Privacy policy
Last updated: October 9, 2026
Don't Wait is built to need as little data about you as possible. We don't require an account to use any feature. Here's exactly what we store and why.
Data we store on your device
Your direction filter, vehicle type, favorited crossings, expanded card, search query, and whether you've granted location access — all of these are kept in your browser's localStorage (or the equivalent storage inside the Don't Wait mobile app). Nothing about these preferences leaves your device unless you sign in. Clearing your browser data, or deleting the app, wipes them entirely.
Location
If you tap "Find nearest crossings," your browser or phone asks for permission to share your location. The coordinates are used only to sort the list of crossings by distance, and they stay on your device. We never send your coordinates to our servers.
Accounts (optional)
If you choose to sign in with email, we store your email address and a list of your favorited crossings + UI preferences in our database (Cloudflare D1). This lets your favorites follow you across devices. We send exactly one kind of email: the sign-in email, which contains a 6-digit code and a sign-in link. Codes and links expire after 15 minutes and are deleted from our database within a day after that. Signed-in sessions last up to 90 days unless you sign out. We don't send marketing email and we don't sell or share your email address.
Delete your account any time from the My Account page (website or app): choose "Delete account" and confirm. This immediately and permanently removes your email address, favorites, preferences, and all sessions from our database. You can also email hello@dontwait.app and we'll do it for you.
Bot protection & abuse limits
When you request a sign-in email or send a contact message, Cloudflare Turnstile checks that you're a person, usually invisibly. To do that, Cloudflare processes signals about your browser or device, such as your IP address and browser characteristics, only to tell people from bots; see Cloudflare's Turnstile privacy addendum. To stop our sign-in and contact forms being used to send spam, we also keep a one-way hash (not the actual value) of the email address and IP address used, for up to 2 days.
App updates (iOS app)
The app checks dontwait.app for a newer version of its interface when it opens and while you use it, and downloads it if you choose "Update now". These requests contain the app's version identifiers and anonymous status codes about the update or loading process (for example, that an update finished downloading) so we can fix problems. They don't include your location, email address, or any account information, and like any request they appear in our hosting provider's server logs (see below).
Commute alerts (iOS app)
If you set up a commute alert, we store your phone's push-notification token (issued by Apple), the crossings, days and time you chose, and your time zone, so we can send the current wait times at that time. Alerts don't require an account and aren't linked to your email. Delete an alert in the app to remove it; turning off notifications for Don't Wait or deleting the app stops all alerts, and we delete the token and its alerts as soon as Apple tells us it's no longer valid. Notifications are delivered by Apple's Push Notification service.
Service providers
Don't Wait is run on two service providers, who process data only on our behalf and under data-protection terms that require them to protect it at least as well as this policy does: Cloudflare (hosting, database, bot protection, and website analytics; privacy policy) and Resend (delivering sign-in and contact-form emails; privacy policy). We don't sell personal information or share it with anyone else.
Cookies
On the website we set one cookie, sid, only after you sign in. It identifies
your session and expires after 90 days. The mobile app stores the same session token in
the app's private storage on your device instead of a cookie, and removes it when you
sign out. We don't use any tracking cookies.
Contact form & server logs
If you send us a message through the contact form, the email address and message you type are delivered to our inbox by email (via Resend) and used only to reply; they aren't stored in our database. Like most web services, our hosting provider (Cloudflare) processes standard request data such as IP address, user-agent, and the page or API address requested, to deliver the service and defend it against abuse. These logs are kept only for a limited period for operations and security.
Analytics & ads
On the website we use Cloudflare's built-in, privacy-respecting analytics (no cookies, no personal data). The mobile app contains no analytics or advertising SDKs and does not track you across other apps or websites. We may show advertisements via Google AdSense or similar networks in the future; if and when we do, this policy will be updated to describe the data those networks collect and how to opt out.
Children
Don't Wait is not directed at children under 13. We don't knowingly collect data from anyone under 13.
Contact
Questions about this policy? Email hello@dontwait.app.