At a glance
- We do not sell or rent your personal information or share it for cross-context behavioral advertising.
- A posted request is public. Your name, age, preferences, meetup location and other request details are available to people browsing Wingman.
- 90 seconds is a live-request timeout. It is measured from the last successful connection that renews your request. It is not a deadline for erasing every server, backup, browser or screenshot copy.
- This browser remembers information. Drafts, photos and previous requests can stay on your device after you leave.
Wingman is operated by Todd Hendricks in Illinois, USA. This policy covers the Wingman website and installed web app. There is no account registration, but that does not make your activity anonymous. Contact todd@hendricks.cc with privacy questions.
Information we process and why
- Your request: the name, age, gender, preferred company, plan text and optional photo you provide; your chosen meetup address and coordinates, time or relative travel allowance, selected transportation mode, travel radius, time-advance settings and wingfam status. We use these to display your plan and identify nearby, compatible requests.
- Location and searches: with browser permission, Wingman requests device location at startup and watches for updates while the page is visible. The watch stops when hidden and restarts on return. The browser and operating system determine the update frequency. Suitability and automatic business preparation sample the latest coordinates separately, initially and about every 30 seconds while visible; cached results can avoid downstream requests. Background timers and operating-system restrictions can delay updates. Refreshes update nearby discovery without moving an already selected meetup point. After the current-location suitability screen succeeds, Wingman automatically sends the device coordinates through our server to prepare a mapped business within 50 metres, including its checked main entrance or mapped center. Unsuitable, unknown or failed screens suppress automatic business preparation. The detected name is displayed; clicking Use my location copies this prepared result without a new lookup. The most recent prepared business or no-business result is reused in page memory for up to 24 hours within 5 metres of its lookup origin. Movement or expiry can trigger new preparation on a device update; failures can retry after 30 seconds. Retained precise coordinates can reuse a prepared result. Your device location supports aggregate nearby visitor counts, helps center the map and checks that your proposed meeting point is within the supported area. The distance from your supplied location to that point, together with your selected transportation mode, also limits relative travel-time choices. This calculation uses no new routing provider and does not add a stored journey origin. If device location is unavailable, an IP-based lookup can provide an approximate area. Address searches, selected map points and nearby-business searches process the search text or geographic area needed to find a place. Device coordinates are also screened to choose a close business view for suitable locations or a wider request view otherwise. The browser temporarily reuses the most recent presentation result within 5 metres for up to 24 hours; this affects map zoom and whether business preparation runs, not approval of a new meetup point. Movement or expiry prompts a new check on a device update; failures can retry after 30 seconds. Candidate meetup coordinates and these device coordinates are sent through our server to the existing Overpass providers to check mapped land use, building footprints and venue eligibility. Names, photos and plan text are not sent for that check. Suitability results are also cached in our database for 24 hours using exact coordinate pairs and a screening-rule version. Each row stores the approved/rejected result, whether it is a business, an explanation and expiry, without a visitor identifier, session identifier, profile or IP address. Exact coordinates can still describe a sensitive place; these are geographic lookup records, not anonymous location data. Expired rows are removed during later successful uncached suitability checks. Up to 500 results may additionally be reused in temporary server memory for the remainder of the same 24-hour period. Expiry stops reuse; it is not a separate physical-deletion timer, and database backup limitations still apply. Reusable mapped venue and building geometry is also cached for 24 hours with its lookup coordinates and expiry. Points within 5 metres can reuse this data when it has sufficient boundary detail; each selected point is classified separately. Derived results retain the source data expiry. Up to 100 map-data records may be held in server memory. Expired map-data rows are removed by shared background cleanup. Provider failures are not stored as suitability decisions. Provider logs have their own retention. Your browser time zone helps interpret your proposed meeting time.
- Match coordination: invitations, acceptances, proposed places and times, readiness confirmations, recognition details and an optional phone number help you agree on and find each other at a meetup.
- Session and technical information: a random session identifier and short-lived cookie let you manage your request without an account. The server stores a hash of the session token. IP-derived hashes and counters help limit abusive requests. Hosting systems also process network and device information, requested URLs, timestamps, errors and other operational records to deliver, secure and troubleshoot the service.
- Messages to the operator: if you email us, we receive your email address, message and anything you include so we can respond to a question, rights request or report.
