Privacy Policy
Effective 2 October 2026
WME Sync ("the Service", "we", "us") lets Waze Map Editor userscripts sync their settings and data across browsers. It's part of WMEKit, an independent, unofficial community project that is not affiliated with, endorsed by, or operated by Waze or Google. For questions or data requests, email wazer@wmekit.com.
This policy supplements the main WMEKit Privacy Policy. Your WMEKit account, which you use to sign in to the WME Sync dashboard, is covered by the WMEKit Privacy Policy: your sign-in methods, sessions, security log, sign-in cookies, analytics choices, your rights, international transfers, and how to complain to a regulator. This page goes into detail about what WME Sync itself stores. Where the two differ about WME Sync, this page applies.
1. How WME Sync works
You don't need a WMEKit account to sync. The first time a userscript syncs for your Waze username, WME Sync creates that username and gives you a PIN. Your scripts then use tokens to read and write data for that username. A WMEKit account is optional: signing in to the dashboard and linking your username with its PIN lets you browse, export and delete your data, change your PIN, and manage your tokens.
2. What we store
Waze usernames: the username, when it first synced, which WMEKit account it's linked to (if any), and when it was linked. A Waze username is a public identifier you chose, but it can identify you, so we treat it as personal data.
PINs: only a one-way hash. We can't see or recover your PIN. We show a generated PIN once, when it's created.
Script tokens: hashes of the tokens your scripts use, a label (by default the script and browser name, such as "my-script on Firefox"), when each was created and last used, and whether it's been revoked.
Synced data: whatever your userscripts choose to store, as JSON, grouped by script, with its size and when it was last changed. We don't inspect or use this data for anything except storing it and giving it back to you.
If you use the dashboard: a copy of your WMEKit account ID, name and email address, so we can show who's signed in and link usernames to you.
Abuse protection: failed PIN attempts (the username and IP address) and new usernames created per IP address, to stop people guessing PINs or claiming usernames in bulk.
3. Who can see your synced data
Your scripts. A token gives access to everything stored for your username, not just the script that requested it. Any userscript you've let sync with your username (including scripts written by other people) can read and change the data of every other script syncing under it. Only install scripts you trust, and revoke tokens you don't recognise on the dashboard.
Anyone with your PIN can get a token for your username. wme-sync-lib stores your PIN in each script's own userscript-manager storage so it can sign in again on its own. Keep your PIN private, and change it on the dashboard if you think someone else has it.
You, on the dashboard, once your username is linked to your WMEKit account.
WME Sync admins can see account names and emails, linked usernames, and how much data and how many tokens each username has. They can delete (release) a username, for example one claimed by someone it doesn't belong to. The dashboard doesn't show them the contents of your data.
Don't use WME Sync to store passwords, API keys, or other secrets. It's meant for settings and similar data.
4. What we share
We don't sell your data, show ads, or share your synced data with anyone else.
5. How long we keep it
Synced data, usernames and PIN hashes: until you delete the username on the dashboard, or an admin releases it. Unlinking a username from your account (or deleting your WMEKit account) keeps its data, PIN and tokens, so your scripts keep syncing. Delete the username to remove them.
Tokens: access tokens expire after 180 days and refresh tokens after 2 years. Expired tokens are deleted daily, and revoked ones 30 days after they're revoked.
Failed PIN attempts and new-username records: deleted after 24 hours.
Your account copy: while you use the dashboard. Ask us and we'll delete it.
Backups: deleted data can remain in database backups for up to 30 days.
6. Your rights and choices
Once your username is linked, the dashboard lets you, at any time:
browse your synced data and download it all as JSON;
delete your username and everything stored for it;
change your PIN, and see and revoke your scripts' tokens.
You have the same rights over your WME Sync data as over your WMEKit account (to access, correct, export or delete it, and to object to or restrict how it's used). They're explained in the WMEKit Privacy Policy. For anything the dashboard can't do, email wazer@wmekit.com. We'll respond within 30 days and may ask you to prove the username is yours (for example with its PIN).
7. Changes
We'll update the effective date above whenever this policy changes. If a change significantly affects how we use your data, we'll tell you before it takes effect. WMEKit is run from South Africa. See also our Terms of Service.