Privacy Policy
Last updated: 6 September 2026
This page explains what data Mahak collects, why, and what you can do about it. Written in plain English.
The short version
- We collect your name, email, and profile picture when you sign in.
- Your contributions are public. Anyone can see them.
- We do not sell your data or show ads.
- We do not use tracking cookies.
- You can ask us to delete your data at any time.
What we collect
| Data | Why | Public? |
|---|---|---|
| Name and profile picture | To show who contributed what | Yes |
| Email address | To identify your account (from your sign-in provider) | No |
| Contributions (outputs, votes, suggestions) | They are the point of the site | Yes |
| Handle (if you use one) | To sign contributions without a full account | Yes |
| IP address | For rate limiting and bot protection only | No (not stored long-term) |
| Your country/region when voting (from Cloudflare edge geo) | To study cultural and dialect differences in evaluation; published only as suppressed aggregates (buckets under 5 voters withheld) | No (aggregates only) |
| Arena skip statistics | To study cultural differences in which matches judges skip: we record the prompt, the two models, and coarse Cloudflare geo (country, region, timezone) — no identity, no IP, no free text | No (aggregate data) |
What we do not collect
- No tracking cookies.
- No advertising identifiers.
- No data from third-party sites you visit.
- We do not sell, rent, or trade your data to anyone.
Third-party services
| Service | What it does | What it sees |
|---|---|---|
| GitHub | Sign-in provider (if you choose GitHub) | Your Mahak redirect |
| Sign-in provider (if you choose Google) | Your Mahak redirect | |
| Cloudflare | Hosting, DNS, DDoS protection | Request metadata (IP, headers) |
| Cloudflare Turnstile | Bot protection | Browser signals and challenge data, per Cloudflare’s privacy policy |
| Bareed (Waqf mail) | Delivers the newsletter confirmation email | Your email address and the destination |
| Cloudflare Web Analytics | Page views (cookieless, privacy-first) | Page URL, referrer — no cookies, no fingerprinting |
These providers have their own privacy policies. We recommend reading them.
Sign-in providers
When you sign in with GitHub or Google, that provider tells us your name, email, and profile picture. We store these to identify your account. We do not post to your account or access anything else.
You can revoke Mahak's access at any time from your provider's settings:
- GitHub: Settings → Applications
- Google: Account → Security → Third-party access
Contributions are public
When you submit an output, vote, or suggest a prompt, that action is public and attributed to you (by your account name or handle). Anyone can see it. Anyone can copy it. This is by design — Mahak is an open, community-driven project.
Do not paste personal data about yourself or others into model outputs. Once public, we cannot fully retract it from caches or mirrors.
API tokens (PATs)
If you mint a personal access token, we store a hash of it — never the token itself. We store the token name, prefix (first few characters), scopes, and creation date so you can manage your tokens.
Data retention
We keep your data as long as your account is active. If you ask us to delete your account:
- Your login data (email, provider link) is deleted.
- Your contributions become "anonymous" but may remain public (they are part of the public dataset).
- Your API tokens are revoked.
Your rights
You can:
- See all your public contributions on the site.
- Ask for a copy of your data.
- Ask us to correct anything wrong.
- Ask us to delete your account.
To exercise any of these, email mahak@waqf.dev or open an issue at the project repository.
Children
Mahak is not directed at children under 13. If you believe a child has created an account, tell us and we will remove it.
Changes
We may update this policy. We will change the "last updated" date above. If the changes are significant, we will try to tell you.
Contact
Questions? Email mahak@waqf.dev or open an issue at the project repository.