spicy-mayo.com

Privacy policy

We collect the minimum information needed to send a single launch notification. This page explains exactly what we collect, why, and how to ask for it to be deleted.

What we collect

  • Email address — the address you submit to the waitlist form.
  • Country — a 2-letter ISO code read from the request's request.cf.country field at the Cloudflare edge, so we can roughly see where interest is coming from. We do not store your IP address.
  • Source — which form on the page you used (e.g. hero).
  • Submission timestamp — when you submitted the form.

We do not set any tracking cookies. We do not run third-party analytics scripts on this page. We use Cloudflare Web Analytics, which is cookieless and aggregate-only. We use Cloudflare's per-IP Rate Limiting binding to stop abuse of the waitlist endpoint; the rate limit key (your IP) is held by Cloudflare's edge and is not written to our database.

Why we collect it

The only purpose is to send you one email when spicy-mayo (or its eventual product name) becomes publicly available. If the model is never released, the list is deleted.

We do not sell, rent, or share the list with anyone.

How long we keep it

Until you ask us to delete it, or until 12 months after the public release of the model — whichever comes first.

How to request deletion

Email the address you signed up with to delete@spicy-mayo.com with the subject "Delete". We will remove the row from the waitlist table within 7 days and confirm by reply.

Where the data lives

Email records are stored in a Cloudflare D1 database colocated with the application. Country is a 2-letter ISO code, not an IP address. Cloudflare's per-IP Rate Limiting binding enforces the waitlist abuse cap at the edge; the rate limit key is not persisted to our database.

Changes to this policy

If we change what we collect or how we use it, the change will be reflected on this page with a new "last updated" date.

Last updated: 10 September 2026.