YWG.AI

CURRENT FREE AND PRO API

Privacy

YWG.AI is operated by DIEGO TI LTDA. This page describes the current API. It does not certify legal compliance or replace your own privacy review.

Account access

YWG stores a verified email address for sign-in. A link expires after 15 minutes. YWG stores a hash of each private API token, not its raw value. A token expires after 30 days, and you can revoke it through the account API.

Dashboard login cookie

The dashboard on dash.ywg.ai uses the first-party __Host-ywg_dash cookie to keep this browser signed in after a reload. It contains a random session value, not your API key. The cookie is Secure, HttpOnly, SameSite=Strict, and host-only. Browser scripts cannot read it. The server stores only its SHA-256 hash, its source token and account references, read-only scopes, and expiry and revocation times.

The session expires after at most 30 days or at the source token's expiry, whichever comes first. Revoking the token or removing its read scopes invalidates the session. Sign out on shared devices; that revokes this browser session and clears its cookie. The dashboard cookie authorizes only selected account-scoped reads on dash.ywg.ai. It cannot change sites or billing. This login cookie is separate from the analytics collector, which sets no cookie or browser identifier.

Cloudflare Email Service delivers sign-in mail. Cloudflare Turnstile checks requests for abuse. Cloudflare edge services and request logs may process technical data, including a client IP and User-Agent. Do not assume that no provider processes an IP address or sets a security cookie.

Analytics events

YWG stores bounded event paths, names, properties, and times. The default policy for new events can also store page titles, URL queries, UTM and click IDs, referrer paths and queries, screen size, language, normalized browser/OS/device, and country/region/city from Cloudflare request metadata. A site owner can set bounded collection choices at site creation or through GET/PATCH /v1/sites/{id}/collection for future events. A site can exclude path prefixes, skip sensitive query/hash keys, honor DNT, or filter known bots. A policy reduction affects new events only. It does not erase older data. An optional first-party browser script reads public site flags with an exact HTTPS Origin and removes disabled fields before it sends an event. A site can opt in to an early DNT/GPC check that prevents even this public config request. The server applies the policy again. Do not send personal data in a path, query, title, referrer, or event label.

A separate site-bound server token can submit bounded events from a trusted application. The application must verify any Stripe or HookFork signal before it sends an event. YWG does not verify a payment or change a Pro entitlement from this event. The API rejects a browser Origin, cookies, raw payment IDs, customer details, and free text. It stores a fixed path, typed financial deltas, and a hash of the idempotency key. Server events have no visitor ID, visit ID, location, raw IP, or User-Agent in the analytics database. Server events add to custom counts but not visitor identity coverage. Refund amounts describe one event, not a cumulative total. A dispute amount reports a newly opened case, not current unresolved exposure or a settled loss. The report shows volume after refunds, not Stripe accounting net or paid access. Revenue reports keep currencies separate.

Check your URLs before collection. The default new-site policy can store a full URL query, click IDs, and referrer path and query. These strings can contain a magic code, token, or other personal data. For a site with sensitive URLs, set url_query=none, click_ids=false, referrer=domain, dnt=true, and drop_sensitive_queries=true before collection. Add private path prefixes to exclude_paths. The API contract documents this reduced policy.

For a site with session collection on, YWG transiently processes the Cloudflare client IP and request User-Agent with a server-only HMAC secret. It stores a monthly-rotating pseudonym and an approximate visit ID. A visit can continue for 30 minutes after its most recent event. The analytics database does not store raw IP addresses, user agents, or cookies. The collector does not set a browser ID or cookie.

Shared networks and the same User-Agent can merge people; a changed User-Agent or device can split one person. Events without trusted inputs or a configured HMAC key have no identity. Older event rows also lack identities. Reports show coverage and must not call uncovered events zero visitors. Origin headers can be forged. Do not treat these estimates as consent or proof of a person.

Replay status

Replay is off by default for new sites. Feiticaria's owner-only server policy permits consent-required replay only on exact /ajuda/ with strict masking. This policy does not start a recording from an ordinary pageview. The site must show a reviewed opt-in control and call the recorder only after a visitor's explicit choice. The Worker also requires a recent identified pageview and a short-lived grant. A site-controlled consent assertion does not prove a human choice. The strict mask hides all text and source attributes. The recorder blocks form controls, the IssueProbe host and its shadow subtree, private routes, and DNT/GPC requests. The Worker stores bounded sanitized chunks in a private R2 bucket. The account API offers completed recordings only until seven days after the first accepted chunk. Stopping future capture does not instantly erase earlier chunks. Bounded cleanup and an eight-day bucket rule remove expired objects later; physical deletion can take more time. Replay shows observed browser changes, not a person's identity or unobserved server activity. Other sites remain off, and paid Pro replay is not available.

Paid billing

Stripe hosts Pro Checkout and the Customer Portal. YWG stores a Stripe Customer ID, Subscription ID, billing status, and paid-period times for a Pro account. Stripe handles payment details. The YWG analytics database does not store card numbers. A Checkout return alone does not prove payment.

Limits and removal

Free accounts can use one verified site, send up to 10,000 events per UTC month, and retain events for 30 days. Pro accounts can use five verified sites, send up to 100,000 events per UTC month, and retain events for 365 days. Old events enter a bounded daily cleanup job. Cleanup can take additional time when a backlog exists. Do not promise immediate deletion from backups.

For account deletion, send an authenticated empty POST to /v1/account/deletion-request. This records a request for operator review. It does not delete data automatically. The API contract lists the route. There is no confirmed public support mailbox for this site, so this page does not invent one.