Skip to policy
WhateverGo
Legal centre Privacy Terms Cookies & storage AI notice

Privacy

Privacy Policy

This policy explains what WhateverGo collects, why it is used, who receives it, how long it is kept, and the choices available to you.

Effective 17 July 2026Last updated 30 July 2026Version 2.3
On this page Who we are Data we handle Why we use it Recipients International processing Retention Your rights Young users Regional notices Contact

1. Who we are and what this covers

WhateverGo is an independent educational project operated by the owner and administrator of whatevergo.com. For privacy questions, requests and complaints, email yuchenwang0115@gmail.com.

This policy covers the public website, account system, private study workspace, AI tutor features and related APIs. It does not govern websites or services that you open independently through external links.

Important: WhateverGo is an overseas website and is not established in Mainland China. A person in Mainland China who enters information into WhateverGo sends it directly to an overseas service. This policy does not describe that ordinary collection as a transfer by a Mainland China data controller from China to another country.

2. Data we handle

CategoryExamplesSource
Account and profileEmail address, display name, Google account identifier where you choose Google sign-in, internal user ID, verification and administrator status, plus any administrator-only access restriction status, reason and timestamp.You, Google sign-in and WhateverGo administrators.
Authentication and securityHashed session token, CSRF token, expiry and last-seen times, password hash, salt and password-work-factor record for an enabled email-password account, hashed email-verification or reset token, rate-limit records, peppered device identifier, hashed or minimised IP address and user-agent signals, plus a short-lived live-presence record containing the current IP address and approximate country, region and city.Your browser and Cloudflare network requests.
Study and chat contentSubject choices, saved chats, prompts, replies, uploaded images sent for vision analysis, completion state and tutor preferences.You and your use of the workspace.
FeedbackThe feedback type and message, the page title and path where it was submitted, viewport size, submission time and processing status, linked to your signed-in account.You and the feedback box.
Technical and service dataRequest time, route, response status, error and security logs, approximate network/region signals, aggregate site measurements and a daily aggregate count of anonymous homepage visits.Your device, Cloudflare and the service.
Browser storageTheme, locally saved tutor chats, current chat, highlights, completed lessons, navigation state, feedback-button position and a pseudonymous device ID.Stored locally by your browser.
CommunicationsEmails, privacy requests, support messages and information needed to resolve them.You.

We do not ask for payment-card data, government identity numbers, health records or advertising profiles. Do not place sensitive personal information, confidential school records or examination answers that must remain private into an AI prompt.

3. Why we use data

We use personal data only for the following purposes:

  • create and secure accounts, complete Google sign-in or enabled email-password sign-in and maintain sessions;
  • provide saved study workspaces, chats, notes and AI tutor responses;
  • receive, investigate and resolve feedback about content and service features;
  • show the restricted site administrator which signed-in accounts are currently online and their approximate location, with the current IP address available only on demand for support and security;
  • prevent abuse, enforce quotas, diagnose failures and protect users and the service;
  • operate, measure and improve reliability and accessibility;
  • answer support, rights and legal requests; and
  • comply with applicable law and establish, exercise or defend legal claims.

UK lawful bases, where UK data protection law applies

PurposeLawful basis
Account, authentication, saved workspace and requested AI featuresPerformance of the agreement you request.
Security, fraud prevention, rate limits, service reliability and privacy-preserving aggregate measurementLegitimate interests in operating a safe and dependable educational service, balanced against user rights.
Legal and rights requestsLegal obligation, or legitimate interests in handling claims and compliance.
Any future optional, non-essential tracking or communicationsConsent where required. It will be requested separately and may be withdrawn.

WhateverGo does not sell personal data, run behavioural advertising or use personal data for direct marketing.

