Privacy

Privacy policy

Hypotheses preserves decision context while minimizing the information it collects and exposes. This policy covers the website and the public and account-authorized MCP tools for ChatGPT and Claude.

Effective August 11, 2026

Information we process

On the public plugin, we process only the search terms and public record identifiers supplied for a tool call. The plugin returns public hypothesis titles, descriptions, evidence criteria, categories, and canonical links. It does not request passwords, authentication secrets, payment information, government identifiers, health information, precise location, or the full AI conversation history.

If you create a Hypotheses web account, we process your email address, authentication status, profile details you choose to provide, and the projects, hypotheses, evidence, comments, files, or decisions you choose to save. Public contributions are visible to other visitors when you explicitly publish them.

Community activity can include your public profile fields, follows, structured evidence contributions, discussion comments, evidence reviews, decision outcomes, and notifications. Profile discovery and evidence-recruitment contact are separate choices and both are off unless you enable them. Blocking is private to the blocking account. Reports are visible to authorized moderators and include the reporter, target, selected reason, optional details, status, and recorded moderation action.

If you authorize an AI connector, we process the account identity and permission scopes attached to that connection. Private tools receive only the tool arguments the AI client sends. Hypotheses does not automatically import a complete ChatGPT or Claude conversation. A private capture is stored only after the connector prepares a structured preview and a separate save action is confirmed.

How we use information

We use information to authenticate accounts, deliver requested tool results, preserve user-created decision records, operate collaboration features, prevent abuse, troubleshoot failures, and improve reliability. We do not sell personal information or use plugin inputs for advertising or behavioral profiling.

OAuth access and refresh tokens are random credentials stored only as one-way hashes. Access tokens are short-lived, refresh tokens rotate when used, and every private tool request is checked for the expected user, client, resource, expiry, and permission scope.

Service providers and recipients

Hypotheses uses Vercel for application hosting and delivery, and Google Firebase for authentication, database, and file storage. These providers process information on our behalf to operate the service. Public hypothesis content is shared with visitors and MCP clients only after it has been marked public. Unlisted briefs are available to people with the exact link but are excluded from public discovery and anonymous MCP results. Public community contributions and comments are shown on their associated brief. We may disclose information when required by law or to protect users and the service.

Retention

Public plugin search inputs are used to answer the request and are not intentionally stored in the Hypotheses database. Infrastructure providers may retain limited operational logs under their own security and retention controls. Account and project data remains until the account owner deletes it, requests deletion, or it is removed under our terms. Routine backups may retain deleted data for a limited period before expiry.

Reports and moderation actions may be retained after content is removed when needed to prevent abuse, document enforcement, resolve disputes, or meet legal obligations. Notifications and public activity derive from actual product events; Hypotheses does not create synthetic community activity.

Short-lived authorization requests, authorization codes, and capture previews automatically stop being accepted after expiry. Connector credentials remain usable until they expire, rotate, are revoked, or the connection is removed.

Your choices and controls

You can manage account information and public hypothesis content through the web controls currently available. Self-service deletion for private connector captures is not yet available; request correction, export, or deletion through the support page. You can remove the Hypotheses connector from ChatGPT or Claude at any time. Legal rights may vary by location.

You can change a brief between private, unlisted, and public; follow or unfollow records; block or unblock accounts; and control profile discovery and recruitment consent. Unpublishing removes a brief from public discovery and MCP results. Previously shared copies, lawful moderation records, and limited backups may persist. Contact support to request account export or deletion.

Removing a connector stops the client from making new authorized requests. You can also decline any capture preview or write confirmation without changing your workspace.

Security and changes

We use access controls, encrypted transport, server-side authorization, and managed infrastructure to protect information. No service can guarantee absolute security. We may update this policy as the product evolves and will publish the effective date with the current version.