Skip to content
← Wayfynd

Privacy Policy

Last updated: September 14, 2026

Who runs this

Wayfynd is operated by an individual developer, not a registered company, who is responsible for your personal data (the "controller"). If you have a question about your data or this policy, contact bluedaehyun@gmail.com.

What we collect

  • Account info: your email address and password. Your password is handled by our authentication provider (Supabase) and stored only in hashed form — we never see it.
  • Date of birth: asked at signup so we can confirm you're old enough to use Wayfynd.
  • Career DNA: the answers you give during onboarding — income goal, work style, education willingness, available time, interests, things you'd rather avoid, and your current situation.
  • Progress data: lessons and challenges you've completed, difficulty ratings, time taken, XP and readiness scores, and career paths you've chosen or simulated.
  • Challenge submissions and Daily Challenge answers, with the feedback generated for them.
  • AI Coach conversations: the messages you send and the replies you receive.
  • Check-in photos: photos of your work you upload, with the AI feedback on them.
  • Subscription info from Paddle: your Paddle customer and subscription IDs, plan, status, and renewal date. We never see or store your card details — Paddle handles payment directly.
  • Technical data: our hosting provider processes IP addresses and request logs to deliver and secure the site, and error reports record technical details when something in the app breaks.

We don't use advertising trackers or third-party analytics.

How and why we use it

  • To provide the service you signed up for (performance of our contract with you): your account, Career DNA, matches, roadmap, progress, AI Coach, check-ins, and subscription.
  • To keep Wayfynd safe and working (our legitimate interests): preventing abuse, securing accounts, and finding and fixing errors.
  • To send reminder emails about your lessons (our legitimate interests). Every reminder has an unsubscribe link.
  • To meet legal obligations: confirming users are old enough, and keeping the transaction records Paddle is required to keep for tax purposes.

We don't sell your data or share it for targeted advertising.

Who else processes it

We use these service providers, each only for the job described:

  • Supabase — database, login and authentication, and private photo storage.
  • Vercel — hosts the website.
  • Paddle — processes payments and subscriptions as our merchant of record. For purchase and tax data, Paddle also acts as its own controller under its own privacy policy.
  • Resend — delivers email, such as sign-up verification codes and reminder emails.
  • Anthropic — generates AI Coach replies and check-in photo feedback. The message or photo you submit is sent to Anthropic to produce that response.
  • Sentry — error monitoring. When something breaks, technical details about the error are sent to Sentry. It's configured not to collect your name or email address.

Some of these providers are based in the United States, so your data may be processed outside your country. Where that applies, we rely on the safeguards those providers offer, such as Standard Contractual Clauses or the EU–U.S. Data Privacy Framework.

How long we keep it

  • Your account data is kept while your account is open.
  • When you ask us to delete your account, we delete your data within 30 days. Copies in our providers' backups are removed on their normal backup cycles.
  • Paddle keeps transaction records for as long as tax law requires.
  • Error reports are kept by Sentry for a limited period, no longer than 90 days.

Your rights

  • Edit your Career DNA at any time from your Profile.
  • Delete saved career scenarios from within the app (Simulator page).
  • Stop reminder emails with the unsubscribe link in any reminder.
  • Ask us for a copy of your data, to correct it, to delete your account and all associated data, or to object to or restrict how we use it — email bluedaehyun@gmail.com and we'll respond within 30 days.
  • If you're in the EU, EEA, or UK, you can also complain to your local data protection authority.

Cookies

We only use cookies and similar storage that the site needs to work: keeping you signed in, remembering your light or dark theme, a short-lived cookie used during signup, and cookies Paddle sets during checkout to prevent fraud. We don't use advertising or analytics cookies.

Children

Wayfynd is not for children under 13. We ask for your date of birth at signup and don't create accounts for anyone under 13. If we learn an account belongs to a child under 13, we delete it and its data. If you believe that's happened, contact us.

Security

Every connection to Wayfynd is encrypted, passwords are hashed, and database access rules limit each account to reading only its own data. Check-in photos are stored privately and shown only through short-lived links, and you can turn on two-factor authentication. No system is perfectly secure, but we take reasonable steps to protect your data.

Changes to this policy

If this policy changes in a way that matters — like adding a new service provider who processes your data — we'll update the date at the top and let you know in the app or by email.

Related