← Back to the live signal
Legal centerTermsPrivacyRulesReport

Privacy notice

Small data footprint, clearly explained

Last updated: 15 August 2026

Who operates this processing

RWReset is an independently operated community project and acts as controller for the application records described here. It is not OpenAI. Privacy, access, correction, deletion, objection and safety requests can be submitted through the Legal & Safety Report. The operator's verified legal identity and service address must be added before any launch that legally requires those public particulars.

Anonymous browser identity

On the first API request, the server creates a random identifier, cryptographically signs it and stores it in the Secure, HttpOnly awr_actor cookie for up to one year. D1 maps it to a stable public name such as Builder #000123. It supports ownership views, rate limits, one standard button signal plus one hidden bonus terminal signal per active cycle, and one poll response per actor. It is pseudonymous, not proof of a unique person.

Data you submit

Depending on the feature, D1 stores comments, replies, titles, category and project metadata, direct project or repository links, plan labels, helpful votes, poll choices, chat messages, reports, moderation and sanction records, and service timestamps. A legal report stores the category, target, explanation, good-faith declaration, case status and the contact details you provide. Do not submit secrets or sensitive personal data.

Network and device data

Cloudflare necessarily processes request metadata such as IP address, TLS and browser headers to deliver and protect the service. RWReset can derive a one-way HMAC rate-limit key from the trusted edge network identity; the application does not intentionally store the raw IP in its D1 community records. Operational logs may include request path, status, timing, request ID and database-query count, but are designed not to log comment or chat bodies, cookies, authorization tokens or secrets.

Purposes and legal grounds

  • Provide requested service functions and remember the same anonymous actor.
  • Publish content you choose to submit and maintain its discussion context.
  • Prevent duplicate actions, spam, attacks and moderation evasion.
  • Moderate content, investigate reports and establish or defend legal claims.
  • Operate optional AI features described below.
  • Maintain reliability, diagnose errors and understand aggregate service use.

Depending on applicable law, these purposes rely on performance of the service requested by you, legitimate interests in operating a safe community, compliance with legal obligations, and consent where the interface specifically asks for it. You may withdraw a consent without affecting earlier lawful processing.

Community AI review

When enabled, a server-side AI check may process submitted archive text and project metadata for safety, relevance or likely duplication. Suggested wording is never published unless the author accepts it. A human owns final publication decisions. Approved content may contribute to an aggregate Community Pulse. See the AI Transparency Policy.

Live chat and agent questions

Chat records are stored in D1; a Durable Object relays already committed events and is not a second message database. Deterministic chat moderation does not send messages to AI. An explicit @ResetAgent mention in an enabled room may send that message and bounded recent context to OpenAI, and stores the labelled reply and run metadata. A public agent question may also be sent with aggregate site facts; that endpoint stores operational run metadata but not the question or generated answer in D1.

Processors and transfers

Cloudflare provides edge delivery, security, Workers, D1 and Durable Objects. OpenAI processes only the bounded content sent when an enabled AI feature is invoked. These providers may process data in countries different from yours under their own infrastructure and contractual safeguards. RWReset does not claim a particular D1 jurisdiction or zero-data-retention OpenAI configuration unless that deployed setting has been separately verified.

Provider notices: Cloudflare Privacy Policy and OpenAI Enterprise Privacy. The external-site safety checkpoint appears before either destination opens.

What the MVP does not request

RWReset does not request access to your OpenAI account, Codex usage, subscription, billing, precise GPS location, contacts or payment history. Agent Fuel is manually maintained and does not automatically track support payments. The site currently has no advertising, cross-site tracking or marketing analytics. See the Cookie Notice.

Local time

Your browser formats UTC timestamps using its own IANA timezone. This is for display and is not derived from GPS. The timezone need not be sent to the server for basic timestamp display.

Public visibility

Approved archive posts, project links, chat messages and the numbered Builder name are public. Search engines or third parties may copy public material. Removing it from RWReset cannot guarantee deletion from caches, screenshots or independent archives. Legal-report contact information is not published.

Retention

The current MVP has no automatic expiry for community, moderation or legal-report records. They remain in D1 until an operator deletes them, they are no longer reasonably needed, or a documented retention schedule is implemented, subject to evidence needed for abuse prevention, disputes and legal duties. The actor cookie expires after up to one year but deletion or expiry of the cookie does not delete server records. Provider and security-log retention is governed by deployed settings and provider terms.

Your rights and choices

Subject to applicable law, you may request access, correction, deletion, restriction, objection, portability or withdrawal of consent, and may complain to a competent data-protection authority. Because RWReset does not require an account, the operator may need the current actor cookie, case ID or other reasonable proof to avoid disclosing or deleting another person's data. Submit a privacy request.

Security and incidents

RWReset uses HTTPS, signed HttpOnly identity cookies, origin checks, rate limits, least-privilege admin access and parameterized D1 queries. No service can guarantee absolute security. If you suspect compromise or exposed personal data, submit a security report without including passwords, keys or exploit payloads that could harm others.

Children and changes

The service is not directed to children under 16 and does not knowingly seek their personal data. A material change to processing will be reflected by a new update date and, where required, a more prominent notice or fresh consent.

!

External destination

You are leaving RWReset

This link opens a third-party website that RWReset does not operate, control or continuously verify.

Destination
External site
Full address
Check before you continue.

The destination's own terms and privacy policy apply. Do not enter passwords, payment details or private data unless you trust and have independently verified the site.

A community link or its review is not an endorsement or safety guarantee. Read the external-links policy.