Privacy
This notice explains what personal data HYPESCRAPER processes, why, on what legal basis, who helps us, how long we keep it and what you can do about it. The controller is the operator named on the imprint. Privacy requests go through the contact form.
Visitors (no account)
- No cookies, no analytics, no tracking pixels, no third-party scripts. Preferences and any draft you start stay in your own browser.
- Page loads of hypescraper.io go through Cloudflare, which processes your IP address and request data to deliver the page and protect the site. We do not receive those logs.
- The daily question and Hype or real? work without an account. We store your answer under a fingerprint that changes every day, never your IP address; the fingerprint is deleted after 7 days and only totals remain.
Accounts
- Login: your email address, a password fingerprint and, for admins, an authenticator-app second factor are held by Supabase (EU region, Ireland; Supabase Inc. is a US company) as our processor. Your browser keeps the login session in local storage; there is no login cookie.
- Bot protection: the sign-up, login and password-reset forms load Cloudflare Turnstile, which processes technical data about your browser to tell humans from bots. It is loaded on those forms only.
- Our databases: a random user id, your handle, the 18+ declaration, your rank, points and badges, your Pro end date, whether you show your handle on the weekly board, and the optional profile bands you choose (role, team size, providers). Not your email and not your password.
- Your content: reports, questions and answers you post, and moderation decisions about them. The link from your account to them is stored as an encrypted reference in a separate identity database.
- Votes, daily answers, game plays: stored under keyed fingerprints, never under your account id.
Emails we send
We send a small number of emails through Oracle Cloud Email Delivery (Frankfurt): notices about your question (an answer arrived, it closed, it needs an edit), refunds, files ready to download, the end of your Pro, and — only if you switch it on — a weekly digest of new reports matching your alerts. We fetch your address from the login provider at the moment we send and do not store it in our databases or logs. Every email says why you got it. The digest has a one-click unsubscribe link. No tracking pixels, no redirect links, no images. Oracle keeps a delivery log with the recipient address for 30 days. Supabase also sends confirmation and password-reset emails through the same service.
Payments
At the moment payments are simulated: no card can be charged and no card data exists anywhere. We keep orders under an opaque token with the product, the amount, the state and any refund. When real payments start, a payment provider will process them, and this notice will be updated before that happens.
Companies (research questions, Reality Report, sponsored placements)
A sponsor's name is shown to respondents and on public receipts. Orders are stored like any other order. Sponsors never receive respondents' identities, handles or emails. Respondents' answers are stored with their profile bands, not their account.
Sponsored placements and the view counter
When at least half of a sponsored box has been on your screen for one second while the tab is visible, your browser sends one request to ads.hypescraper.io. It carries no cookie and stores nothing on your device. Our server drops your IP address and request headers before it writes its log; each line keeps only the time, the campaign code, the placement, the release number, a short page token, whether the request came from a hypescraper.io page (yes or no), and a bot yes/no class. Repeats from the same network within 10 minutes are checked in memory and never written. Lines are deleted after 72 hours; only daily counts are kept. Pro members see no sponsored boxes and send no requests.
Contact form
When you write to us through the contact form, we store the topic, your message, the reply address you chose to give (optional) and, if you were logged in, a link to your account. Only admins read it. We use it only to answer you and to act on what you report, and we delete it 90 days after we have handled it. Nothing is logged with your IP address.
Legal bases (GDPR Art. 6)
- Running your account, your content, ranks, Pro, questions, research answers and the emails about them: performance of the contract you accept with the terms (Art. 6(1)(b)).
- The weekly digest: your consent, given when you switch alerts on and withdrawn by unsubscribing (Art. 6(1)(a)).
- Security, abuse prevention, rate limits, bot protection, moderation and the view counter: legitimate interests in keeping the site safe, honest and paid for (Art. 6(1)(f)).
- Records the law requires (for example payment records once real payments exist): legal obligation (Art. 6(1)(c)).
Logs
Our write API logs method, route, status and duration, never your IP address or user agent. The Ghost address keeps no access log. Throttling uses an in-memory counter keyed by a daily-rotating fingerprint of your network.
Who processes data for us
- Oracle Cloud Infrastructure, Frankfurt (EU): servers, databases, encrypted backups, outgoing email.
- Supabase, EU region (Ireland): login.
- Cloudflare: delivery of the static site and Turnstile bot protection.
Where a provider is based outside the EU or may access data from outside it, the transfer relies on the provider's data processing terms, including the EU Standard Contractual Clauses or the EU–US Data Privacy Framework where the provider is certified.
How long we keep it
- Account data: while your account exists. Deleting your account on Me deletes your login at Supabase and every row about you in our identity database at once. Published reports and answers stay, shown as "an operator", with nothing linking them to you.
- When Pro ends, your alerts and briefs are kept for 90 days in case you come back, then deleted.
- Daily answers and game plays: the fingerprint is deleted after 7 days. Streak data for logged-in badges: 30 days. Sent-email records: 30 days. Pro brief PDFs: 30 days.
- View-counter log lines: 72 hours. Email delivery logs at Oracle: 30 days. Encrypted backups: at most 35 days. Server disk snapshots: 6 days.
Your rights
You have the right to access, correct, delete and export your data, to restrict or object to processing, and to withdraw consent at any time without affecting what happened before. On Me you can see and change your profile, download your data and delete your account. For anything else, use the contact form (topic "Privacy"); we answer within one month. Ghost reports and anonymous plays are not linked to anyone, so we cannot find them for you (GDPR Art. 11); use your burn key instead. You may also complain to a data-protection supervisory authority, in particular in the EU country where you live or work.
Age
Accounts are for people aged 18 or over, by self-declaration at sign-up.
Automated decisions
We make no decisions with legal or similarly significant effects about you by automated means. Refunds under our guarantees are automatic and only ever in your favour. A person reviews every moderation decision.