Privacy
Privacy policy
WitchWatch collects the minimum needed to publish community sightings and keep them honest. No accounts, no advertising, no data sales.
Last updated September 2, 2026
What is collected when you report
- The report itself: stock state, product, retailer, store name, address, city, state, ZIP, observation time, quantity range, observation type, an optional retailer proof link and an optional note. All of it is public by design.
- A hash of your connection address, salted with a secret and scoped to the day. It exists to enforce rate limits and duplicate control. It is not reversible in practice, is never shown, and is cleared from reports after 30 days.
- The submission time.
No name, email, phone number, account or device identifier is requested or stored with a report.
What is collected when you check a report
A random key that your browser stores locally (so one browser counts once per report), the action you chose, the time, and the same day-scoped address hash. The key never identifies you across sites and can be cleared with your browser data.
Location
Location is requested only when you press a location button. Your browser’s coordinates are rounded to about a mile on your device, sent once to find the nearest ZIP code, and not stored. Search pages carry a ZIP or a place name, never coordinates. Report positions on the map come from store ZIP code centers, never from any person’s location.
Usage counters
WitchWatch keeps daily counters of actions such as searches, report starts and retailer link clicks, with a coarse key (for example the stock-state filter used or the retailer opened). Counters contain no identifiers, no query text and no coordinates. There is no third-party analytics script and no advertising code.
Cookies and storage
WitchWatch sets no cookies. It uses browser storage for the check key described above and, if you install it to your home screen, a small cache of the app shell, the offline page, product codes and retailer links. Cached pages are labeled with their retrieval time and never present cached reports as current.
Hosting and logs
The site runs on Cloudflare Workers with a Cloudflare D1 database. Cloudflare processes requests, including addresses, as the hosting provider and keeps short-lived operational logs. WitchWatch links out to Alani Nu, Target, Walmart, Kroger, Five Below, Sam’s Club, Amazon and Google Maps; those sites apply their own policies once you leave.
Messages
The contact form stores your message, an optional reply address you choose to give, and the day-scoped address hash, privately for the operator. Messages are kept for up to 365 days and are never published or added to any list.
Retention and removal
Active reports expire on the published schedule. Expired and hidden reports are kept for 90 days for moderation history, then deleted. To remove a report you filed or to request deletion of a message, use the contact and removal form.
Children
The product tracked here is a caffeinated energy drink that its manufacturer does not recommend for children. WitchWatch is not directed at children and offers no games, rewards or incentives.
Changes
This policy changes only when the site’s behavior changes. The date at the top is the last revision.