1. Who we are and what this covers
WhateverGo is an independent educational project operated by the owner and administrator of whatevergo.com. For privacy questions, requests and complaints, email yuchenwang0115@gmail.com.
This policy covers the public website, account system, private study workspace, AI tutor features and related APIs. It does not govern websites or services that you open independently through external links.
2. Data we handle
| Category | Examples | Source |
|---|---|---|
| Account and profile | Email address, display name, Google account identifier where you choose Google sign-in, internal user ID, verification and administrator status, plus any administrator-only access restriction status, reason and timestamp. | You, Google sign-in and WhateverGo administrators. |
| Authentication and security | Hashed session token, CSRF token, expiry and last-seen times, password hash, salt and password-work-factor record for an enabled email-password account, hashed email-verification or reset token, rate-limit records, peppered device identifier, hashed or minimised IP address and user-agent signals, plus a short-lived live-presence record containing the current IP address and approximate country, region and city. | Your browser and Cloudflare network requests. |
| Study and chat content | Subject choices, saved chats, prompts, replies, uploaded images sent for vision analysis, completion state and tutor preferences. | You and your use of the workspace. |
| Feedback | The feedback type and message, the page title and path where it was submitted, viewport size, submission time and processing status, linked to your signed-in account. | You and the feedback box. |
| Technical and service data | Request time, route, response status, error and security logs, approximate network/region signals, aggregate site measurements and a daily aggregate count of anonymous homepage visits. | Your device, Cloudflare and the service. |
| Browser storage | Theme, locally saved tutor chats, current chat, highlights, completed lessons, navigation state, feedback-button position and a pseudonymous device ID. | Stored locally by your browser. |
| Communications | Emails, privacy requests, support messages and information needed to resolve them. | You. |
We do not ask for payment-card data, government identity numbers, health records or advertising profiles. Do not place sensitive personal information, confidential school records or examination answers that must remain private into an AI prompt.
3. Why we use data
We use personal data only for the following purposes:
- create and secure accounts, complete Google sign-in or enabled email-password sign-in and maintain sessions;
- provide saved study workspaces, chats, notes and AI tutor responses;
- receive, investigate and resolve feedback about content and service features;
- show the restricted site administrator which signed-in accounts are currently online and their approximate location, with the current IP address available only on demand for support and security;
- prevent abuse, enforce quotas, diagnose failures and protect users and the service;
- operate, measure and improve reliability and accessibility;
- answer support, rights and legal requests; and
- comply with applicable law and establish, exercise or defend legal claims.
UK lawful bases, where UK data protection law applies
| Purpose | Lawful basis |
|---|---|
| Account, authentication, saved workspace and requested AI features | Performance of the agreement you request. |
| Security, fraud prevention, rate limits, service reliability and privacy-preserving aggregate measurement | Legitimate interests in operating a safe and dependable educational service, balanced against user rights. |
| Legal and rights requests | Legal obligation, or legitimate interests in handling claims and compliance. |
| Any future optional, non-essential tracking or communications | Consent where required. It will be requested separately and may be withdrawn. |
WhateverGo does not sell personal data, run behavioural advertising or use personal data for direct marketing.
5. International processing
WhateverGo is an online service with infrastructure and providers in more than one jurisdiction. Depending on the feature, data may be processed through Cloudflare's global network, Google services, and AI providers in Mainland China. The destination may therefore have different privacy laws from your home jurisdiction.
Where UK transfer rules apply, WhateverGo will use an applicable adequacy regulation, contractual safeguards such as the UK International Data Transfer Agreement or UK Addendum, or another lawful exception as appropriate. For Hong Kong and Singapore, reasonable contractual and organisational measures are used to require protection comparable to the applicable local standard.
6. How long we keep data
| Record | Typical retention |
|---|---|
| Account profile | Until account deletion, then removed or de-identified unless law or a live security/legal matter requires limited retention. |
| Session | Up to 7 days, or earlier on sign-out, revocation or deletion. |
| Live presence, approximate location and current IP address | About 5 minutes after the last visible-page heartbeat; overwritten by newer activity and removed automatically or on sign-out. |
| Recognised device record | Removed after about 30 days of inactivity. |
| Google OAuth state | About 10 minutes. |
| Email verification/reset token records | About 30 minutes when the optional email-password account feature is enabled. |
| Daily anonymous homepage-visit total | Stored as a date and aggregate count, without an account identifier; retained only as long as reasonably needed for basic service measurement. |
| Rate-limit counters | Reset by the applicable minute or daily window and cleaned up automatically. |
| Saved study and chat data | Until you delete it, delete the account or request deletion, subject to short operational backup and legal exceptions. |
| Feedback submissions | Until account deletion or an earlier valid deletion request, subject to limited security, operational and legal exceptions. |
| Browser local storage | Until the site or you clear it, or browser settings remove it. |
| Security and error logs | Only as long as reasonably needed for security, diagnosis and legal obligations; periods may vary with severity. |
Provider-side retention is governed by provider arrangements and may differ. Deletion from active systems may not immediately remove encrypted backups, which are isolated and expire on their normal rotation.
