Skip to content
مَحَكّ

Privacy Policy

Last updated: 6 September 2026

This page explains what data Mahak collects, why, and what you can do about it. Written in plain English.

The short version

  • We collect your name, email, and profile picture when you sign in.
  • Your contributions are public. Anyone can see them.
  • We do not sell your data or show ads.
  • We do not use tracking cookies.
  • You can ask us to delete your data at any time.

What we collect

DataWhyPublic?
Name and profile pictureTo show who contributed whatYes
Email addressTo identify your account (from your sign-in provider)No
Contributions (outputs, votes, suggestions)They are the point of the siteYes
Handle (if you use one)To sign contributions without a full accountYes
IP addressFor rate limiting and bot protection onlyNo (not stored long-term)
Your country/region when voting (from Cloudflare edge geo)To study cultural and dialect differences in evaluation; published only as suppressed aggregates (buckets under 5 voters withheld)No (aggregates only)
Arena skip statisticsTo study cultural differences in which matches judges skip: we record the prompt, the two models, and coarse Cloudflare geo (country, region, timezone) — no identity, no IP, no free textNo (aggregate data)

What we do not collect

  • No tracking cookies.
  • No advertising identifiers.
  • No data from third-party sites you visit.
  • We do not sell, rent, or trade your data to anyone.

Third-party services

ServiceWhat it doesWhat it sees
GitHubSign-in provider (if you choose GitHub)Your Mahak redirect
GoogleSign-in provider (if you choose Google)Your Mahak redirect
CloudflareHosting, DNS, DDoS protectionRequest metadata (IP, headers)
Cloudflare TurnstileBot protectionBrowser signals and challenge data, per Cloudflare’s privacy policy
Bareed (Waqf mail)Delivers the newsletter confirmation emailYour email address and the destination
Cloudflare Web AnalyticsPage views (cookieless, privacy-first)Page URL, referrer — no cookies, no fingerprinting

These providers have their own privacy policies. We recommend reading them.

Sign-in providers

When you sign in with GitHub or Google, that provider tells us your name, email, and profile picture. We store these to identify your account. We do not post to your account or access anything else.

You can revoke Mahak's access at any time from your provider's settings:

Contributions are public

When you submit an output, vote, or suggest a prompt, that action is public and attributed to you (by your account name or handle). Anyone can see it. Anyone can copy it. This is by design — Mahak is an open, community-driven project.

Do not paste personal data about yourself or others into model outputs. Once public, we cannot fully retract it from caches or mirrors.

API tokens (PATs)

If you mint a personal access token, we store a hash of it — never the token itself. We store the token name, prefix (first few characters), scopes, and creation date so you can manage your tokens.

Data retention

We keep your data as long as your account is active. If you ask us to delete your account:

  • Your login data (email, provider link) is deleted.
  • Your contributions become "anonymous" but may remain public (they are part of the public dataset).
  • Your API tokens are revoked.

Your rights

You can:

  • See all your public contributions on the site.
  • Ask for a copy of your data.
  • Ask us to correct anything wrong.
  • Ask us to delete your account.

To exercise any of these, email mahak@waqf.dev or open an issue at the project repository.

Children

Mahak is not directed at children under 13. If you believe a child has created an account, tell us and we will remove it.

Changes

We may update this policy. We will change the "last updated" date above. If the changes are significant, we will try to tell you.

Contact

Questions? Email mahak@waqf.dev or open an issue at the project repository.