Wingman automatically screens submitted text for dating, sexual solicitation, marriage, wedding and drug-related content, and suggestive, drug-associated or arrow emoji before saving it. The screening runs within Wingman; it does not send text to an external moderation service or keep a separate log of rejected text. The browser may still retain draft text as described below.
Wingman does not add advertising trackers or use your submitted details to target ads. The app does not change its behavior in response to a browser’s Do Not Track signal; the no-sale and no-advertising-sharing commitments apply regardless of that setting. Photos are resized and re-encoded for display, with smaller thumbnail copies; the app does not perform facial recognition or create biometric identification templates.
Recognition choices
We store the recognition option selected for a wingmatch alongside any written description. Your partner can see whether you chose “I’ll find you” before finalization, so both people can resolve a conflicting choice. Written recognition details and preset meeting instructions are included in the finalized exchange. Selecting the front-door option triggers a mapped-business check of the agreed coordinates. These match records follow the match-retention and cleanup rules described below.
Immediate photo removal by visitors
Any visitor, including someone without an account, live request or uploaded picture, can open a photo’s three-dot menu and select the red X beside “This photo violates someone’s rights, copyright, or laws.” After a successful removal, the photo is detached from the live request and its original and thumbnails stop being served. The request itself stays live. The action is immediate and does not wait for the uploader’s approval or an operator review.
We chose this approach to let people act quickly when an image may infringe privacy, consent, copyright or other rights. Protecting someone from continued unwanted exposure takes priority over the inconvenience of losing a profile picture. This means a visitor can remove a photo mistakenly or abusively. Removal does not establish that a law or someone’s rights were actually violated.
The updated app removes visible copies when the removal reaches that page, normally through its next successful check-in or photo-status check. It also clears the uploader’s associated saved browser photo and photo references in saved match data. A closed, offline, suspended or outdated browser cannot be remotely erased: a browser that has recorded the photo’s association checks again when it returns and connects. Older browser copies may lack that association. Screenshots, downloads, device backups and copies outside Wingman remain outside our control.
We attempt deletion of the original and thumbnail files immediately; storage failures are retried by later cleanup while the live photo stays unavailable. A small removal record containing the photo identifier, associated request identifier when available, and removal time is retained without a fixed expiry so returning browsers can recognize the removal. It contains no image or reporter identity and is not subject to the 90-second live-request timeout. Infrastructure logs and backups have their separate retention described below.
This tool removes the selected uploaded photo and references to that same upload. It does not automatically recognize separately uploaded duplicates. For duplicate images, repeated uploads, other content or a formal rights request, use Report a concern.
Live expiry, server cleanup and backups
While your request is active, the page normally checks in about every 10 seconds. A successful renewal extends its live expiry by 90 seconds. Closing the page, losing connectivity or having the browser suspend it stops renewals when no further check-ins reach the server. A background tab can still check in, so simply switching tabs does not necessarily end a request.
After 90 seconds without renewal, the live API stops returning your request. Previously loaded screens may not reflect that until they refresh successfully. Physical deletion happens separately and can take longer.
- Requests and matches: later matching, meetup-check, business-search or place-search API activity can schedule background cleanup after its response. A shared database lease limits cleanup to one owner, with a cooldown and bounded batches; there is no independent deletion timer. It deletes expired records and associated match records, and also retires scheduled plans whose meeting time is more than an hour past. Relative (“Now / travel time”) requests have no appointment-age cutoff, but use the same heartbeat-based session expiry and removal process. With no later traffic, a backlog, an interrupted background task or an error, expired database records can remain longer. Live access checks exclude expired records before physical deletion. Leaving through the app requests deletion of your live request immediately.
- Finalized plans and wingfams: completing a wingmatch triggers cleanup of ordinary matched requests. An active wingfam request can remain open, and a short-lived permission record can retain the public request details needed to reopen a wingfam. That record can renew while the relevant final screen remains active and is removed by later cleanup after expiry.
- Uploaded photos: the photo endpoint stops serving a photo once it has no active associated request. Removal of stored originals and thumbnails happens in background cleanup batches triggered by subsequent matching, meetup-check, business-search or place-search API activity. A valid wingfam reopening permission can temporarily preserve the photo. Cleanup failures are retried on later activity, so storage deletion has no guaranteed 90-second deadline.
