Legal
Privacy Policy
Effective September 23, 2026 · Kratu AI LLC
The short version: we collect what we need to run Hypothis and keep it secure; we don't sell your data or use ad trackers; AI features send your research content to Google's Gemini API; analytics are consent-based; you can download or delete everything from Settings.
1. Who we are and what this policy covers
Hypothis is operated by Kratu AI LLC, a Utah limited liability company, 2114 Wasatch Blvd, Sandy, UT 84092 ("we", "us"). This policy explains what personal information we collect through hypothis.ai, the Hypothis app, our emails and public research forms, how we use and share it, and the choices and rights you have.
- Account holders (founders using Hypothis): we are the controller (GDPR) / business (CCPA) for your account data.
- Respondents (people answering a founder's form): the founder who published the form is the controller of your answers; we process them on the founder's behalf as a processor / service provider under our Data Processing Addendum. See Section 13.
- Website visitors: we are the controller for analytics and cookie data.
2. Information we collect
| Category | Examples | Source |
|---|---|---|
| Identifiers & contact details | First and last name, email address, account ID; for sign-in with Google/Microsoft/Apple: provider ID, profile picture, and (for Apple) a private relay email | You; your sign-in provider |
| Account credentials | Password (stored only as an Argon2id hash); encrypted OAuth tokens | You; your sign-in provider |
| Commercial & billing information | Plan, subscription and trial history, credit usage, invoices. Card details are collected and held by Stripe — we never see full card numbers | You; Stripe |
| Your content | Ideas, hypotheses, research plans, personas, forms, templates, verdicts, reports, integrations you configure | You |
| Onboarding & marketing attribution | Founder stage, technical background, "how did you hear about us"; UTM tags, ad click IDs (gclid/fbclid) and referrer from the link that brought you | You; your browser |
| Device, usage & approximate location | IP address, browser and OS, device type, pages viewed and clicks (product analytics, with consent where required), time zone, country derived from IP | Your browser and device; Cloudflare |
| Security & anti-abuse signals | Cloudflare Turnstile challenge results; on public forms, automated-browser signals from an in-browser bot-detection check (FingerprintJS BotD, open source, runs locally). Failed-login counters keyed to a hash of your email and your IP, kept for up to 1 hour | Your browser; Cloudflare |
| Communications & consent records | Emails you send us, abuse reports, email preferences, a log of when you accepted our Terms/Privacy Policy and gave or withdrew marketing or analytics consent (with truncated IP and browser type) | You |
| Respondent data (on founders' behalf) | Form answers; optional name/email a respondent chooses to leave; truncated IP, approximate city/country, device, browser and time zone; if a respondent is signed in to Hypothis while answering, their Hypothis account email | Respondents; their browser |
We do not use device fingerprinting to recognise or track you across sites or visits, use advertising or retargeting pixels, or buy personal information from data brokers. We don't intentionally collect sensitive personal information other than account login credentials, which are used only to sign you in.
3. How we use information, and our legal bases
For visitors and users in the EU/EEA, UK and Switzerland, each use relies on a legal basis under the GDPR:
| Purpose | Legal basis (GDPR) |
|---|---|
| Create and run your account; provide features you request (including AI drafting, analysis and verdicts); process payments; send account, security, billing and trial notices | Contract |
| Keep the Service secure: bot checks, rate limits, fraud and abuse prevention, enforcing our Terms and Acceptable Use Policy | Legitimate interests (protecting users and the Service) |
| Debugging and quality control of AI features (short-lived prompt/output logs) | Legitimate interests (a reliable, safe product) |
| Product analytics with PostHog / Google Analytics | Consent (EU/UK/CH); legitimate interests elsewhere, with opt-out |
| Understanding which channels bring founders (attribution, onboarding survey) | Legitimate interests |
| Marketing email (product news, tips, offers) | Consent — or, outside the EU/UK/CH, our existing relationship with you, and you can opt out any time |
| Keeping records required by law (tax, accounting), responding to legal requests, establishing or defending legal claims | Legal obligation; legitimate interests |
4. AI processing
Hypothis uses Google's Gemini API to draft hypotheses and forms, analyse responses, produce verdicts and — if a founder turns it on — ask respondents adaptive follow-up questions in real time. To do this, the relevant idea and research content, and respondents' open-ended answers (including answers to adaptive follow-up questions), are sent to Google. When we analyse responses, fields we detect as contact details are excluded, and email addresses, phone numbers and links written inside answers are redacted first.
