Information we process
On the public plugin, we process only the search terms and public record identifiers supplied for a tool call. The plugin returns public hypothesis titles, descriptions, evidence criteria, categories, and canonical links. It does not request passwords, authentication secrets, payment information, government identifiers, health information, precise location, or the full ChatGPT conversation history.
If you create a Hypotheses web account, we process your email address, authentication status, profile details you choose to provide, and the projects, hypotheses, evidence, comments, files, or decisions you choose to save. Public contributions are visible to other visitors when you explicitly publish them.
How we use information
We use information to authenticate accounts, deliver requested tool results, preserve user-created decision records, operate collaboration features, prevent abuse, troubleshoot failures, and improve reliability. We do not sell personal information or use plugin inputs for advertising or behavioral profiling.
Service providers and recipients
Hypotheses uses Vercel for application hosting and delivery, and Google Firebase for authentication, database, and file storage. These providers process information on our behalf to operate the service. Public hypothesis content is shared with visitors and MCP clients only after it has been marked public. We may disclose information when required by law or to protect users and the service.
Retention
Public plugin search inputs are used to answer the request and are not intentionally stored in the Hypotheses database. Infrastructure providers may retain limited operational logs under their own security and retention controls. Account and project data remains until the account owner deletes it, requests deletion, or it is removed under our terms. Routine backups may retain deleted data for a limited period before expiry.
Your choices and controls
You can edit account information and project content through the website, choose whether a hypothesis is public, and request access, correction, export, or deletion through the support page. You can remove the Hypotheses plugin from ChatGPT or Codex at any time. Legal rights may vary by location.
Security and changes
We use access controls, encrypted transport, server-side authorization, and managed infrastructure to protect information. No service can guarantee absolute security. We may update this policy as the product evolves and will publish the effective date with the current version.