- Abuse prevention and map results: IP-derived rate-limit records generally have a two-minute expiry and are removed during later cleanup. Address and business-name search results are cached in D1 for 24 hours when nonempty and 30 seconds when empty, using normalized search text or exact reverse-lookup coordinates. These shared rows contain result addresses, coordinates and expiry without visitor/session identifiers; up to 500 entries also remain in server memory. Expired rows stop being reused and are deleted by shared background cleanup; provider errors are not cached. Selected places use the separate coordinate suitability cache. Shared raw business-query results are retained for 24 hours, including valid empty results; those results concern searched places and areas rather than your full profile.
Hosting backups and logs have separate retention. The site uses Cloudflare D1 database storage. Cloudflare documents automatic database recovery history of up to 7 days on Workers Free or 24 hours on Workers Paid. Deleted database information may remain recoverable during the applicable window. See Cloudflare’s D1 Time Travel and backups policy (opens in a new tab) for its current documentation. These are provider plan limits, not a claim about which plan Wingman’s hosting platform uses.
The 90-second timeout does not apply to provider logs, backup history, browser storage, copies already received by someone else, or emails and reports sent to the operator. Hosting providers apply their own retention settings and legal obligations. Support and report correspondence may be kept as needed to handle the matter and meet legal obligations; it is not subject to a fixed 90-second deletion schedule. We do not promise that every copy is erased when you leave.
Live visitor counts
To count browsers viewing available wingmen, the visible homepage sends a random, short-lived visitor identifier with its regular activity checks. Ordinary tabs share this identifier through local storage. The server stores its hash, a 90-second expiry, available device coordinates or approximate IP-based coordinates, approximate city, state/province and country labels derived from device coordinates when available, with Cloudflare’s incoming-connection geography as a fallback, and a temporary request-session hash used to exclude people with an open request from the nearby viewer count. Visitor coordinates and identifiers are not included in public responses. Public aggregate counts include a breakdown by city, state/province and country, including groups with one viewer. The breakdown can be sorted by count or by approximate straight-line distance from your supplied device or IP-fallback coordinates to a public city map point. Distances are not calculated to other visitors’ positions. To obtain public city points, our server sends only city name, state/province and country to Photon. These separate city-point cache rows store the geographic name key, public city coordinates and expiry, without visitor identifiers or individual visitor coordinates. Successful city points are reused for 24 hours and unsuccessful lookups for 30 seconds; expired rows are removed during later uncached city-point lookups. Distances are computed for the current response, not stored as a visitor history. Your browser locale formats distances locally in miles or kilometres. The popover hides state/province and country labels when they match the viewing browser’s approximate region and country, but the grouped response retains those labels. To resolve device coordinates into geographic labels, our server sends coordinates rounded to three decimal places to Photon, our existing address-lookup provider. Subdivision and neighbourhood labels are excluded from city selection. When no usable city/town label is returned, an additional query to the same Photon provider searches for a nearby city-level place within 20 km, matching the known country and state/province. This is an approximate community label and may differ from your postal city or legal municipality. Rounded-coordinate city lookup results are also cached in the database for reuse across visitors and server restarts. Successful results are reused for 24 hours; unsuccessful lookups are reused for 30 seconds before retrying. These lookup records contain the coordinate grid cell and city/region/country labels, without visitor identifiers, session identifiers or IP addresses. Expired lookup rows are removed during later cache lookup activity, and provider backup limitations still apply. Up to 500 results may additionally be reused in server memory for five minutes. This avoids a lookup for every heartbeat or small GPS change. Without usable device labels, Cloudflare’s IP-based geography supplies a fallback; if hosting labels are missing, available approximate IP coordinates can also be reverse-geocoded. IP-based geography may differ from physical location, especially on mobile networks or VPNs. This feature does not add raw IP addresses to visitor records. Small-area counts may still reveal that someone is present, especially where few people are nearby. This is not a verified count of individual people: separate devices, private windows, blocked storage, automated clients or simultaneous new tabs can affect accuracy. Viewers include people who have posted a request.
After 90 seconds without renewal, a visitor no longer counts. Expired server entries are removed on subsequent matching-API activity; the city, region and country labels follow that same lifecycle. Physical deletion and provider backups have the limitations described above. The browser marker may remain while the site is closed, but an expired marker is replaced on a later visible visit. It is not used for a cross-site profile or advertising.