4. Service providers and recipients

RecipientRole and data involved
CloudflareHosts the website, Worker, D1 database and KV storage; provides network security and privacy-preserving Web Analytics. When enabled, Cloudflare's email service sends verification and password-reset messages. Network requests may include IP address, user agent and request metadata.
GoogleProvides OAuth sign-in. Google receives the sign-in request and returns identity attributes that you approve, normally email, display name and a Google account identifier.
DeepSeekProcesses text prompts and recent conversation context for text AI responses. WhateverGo does not intentionally include your account email or internal user ID in that AI payload.
Moonshot AI / KimiProcesses prompts and images submitted to vision features. WhateverGo does not intentionally include your account email or internal user ID in that AI payload.
Public authorities or advisersOnly when reasonably necessary to comply with law, protect rights or security, or handle a legal claim.

AI providers process submitted content under their own platform terms and technical practices. Kimi states that API inputs and outputs are not used for model training. DeepSeek documents server-side context caching for API performance; unused cache is generally removed after a period ranging from hours to days. WhateverGo does not promise that every provider applies zero retention unless a binding provider commitment says so. See the AI Data & Safety Notice.

Provider policies: Cloudflare, Google, DeepSeek, and Kimi Open Platform.

5. International processing

WhateverGo is an online service with infrastructure and providers in more than one jurisdiction. Depending on the feature, data may be processed through Cloudflare's global network, Google services, and AI providers in Mainland China. The destination may therefore have different privacy laws from your home jurisdiction.

Where UK transfer rules apply, WhateverGo will use an applicable adequacy regulation, contractual safeguards such as the UK International Data Transfer Agreement or UK Addendum, or another lawful exception as appropriate. For Hong Kong and Singapore, reasonable contractual and organisational measures are used to require protection comparable to the applicable local standard.

Mainland China clarification: WhateverGo's direct collection by an overseas service is not presented as an outbound transfer performed by an organisation established in Mainland China. Separately, sending an AI prompt to DeepSeek or Kimi may mean that content is processed in Mainland China.

6. How long we keep data

RecordTypical retention
Account profileUntil account deletion, then removed or de-identified unless law or a live security/legal matter requires limited retention.
SessionUp to 7 days, or earlier on sign-out, revocation or deletion.
Live presence, approximate location and current IP addressAbout 5 minutes after the last visible-page heartbeat; overwritten by newer activity and removed automatically or on sign-out.
Recognised device recordRemoved after about 30 days of inactivity.
Google OAuth stateAbout 10 minutes.
Email verification/reset token recordsAbout 30 minutes when the optional email-password account feature is enabled.
Daily anonymous homepage-visit totalStored as a date and aggregate count, without an account identifier; retained only as long as reasonably needed for basic service measurement.
Rate-limit countersReset by the applicable minute or daily window and cleaned up automatically.
Saved study and chat dataUntil you delete it, delete the account or request deletion, subject to short operational backup and legal exceptions.
Feedback submissionsUntil account deletion or an earlier valid deletion request, subject to limited security, operational and legal exceptions.
Browser local storageUntil the site or you clear it, or browser settings remove it.
Security and error logsOnly as long as reasonably needed for security, diagnosis and legal obligations; periods may vary with severity.

Provider-side retention is governed by provider arrangements and may differ. Deletion from active systems may not immediately remove encrypted backups, which are isolated and expire on their normal rotation.

7. Security and automated decisions

Measures include HTTPS, secure and HttpOnly session cookies, hashed session secrets, CSRF protection, strict origin controls, rate limits, pseudonymous device identifiers, restricted administrator access, security headers and minimisation of information sent to AI providers. No online system is risk-free, so do not submit data that is unnecessary for study.

WhateverGo does not use personal data to make decisions that produce legal or similarly significant effects. AI answers assist study; they do not determine grades, admission, employment, credit or access to public services.

8. Your choices and rights

Depending on where you live and which law applies, you may ask to access, correct, delete or restrict personal data; object to certain processing; receive portable data; withdraw consent; or complain to a regulator. Legal exceptions may apply.

Send a request to yuchenwang0115@gmail.com. Include the account email, the right you want to use and enough detail to locate the data. We may ask for proportionate proof that you control the account, but do not send identity documents unless specifically and securely requested.

