Transparency

Privacy Policy

We keep this notice plain: what we collect on the landing site, why we collect it, and how you control it.

Last updated: August 21, 2026

What we collect

Technical request data, plus audience measurement counted server-side. This site stores no analytics data on your device.

What we do not capture

No landing prompt text in analytics, and no direct contact fields in analytics events.

Your control

Use Privacy settings in the footer to object to measurement. We also honour Global Privacy Control and Do Not Track.

Scope

This notice covers the public landing site at hedgehunt.app, the AI processing of gameplay that happens when you play or build a hunt, and what you write when you create a hunt. Other product data flows are described in the app itself.

Data we process

We process technical request data to serve the website. For audience measurement, your browser also sends analytics requests to hedgehunt.app/ingest carrying the page viewed and interactions on it. No analytics data or identifier is kept on your device for this, and the identifier used to group those requests is derived on our servers and regenerated daily, so it cannot link your visits across days or across sites.

If you have a HedgeHunt account, we also record the moments that matter in the builder, such as creating, saving, publishing and releasing a hunt, so we can see where the product gets in the way. You can object to this from Settings, Account inside the builder, separately from the setting on this site.

Campaign links may include marketing parameters (UTM values). We recommend that campaign partners avoid placing personal identifiers in these values.

If you arrived from a campaign link and then created an account, we record which campaign that was on your account, once, so we can tell which of our own campaigns bring people to HedgeHunt. We keep only the three campaign values from the link, never the full address, and only ever the first one: a campaign link you follow later does not change what is recorded. Objecting from Settings, Account deletes it rather than only stopping future counting.

Technical analytics schema (expand)

Event names

  • lp_page_view
  • lp_cta_click
  • lp_footer_link_click
  • lp_prompt_chip_click
  • lp_prompt_submit
  • lp_scroll_depth

Event properties

  • landing_path
  • cta_location
  • link_name
  • chip_label
  • prompt_length_bucket
  • depth_percent

Attribution/context properties

  • referrer_domain
  • source_channel
  • traffic_type
  • utm_source
  • utm_medium
  • utm_campaign
  • utm_content
  • utm_term

Data we do not capture in landing analytics

  • Prompt text content from the landing textarea
  • Name, email, or phone fields in landing analytics events
  • Payment data

Cookies and storage

These are the storage keys currently used by the landing site and analytics integration.

Cookie and storage inventory
Cookie and local storage keys used by the landing site
Key Purpose Retention Category
hh_landing_analytics_objection Set only if you turn audience measurement off. Local storage on hedgehunt.app, holds no identifier. Cleared when you turn measurement back on or clear browser storage. Until you clear it or clear browser storage Essential
hh_landing_analytics_preference_set Records that you have made an analytics choice on this site, so an older consent record is not applied over it. Until you clear browser storage Essential
hh_landing_debug Turns on analytics debug logging when ?debug=1 is used. Set by us during QA, never automatically. Until removed from browser storage Optional
hh_landing_internal_traffic Marks internal traffic mode when ?internal=1 is used. Set by us during QA, never automatically. Until removed from browser storage Optional
__mplssupport__ Written and immediately deleted by the analytics library to check whether browser storage is available. Carries no data about you and does not survive the check. Deleted during the same check Essential
test Written and immediately deleted by the analytics library to check whether browser storage is available. Carries no data about you and does not survive the check. Deleted during the same check Essential
ph_debug Read by the analytics library to see whether debug logging is switched on. Written only when we turn debug mode on during QA, never during a normal visit. Until removed from browser storage Optional
hh_cookie_consent_v1 The cookie consent record set by the hunt builder and player apps. This site only reads it, once per visit until you make a choice here, so an earlier decision to decline analytics is not silently reversed. This site never writes or clears it. Owned by the builder and player apps, not set or cleared by this site Optional
ph_* PostHog analytics identifiers, set by the builder and player apps on their own subdomains under their own consent banner. This marketing site sets none; a cross-subdomain cookie from a signed-in app session can still be visible on the apex domain. Defined by PostHog/browser settings Optional

AI processing of gameplay

When you play a hunt, what you submit can be sent to third-party AI providers. This happens in two situations. First, when the person who built the hunt turns on AI grading, your typed answer, photo or audio recording is sent to an AI provider to decide whether it counts as correct. Second, the hunt's creator can ask for a written summary of where players got stuck, which sends recent answers, skip requests and problem reports so the summary can quote real examples back to them.

We do not send your name, email address or account identifier with any of this. Before content is used for the creator-facing summary, we automatically remove email addresses and phone numbers found in the text. That removal is limited to those two patterns, so please avoid putting other personal details, such as your home address, into free-text answers or problem reports.

Summaries produced this way are cached for up to 30 days and then deleted. The creator of a hunt can see the answers submitted to it, including yours, as part of their own analytics.

What you write when you create a hunt

When you use the AI generator in the builder, we keep two things you typed: the description of the hunt you asked for, and the place you named, if you named one. We keep them so we can see what people are trying to build and make the generator better at building it.

The place field asks for a town, an area or a landmark, which is all the generator needs. You do not need to give a precise home address, and we would rather you did not.

Both are stored with your account and kept for as long as the account exists. There is no scheduled deletion, because they describe your own hunts. Neither is ever shown to other creators, and neither is ever sent to the people who play your hunts.

Your description is sent to OpenAI to generate the hunt, which is the same cross-border transfer described in the next section.

Our legal basis is legitimate interests: understanding what people ask for is how we improve the product. You can object at any time by emailing us at the address in the Contact section, and we will delete what you have written.

Processors and transfers

PostHog processes analytics data on our behalf for the landing site. Processing may involve cross-border transfers depending on PostHog's infrastructure region.

For the AI processing described above, OpenAI and Google act as processors on our behalf. Both operate outside the EEA, so this involves a cross-border transfer of the content you submit while playing.

Your rights

Depending on your location, you may have rights to access, delete, or correct data, and to object to or restrict specific processing operations. To exercise any of these rights, email [email protected].

Contact

For privacy requests, email [email protected].