Privacy Policy
Last updated: February 2026
1. Information We Collect
When you create a Welp account, we collect: email address, display name, and an encrypted (bcrypt-hashed) password. If you sign in with Google, we receive your basic Google profile.
When you submit a review, response, or story, we store the content along with the time it was submitted and the account that submitted it. We never share your identity with the public — only the reviewer and the reviewed person know who wrote which review.
We also collect anonymous traffic data: page paths visited, referrer, and a salted hash of your IP + user agent (truncated, non-reversible). We use this only to count visitors and improve the Service.
2. How We Use Your Information
- To operate, maintain, and improve the Service
- To compute the Statistics & Skinny summary on each profile
- To send transactional emails (review notifications, password reset, etc.) via Resend
- To enforce our community guidelines (AI moderation, ding system)
- To detect abuse and protect the Service
3. AI Moderation
All written content is screened by an AI model (Claude Sonnet 4.5) before publication. The text is sent only to the moderation provider for the purpose of policy review and is not retained outside the Service.
4. What We Do NOT Do
- We do not sell, rent, or trade your personal information.
- We do not show your identity to the public — reviews are anonymous to other users.
- We do not verify the truthfulness of user-submitted content.
- We do not track you across other websites.
5. Cookies & Storage
Welp uses a session cookie (or a JWT in browser local storage) so we can keep you signed in. We also store a small visitor hash (as described above) to count site traffic. We do not use third-party advertising cookies.
6. Email Communications
We send transactional emails (password reset, new review notification, claim disputes, etc.) from whatsup@welp3x3.com. Replies go to Welp3x3@gmail.com. We do not send marketing emails.
7. Data Retention
Reviews are permanent and retained as long as the Service operates. Account data is retained while your account is active. Password-reset tokens expire after 1 hour. Visitor traffic logs are retained for analytics for up to 24 months.
8. Your Rights (GDPR / CCPA)
If you live in the European Economic Area, the UK, or California, you have the right to access, correct, or delete the personal information we hold about you, and to object to certain uses. To exercise these rights, email Welp3x3@gmail.com. Note: reviews you have submitted are part of the public record of the Service and cannot be edited or deleted.
9. Children
Welp is not intended for anyone under 18. We do not knowingly collect information from minors.
10. Security
Passwords are stored as bcrypt hashes. Communication with the Service uses HTTPS. We follow industry-standard practices, but no system is perfectly secure — please use a strong unique password.
11. Third-Party Services
We use the following providers to operate the Service:
- MongoDB Atlas — primary data storage
- Resend — transactional email delivery
- Anthropic (Claude) — AI content moderation and summaries
- ipwho.is — anonymous IP geolocation for traffic analytics
12. Changes to This Policy
We may update this Privacy Policy at any time. Continued use of the Service after changes means you accept the updated policy.
13. Contact
Questions about this Privacy Policy can be sent to Welp3x3@gmail.com.