Word Monument.
Menu

Legal

Privacy Policy

Word Monument is a public wall you pay a dollar to write on. There are no accounts and no logins, so there is very little about you for us to hold. And what little we do keep, we keep deliberately. This page says exactly what that is, who else touches it, and what you can ask us to do about it.

Last updated 2026-07-12

Who is responsible for your data

The data controller for Word Monument is Word Monument. If you have a question about this policy, want to exercise one of the rights described below, or think something here is wrong, you can reach us at hello@wordmonument.com. That inbox is the single channel for every privacy request on this site.

What we collect

  • The characters you place and their grid coordinates. This is the product itself. It is public and permanent by design (see below), and it is the one thing here we intend to keep forever.
  • Payment details: handled by Stripe, not us. Your card number is entered on Stripe and never reaches our servers. We store only the fact that an order was paid and a Stripe reference for it.
  • An email address, only if you give one at checkout. It is used to send your receipt and, if something goes wrong with your order, to reach you about it. It is optional and it is not used for marketing.
  • A pseudonymized fingerprint of your IP address. We do not store your raw IP. We store a short, keyed hash of it, used purely to enforce per-visitor limits and stop abuse, detailed in its own section below.
  • The text you place, sent for automated moderation. The assembled message is checked by an automated moderation service to catch content that breaks our Content Policy.

What we deliberately do not collect

  • No accounts, usernames, or passwords. There is nothing to sign up for.
  • No raw IP addresses stored or written to our own logs.
  • No advertising or cross-site tracking cookies, pixels, or fingerprinting.
  • No sale or rental of your data to anyone, for any purpose.
  • No sensitive categories of data (health, biometrics, precise location, and the like). If you volunteer something sensitive inside the characters you place, remember that it becomes public.

Cookies and local storage

Ordinary visitors and buyers get no tracking cookies at all. We do not set analytics or advertising cookies to browse the monument or to buy a cell.

The only cookie our application sets is an httpOnly admin session cookie, issued exclusively to the operator when signing in to the password-protected moderation console. It never touches a normal visit. Separately, our security provider (Cloudflare) may set a short-lived, essential bot-protection cookie to tell real visitors from automated traffic; it carries no advertising or cross-site tracking.

Two small pieces of state live in your browser’s sessionStorage: not cookies, never sent to a server, and wiped the moment you close the tab. One remembers which headline variant our homepage copy test showed you so it stays consistent while you read; the other holds the cells you are mid-way through selecting so a reload doesn’t lose them. Both are purely functional. Neither tracks you across sites or persists after the tab is closed.

Placed characters are public and permanent

The whole point of the monument is that what you write stays up. The characters you place and their positions are visible to anyone who loads the grid, are included in share images derived from it, and are intended to remain indefinitely. Treat every character you place as a public, permanent statement, because that is what it is. Do not place anything you would not want the world to read, now or years from now.

How we handle your IP address (pseudonymization)

Rate-limiting and abuse prevention need some stable, per-visitor signal, but they do not need to know who you are. So instead of storing your IP address, we run it through a keyed one-way function (HMAC-SHA256 using a secret that lives only on the server) and keep just a truncated slice of the result. That value is recorded as reserved_by_ip_hash when you reserve or buy cells and reporter_ip_hash when you report a cell.

Because the secret key is required to compute the hash, nobody with access to the database can reverse a stored value back into an IP address or brute-force the space of possible addresses. The raw IP is used transiently in memory to compute the hash and is then discarded. It is never written to our database or application logs. The hashes exist only to count how many cells come from one source and to catch abuse; they are not used to identify or profile you.

Automated moderation and OpenAI

After a purchase (and periodically thereafter as a safety sweep), the assembled text of the characters on the affected cells is sent to OpenAI’s moderation endpoint, which returns an automated assessment of whether the content is likely to violate our Content Policy. Flagged content is queued for human review and may be removed.

We disclose this plainly because it means user-submitted content leaves our infrastructure: OpenAI receives the text you placed on the public grid. It receives that text alone, for moderation only: not your email, not your payment, and not the IP hashes. A quicker, self-contained blocklist check also runs before payment; that one stays entirely on our own servers.