- We keep verbatim AI prompts and outputs for up to 30 days to debug and improve reliability, then delete them automatically. Usage counts (for billing) are kept longer without the content.
- We don't use your content or respondent data to train AI models, and we use Google's paid API tier, under which Google doesn't use API data to train its models.
- Verdicts are assessments of a business idea, not decisions about a person. We don't make decisions with legal or similarly significant effects about anyone based solely on automated processing, and Hypothis isn't used to make decisions about employment, credit, housing, insurance, healthcare or similar consequential matters affecting an individual.
- You're interacting with an AI system. Adaptive follow-up questions shown to respondents (when a founder enables that feature) are generated by AI in real time and are labeled as such on the form. Ask us any time and we'll confirm whether you're interacting with a person or an AI system.
6. Marketing email and text messages
- Account, security, billing and trial emails (for example email verification, receipts, "your trial ends in 3 days") are part of the Service and are sent regardless of marketing preferences.
- Marketing email (product news, founder tips, discount offers) is off by default. You can opt in at sign-up or in Settings. If you're outside the EU/UK/Switzerland and haven't opted out, we may occasionally send you offers related to your account (for example a discount after your trial ends).
- Every marketing email includes an unsubscribe link that works in one click, and our postal address. You can also turn marketing off in Settings → Account → Email preferences, or email [email protected]. We honour opt-outs immediately.
- We keep unsubscribed addresses on a suppression list so we don't email them again, even if the account is deleted.
Text messages (SMS)
We don't currently send text messages. If we add SMS, we'll only send marketing texts with your prior express written consent, which is never a condition of purchase; you'll be able to reply STOP to opt out and HELP for help; message and data rates may apply; and we won't share your mobile number or SMS consent with third parties for their marketing.
8. How long we keep information
| Information | Retention |
|---|---|
| Account data and your content | For as long as your account exists. After you delete your account: locked for 30 days (so you can restore it), then permanently deleted |
| Database backups | Rolling encrypted backups, overwritten within 30 days |
| AI prompts and outputs | Up to 30 days |
| Respondent IP addresses | Stored truncated (last part removed) from the start; removed entirely after 30 days |
| Respondent answers | Until the founder deletes them or their account |
| Billing records | Invoices and transaction records are kept by Stripe for as long as tax and accounting law requires (typically 7 years) |
| Consent and email-suppression records | Kept to prove consent and honour opt-outs; suppression entries are kept after account deletion so we never email you again |
| Security logs and anti-abuse counters | Short-lived: rotated automatically; login-failure counters expire within 1 hour |
| Deletion records | A minimal record that a deletion happened (hashed email, dates), kept as proof we honoured your request |
9. Security
We use TLS encryption in transit, Argon2id password hashing, AES-256-GCM encryption for stored sign-in tokens, tenant isolation in the database, least-privilege access, rate limiting and bot protection, and off-site encrypted backups. No system is perfectly secure; if we learn of a breach affecting your personal information, we'll notify you and regulators as the law requires. Report vulnerabilities to [email protected].
10. International transfers
We're based in the United States and our main infrastructure is in the U.S.; some subprocessors (such as Brevo in France) are elsewhere. When we transfer personal data from the EU/EEA, UK or Switzerland, we rely on the EU–U.S. Data Privacy Framework (and its UK and Swiss extensions) where our subprocessors are certified, and otherwise on the European Commission's Standard Contractual Clauses (with the UK Addendum), plus supplementary measures where appropriate.
11. Your privacy rights
Everyone
- Access & portability: Settings → Account → Privacy & your data → Download gives you a ZIP of your account data.
- Correction: edit your name in Settings, or ask us to correct anything else.
- Deletion: Settings → Delete account.
- Marketing & analytics opt-out: Settings → Email preferences; the unsubscribe link; .