7. Security and automated decisions
Measures include HTTPS, secure and HttpOnly session cookies, hashed session secrets, CSRF protection, strict origin controls, rate limits, pseudonymous device identifiers, restricted administrator access, security headers and minimisation of information sent to AI providers. No online system is risk-free, so do not submit data that is unnecessary for study.
WhateverGo does not use personal data to make decisions that produce legal or similarly significant effects. AI answers assist study; they do not determine grades, admission, employment, credit or access to public services.
8. Your choices and rights
Depending on where you live and which law applies, you may ask to access, correct, delete or restrict personal data; object to certain processing; receive portable data; withdraw consent; or complain to a regulator. Legal exceptions may apply.
Send a request to yuchenwang0115@gmail.com. Include the account email, the right you want to use and enough detail to locate the data. We may ask for proportionate proof that you control the account, but do not send identity documents unless specifically and securely requested.
See the Data Rights & Account Deletion Guide for steps, regional response periods and regulator contacts.
9. Young users
WhateverGo is intended for people aged 16 or older. Do not create an account or use AI features if you are under 16. If you are under 18, use the service only with permission from a parent or guardian and appropriate supervision.
If you believe a child under 16 has provided personal data, contact us so that it can be reviewed and deleted. Read the Young Users & Parents Notice.
10. Regional privacy supplements
中国大陆
WhateverGo 是在中国大陆境外运营的网站,并非在中国大陆设立的个人信息处理者。用户直接访问本网站并提交资料,属于境外网站直接收集和处理资料;本政策不会把这一过程错误描述为“中国境内处理者向境外提供个人信息”。
如果 WhateverGo 的活动符合《中华人民共和国个人信息保护法》第三条所规定的域外适用情形,例如以向中国境内自然人提供产品或服务为目的处理其个人信息,WhateverGo 将在适用范围内遵守该法,包括告知、最小必要、安全保护、个人权利请求及必要的境内代表或专门机构等要求。若某项功能在适用法律要求的合规机制完成前无法合法提供,WhateverGo 可以在相关地区暂停该功能。
文本或图片 AI 功能可能把用户主动提交的内容发送给位于中国大陆的 DeepSeek 或 Kimi 处理。这是向中国大陆提供内容,并非声称由中国境内处理者将资料“出境”。未满 16 周岁的用户不得使用本服务,因此本服务不以处理不满 14 周岁未成年人的个人信息为目的。
你可以请求查阅、复制、更正、补充或删除适用范围内的个人信息,撤回基于同意的处理,或要求解释处理规则。请发送邮件至 yuchenwang0115@gmail.com。参考:《中华人民共和国个人信息保护法》官方文本。
United Kingdom
Where the UK GDPR and Data Protection Act 2018, as amended, apply, the WhateverGo operator is the controller for account and service data. The lawful bases are listed in section 3. You may have rights of access, rectification, erasure, restriction, objection, portability, consent withdrawal and complaint. A valid request is normally answered within one month, subject to lawful extensions.
You may complain to the UK Information Commissioner's Office. International transfers are handled as described in section 5. Any electronic-storage or communications technology is also handled in accordance with PECR, as amended.
Hong Kong SAR
Where the Personal Data (Privacy) Ordinance applies, WhateverGo follows the six Data Protection Principles: fair and necessary collection, accuracy and limited retention, use for the stated or compatible purpose, security, openness and access/correction. WhateverGo does not use personal data for direct marketing.
A data access or correction request may be made by email; a compliant data access request is handled within the statutory period, generally 40 days, subject to permitted exceptions and any prescribed form requirements. Cross-border providers are managed through reasonable contractual and security measures. Although breach notification is not generally a statutory requirement in Hong Kong, WhateverGo will assess notification to affected users and the PCPD when appropriate.
You may contact the Office of the Privacy Commissioner for Personal Data.
Singapore
Where the Personal Data Protection Act 2012 applies, WhateverGo observes the applicable notification, purpose limitation, consent or other lawful exception, access and correction, accuracy, protection, retention limitation, transfer limitation, breach notification and accountability obligations.
The contact in section 11 acts as the privacy contact for Singapore. Overseas recipients will be subject to measures intended to provide a standard of protection comparable to the PDPA. You may contact the Personal Data Protection Commission after first giving us a reasonable opportunity to address the issue.
11. Changes and contact
We may update this policy when the service, providers or law changes. Material changes will be highlighted on the site or, where appropriate, sent to account holders before they take effect. The date and version at the top identify the current policy.
Privacy contact and service operator: yuchenwang0115@gmail.com. Website: whatevergo.com.