WMEKit Account

Privacy Policy

Effective 2 October 2026

Your WMEKit account (auth.wmekit.com, "the account service", "we", "us") is the one sign-in for WMEKit apps such as WME Requests and WME Sync. WMEKit is an independent, unofficial community project for Waze Map Editors. It is not affiliated with, endorsed by, or operated by Waze or Google. WMEKit is run from South Africa, so this policy follows the Protection of Personal Information Act (POPIA), and the GDPR and UK GDPR for people in Europe and the UK. It explains what we collect, why, how long we keep it, who it's shared with, and the choices you have. If anything is unclear, email wazer@wmekit.com.

1. The short version

  • We collect only what's needed to sign you in and keep your account secure.
  • We don't sell your data, show ads, or share your data for anyone else's marketing.
  • Analytics are off unless you accept them, and you can sign in perfectly well without them.
  • Apps you sign in to receive your name and email address. What each app stores is covered by its own privacy policy.
  • You can ask for a copy of your data, have it corrected, or have your account deleted at any time.

2. What this policy covers

This policy covers the account service: signing up, signing in, the account and security pages, and the emails it sends. Each WMEKit app has its own privacy policy for the data it keeps itself (for example the requests you submit in WME Requests, or the settings you sync in WME Sync).

3. What we collect

Information you give us

  • Account details: your email address and name. Your name is shown to you and to admins of the apps you use.
  • Password: stored only as a one-way hash (scrypt). We can never see or recover your password.
  • Passkeys and security keys: the public key, a name you choose, and technical details your device provides (such as whether it's backed up). The private key never leaves your device.
  • Two-factor authentication: your authenticator app secret and backup codes, stored encrypted. Email sign-in codes are stored hashed and expire after 3 minutes.

Information from Google or Discord

If you sign in with or connect Google or Discord, that provider tells us your account ID there, your name, email address, whether the email is verified, and your profile picture. We store these along with the tokens the provider issues for the connection. We don't request access to your contacts, files, messages, or anything else. You can disconnect a provider at any time on your account page.

Information collected automatically

  • Sessions: one per signed-in browser, with its IP address and browser (user agent).
  • Security log: sign-ins, failed sign-in attempts, and changes to how you sign in (such as a new password, passkey or two-factor setting). Each entry records the time, IP address, approximate country (derived from the IP address), and browser. You can see this log on your account page. WMEKit apps can add entries too, for example when you link a Waze username in WME Sync.
  • Bot protection: sign-up, sign-in and password-reset forms use Cloudflare Turnstile, which looks at signals from your browser to tell people from bots.
  • Error reports: if something breaks on our servers, technical details of the error (and, if you're signed in, your account ID) may be sent to PostHog so we can fix it.
  • Analytics (only if you accept): which pages you visit and what you click, your browser and device type, and approximate location from your IP address, collected by PostHog. If you're signed in, this is linked to your account ID, name and email address.

4. How we use it, and why

POPIA, the GDPR and the UK GDPR each require a lawful reason (a "legal basis") for using personal information. These are ours:

PurposeLegal basis
Creating your account, signing you in to WMEKit apps, sending verification, password and sign-in code emailsProviding the service you asked for (contract)
Keeping accounts secure: the security log, bot protection, alerting you to important account changes, detecting and stopping abuse, error reportsOur legitimate interest in keeping the service and your account safe
Product analyticsYour consent, which you can withdraw at any time
Answering your emails and requestsOur legitimate interest in helping you, or a legal obligation (for data requests)

We send emails only about your account: verification, password resets, sign-in codes, invitations from an app admin, and security alerts. We don't send marketing emails.

5. Who we share it with

  • WMEKit apps you use (currently WME Requests and WME Sync) receive your account ID, name, email address, profile picture, and whether your email is verified, so they can show who's signed in. They don't receive your password, passkeys, two-factor secrets, or security log.
  • Cloudflare hosts the service and its database, sends our emails, and provides Turnstile bot protection.
  • PostHog receives error reports and, only if you accept analytics, usage analytics.
  • Google and Discord, only if you choose to sign in with them. They'll know you signed in to WMEKit, under their own privacy policies.
  • Authorities, only if we're legally required to, or if it's necessary to protect someone's safety or the security of the service.