Who else processes your data (sub-processors)

We keep the list of third parties short and name every one of them. Each processes only what it needs to do its job, under its own terms:

  • StripePayment processing

    When you buy a cell you are handed off to Stripe to enter and submit your card details. Those card numbers go directly to Stripe and never pass through, or get stored on, our servers. Stripe returns only a payment confirmation and a reference we use to fulfil the order. Stripe is an independent controller of the payment data it collects and handles it under its own privacy policy.

  • SupabaseApplication database

    Supabase hosts the database that holds the monument itself: the placed characters and their grid coordinates, order records, any checkout email you provide, and the pseudonymized IP hashes described below. It stores data on our behalf and processes it only to run the service.

  • CloudflareHosting, CDN & bot protection (Turnstile)

    Cloudflare serves the site from its global edge network and runs Turnstile, the challenge that verifies you are a person rather than an automated script before a purchase. As the network in front of the site, Cloudflare processes connection metadata (including your IP address in transit) to route requests and block attacks, and may keep short-lived operational logs for security. It does not receive the contents of your payment.

  • OpenAIAutomated content moderation

    To keep the grid free of hateful, abusive, or illegal content, the assembled text of placed characters is sent to OpenAI’s moderation endpoint for an automated classification. This is text you have chosen to publish on a public wall; it is submitted for the sole purpose of moderation and is not tied to your identity. OpenAI processes it under its API data-usage terms.

International data transfers

The providers above are based in, or process data in, the United States. If you use the site from the United Kingdom, the European Economic Area, or elsewhere, your data (principally the text you choose to publish, and, where applicable, your checkout email and the pseudonymized hashes) is transferred to and processed in the US. Where the law requires it, those transfers rely on the safeguards offered by each provider, such as Standard Contractual Clauses. You can ask us for details using the contact address above.

Legal basis for processing (GDPR / UK GDPR)

Where the UK GDPR or EU GDPR applies to you, we rely on the following legal bases:

  • Performance of a contract. Taking your payment, placing your characters, sending your receipt, and delivering the cell you bought are all processing necessary to carry out the purchase you asked for.
  • Legitimate interests. Preventing fraud and abuse, enforcing per-visitor limits, running content moderation, and keeping the service secure rest on our legitimate interest (and the public interest) in running a wall a million people can write on without it filling with abuse. We have designed these to be as data-minimizing as we can (pseudonymized hashes rather than stored IPs, no profiles).
  • Legal obligation. We may retain certain transaction records where accounting or tax law requires it, and we act on lawful requests and mandatory reporting obligations (for example, content involving the exploitation of minors).

Your rights and how to use them

Depending on where you live, you may have the right to request access to the personal data we hold about you, to have it corrected, to have it deleted, to restrict or object to certain processing, and to data portability. To exercise any of these, email hello@wordmonument.com. We will respond within the timeframe the applicable law requires.

One honest limit: a deletion request cannot remove characters you have already placed. They are public and permanent by design, and the monument would not work if any cell could be recalled. Deletion applies to other associated data we hold, such as a checkout email on file. If a specific cell needs to come down because it breaks the rules, that is a moderation matter: use the Report control on the grid or see our Content Policy. You also have the right to complain to your local data-protection authority.

California privacy (CCPA / CPRA)

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We never have. California residents have the right to know what personal information we collect and to request its deletion, subject to the same permanence limit above, and we will not discriminate against you for exercising those rights. Use the same contact address to make a request.

Children

Word Monument is not directed to children, and it is intended for people aged 18 or older. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us information or placed content, contact us and we will address it, including removing associated data where we are able to.

How long we keep things

  • Placed characters and their positions: indefinitely. Permanence is the product.
  • Payment data: held and retained by Stripe under its own policy; on our side we keep only the minimal order record and reference for as long as accounting and legal obligations require.
  • Pseudonymized IP hashes: kept only as long as they are useful for rate-limiting and abuse prevention.
  • Checkout email, if provided: kept for order support and required record-keeping, then removed on request or when no longer needed.

Changes to this policy

We may update this policy as the service evolves or as the law requires. Material changes will be reflected by the “Last updated” date at the top of this page. Significant changes to how we handle data will be described plainly rather than buried.

Contact

For anything in this policy (a question, a correction, or a request about your data), email hello@wordmonument.com. You can also read the Terms of Service for how the money side works.