Privacy Policy

This privacy policy applies to the websites hypothesis.sh, conclusion.sh, falsify.sh, and observation.sh (collectively, "the Service"), as well as any associated mobile applications. It describes what data is collected, how it is used, and your rights with respect to that data. Last updated: August 25, 2026.

What We Collect

Analytics

The Service uses Vercel Analytics to collect anonymous usage data, including page views, referrer URLs, device type, operating system, browser, and approximate location (country/region level). This data is aggregated and does not identify individual users. Vercel Analytics does not use cookies or persistent identifiers for tracking. See vercel.com/legal/privacy-policy for details on how Vercel handles this data.

Data collected automatically

When you visit the Service, your IP address and standard HTTP request headers are processed by our hosting provider (Vercel) as part of serving each request. Vercel derives approximate geolocation information from your IP address (city, region, country, latitude/longitude, and timezone). We do not log or store this information except as described below.

Webhook sessions and events

The webhook experiment lets you create a temporary endpoint to inspect incoming HTTP requests.

Web (anonymous) sessions: When you create a session from the website without a device account, your IP address is stored alongside a randomly generated session ID solely to enforce a per-IP rate limit and prevent abuse. Anonymous sessions and all associated webhook events are automatically deleted after one hour of inactivity.

Mobile app sessions: When you use the webhook feature in the mobile app, a persistent session is created and associated with your device ID. Webhook events received by that session are stored indefinitely and are not subject to automatic expiration. You may request deletion of this data at any time by contacting us at the address below.

Push notification tokens

If you use the push notification feature (available in the mobile app and the push-test tool), the following data is stored in our database so we can deliver notifications to your device:

  • A randomly generated device identifier (UUID) created on your device
  • Your device push token issued by the platform (Apple APNs on iOS, Google Firebase Cloud Messaging on Android)
  • The platform name (e.g. "ios" or "android")

This data is used solely to route push notifications to your device. You can stop receiving notifications at any time by disabling notification permissions in your device settings.

My IP tool

The My IP tool calls our API to return your IP address and Vercel-derived geolocation data directly to you in the browser. This data is not stored on our servers.

Client-Side Tool Processing

The vast majority of tools on the Service (Base64, JWT inspector, regex tester, UUID generator, color converter, and others not listed above) process all input entirely in your browser. No tool input or output is transmitted to our servers. There are no user accounts and no login is required.

Third-Party Services

Vercel

The Service is hosted on Vercel. Vercel processes every request and may retain server logs, including IP addresses, in accordance with their own privacy policy. Vercel also powers the analytics described above. See vercel.com/legal/privacy-policy for details.

Apple Push Notification Service (APNs)

Push notifications to iOS devices are delivered via Apple's APNs infrastructure. When a notification is sent, your push token is transmitted to Apple's servers. See Apple's privacy documentation for details on how APNs handles this data.

Google Firebase Cloud Messaging (FCM)

Push notifications to Android devices are delivered via Google's Firebase Cloud Messaging infrastructure. Your Android push token is issued by Google, and when a notification is sent that token and the notification content are transmitted to Google's servers. See firebase.google.com/support/privacy for details on how Firebase handles this data.

Data Retention and Deletion

Anonymous webhook sessions and their events are deleted automatically after one hour of inactivity. Mobile app webhook sessions and events, as well as push notification tokens, are retained indefinitely. You may request deletion of any data associated with your device by contacting us at the address below with your device ID.

Children's Privacy

The Service is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, please contact us and we will delete it promptly.

Changes to This Policy

We may update this policy from time to time. The "last updated" date at the top of this page reflects the most recent revision. Continued use of the Service after changes are posted constitutes acceptance of the updated policy.

Contact

Questions or requests regarding this privacy policy can be sent to kd@keegandonley.com.