Privacy
What we collect, and what we deliberately don’t.
Draft. This describes exactly what the system does today, written from the code. It has not been reviewed by a lawyer and is not yet a complete legal notice. If you are deciding whether to trust us with something sensitive, read it as a factual description of our behaviour rather than as a guarantee.
There is no account
You cannot create one, and we do not offer one. We never ask for your name, email address, or any way to contact you — which also means we cannot contact you, including about your own submission.
What a submission stores
Your answers, exactly as you gave them:
- Company, function, level, whether you worked onsite, hybrid or remotely
- The country you worked in — never a city
- The years you joined and left — never exact dates
- How the job ended, and whether it was your decision
- Your reasons, what might have made you stay, and whether you would go back
- Your written story, if you chose to write one
Published stories show a widened version of this, not the raw values. See how it works for what that means in practice.
What we store to prevent abuse
Alongside a submission we keep a salted hash of your IP address, your browser user-agent, and a random token held by your browser. A salted hash cannot be reversed into the original value.
We keep these for 90 days, after which they are deleted while the story itself remains. We use them only to detect duplicate and automated submissions.
We do not store raw IP addresses.
Cookies and tracking
Your draft submission is held in your browser’s session storage while you complete the form, and cleared when you finish or close the tab. It is never sent to us until you press submit, so an abandoned form leaves no trace at all.
We do not use advertising cookies and we do not sell data. We do not have a business model that depends on doing either.
Who else processes your submission
These are the third parties involved, and what each one sees:
- Supabase — hosts the database. Sees everything stored above.
- Cloudflare — serves the site and provides the anti-bot check. Sees requests in transit.
- Moonshot AI — automated screening. If you write a story, its text is sent to their API so it can be checked for names, contact details and other risks before a person reviews it. Structured answers with no written story are never sent anywhere.
Because Moonshot processes data outside the EU and UK, a written story leaves that jurisdiction. If that matters to you, submit without writing one — the structured answers are the part we actually count.
Publication is public and permanent-ish
A published story is on the open internet. We can remove it from this site, and we will if it breaks our guidelines. We cannot remove it from search-engine caches, archives, or anyone’s screenshot. Please treat submitting as irreversible.
Your rights, and their limits
We hold no information that identifies you, which is a genuine privacy protection and an awkward one: it means we cannot find “your” submission on request, because we have no way to tell which one is yours or that you are the person who wrote it.
If a published story concerns you — including if you believe it describes or identifies you — use the Report link on it. That reaches a person and is the fastest route to having something looked at.
For anything else, including a request about a story that names or describes you, contact privacy@whydidileave.com.
Employers
Employers never receive author identities, and there is no arrangement — paid or otherwise — by which a company can have a legitimate story removed.
Last updated 13 August 2026. If we change how any of this works, this page changes with it.