Last browser activity: while the Wingman page is visible, it observes pointer movement and presses, mouse-wheel or touch scrolling, taps and keyboard interaction. Scroll events count only near a trusted input event, so automatic page positioning alone does not mark someone active. This activity feature keeps only the latest interaction time in page memory; it does not collect key values, typed content, pointer coordinates, scroll positions, event histories or activity in other tabs, sites or apps. When this page has a live request, or posts or reopens one, the next existing heartbeat or request action sends elapsed milliseconds since that interaction to Wingman. No separate request is sent for each movement. The server converts that reported age into an approximate timestamp and stores the newest value on the request; an older report from another tab does not replace a newer value. The public request, quick info and wingmatch views show elapsed time since this activity separately from request age and the last check-in. This is browser-reported activity and can be delayed, blocked or inaccurate; it is not proof that a person is watching or will respond. Browsing without posting does not store an activity timestamp on a visitor record. The timestamp follows the request’s existing expiry and deletion rules; already received snapshots or the existing short-lived finalized-match recovery copy can retain it under the rules described above. It is not added to saved previous-request history, a separate activity log, an advertising profile or a cross-site identifier. Reloading clears the page’s interaction observation; the server can retain the previously reported request timestamp until the request is deleted.
To prevent duplicate map lookups, D1 also stores short-lived lookup leases containing a lookup key, random per-attempt owner token and 20-second expiry. Text keys include normalized searches; suitability keys contain exact coordinates; business keys hash the full map query. These records are not linked to visitor/session identifiers. They are released when work ends or become eligible for replacement after expiry. Abandoned expired rows are removed by shared background cleanup, not by a separate timer. Raw business responses, including valid empty results, are cached in D1 for 24 hours, with up to 100 entries in server memory. Expired results are removed by shared background cleanup. These lifetimes do not override hosting backups.
The suitability diagnostics also display check times, result sources, cache expiry and reuse explanations in page memory. This does not create a persistent browser suitability cache. The diagnostics Log displays failures from this page’s provider requests and lookup coordination events such as cache hits and waits, as well as IP-fallback attempts, cache provenance, result and expiry times, and changes between IP and device location. IP-fallback events do not include the IP address or coordinates. Entries include timestamp, API purpose, provider hostname, HTTP status and up to 4,096 characters of provider output. That output can echo a searched location. Coordination events include only the lookup category and event, not the query, coordinates or owner token. The latest 100 entries are kept only in page memory and clear on reload; they are not written to browser storage or a shared diagnostic database. Provider labels omit query strings. Other visitors cannot retrieve this page’s log through the app.
Your appearance choice (Light, Dark or Auto) is stored locally under wingman-theme and shared between same-site tabs. Auto is the default and follows your device appearance. This preference is not sent to Wingman’s server.
What stays in this browser
The browser uses a short-lived posting marker and a change signal to coordinate Wingman tabs. These contain a temporary random marker and timing information, not your request text or photo. They do not create a persistent browser identity. The browser also records dismissed wingmatch identifiers for up to 24 hours so closing a completed match persists across reloads. Expired dismissal entries are ignored and replaced on later dismissals. A saved photo identifier lets this browser check whether its associated profile photo was removed.
Wingman uses browser storage for convenience and recovery. This can remain on your device after you close the site, including on a shared device. A later visit can use these values again.
- Draft and profile photo
- Your saved form details, including unposted plan text, search radius, selected place and time settings, and processed photo stay in local storage until you reset or remove them, overwrite them, or clear this site’s data. Active request displays also show time since creation and the last server-observed check-in derived from the existing expiry timestamp; these displays do not create a new tracking record. Typing a draft does not itself post a public request, but location and search features still contact the services described here.
- Previous requests
- Up to five previous requests, including saved plan details and comments, are kept in this browser for reuse. They remain until replaced by newer entries, cleared with the history control, or removed through browser settings.
- Final wingmatch recovery copy
- The browser can save the finalized plan, recognition details and any exchanged phone number to recover from a reload. Its usable lifetime is 90 seconds from its last save and can be renewed while the final screen is open. Expired copies are discarded when the app next reads them; a closed browser cannot run a deletion timer, so the underlying saved value can remain on the device longer.
