Hypothesisly
How it worksDocsPricingSecurityAbout
Log in
How it worksDocsPricingSecurityAboutLog in
Privacy

Privacy.

Last updated 15 June 2026 · v1 draft

This policy explains what personal data Hypothesisly (“we”, “us”) collects, why, who we share it with, and the choices and rights you have. We collect as little as we need to run audits and support you — nothing for advertising, and we never sell your data.

Hypothesisly is a business tool. If you run audits on behalf of clients, you remain responsible for those clients’ data under your own agreements: we act as your processor for the audit data you submit, and as a controller for your own account data.

We serve customers in the UK, EU, and US, and we aim to meet the privacy laws that apply in each — the UK GDPR and Data Protection Act 2018, the EU GDPR, and US state laws such as California’s CCPA/CPRA.

Who we are

Hypothesisly provides an AI CRO (conversion-rate-optimisation) audit service for ecommerce. For privacy questions, data requests, or to reach the person responsible for data protection, email hello@hypothesisly.com; for security and data-protection matters specifically, security@hypothesisly.com.

What we collect

  • Account data — your name, work email, company, and website, provided when you request access or sign up, plus authentication data handled by our auth provider.
  • Audit data — the URLs you submit, page snapshots and screenshots we capture, and the analytics you choose to connect (Google Analytics 4 figures, and Microsoft Clarity behavioural signals where you enable it), together with the hypotheses generated and the test outcomes you log.
  • Communications — messages you send us, such as early-access requests or support emails.
  • Usage data — where we measure it, limited and aggregated information about how the app is used, to fix bugs and prioritise work. See our Cookies page.

How and why we use it

We use personal data to:

  • provide the service — run your audits, generate and store hypotheses, and show your results (legal basis: performance of our contract with you);
  • authenticate you and keep your account secure (contract, and our legitimate interest in securing the service);
  • support you and respond to your requests (contract / legitimate interest);
  • fix bugs and improve the product using aggregated usage data (legitimate interest);
  • meet legal obligations where they apply.

We do not use your data for advertising, we do not sell it, and we do not add you to a marketing list without you asking.

Who processes it (subprocessors)

We rely on a small set of subprocessors to operate the service:

  • Supabase — database and file storage, hosted in the EU (Ireland).
  • Clerk — authentication and account management.
  • Cloudflare — hosting, content delivery, and edge security.
  • Anthropic — hypothesis generation via the Claude API, under a contractual zero-retention arrangement: your audit data is not retained beyond the API call and is not used to train models.
  • Microsoft Clarity — behavioural analytics, only when you connect it.
  • Cal.com — demo scheduling, if you book a demo.

Each subprocessor is bound by its own data-processing terms. The Security page describes how data is protected at each step.

Where your data lives & international transfers

Your audits, hypotheses, and stored data are held in the EU (Ireland). Several of our subprocessors are based in the United States and may process limited data there. Where personal data leaves the UK or EU, we rely on appropriate safeguards — such as the EU–US and UK–US Data Privacy Framework, Standard Contractual Clauses, or the UK Addendum — so your data keeps an equivalent level of protection. US customers’ data is likewise stored in the EU; no US data-residency is required for the service.

How we protect it

Data is encrypted in transit (TLS) and at rest. Connected analytics tokens (Google Analytics 4 and Microsoft Clarity) are encrypted at rest with AES-256-GCM. Access is scoped per account — no account can read another account’s data. Full detail is on the Security page.

How long we keep it

We keep your data while your account is active, and you can export your audits and hypotheses at any time. When you delete your account, your data enters a 30-day read-only window so you can still export it, after which it is permanently removed from active storage and from backups in the ordinary course.

Your rights

UK & EU (UK GDPR / EU GDPR). You have the right to access, correct, export (port), delete, or restrict the processing of your personal data, to object to certain processing, and to withdraw consent where we rely on it. You can complain to a supervisory authority — in the UK, the Information Commissioner’s Office (ICO); in the EU, your local data-protection authority.

United States (including California). Subject to your state’s law (such as California’s CCPA/CPRA), you have the right to know what personal information we collect and how we use it, to access and delete it, to correct it, and to opt out of the “sale” or “sharing” of personal information. We do not sell your personal information and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of. We won’t discriminate against you for exercising your rights, and you may use an authorised agent to make a request.

To exercise any right, email hello@hypothesisly.com. We’ll verify your request and respond within the timeframes the law requires.

Cookies

We keep cookies to a minimum and use no advertising or cross-site tracking cookies. See the Cookies page for specifics and how to manage them.

Children

Hypothesisly is a business product, not intended for or directed at children. We do not knowingly collect data from anyone under 16.

Changes

If we make material changes to this policy, we’ll update this page and the date above and, where appropriate, notify you.

Contact

Questions or requests: hello@hypothesisly.com.

Hypothesisly

A CRO audit agent for ecommerce.

© 2026 Hypothesisly

Product
  • How it works
  • Pricing
  • Security
  • Book a demo
Company
  • About
  • Early access
  • Contact
Resources
  • Docs
  • Security
  • hello@hypothesisly.com
PrivacyTermsCookies