Your script has
a short stay.
WaveScript is built around temporary sessions.
What a session stores
To keep your devices in sync, the service temporarily stores your script, reading position, playback settings, and session access tokens on Cloudflare. Sessions expire 24 hours after creation. You can end a session earlier from the original editor, which removes its application data and disconnects the devices.
Who can join
Anyone who knows your six-digit code can read your script and control playback. The original browser keeps the editor access token in session storage. Scripts are sent over HTTPS and secure WebSockets in production; this is not end-to-end encryption.
Saving on this device
Save locally stores a separate draft in this browser’s local storage. It stays there until you choose Forget saved or clear the website’s browser data. This local copy is not removed when a session expires. Drafts are not saved locally unless you choose to save them.
Anonymous usage analytics
WaveScript sends a small set of usage events to PostHog in the EU, such as opening a screen, creating a session, and using playback controls. A random anonymous analytics identifier is stored in this browser’s local storage for up to 180 days from creation. Its last-use timestamp is updated when analytics is used; the expiry date does not extend. This lets us measure returning browsers without an account, email address or fingerprint. Clearing website data removes the ID. No personal profiles, session replay or automatic page-content capture are enabled. Scripts, titles, session codes, access tokens, full URLs, query strings and referrer paths are excluded. Do Not Track and Global Privacy Control disable analytics and analytics ID creation. PostHog receives network information needed to handle requests; location enrichment is disabled.
Short campaign links use a one-time attribution cookie lasting at most five minutes. The site reads and deletes it on arrival, and records only the short campaign code and optional placement number. There are no persistent analytics cookies. Playback milestones use opaque first-party deduplication markers for at most 24 hours so connected devices do not count the same milestone more than once. These markers are not sent to PostHog. Temporary playback measurement checkpoints and your remote layout are kept in this tab’s session storage.
Service infrastructure
WaveScript does not ask for your name or email. Fonts are served with the app. Cloudflare processes network information such as IP addresses to deliver and protect the service. Rate limits help prevent abuse; scripts and access tokens are not intentionally logged by the application.
Browser support
Live sessions need an internet connection. Fullscreen and keeping the display awake depend on your browser and device. Adding WaveScript to your home screen does not make live sessions available offline.
Back to your words