See the Data Rights & Account Deletion Guide for steps, regional response periods and regulator contacts.

9. Young users

WhateverGo is intended for people aged 16 or older. Do not create an account or use AI features if you are under 16. If you are under 18, use the service only with permission from a parent or guardian and appropriate supervision.

If you believe a child under 16 has provided personal data, contact us so that it can be reviewed and deleted. Read the Young Users & Parents Notice.

10. Regional privacy supplements

中国大陆

WhateverGo 是在中国大陆境外运营的网站,并非在中国大陆设立的个人信息处理者。用户直接访问本网站并提交资料,属于境外网站直接收集和处理资料;本政策不会把这一过程错误描述为“中国境内处理者向境外提供个人信息”。

如果 WhateverGo 的活动符合《中华人民共和国个人信息保护法》第三条所规定的域外适用情形,例如以向中国境内自然人提供产品或服务为目的处理其个人信息,WhateverGo 将在适用范围内遵守该法,包括告知、最小必要、安全保护、个人权利请求及必要的境内代表或专门机构等要求。若某项功能在适用法律要求的合规机制完成前无法合法提供,WhateverGo 可以在相关地区暂停该功能。

文本或图片 AI 功能可能把用户主动提交的内容发送给位于中国大陆的 DeepSeek 或 Kimi 处理。这是向中国大陆提供内容,并非声称由中国境内处理者将资料“出境”。未满 16 周岁的用户不得使用本服务,因此本服务不以处理不满 14 周岁未成年人的个人信息为目的。

你可以请求查阅、复制、更正、补充或删除适用范围内的个人信息,撤回基于同意的处理,或要求解释处理规则。请发送邮件至 yuchenwang0115@gmail.com。参考:《中华人民共和国个人信息保护法》官方文本。

United Kingdom

Where the UK GDPR and Data Protection Act 2018, as amended, apply, the WhateverGo operator is the controller for account and service data. The lawful bases are listed in section 3. You may have rights of access, rectification, erasure, restriction, objection, portability, consent withdrawal and complaint. A valid request is normally answered within one month, subject to lawful extensions.

You may complain to the UK Information Commissioner's Office. International transfers are handled as described in section 5. Any electronic-storage or communications technology is also handled in accordance with PECR, as amended.

Hong Kong SAR

Where the Personal Data (Privacy) Ordinance applies, WhateverGo follows the six Data Protection Principles: fair and necessary collection, accuracy and limited retention, use for the stated or compatible purpose, security, openness and access/correction. WhateverGo does not use personal data for direct marketing.

A data access or correction request may be made by email; a compliant data access request is handled within the statutory period, generally 40 days, subject to permitted exceptions and any prescribed form requirements. Cross-border providers are managed through reasonable contractual and security measures. Although breach notification is not generally a statutory requirement in Hong Kong, WhateverGo will assess notification to affected users and the PCPD when appropriate.

You may contact the Office of the Privacy Commissioner for Personal Data.

Singapore

Where the Personal Data Protection Act 2012 applies, WhateverGo observes the applicable notification, purpose limitation, consent or other lawful exception, access and correction, accuracy, protection, retention limitation, transfer limitation, breach notification and accountability obligations.

The contact in section 11 acts as the privacy contact for Singapore. Overseas recipients will be subject to measures intended to provide a standard of protection comparable to the PDPA. You may contact the Personal Data Protection Commission after first giving us a reasonable opportunity to address the issue.

11. Changes and contact

We may update this policy when the service, providers or law changes. Material changes will be highlighted on the site or, where appropriate, sent to account holders before they take effect. The date and version at the top identify the current policy.

Privacy contact and service operator: yuchenwang0115@gmail.com. Website: whatevergo.com.

Legal note: This document records WhateverGo's operational privacy commitments. It is not personal legal advice. Mandatory rights under applicable law prevail over any inconsistent wording.
© 2026 WhateverGo · Independent educational project
Legal centreTermsCookiesAI noticeYoung usersData rights