Privacy Policy
Last updated 13 August 2026 · Applies to weienwong.online and every service on its subdomains.
Operator note — remove this box before publishing. This policy accurately describes what the software currently does, but it is not legal advice. Fill in the registered entity and governing jurisdiction in the “Who runs this service” and “Governing law” sections below, and have a qualified lawyer review the result if you operate in the EU, UK or California.
Contents
1. Who runs this service
To complete: name the legal entity that operates this service (sole trader, LLC, Ltd, etc.), its registered address, and any company number. Under GDPR Article 13 and CCPA this identification is mandatory, not optional.
weienwong.online (“the Service”) is operated by Weien Wong (“we”, “us”). You can reach us at contact@weienwong.online for any question about this policy or about data we hold on you.
2. What we collect
Account information
When you create an account we store your email address and a bcrypt hash of your password. We never store your password in a form we can read.
Session records
Each sign-in creates a session record so that you can be signed out again and so a stolen session can be revoked. It holds a session identifier and its issue and expiry times.
Visit analytics
Every page request to the hub and its subdomains is logged. Each record contains:
- the path visited and which subdomain served it;
- your IP address;
- an approximate country, region and city derived from that IP address;
- your browser’s user-agent string;
- the referring URL, where your browser sends one;
- the time of the request;
- a pseudonymous visitor identifier that rotates daily, used to count unique visitors without linking them across days;
- a flag marking requests we identify as automated crawlers.
We want to be explicit about one point that is often glossed over: the pseudonymous visitor identifier is in addition to, not instead of, the IP address. The raw IP address is retained in the log.
3. Why we collect it
- Account and session data — to sign you in, keep you signed in across our subdomains, and let you sign out.
- Visit analytics — to understand which services are used, to see where traffic comes from, and to detect abuse such as automated signups or credential-stuffing.
- Rate limiting — failed sign-in attempts are counted against your IP address to slow down password guessing.
We do not sell personal data, and we do not run third-party advertising or tracking pixels.
4. Cookies and single sign-on
Signing in sets an authentication cookie scoped to .weienwong.online. That
scope is deliberate — it is what allows one account to work across every service on our
subdomains without signing in again. It also means that signing in on the hub
signs you in everywhere, and signing out revokes that access everywhere.
We also store your light or dark theme preference in your browser’s local storage. That never leaves your device and is not personal data.
We set no advertising or cross-site tracking cookies.
5. Third parties that receive data
To turn an IP address into an approximate location, we send that IP address to ip-api.com, a third-party geolocation provider. No other personal data is included in that request, and it is the only routine transfer of visitor data outside our own servers.
Everything else — accounts, sessions, analytics, and the data our services collect — is stored on servers we control and is not shared with anyone else, except where we are legally required to disclose it.
6. How long we keep it
To complete: visit logs currently have no automatic expiry — they are kept indefinitely. GDPR storage limitation expects a defined retention period. Decide on one (90 days is a common choice for web analytics), state it here, and add a scheduled deletion job to enforce it.
- Account data — kept until you ask us to delete your account.
- Session records — expire automatically and are removed after they lapse.
- Visit logs — currently retained indefinitely. See the note above.
7. Your rights
Depending on where you live you may have the right to access the personal data we hold about you, correct it, have it deleted, object to how we use it, or receive a copy in a portable format. Email contact@weienwong.online and we will respond within 30 days.
To delete your account and the personal data attached to it, email us from the address you registered with.
8. Data our services collect about others
Several services on this platform collect publicly available information from third-party sources — for example public posts from Reddit and X, business listings from Google Maps, market data from Binance, and network metrics from Bittensor.
Where that material includes personal data such as a public username or a business contact address, we process it to provide the requested dataset to the account that asked for it. If you believe we hold information about you gathered this way and you want it removed, email contact@weienwong.online with enough detail to identify the record and we will remove it.
9. Security
Passwords are hashed with bcrypt. All traffic is served over HTTPS. Sessions can be revoked. Sign-in attempts are rate limited.
Because one account grants access to every service on our subdomains, the strength of your password matters more here than on a single-purpose site. We require a minimum length and reject the most commonly breached passwords, but we strongly recommend a unique password from a password manager.
No system is perfectly secure, and we cannot guarantee absolute security.
10. Changes to this policy
If we change this policy we will update the date at the top of this page. Material changes affecting how we use your personal data will be announced on the hub.
Questions about your data?
Email contact@weienwong.online. See also our Terms of Service.