WWENROUH

Display preferences

Language

Appearance

Appearance

Sign in

Closed alpha · Privacy

How WENROUH handles your data

This notice describes the limited organizer, invitation, guest, RSVP, and destination workflow in the current release candidate.

Shared plan availability

Current joined members can add plan-scoped date and time windows showing when they are free. Other current members can see each participant’s display name, exact saved windows, and the group’s overlap. Availability is absent from the public invitation preview, is not sent to an external calendar, and never changes the plan schedule automatically. Only the creator may deliberately review an overlap and save a plan edit. Removed members lose access immediately, and deleting the plan or creator account deletes its live availability records. Device-alert content remains generic and never includes availability details.

Plan history

WENROUH keeps permanent before-and-after records for creator plan-detail edits and privacy-minimal records for completed creator-only actions such as invitation administration, guest removal, poll and task administration, message moderation, and gallery deletion. Action records keep only the organizer, time, action class, and bounded aggregate counts; they do not keep removed media names, object keys, URLs, message text, invitation secrets, or member identities. Current authorized members can read this history in plan chat. Mere page access is not recorded. Invitation previews never receive history, removed members lose access, and deleting the plan or creator account deletes its live history.

Optional plan alerts

An authorized joined member may enable best-effort device alerts for an open plan room. WENROUH stores an enabled flag, the last-seen revision, and an opaque plan-room identifier and navigation path in that browser. Alert text is generic and contains no plan title, destination, coordinates, invitation, or member identity. The notification-only service worker is limited to plan routes and does not cache requests or private plan data. Mobile or background suspension can delay or stop alerts; closed or suspended tabs cannot be notified.

Data WENROUH stores

For creators, WENROUH stores the display name, verified email, database-backed sessions, and a one-way password credential managed by Better Auth. WENROUH does not store a readable password.

For guests, WENROUH stores the display name entered for that plan and opaque plan-scoped session records. Guests do not provide an email address.

A plan can store its title, type, date and time, timezone, description, destination label and coordinates, invitations, memberships, guest sessions, RSVP choices, poll choices, member availability windows, responsibility tasks, short planning messages, and private memory records.

Location and invitation privacy

Before joining, an invitation preview contains only limited plan information. Exact destination coordinates and external direction links appear only after creator ownership or an authorized guest membership is verified for that exact plan.

Invitation links are bearer secrets: anyone who receives a valid, unrevoked link can open the limited preview and ask to join. Keep invitation links inside the intended group and do not post them publicly.

Private plan memories

Only the plan creator and currently authorized joined members can open the private memories gallery. The invitation preview contains no media, count, filename, metadata, or download URL. Cloudflare R2 stores the media in a private bucket, and upload bytes travel directly between your browser and R2 through short-lived signed requests.

Uploads open when the plan is created, including while its working date is tentative, and close 24 hours after the scheduled or creator-ended plan end. The gallery then remains read-only for 30 days and shows its exact scheduled deletion date. Once cleanup begins, changing the plan schedule cannot reopen the gallery. A cleanup service must delete expired objects; production scheduling and monitoring remain deployment prerequisites.

Ordinary photos are re-encoded in the browser to correct orientation, reduce size, and remove embedded EXIF and GPS metadata before upload. Videos at or below 500 MiB remain unchanged and can retain device or location metadata. When a supported source exceeds 500 MiB, WENROUH re-encodes it only on your device, progressively reducing frame rate, resolution, and audio quality until it fits; this strips descriptive container metadata, although technical track metadata may remain. If the device or file cannot be processed safely, the upload fails before any media is sent. Do not upload sensitive media.

A removed member loses gallery access immediately. Their published contributions remain unless the creator chooses to delete them. A member may delete their own contribution and the creator may delete any plan memory. Database authorization is revoked immediately, although a signed download URL already issued to an authorized member can remain usable for up to one minute.

Service providers and external links

Resend processes creator authentication email, including the recipient address and short-lived verification, password-reset, or fallback sign-in message.

When Google sign-in is explicitly enabled and chosen, Google processes the authentication request. WENROUH stores the linked Google provider identifier and minimum account metadata, requests only OpenID identity, email, and profile scopes, requests no Gmail, Drive, or Calendar access, and requests no offline access. Linked provider data is removed with account deletion.

Map views request tiles from OpenFreeMap. Choosing Google Maps, Waze, or Apple Maps opens that external provider and sends it the selected destination coordinates under that provider's own privacy terms.

What is not in this alpha

WENROUH does not use analytics, advertising, tracking pixels, public plan or media discovery, live location tracking, payments, or chat attachments, and it does not sell personal data.

Do not enter emergency, financial, medical, identity-document, or other highly sensitive information in a closed-alpha plan.

Deletion and requests

Creators can remove a guest's current plan access, permanently delete an owned plan, or permanently delete their creator account and owned plans from the live application. These product actions cannot be undone.

Encrypted production backups must expire deleted copies within no more than 14 days before friends-alpha access begins. That backup and restore control is a deployment prerequisite and is not claimed as operational by this local release candidate.

Guests can contact the organizer who shared the invitation to request removal from that plan. WENROUH does not claim a separate support inbox in this release.