Privacy Policy~ 3 min
Privacy Policy
World Watch ("we") respects user privacy and handles personal data responsibly. This policy covers what we collect, how we use it, third parties, and how to request access.
* This policy is a draft. It will be replaced with a finalized version after legal review.
1. What we collect
- Access logs: IP address, User-Agent, referrer URL, pageviews (Vercel Web Analytics)
- Analytics measurement (Phase 2 enhancements): anonymous identifier (UUID stored in localStorage + Cookie, valid for 1 year, used to identify returning visitors); session identifier (UUID stored in localStorage, 30-minute timeout, used for in-session behavior analysis); SHA-256 hash of IP address (the raw IP is NOT stored; used only for country-level aggregation and bot / human classification, not personally identifiable); referral path (referrer URL is stored as scheme + host + path only, query string is discarded) and UTM parameters (utm_source / utm_medium / utm_campaign, etc.); engagement metrics (scroll depth at 25 / 50 / 75 / 100 % and dwell time in 30-second chunks); bot detection (User-Agent pattern matching to classify bot vs. human)
- Local settings: language, filter state, view history (localStorage, browser-only)
- Account info (registered users only): email, display name, auth tokens
- Social features: comments, likes, bookmarks, follow relationships
2. How we use it
- Service operation (article delivery, authentication, social features)
- Quality improvement (anonymous aggregation via Vercel Analytics, error monitoring via Sentry)
- Abuse prevention (rate limit, IP allowlist, etc.)
- Editorial improvement (aggregated reading patterns, no personal identification)
3. Cookies / local storage
We use cookies and localStorage to maintain authenticated sessions and improve usability. We do NOT use third-party advertising cookies. You can delete or disable them in browser settings; some features (e.g. authentication) may stop working.
4. Third-party services
We do not provide personal information to third parties except as required by law. We use the following cloud services as part of operating the service: Vercel (static hosting + Analytics), Fly.io (backend), Supabase (database), Google AI (Gemini translation), Sentry (error monitoring). Each provider's privacy policy applies.
5. Access / correction / deletion
To request access, correction, or deletion of your personal data, please contact info@gospel-ai.tech. We will respond after identity verification, within reasonable scope.
Deletion requests will be processed within 30 days as a rule (in line with GDPR Article 17 and the revised Act on the Protection of Personal Information, Article 35). Records keyed by anonymous_id in the custom_events / analytics_sessions tables are included in the scope of deletion.
6. Revision history
- 2026-05-04: v0.1 draft released
- 2026-05-17: v0.2 — added newly collected items for Phase 2 analytics, clarified 30-day deadline for deletion requests