EU/EEA, UK and Switzerland (GDPR)
You can access, rectify, erase, restrict or object to processing of your personal data, receive it in a portable format, and withdraw consent at any time (without affecting earlier processing). You can object at any time to processing based on legitimate interests and to direct marketing. You may complain to your local data protection authority, though we'd appreciate the chance to help first.
California (CCPA/CPRA) and other U.S. states
Residents of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia and other states with privacy laws have, depending on the state, the right to: know what personal information we collect, use and disclose and access a copy; correct it; delete it; obtain it in a portable format; opt out of its sale, sharing for cross-context behavioural advertising, targeted advertising, and profiling in furtherance of significant decisions (we do none of these); and not be discriminated against for exercising these rights. We don't use sensitive personal information for purposes that would give you a right to limit it.
How to make a request
- Use the in-app tools above, or email [email protected] from your account email.
- We verify requests by confirming control of the account email; we may ask for more information if needed. We don't require you to create an account to make a request.
- You may use an authorized agent; we'll ask for proof of their authority and may verify your identity directly.
- We respond within one month (GDPR) or 45 days (U.S. state laws), and will tell you if we need an extension the law allows.
- Appeals: if we decline a request, reply to our decision or email [email protected] with "Appeal" in the subject. We'll answer within the time your state requires (typically 45–60 days). If you're unhappy with the result you can contact your state Attorney General.
12. Notice at collection for California residents
In the last 12 months we collected the following categories of personal information (as defined by the CCPA):
| Category | Collected | Disclosed for a business purpose to | Sold or shared |
|---|---|---|---|
| Identifiers (name, email, account ID, IP address) | Yes | Hosting, Cloudflare, Stripe, Brevo, Google (sign-in), analytics providers | No |
| Customer records (billing details) | Yes | Stripe | No |
| Commercial information (plans, purchases) | Yes | Stripe, Brevo (plan name only) | No |
| Internet or network activity (usage, device, pages) | Yes | PostHog, Google Analytics (consent-based), Cloudflare, Sentry | No |
| Approximate geolocation (from IP) | Yes | Hosting, analytics providers | No |
| Professional information (founder stage, background) | Yes | Hosting | No |
| Content of communications and research content | Yes | Hosting, Google Gemini (AI features) | No |
| Inferences (idea verdicts — about ideas, not people) | Yes | Hosting | No |
| Sensitive PI: account log-in credentials | Yes | Hosting (hashed) | No |
Sources, purposes and retention for each category are described in Sections 2, 3 and 8. We have not sold or shared personal information, including of consumers under 16. Nevada residents: we don't sell covered information; you can still email [email protected] to register a request.
13. If you answered a form built with Hypothis
The founder who published the form decides what to ask and what to do with your answers; their own privacy notice (if they have one) applies to them. We host the form and store and process your answers on their behalf. Specifically:
- We collect your answers, anything you choose to add (like a name or email for follow-up), your truncated IP address, approximate city/country, device, browser and time zone, and a daily visitor hash that can't be reversed. We use these to show the founder aggregate analytics and to block spam and bots. Your IP is truncated when stored and removed after 30 days.
- If the founder enabled AI follow-up questions, some of your open-text answers are sent to Google's Gemini API in real time to generate the next question.
- If you happen to be signed in to your own Hypothis account while answering, your account email is recorded with your response.
- Public forms don't load analytics or advertising trackers.
- To access, correct or delete your answers, contact the founder who sent you the form. If you can't reach them, email [email protected] with the form link and we'll forward your request and help as a processor must.
14. Children's privacy
Hypothis isn't directed to children. You must be at least 16 to create an account. We don't knowingly collect personal information from children under 13 (or under 16 in the EU/UK), and founders may not use Hypothis to do so without the consents the law requires. If you believe a child has given us personal information, email [email protected] and we'll delete it.
15. Changes to this policy
We'll post any changes here and update the effective date. For material changes we'll notify account holders by email or in the app before they take effect, and ask for consent again where the law requires.
16. Contact us
Kratu AI LLC, Attn: Privacy, 2114 Wasatch Blvd, Sandy, UT 84092 · [email protected]. For respondents to a founder's form, see Section 13.