Privacy Policy

By using this application, you agree to the collection and use of your personal information as described in this policy.

Data collection

Users may choose to create accounts and authenticate using Google Sign-In. In connection with account creation, authentication, and use of the service, we collect personal information including identifiers such as name and email address, and limited internet or network activity information necessary to operate the service.

Authenticated users may choose to upload data for processing. Uploaded content may contain personal information.

We collect personal information directly from users, from Google Sign-In, and from users' interactions with the service.

Data use

We use personal information as necessary to provide and maintain the service, authenticate users, process uploaded content, provide technical support, secure the service, prevent misuse, and comply with law. We disclose personal information to service providers and contractors that help us operate the service, including cloud hosting and AI processing providers such as Amazon Web Services, OpenAI, and Anthropic, and our analytics provider PostHog, under contractual confidentiality obligations. We do not sell personal information or share it for cross-context behavioral advertising.

Data retention

We retain personal information for as long as reasonably necessary to provide the service, maintain active accounts, comply with legal obligations, resolve disputes, enforce agreements, and maintain limited backup copies for a short period. You can delete your data at any time. Deletion removes content from active systems; residual copies may persist in backups for a limited time.

Analytics events have no expiry set in PostHog; we keep them until we delete them.

Analytics

We use PostHog (US Cloud) to understand how the website and the app are used. PostHog requests go through our own domain and are forwarded to PostHog.

Where consent is required (the EU, EEA, UK, and Switzerland), we show a banner before setting analytics cookies. We determine this from the country of your connection. If your country can't be determined, we show the banner.

Before you choose, and if you choose Decline, PostHog runs without cookies or browser storage. Page views and the events listed below are still sent to PostHog. Decline means no cookies. It does not mean no analytics. Outside those regions, PostHog uses a cookie and browser storage by default. In any region, choosing Accept enables them.

What is sent: page views, the time you leave a page, six named events (sign-in clicked, sign-in completed with the sign-in method, outbound link clicked, contact form submitted but never the fields, docs page viewed, and homepage section viewed), and clicks. For each click we send the page, the type and position of the element clicked, and for some buttons a fixed name we assign, such as "export". We don't send the text of what you clicked or its attributes. We never send file names, file paths, share links, prompts, chat messages, or the contents of your data. We don't record sessions.

When you sign in and analytics is allowed, we link your analytics activity, including your earlier visits from the same browser, to your account, using your email address and its domain. Signing out clears the link on that browser.

PostHog receives your IP address with each event and uses it to estimate your country and city.

The site runs on Amazon Web Services behind Amazon CloudFront, which receives your IP address to serve the page.

Your rights

Depending on your location, you may have rights to know, access, correct, or delete your personal information, and to not be discriminated against for exercising those rights. Contact root@hyperparam.app for privacy requests.

Cookies and browser storage

NameTypePurposeLifetime
Sign-in cookies (next-auth)CookieKeep you signed in. Essential30 days, or until sign-out
hyp_consentCookieRemembers your Accept or Decline choice180 days
hyp_regionSession cookieRemembers whether this connection requires a consent choiceUntil the browser closes
PostHog cookie and storage entryCookie and local storageVisitor and session IDs, linked to your account after sign-in when analytics is allowed. Set after Accept, or by default where consent isn't required365 days
hyp_sign_in_methodLocal storageRemembers which sign-in method you started, so we can count a completed sign-in. Removed once you're signed inUntil sign-in completes
hyp_internalLocal storageMarks Hyperparam staff traffic so we can exclude it. Set only by a staff linkUntil cleared

You can change your choice at any time: Cookie settings. The same link is in the footer of the homepage.

Updated: