This privacy policy applies to the websites hypothesis.sh, conclusion.sh, falsify.sh, and observation.sh (collectively, "the Service"), as well as any associated mobile applications. It describes what data is collected, how it is used, and your rights with respect to that data. Last updated: August 25, 2026.
The Service uses Vercel Analytics to collect anonymous usage data, including page views, referrer URLs, device type, operating system, browser, and approximate location (country/region level). This data is aggregated and does not identify individual users. Vercel Analytics does not use cookies or persistent identifiers for tracking. See vercel.com/legal/privacy-policy for details on how Vercel handles this data.
When you visit the Service, your IP address and standard HTTP request headers are processed by our hosting provider (Vercel) as part of serving each request. Vercel derives approximate geolocation information from your IP address (city, region, country, latitude/longitude, and timezone). We do not log or store this information except as described below.
The webhook experiment lets you create a temporary endpoint to inspect incoming HTTP requests.
Web (anonymous) sessions: When you create a session from the website without a device account, your IP address is stored alongside a randomly generated session ID solely to enforce a per-IP rate limit and prevent abuse. Anonymous sessions and all associated webhook events are automatically deleted after one hour of inactivity.
Mobile app sessions: When you use the webhook feature in the mobile app, a persistent session is created and associated with your device ID. Webhook events received by that session are stored indefinitely and are not subject to automatic expiration. You may request deletion of this data at any time by contacting us at the address below.
If you use the push notification feature (available in the mobile app and the push-test tool), the following data is stored in our database so we can deliver notifications to your device:
This data is used solely to route push notifications to your device. You can stop receiving notifications at any time by disabling notification permissions in your device settings.
The My IP tool calls our API to return your IP address and Vercel-derived geolocation data directly to you in the browser. This data is not stored on our servers.
The vast majority of tools on the Service (Base64, JWT inspector, regex tester, UUID generator, color converter, and others not listed above) process all input entirely in your browser. No tool input or output is transmitted to our servers. There are no user accounts and no login is required.
The Service is hosted on Vercel. Vercel processes every request and may retain server logs, including IP addresses, in accordance with their own privacy policy. Vercel also powers the analytics described above. See vercel.com/legal/privacy-policy for details.
Push notifications to iOS devices are delivered via Apple's APNs infrastructure. When a notification is sent, your push token is transmitted to Apple's servers. See Apple's privacy documentation for details on how APNs handles this data.
Push notifications to Android devices are delivered via Google's Firebase Cloud Messaging infrastructure. Your Android push token is issued by Google, and when a notification is sent that token and the notification content are transmitted to Google's servers. See firebase.google.com/support/privacy for details on how Firebase handles this data.
Anonymous webhook sessions and their events are deleted automatically after one hour of inactivity. Mobile app webhook sessions and events, as well as push notification tokens, are retained indefinitely. You may request deletion of any data associated with your device by contacting us at the address below with your device ID.
The Service is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, please contact us and we will delete it promptly.
We may update this policy from time to time. The "last updated" date at the top of this page reflects the most recent revision. Continued use of the Service after changes are posted constitutes acceptance of the updated policy.
Questions or requests regarding this privacy policy can be sent to kd@keegandonley.com.