Privacy

Privacy.

What we collect, what we don't, and what you can do about it.

Last updated 2026-07-22

The short version

You use Weird Requests under a handle. Your legal name is never shown to other users, and your email address is never shown to anyone.

We collect what a marketplace needs to work: an account, what you post, the messages you send, and the record of money moving. We do not sell it, we do not share it for advertising, and we do not use it to train AI models.

Three things worth knowing up front:

  • Payments are handled by our payment providers, not by us. We never see your full card number.
  • Everything uploaded is scanned for child sexual abuse material. Matches are reported to the authorities, and that is the one area where we hand over everything we hold without notifying you first.
  • Deleting your account does not erase your financial records. Law requires us to keep them. We explain exactly what survives below.

This policy applies to the Weird Requests website, mobile applications and related services.

Who is responsible for your data

The controller of your personal data is:

Digital Envision LLC 16192 Coastal Highway Lewes, DE 19958 United States

Contact for any privacy matter, including requests and complaints: support@weirdrequests.com

We have not appointed a Data Protection Officer, as we are not required to. We have not appointed an Article 27 representative in the EU or UK. If that changes, this section will be updated.

What we collect

Information you give us

  • Account: email address, display name, @handle, and a password, which is stored only as a cryptographic hash.
  • Profile: bio, avatar, display currency, preferred language, away status.
  • Security: two-factor authentication secrets and backup codes, if you enable them.
  • Marketplace activity: requests, applications, offers, delivered work, ratings, tips, disputes and dispute evidence.
  • Messages you exchange with other users, and any files attached.
  • Location, if you attach one to a request: a free-text place name, a country code, and approximate coordinates.
  • Correspondence you send to support@weirdrequests.com.
  • Brand applications: business name, website, description and supporting documents, if you apply for a brand account.

Information from payment providers

Which of the following we receive depends on the payment and payout methods available to you and which you use.

  • Stripe customer identifier; connected-account identifier and payout status if you get paid; the last four digits and brand of a saved card.
  • Coinbase Commerce charge identifiers, and a payout address if paid in cryptocurrency.
  • Wise recipient identifier for bank-transfer payouts.

We never receive or store your full card number, security code, bank credentials, or the identity documents used for verification. Those go directly to the provider, which holds them under its own policy. We receive only a status.

Information collected automatically

  • IP address, used for rate limiting, fraud prevention, security and abuse investigation.
  • Browser and device user agent, stored with push-notification registrations.
  • Session records, so you can see and revoke where you are signed in.
  • Usage and interaction events through Google Analytics and Vercel Analytics.
  • Audit logs of consequential actions, and a transaction event log for every movement of money.
  • Content moderation outcomes, including automated scan results attached to uploads.

Information we do not collect

We do not ask for your date of birth, government identification, or home address. Where verification is legally required before we can pay you, Stripe performs it and holds those documents.

We do not knowingly collect special category data — health, biometrics, religion, politics, sexual life — and ask that you do not put it into requests, messages or deliveries.

How we use it

  • Operating your account and authenticating you.
  • Publishing requests and showing them to relevant users.
  • Delivering messages and notifications, in-product, by email and by push if enabled.
  • Taking payment, holding escrow, releasing payouts, and issuing refunds.
  • Moderating content and enforcing the Content Rules.
  • Detecting and preventing fraud, abuse, spam and security incidents.
  • Handling disputes between users.
  • Providing support and responding to you.
  • Meeting legal obligations: tax and accounting records, responses to lawful requests, and mandatory reporting of child sexual abuse material.
  • Understanding how the product is used so we can improve it.

We do not

  • sell your personal information;
  • share it for cross-context behavioural advertising;
  • use it to train machine-learning models;
  • track you across other websites;
  • use automated profiling to make decisions with legal effects, other than the content screening described below.

Our legal bases (UK/EU/EEA)

If you are in the United Kingdom, European Union or European Economic Area, we rely on the following bases under the UK GDPR and EU GDPR:

Performance of a contract (Article 6(1)(b))

Creating and running your account, publishing requests, delivering messages, processing payments and payouts, and handling disputes. Without this we cannot provide the service you signed up for.

Legitimate interests (Article 6(1)(f))

Security, fraud and abuse prevention, content moderation, enforcing our Terms, maintaining audit logs, and understanding aggregate product usage. We have assessed these interests against your rights and freedoms and consider them proportionate. You may object at any time — see "Your rights".

