What we collect
Technical request data, plus audience measurement counted server-side. This site stores no analytics data on your device.
Transparency
We keep this notice plain: what we collect on the landing site, why we collect it, and how you control it.
Last updated: August 21, 2026
What we collect
Technical request data, plus audience measurement counted server-side. This site stores no analytics data on your device.
What we do not capture
No landing prompt text in analytics, and no direct contact fields in analytics events.
Your control
Use Privacy settings in the footer to object to measurement. We also honour Global Privacy Control and Do Not Track.
This notice covers the public landing site at hedgehunt.app, the AI processing of gameplay that happens when you play or build a hunt, and what you write when you create a hunt. Other product data flows are described in the app itself.
We process technical request data to serve the website. For audience measurement, your browser also sends analytics requests to hedgehunt.app/ingest carrying the page viewed and interactions on it. No analytics data or identifier is kept on your device for this, and the identifier used to group those requests is derived on our servers and regenerated daily, so it cannot link your visits across days or across sites.
If you have a HedgeHunt account, we also record the moments that matter in the builder, such as creating, saving, publishing and releasing a hunt, so we can see where the product gets in the way. You can object to this from Settings, Account inside the builder, separately from the setting on this site.
Campaign links may include marketing parameters (UTM values). We recommend that campaign partners avoid placing personal identifiers in these values.
If you arrived from a campaign link and then created an account, we record which campaign that was on your account, once, so we can tell which of our own campaigns bring people to HedgeHunt. We keep only the three campaign values from the link, never the full address, and only ever the first one: a campaign link you follow later does not change what is recorded. Objecting from Settings, Account deletes it rather than only stopping future counting.
lp_page_view lp_cta_click lp_footer_link_click lp_prompt_chip_click lp_prompt_submit lp_scroll_depth landing_path cta_location link_name chip_label prompt_length_bucket depth_percent referrer_domain source_channel traffic_type utm_source utm_medium utm_campaign utm_content utm_term Essential operations are processed under legitimate interests for security and service availability.
Audience measurement on this site is also processed under legitimate interests. It keeps no analytics data or identifier on your device: the only device storage involved is a throwaway key the analytics library writes and immediately deletes to check whether storage works at all, plus the two values that record your objection and the fact that you made a choice, if you make one. You can object at any time from Privacy settings, and we honour Global Privacy Control and Do Not Track signals.
Analytics inside the builder and player apps is processed under consent, collected by those apps' own banner, and is separate from this site. Product analytics tied to a signed-in account, including the campaign an account came from, is processed under legitimate interests and can be objected to from Settings, Account in the builder.
Delivery of measurement events is best effort. Ad blockers, network failures and browser settings mean some events never arrive, so these counts are a sample of activity rather than a complete record.
When you play a hunt, what you submit can be sent to third-party AI providers. This happens in two situations. First, when the person who built the hunt turns on AI grading, your typed answer, photo or audio recording is sent to an AI provider to decide whether it counts as correct. Second, the hunt's creator can ask for a written summary of where players got stuck, which sends recent answers, skip requests and problem reports so the summary can quote real examples back to them.
We do not send your name, email address or account identifier with any of this. Before content is used for the creator-facing summary, we automatically remove email addresses and phone numbers found in the text. That removal is limited to those two patterns, so please avoid putting other personal details, such as your home address, into free-text answers or problem reports.
Summaries produced this way are cached for up to 30 days and then deleted. The creator of a hunt can see the answers submitted to it, including yours, as part of their own analytics.
When you use the AI generator in the builder, we keep two things you typed: the description of the hunt you asked for, and the place you named, if you named one. We keep them so we can see what people are trying to build and make the generator better at building it.
The place field asks for a town, an area or a landmark, which is all the generator needs. You do not need to give a precise home address, and we would rather you did not.
Both are stored with your account and kept for as long as the account exists. There is no scheduled deletion, because they describe your own hunts. Neither is ever shown to other creators, and neither is ever sent to the people who play your hunts.
Your description is sent to OpenAI to generate the hunt, which is the same cross-border transfer described in the next section.
Our legal basis is legitimate interests: understanding what people ask for is how we improve the product. You can object at any time by emailing us at the address in the Contact section, and we will delete what you have written.
PostHog processes analytics data on our behalf for the landing site. Processing may involve cross-border transfers depending on PostHog's infrastructure region.
For the AI processing described above, OpenAI and Google act as processors on our behalf. Both operate outside the EEA, so this involves a cross-border transfer of the content you submit while playing.
Depending on your location, you may have rights to access, delete, or correct data, and to object to or restrict specific processing operations. To exercise any of these rights, email [email protected].
For privacy requests, email [email protected].