Cloudflare and PostHog process data on our behalf and may only use it to provide their services to us. We don't sell personal data or share it for advertising.

6. International transfers

Cloudflare runs a global network, and our service providers may process data in countries other than yours, including the United States. We only use providers bound by agreements that protect your data to a standard comparable to POPIA (as section 72 of POPIA requires), such as standard contractual clauses for data from Europe and the UK.

7. How long we keep it

  • Your account and sign-in methods: until you delete your account or ask us to. Removing a passkey, security key or connected provider deletes it straight away.
  • Sessions: deleted when you sign out. Otherwise a session expires after 7 days without use.
  • Security log: the most recent 200 entries per account. Older entries are deleted automatically.
  • Email links and codes: single-use, and they expire (sign-in codes after 3 minutes).
  • Disabled accounts: kept while disabled, so the account can't simply be recreated. You can still ask us to delete it.
  • Backups: deleted data can remain in database backups for up to 30 days before it's overwritten.
  • Analytics and error reports: kept by PostHog under its retention settings, and deleted with your account on request.

8. Cookies and similar technologies

Essential cookies keep you signed in. They're scoped to wmekit.com so every WMEKit app can recognise you, and they're needed for the service to work, so they don't need consent.

NamePurposeLasts
wmekit.session_tokenKeeps you signed in across WMEKit apps7 days, renewed while you use it
wmekit.session_dataA signed copy of your session, so apps don't look it up on every request5 minutes
wmekit.two_factorRemembers that you're midway through a two-factor sign-in10 minutes
wmekit.trust_deviceSkips the two-factor step on a device you chose to trust30 days
Sign-in state cookiesProtect a Google or Discord sign-in from being tampered withMinutes, during sign-in
wmekit-account-cookie-consent (local storage)Remembers your analytics choiceUntil you clear it
mantine-color-scheme-value (local storage)Remembers light or dark modeUntil you clear it
ph_* (PostHog), only if you accept analyticsTells visits apart for analyticsUp to 1 year

To change your analytics choice, clear this site's data in your browser and choose again when the banner reappears.

9. How we protect it

Everything is served over HTTPS. Passwords and email codes are hashed, two-factor secrets are encrypted, and passkeys and security keys never share their private keys with us. Sign-in forms are protected against bots, and the security log lets you spot activity you don't recognise. You can add two-factor authentication on your account page. No system is perfectly secure, so if we ever learn of a breach that affects your data, we'll tell you and, where required, the relevant authorities.

10. Your rights and choices

On your account page you can at any time:

  • see your security log and connected sign-in methods;
  • change your password, and add or remove passkeys, security keys and two-factor methods;
  • connect or disconnect Google and Discord;
  • sign out, which ends your session in every WMEKit app.

Depending on where you live, you may also have the right to access your data, get a copy of it in a portable format, have it corrected or deleted, restrict or object to how we use it, and withdraw consent. To use any of these, email wazer@wmekit.com from the address on your account. We'll respond within 30 days and may need to confirm it's really you. Deleting your WMEKit account doesn't by itself delete data an app keeps (such as your synced settings in WME Sync); tell us if you'd like that removed too, and we'll do it.

If you're unhappy with how we've handled your data, please contact us first. You also have the right to complain to South Africa's Information Regulator, or, if you live elsewhere, to your local data protection authority.

11. Children

WMEKit is meant for Waze Map Editors and isn't directed at children. You must be at least 16 to create an account. If you believe a child has given us their data, contact us and we'll delete it.

12. Changes to this policy

We'll update the effective date above whenever this policy changes. If a change significantly affects how we use your data, we'll tell you by email or with a notice when you sign in, before it takes effect.

13. Contact

For questions, requests or complaints about privacy, email wazer@wmekit.com. See also our Terms of Service.