WISEWater Gauge
Privacy

What we do with your data

WiseWaterGauge keeps records about water, and unavoidably about the people and addresses the water belongs to. This page says what that is, who can see it, and how to get rid of it.

Last updated 22 September 2026

The short version

  • Your readings are yours. A service company sees them only for the sources you pick, and only after you accept its request.
  • Before you accept, a company sees your name, the property address and what kind of source it is. No readings.
  • Our administrators can count accounts and tests. The database gives them no way to read your water data.
  • The only cookie this site sets keeps you signed in. There are no analytics, no trackers and no advertising here.
  • The one thing we send to an outside AI service is a ZIP code, when you ask what the local utility publishes.
  • You can delete your account yourself, and it takes your properties, sources and readings with it.

What we hold

Your account. An email address, and a name if you gave one. A phone number is optional and most accounts have none. Your password is handled by our authentication provider and stored as a hash: nobody here can read it, and neither can we recover it for you, which is why resetting it is the only route back in.

Your places and your sources. Each property has a label, and optionally a street address, city, state and postal code. Each water source on it has a name and a kind: a tap, a well, a filter, a pool, a hot tub.

Your readings. The values you log, the date and time, any notes you add, and which test kit or method you used. This is the heart of the product and the most personal thing in it: a year of readings describes a household.

Equipment and maintenance. What is installed on a source, what is on a schedule, what was done and when, and by whom.

Bills, if you get them here. If a service company invoices through WiseWaterGauge, the invoice, its lines and its payment status are stored. We take no payment: there is no card, no processor and no bank detail anywhere in this product. “Paid” means the company said so.

What you send us. A message through the contact form is emailed to our support inbox with the address you gave so we can reply. It is not written to any database here.

Who can see your water data

You can. Every source, every reading, on every property you own.

A service company you are connected to can, for the sources you chose to share and from the moment you accepted. Not before. While a company’s request is pending, it sees your name, the property address and what kind of water source it is, and not a single reading: the request has to describe enough for the company to know which job it is, and stops there.

A company that invites you by email learns nothing by inviting you. The confirmation it gets is identical whether or not that address already has an account, on purpose, so that this product cannot be used to find out where somebody has one.

Our administrators can see how many accounts, sources and tests exist, and can review and approve companies applying to the public directory. They cannot read your water data. That is not a policy we follow carefully, it is a fact about the database: no administrator branch exists on your water sources or your readings, so those rows are as invisible to an administrator as they are to a stranger. The one administrative exception anywhere near this data is scoped to the published benchmarks an administrator curates: bottled water and the like, which belong to nobody. Reviewing a company’s listing does show the name and email of the staff accounts behind that company, because approving an application you cannot contact is not a review.

Our own notification system can look up the email address it needs to write to, and is granted nothing else. It cannot read test results, any specification, a property’s address, or the address on an invitation. Those are column-level grants in the database rather than a convention in our code.

What leaves WiseWaterGauge

Five things, and this is the whole list.

Hosting and the database. Everything above is stored with our hosting and database provider, which also handles sign-in.

Email delivery. Account mail and notifications pass through an email provider to reach your inbox, which means the address and the contents of the message do too.

Google or Apple, if you use them. Signing in that way tells us your email address and confirms the sign-in. The sign-in sends them nothing about you in return, and nothing about your water.

A street address, as you type it into an address field. When you enter a property’s or a company’s address, Google suggests matching addresses, and to do that it receives what you have typed into that one field, from the third character on. It receives nothing else: no account, no name, and none of your readings. Nothing is sent until you start typing an address, and the field works as an ordinary text box if you would rather not pick a suggestion.

A ZIP code, when you ask what the utility publishes. The public-supply column on Compare is assembled by asking an AI model to find what the utility serving that ZIP code has published. We send the ZIP code and nothing else: no account, no name, no address, and none of your readings.

There are no advertising networks here, no analytics services, no data brokers and no third-party trackers. We do not sell your data and there is nothing in this product to sell it for. Even the fonts are served from this site rather than fetched from somebody else as you read, and Google’s address script is fetched only once you type into an address field, never as you browse.

Cookies

One cookie, one purpose: keeping you signed in. It is set when you sign in, refreshed as you move around, and cleared when you sign out. Signed out, this site sets nothing.

There are no analytics or advertising cookies, which is why you have never seen a consent banner here. There is nothing to consent to.

Our hosting provider keeps ordinary server logs, an IP address, a time, which page was asked for, for operating the service and noticing abuse. We do not build profiles from them.

Email we send, and how to stop it

A handful of messages are part of the transaction and arrive whatever your settings say: confirming your address, resetting your password, and an invoice a company has issued you. A bill is a demand for money and offering a switch we intend to ignore would be the dishonest option.

Everything else is yours to turn off, topic by topic and channel by channel, in your notification settings. Reminders, alerts about a reading, requests and their answers: each can be switched off on its own.

If you are hearing from us because a company entered you as a customer and you have no account, every message carries a link that stops all email to that address, from us and from any company. It stops the mail and leaves the records exactly as they are, so you can still claim them later from a link you already have.

What is public

The provider directory is public. A verified company’s name, description, city, state and the ZIP codes it serves are visible to anybody and indexed by search engines: that is the point of a listing. Nothing about a consumer account appears there, ever.

The Learn pages, the home page and this one are public and contain no personal data of any kind. They are the same pages for a signed-in reader, a visitor and a crawler.

One thing to treat carefully: an invoice sent to a customer who has no account opens on a secret link, because there is no sign-in to put in front of it. Anyone holding that link can see that one invoice and nothing else about the account. Treat it like a password, and especially do not post it anywhere.

Deleting your account

You can delete your account yourself, from your settings. It is irreversible and it is thorough: your properties, your sources, every reading on them, your equipment and maintenance history, your notification feed and your preferences, and the login itself all go. We do not keep a shadow copy.

There is one condition. If a service company is currently connected to one of your sources, end the connection first. A company part-way through an arrangement should be told by you ending it rather than by you disappearing, and ending it notifies them.

A company can delete a customer record it created, but only while nobody has claimed it. Once the record is yours, only you can delete it. A company cannot destroy a water history that belongs to somebody else.

There is no self-serve export yet. If you want a copy of what we hold before you delete it, write to us at the address below and ask us for when the feature is available.

Keeping it safe

Access is decided in the database rather than by the pages that draw it. Every table holding your data carries row-level security, so a request for somebody else’s readings comes back empty no matter which page asked or how it was phrased. A page cannot forget to check, because a page is not what checks.

Passwords are stored as hashes by our authentication provider and are never visible to us. Traffic to this site is encrypted in transit.

No system is beyond reach, and we would rather say that than promise otherwise. If you find something wrong here, the address below is the fastest way to reach somebody who can fix it.

Children

WiseWaterGauge is for people looking after water at a property, and is not directed at children. We do not knowingly collect anything from anyone under 13.

Changes to this page

The date at the top is the date this document last changed, and it moves only when the words do. If something here changes materially, we will say so rather than quietly editing the page.

Getting in touch

Questions about any of this, or something you think is wrong:

Support@WiseWaterGauge.com

The contact page has a form if you would rather use one.