WHYL Privacy Policy
WHYL provides a Chrome extension and dashboard that detect longer waits on supported AI sites, optionally display sponsored content during those waits, and record verified rewards in US dollars. This policy explains exactly what data WHYL handles.
Data we collect
- Account data: name, email address, optional company name, account role, referral code, and a short-lived Supabase session token stored by the extension after sign-in. When you choose a dashboard action, the extension validates and copies that token directly into the dashboard's page-owned storage; it is never placed in a URL, query, fragment, history entry, or log.
- Extension activity: the supported AI service being used, random session identifiers, wait timing, campaign shown, foreground video-playback duration, completion status, and basic reliability/error information. WHYL does not collect general browsing history outside the supported sites listed in the extension.
- Local wait estimation: the extension reads the current composer text in browser memory to estimate prompt length and likely response time. Derived wait samples, overlay position, and local prompt fingerprints used to detect 24-hour repeats can remain in your browser.
- Optional conversation data: WHYL does not transmit or save raw prompt or AI response text until you optionally agree to the Conversation Data Terms and Conditions. If enabled, WHYL stores that text with the supported AI site, prompt token count, and wait duration for up to one (1) year to improve wait prediction and reliability. Full detail is at https://app.whyl.ai/conversation-data-terms.
- Fraud-prevention signals: prompt-length bucket, word-diversity ratio, local repeated-prompt flag, trusted click/Enter flag, page-visibility flag, rate-limit events, and a random installation identifier. The server converts the installation identifier and network address into keyed HMAC hashes before storage; it does not store either raw value in fraud records.
- Earnings and payout data: verified view rewards, balances, ledger entries, withdrawal status, and the identifier/status of your Stripe connected account. Stripe collects identity and bank information on Stripe-hosted pages; WHYL does not receive full bank account or card numbers.
- Advertiser data: company details, campaign submissions, creative URLs, budgets, bids, authorization status, and delivery totals.
How and why we use data
- Provide login, the wait-time overlay, verified sponsored-content views, dollar rewards, referrals, fraud prevention, and support.
- For a valid referral, pay the referrer 10% of the referred member's verified ad earnings for 30 days, capped at $10. The referred member keeps the full reward.
- Process connected-account onboarding and reward transfers through Stripe.
- Prevent automated accounts, synthetic/repeated earning prompts, hidden-page playback claims, excessive requests, multi-account abuse, and payout fraud.
- Operate, secure, debug, and measure the reliability of WHYL.
Your choice and controls
You can turn raw conversation sharing off at any time to stop future collection, delete previously collected conversation data from the dashboard, clear extension storage through Chrome, or email us to request deletion of your WHYL account. Extension and dashboard sessions are stored separately after handoff: signing out of the extension removes its session but does not silently sign out a dashboard page that is already open; use the dashboard's logout action to remove that page-owned session. Turning sharing off does not affect rewards.
Retention
Consented raw prompt and AI response text expires and is deleted within one (1) year. Account, campaign, earnings, antifraud, and payout records are retained while the account is active and as reasonably required for financial, security, dispute, and legal obligations. Local prompt fingerprints older than 24 hours are ignored and pruned the next time the extension evaluates a prompt; other local wait samples remain in Chrome until extension storage is cleared. To request account deletion, email the address below.
Service providers and sharing
We do not sell personal information. We share data only as needed with Supabase (authentication and database), Render (application hosting), and Stripe (connected-account verification and transfers), or when legally required or necessary to prevent fraud, abuse, or harm. Advertisers receive aggregate delivery totals, not prompts, responses, identity, or individual browsing activity.
WHYL does not use personal information for personalized advertising, creditworthiness, lending decisions, or unrelated profiling. Sponsored campaigns are selected by wait duration and campaign eligibility, not by prompt content or an advertising profile.
Security
WHYL uses HTTPS, short-lived Supabase authentication tokens, database row-level security, and server-only privileged keys. No internet service can guarantee absolute security.
Chrome permissions
- Host access: ChatGPT, Claude, and Gemini for the user-visible wait overlay, WHYL's API for account, campaign, and reward requests, and only the exact WHYL dashboard host for a user-requested signed-in dashboard handoff.
- Storage: local login session, conversation-sharing preference, random installation identifier, 24-hour repeated-prompt fingerprints, wait samples, and overlay preferences.
- Scripting: maintains the overlay on supported AI pages after extension updates and performs the one-time session write on the exact dashboard host when you open a dashboard action. WHYL does not install a persistent dashboard content script.
Chrome Web Store Limited Use
WHYL's use of information received from Chrome APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. We limit that use to providing or improving WHYL's single disclosed purpose and related security and reliability operations.
Contact and deletion requests
Email whylaithinks@gmail.com. Send account requests from the email address on your WHYL account so we can verify ownership.