TRUST CENTER · DATA HANDLING · WHAT IS ACTUALLY TRUE

What we collect,
and where it lives.

wrxstack is a small, independent product built by one person. This page states plainly what data we hold, the one place it lives, how it is encrypted, who else can see it, and what happens when you delete your account. It does not describe controls we do not have.

contact@wrxstack.com Trust CenterPrivacy policy
01 / What we collect

The data we actually hold.

Two buckets. The account and content you create when you use Atlas or Portfolio, and the coarse analytics the marketing site records. Nothing here is sold, and nothing is shared beyond the vendors listed further down.

CategoryWhat it isWhy we have it
AccountEmail address and password credential for Atlas or PortfolioTo create your account and let you sign back in
Customer contentWhatever you save into the productIt is the point of the product; we store it so you can use it
Contact messagesWhatever you type into the contact formSo we can answer you by email
Site analyticsPage views, coarse device and country dataTo see which pages are read; not tied to a named person

We do not ask for and do not want regulated data. Do not put protected health information, payment card numbers, or government identity documents into wrxstack. There is no HIPAA mode, no PCI scope, and no BAA. See the Trust Center for why.

02 / Where it lives

One place.Not six regions.

Everything runs on managed hosting from Render. There is one region. There is no data residency menu, no per-region key hierarchy, and no cross-region replica, because none of that has been built.

Hosting
Render. The application, the database, and the marketing site all run on Render's managed platform. We do not operate our own servers, and we do not run our own data centers.
Region
One region. Data sits where the Render service is provisioned. You cannot pin a workspace to a region of your choosing, because there is only one and no mechanism to move it.
In transit
TLS 1.3. Every request to wrxstack.com, atlas.wrxstack.com, and portfolio.wrxstack.com is served over TLS. HTTP is redirected, not accepted. You can confirm this yourself with any SSL checker.
At rest
Encrypted by the host. Stored data sits on managed infrastructure with volume-level encryption at rest enabled by Render. This is inherited from the provider, not something we implemented, and we will not claim more than that.
Model prompts
Not used to train models. For AI features, content sent to the model provider is not used to train any model. This is enforced by the provider's API terms on the tier we use, not by a promise we make on our own behalf.
03 / Who else sees it

Everyone who touches it.

The complete list of third parties involved in running wrxstack. If a vendor is not on this list, it does not receive your data. This matches the sub-processor list in the Trust Center, and we update it before adding a vendor, not after.

VendorPurposeWhat it receives
RenderApplication and site hostingAll application data, at rest and in transit
PostHogProduct analytics on the marketing sitePage views, coarse device and country data
Google Tag ManagerAnalytics tag loadingPage load events
FormSubmitContact form deliveryWhatever you type into the contact form
Model providerAI features onlyThe content you send to an AI feature, at the moment you use it
Full sub-processor detail
04 / Deletion and retention

When you delete, it goes.

Delete your account and your content is removed from the live database. Provider backups roll off on their own cycle after that. We do not issue deletion certificates, and we do not keep a seven-year archive of your activity.

DataWhat happens on account deletionHow long backups persist
Account and customer contentRemoved from the live database when you delete your accountUntil the host's backup rotation overwrites it
Contact messagesHeld in email so we can answer; delete on requestStandard mailbox retention
Site analyticsNot tied to your account; retained by PostHog per its defaultsPer PostHog retention
Model promptsNot retained for training by the model providerPer the provider's API terms

To delete your account or ask what we hold about you, email contact@wrxstack.com. For the legal detail on requests, see the CCPA statement and the Privacy policy.

05 / What is logged

What gets written down.

Ordinary operational logs, nothing more. There is no immutable audit stream, no SIEM export, and no sub-second replay of every action, because there is no infrastructure here to produce one.

Application logs

Standard request logs

Render records the ordinary request and error logs any hosted app produces. They exist so one person can find and fix a problem, and they roll off on the platform's schedule.

Site analytics

Coarse and aggregate

PostHog and Google Tag Manager record page views and coarse device and country data on the marketing site. This is not linked to a named account.

Not built

No audit export

There is no customer-facing audit log, no Datadog or Splunk stream, and no seven-year retention tier. If your review requires one, wrxstack does not meet it, and we would rather say so.

06 / What we do not offer

Said plainly, up front.

Rather than let you infer these from silence, here they are in one place. None of the following exists here today, and this page changes before any of it does.

Customer-managed keys
No BYOK, no per-tenant key hierarchy, no customer-supplied root keys. Encryption at rest is the provider default and nothing more.
Data residency
No region menu, no residency guarantee, no cross-region replica. There is one region and no way to choose another.
Regulated data handling
No HIPAA mode, no PHI field encryption, no PCI scope, no BAA. Do not put regulated data here.
Dedicated hardware
No FIPS-validated HSMs, no single-tenant deployment, no on-premise or air-gapped install.
Audit tooling
No immutable audit log, no SIEM streaming, no deletion certificate, and no long-horizon compliance archive.
Trust Center · Data handling

Ask about your data.
We will answer plainly.

Questions about what we hold, where it sits, or how to have it deleted. Email a human. If the answer is "we don't do that," that is what you will get.

contact@wrxstack.com Back to Trust CenterPrivacy policyOne region · provider-default encryption · nothing sold