.
Do you use cookies?
WeSearch uses localStorage for your key and preferences. Delivery, analytics, translation, and feature providers may use their own cookies or similar identifiers under their policies; WeSearch does not use them for ad targeting.
What if a court asks for my data?
We respond per applicable law. The information can include hashed keys, public comments, short-rotation IP logs, operational analytics, and an optional push endpoint. We do not require a real name or email and do not build a per-key reading-history profile.