Legal obligation (Article 6(1)(c))

Retaining financial records for tax and accounting, responding to lawful requests from authorities, and reporting child sexual abuse material.

Consent (Article 6(1)(a))

Optional analytics, push notifications, and making a completed delivery publicly visible. You may withdraw consent at any time; withdrawal does not affect processing carried out before it.

Vital interests (Article 6(1)(d))

In rare cases, where processing is necessary to protect someone's life or physical safety.

Automated screening and decisions

Content you upload or write is screened automatically before and after publication:

  • All uploads are scanned for child sexual abuse material.
  • Text and images are screened by an automated moderation provider for prohibited material.
  • Messages are screened for attempts to move a transaction off-platform.

An automated result can hide content, block a message, hold a delivery, issue a strike, or suspend an account before any person reviews it. We do this because waiting for human review on this category of harm is not acceptable.

You have the right to obtain human review of any such decision, to express your point of view, and to contest it. Write to support@weirdrequests.com and a person will look at it.

We do not use automated processing to make decisions about your creditworthiness, employment, or any comparable matter.

Who we share it with

Other users

Visible to others: your @handle, avatar, bio, ratings, completed-work counts, and away status. The content of a request is visible according to how you published it. Direct offers are visible only to you and the named recipient.

A completed delivery becomes public only if the poster and the fulfiller each separately opt in, and either can withdraw that at any time.

Never visible to other users: your legal name, your email address, your payment details, your IP address, and your location coordinates.

Service providers

Each processes only what it needs, under contract, and may not use it for its own purposes.

  • Vercel — hosting and content delivery (United States).
  • Supabase — primary database (United States).
  • Cloudflare — file storage (R2), video processing (Stream), and automated scanning of uploads.
  • Stripe and Stripe Connect — card payments, payouts, and identity verification for people who get paid.
  • Coinbase Commerce — cryptocurrency payments, where that method is offered.
  • Wise — bank-transfer payouts, where that method is offered.
  • Resend — transactional email.
  • Pusher — real-time chat and notifications.
  • Inngest — background job processing.
  • Upstash — rate limiting.
  • OpenAI — automated moderation of text and images.
  • OpenRouter — the optional AI writing assistant, only when you use it.
  • Google — Analytics, Maps and Places for the location field, and reCAPTCHA for bot protection.
  • Open Exchange Rates — currency conversion rates.
  • Apple, Google, Mozilla and Microsoft push services — delivering notifications to your device, if enabled.

Legal and safety disclosures

We disclose information where legally required, or where we believe in good faith it is necessary to investigate fraud, enforce our Terms, or prevent serious harm.

Child sexual abuse material is reported to the National Center for Missing & Exploited Children and, through them, to law enforcement. That reporting is mandatory. We do not notify the account holder beforehand, and we preserve the related material and records as the law requires.

Where we receive a lawful request for your data and are legally permitted to tell you, we will.

Corporate transactions

If the business is sold, merged, or reorganised, your data may transfer as part of it. You will be notified before any new operator's policy applies to you.

How long we keep it

  • Account and profile: while your account exists.
  • Requests, applications, messages and deliveries: while your account exists, unless deleted sooner.
  • Financial records — transactions, fees, payouts and the event log behind them: seven years from the transaction, as tax and accounting law requires.
  • Audit logs of consequential actions: two years.
  • Session records: until expiry or revocation.
  • Support correspondence: three years.
  • Content confirmed as child sexual abuse material, and the surrounding records: retained as legally required and preserved for the authorities.
  • Backups: rolling, overwritten within 90 days.

What deleting your account actually does

We would rather be straight with you than imply more than we do.

Deleting your account permanently removes your login credentials, two-factor secrets and all active sessions, so nobody can sign in as you again. We then strip the personal information from your profile: email, name, handle, avatar, bio, location, and payment identifiers.

What survives is the financial record. Transaction rows are legally required to be kept, and they reference your account, so the account is anonymised in place rather than deleted outright. What remains cannot identify you.

You cannot delete your account while money is in flight — an unfunded selection, escrow still held, or an open dispute. Resolve those first.

Content you sent to other users, such as messages, remains in their copy of the conversation.