- Saved map view
- The main map’s displayed center coordinates and zoom level stay in local storage so the view can be restored when you reload or return. This is the area you were viewing, which may differ from your device location or meetup point. It remains until another map view replaces it or you clear this site’s browser data.
- Preferences and location cache
- Your sound preference is saved until changed or cleared. An approximate IP-based location can be reused for up to an hour within the tab’s session storage. Expiry controls reuse; it does not guarantee immediate erasure from a closed tab.
- Visitor presence
- A random visitor identifier and 90-second reuse deadline are stored locally so ordinary tabs can share a count. Visible homepage activity renews it. An expired identifier is replaced on a later visit; a closed browser can retain the expired marker until then or until site data is cleared.
- Session cookie and offline files
- A first-party session cookie normally expires 90 seconds after its latest renewal and is restricted from page scripts. The installed web app can cache public icons and an offline page. It does not intentionally put private match records in the offline-file cache.
To remove these local copies, clear Wingman’s cookies and site data in your browser or installed web app. Reset form, remove photo and clear history controls address their respective saved items. Clearing browser data alone does not send a server deletion request and cannot remove a partner’s saved copy.
Service providers and external links
These services receive information needed for the feature you use. Their own policies govern their independent processing and retention. Requests made directly by your browser can reveal your IP address, browser information and, where the browser permits it, referring-page information.
- OpenAI’s Sites hosting platform and Cloudflare: delivery of the website, database, photo storage, network security and operational records. Read the OpenAI Privacy Policy (opens in a new tab) and Cloudflare Privacy Policy (opens in a new tab).
- ipapi.is: the browser contacts this service for an approximate IP-based area when device location is unavailable. It receives your IP address. ipapi.is Privacy Policy (opens in a new tab).
- Photon / komoot: Wingman’s server sends your address search text or selected coordinates to the Photon geocoder to find or label a place.
- OpenStreetMap and Overpass: your browser requests map tiles from OpenStreetMap, revealing the area viewed. Wingman’s server sends nearby search areas to Overpass endpoints operated at overpass.private.coffee, overpass-api.de or VK Maps at maps.mail.ru to find businesses and classify meetup coordinates. The fallback receives the queried point or search area, not your name, photo or request text. VK Maps is an additional provider operated in Russia. Private.coffee policies (opens in a new tab). OpenStreetMap Foundation Privacy Policy (opens in a new tab).
- UNPKG: your browser downloads the Leaflet map library and its styles from this content-delivery service.
- Links you choose: opening directions, screenshot help or another external link sends you to that provider. A directions link includes the selected place; a phone link passes the selected number to your device’s calling app.
Data may be processed in the United States and other countries where these providers operate. A provider link explains that provider’s practices; it does not replace Wingman’s commitments in this policy.
Your choices, rights and security
You can browse without posting, omit an optional photo or phone number, choose what to enter in public fields, change browser location permission, update or leave your live request, and clear saved browser information. Withdrawing a request stops its live availability but cannot recall information someone has already received.
Depending on where you live and which laws apply, you may have rights to access, correct or delete personal information, restrict or object to processing, receive a portable copy, withdraw consent, or complain to a privacy authority. Email todd@hendricks.cc to exercise applicable rights or appeal a decision where that right applies. Provide only enough context to locate the information; do not email passwords or government identification. We may need proportionate verification before releasing or changing information. With no account and short-lived records, we may be unable to identify a past request or retrieve information already deleted. We will not discriminate against you for exercising applicable privacy rights.
We use HTTPS, session controls and limited live availability to help protect information. No website, device or transfer is perfectly secure. Do not post sensitive information you do not want others to retain. We will address security incidents and make legally required notifications under applicable law.
Adults only: Wingman is for people 18 and older. We do not knowingly permit children to use the service. Age is self-reported and not independently verified. Please report a minor’s information or an unsafe photo through Report a concern so we can address it.
Contact and policy updates
For privacy questions, requests or concerns, contact Todd Hendricks at todd@hendricks.cc, Illinois, USA.
We will update this page and its date when our practices change. Material changes will be called out on the site or through another notice appropriate to the change, with consent obtained where required. The Terms of Service explain the rules for using Wingman.