What we collect,
and where it lives.
wrxstack is a small, independent product built by one person. This page states plainly what data we hold, the one place it lives, how it is encrypted, who else can see it, and what happens when you delete your account. It does not describe controls we do not have.
The data we actually hold.
Two buckets. The account and content you create when you use Atlas or Portfolio, and the coarse analytics the marketing site records. Nothing here is sold, and nothing is shared beyond the vendors listed further down.
| Category | What it is | Why we have it |
|---|---|---|
| Account | Email address and password credential for Atlas or Portfolio | To create your account and let you sign back in |
| Customer content | Whatever you save into the product | It is the point of the product; we store it so you can use it |
| Contact messages | Whatever you type into the contact form | So we can answer you by email |
| Site analytics | Page views, coarse device and country data | To see which pages are read; not tied to a named person |
We do not ask for and do not want regulated data. Do not put protected health information, payment card numbers, or government identity documents into wrxstack. There is no HIPAA mode, no PCI scope, and no BAA. See the Trust Center for why.
One place.Not six regions.
Everything runs on managed hosting from Render. There is one region. There is no data residency menu, no per-region key hierarchy, and no cross-region replica, because none of that has been built.
Everyone who touches it.
The complete list of third parties involved in running wrxstack. If a vendor is not on this list, it does not receive your data. This matches the sub-processor list in the Trust Center, and we update it before adding a vendor, not after.
| Vendor | Purpose | What it receives |
|---|---|---|
| Render | Application and site hosting | All application data, at rest and in transit |
| PostHog | Product analytics on the marketing site | Page views, coarse device and country data |
| Google Tag Manager | Analytics tag loading | Page load events |
| FormSubmit | Contact form delivery | Whatever you type into the contact form |
| Model provider | AI features only | The content you send to an AI feature, at the moment you use it |
When you delete, it goes.
Delete your account and your content is removed from the live database. Provider backups roll off on their own cycle after that. We do not issue deletion certificates, and we do not keep a seven-year archive of your activity.
| Data | What happens on account deletion | How long backups persist |
|---|---|---|
| Account and customer content | Removed from the live database when you delete your account | Until the host's backup rotation overwrites it |
| Contact messages | Held in email so we can answer; delete on request | Standard mailbox retention |
| Site analytics | Not tied to your account; retained by PostHog per its defaults | Per PostHog retention |
| Model prompts | Not retained for training by the model provider | Per the provider's API terms |
To delete your account or ask what we hold about you, email contact@wrxstack.com. For the legal detail on requests, see the CCPA statement and the Privacy policy.
What gets written down.
Ordinary operational logs, nothing more. There is no immutable audit stream, no SIEM export, and no sub-second replay of every action, because there is no infrastructure here to produce one.
Standard request logs
Render records the ordinary request and error logs any hosted app produces. They exist so one person can find and fix a problem, and they roll off on the platform's schedule.
Coarse and aggregate
PostHog and Google Tag Manager record page views and coarse device and country data on the marketing site. This is not linked to a named account.
No audit export
There is no customer-facing audit log, no Datadog or Splunk stream, and no seven-year retention tier. If your review requires one, wrxstack does not meet it, and we would rather say so.
Said plainly, up front.
Rather than let you infer these from silence, here they are in one place. None of the following exists here today, and this page changes before any of it does.
Ask about your data.
We will answer plainly.
Questions about what we hold, where it sits, or how to have it deleted. Email a human. If the answer is "we don't do that," that is what you will get.