Your rights

Wherever you live, you can export your data and delete your account from settings, and you can write to us about anything else.

UK, EU and EEA

You have the right to: access your data; correct it; delete it; restrict processing; object to processing based on legitimate interests; data portability; and withdraw consent at any time.

You also have the right to lodge a complaint with your supervisory authority. In the UK that is the Information Commissioner's Office. In the EU it is the authority in your country of residence.

California

Under the CCPA as amended by the CPRA you have the right to know, delete, correct, and to non-discrimination for exercising those rights. We do not sell personal information and do not share it for cross-context behavioural advertising, so there is no opt-out to offer. We do not use or disclose sensitive personal information for purposes requiring an opt-out. You may use an authorised agent, with proof of authorisation.

Other US states

Residents of states including Virginia, Colorado, Connecticut, Utah, Texas, Oregon and Montana have comparable rights. We apply one process to everyone rather than sorting by geography. Where a state provides an appeal right against a refused request, you may appeal by replying to our decision.

How to exercise them

Email support@weirdrequests.com. We respond within 30 days and will tell you if we need a permitted extension. We may need to verify that you control the account before we act — usually by asking you to confirm from the registered email address. There is no fee unless a request is manifestly unfounded or excessive.

How we protect it

  • Passwords are hashed and never stored in readable form.
  • Two-factor authentication is available and recommended.
  • Sessions are listed in settings and can be revoked individually.
  • Traffic is encrypted in transit.
  • Media is not served from public addresses. Every media link is signed and expires, so a leaked link stops working rather than granting indefinite access.
  • Private material — direct messages, deliveries before they are made public, and dispute evidence — is resolved only for someone entitled to see it.
  • Access to production systems is limited to those who need it, and consequential administrative actions are logged.
  • Rate limiting and bot protection guard authentication and abuse-prone endpoints.

No system is perfectly secure and we do not claim otherwise. If we become aware of a breach affecting your personal data, we will notify the relevant supervisory authority within 72 hours where required, and notify you without undue delay where the breach is likely to result in a high risk to your rights.

International transfers

We are based in the United States and most of our providers are too, so your data is processed there and in other countries where those providers operate.

If you are in the UK, EU or EEA, this means your data is transferred outside your home jurisdiction. For those transfers we rely on the European Commission's Standard Contractual Clauses, and the UK International Data Transfer Addendum where applicable, together with supplementary measures where needed.

You may request a copy of the relevant transfer mechanism by writing to support@weirdrequests.com.

Cookies and similar technologies

Strictly necessary

Keeping you signed in, remembering your language, protecting forms against automated abuse, and enforcing rate limits. These cannot be disabled without breaking the service, and we do not ask consent for them.

Analytics

Google Analytics and Vercel Analytics, to understand which pages are used and how often. These rely on your consent where consent is required.

We do not use advertising or retargeting cookies, and we do not permit third parties to track you across other sites through the Platform.

Your controls

Most browsers let you block or delete cookies. Blocking strictly necessary cookies will break sign-in. We honour Global Privacy Control signals where they are legally recognised.

Do Not Track

There is no industry consensus on how to respond to browser Do Not Track signals, so we do not respond to them. We do honour Global Privacy Control as above.

Children

Weird Requests is strictly for adults. You must be 18 or older.

We do not knowingly collect personal data from anyone under 18. If we learn that an account belongs to a minor, we close it and delete the associated data except where retention is legally required.

Requests must not feature anyone under 18 as a subject, whether depicted or described. Content depicting the sexual abuse of a child is reported to the authorities and results in immediate, permanent termination.

If you believe a minor is using the Platform, tell us at support@weirdrequests.com and we will act promptly.

Changes to this policy

We will update this page as our practices change. The date at the top always reflects the current version, and we keep prior versions available on request.

Where a change materially affects your rights, we will tell you before it takes effect — by email or a prominent in-product notice — rather than quietly editing the page. Where the change requires your consent, we will ask for it.

Contact and complaints

Digital Envision LLC 16192 Coastal Highway Lewes, DE 19958 United States

For any privacy question, data request, or complaint: support@weirdrequests.com. We answer within 30 days.

If you are not satisfied with our response and you are in the UK or EEA, you may complain to your data protection supervisory authority. You are not required to contact us first, though we would prefer the chance to put it right.