Welcome to the Hype Star galaxy
Set the mood

Privacy Policy · Effective August 28, 2026

Measure the hype without building a people tracker.

This Policy explains how Hype Star handles information through hypestar.org, its public API, project directory, submission analyzer, traffic counter, customer accounts, permanent basic listings, optional enhancements, featured placements, source-backed profile details, weekly editorial spotlights, and the separately consented weekly newsletter.

01

Who and what this Policy covers.

Hype Star is responsible for the information described here. This Policy covers visitors, people who analyze, submit, claim, or promote a project, profile owners, newsletter subscribers, and people who contact us. It does not cover a listed project’s website or another service reached through a profile link.

Hype Star is a project directory, not a data broker. The launch version is designed around public project information, limited operational data, and private human review.

02

Information we collect.

  • Information you provide: a public project URL, project kind and category, optional profile text or assets, and messages you send us. Contact email and ownership details are collected only if someone separately claims, manages, or pays for a listing.
  • Technical and usage information: IP address and user-agent data used transiently to create salted hashes, request headers, timestamps, pages or profiles requested, outbound project-link events, badge and profile-link copy events, completed native profile-share actions, supporter-step outcomes, and ordinary security and server logs.
  • Project information: project name, domain, category, tagline, description, source links, logo or icon candidates, public-page metadata, and review status.
  • Source-backed detail information: reviewed labels and paraphrases, official source URL and locator, source capture/check/expiry dates, and private evidence excerpts, page and evidence hashes, append-only check outcomes or failure codes, revision history, and reviewer or retirement operator identifiers.
  • Spotlight information: issue title and summary, project reading order, editor-written selection notes, and the public source URL and capture date used when the issue is published.
  • Account information: email, display name, hashed magic-link and session tokens, limited session metadata, verification status, and account-security events.
  • Newsletter information: the email address you enter, normalized address, the exact consent version and language shown, signup surface, request and confirmation times, subscription or suppression status, provider contact reference, and a limited consent-event history. Confirmation capabilities are stored only as keyed hashes.
  • Transaction information: listing or feature SKU, order amount, status, entitlement dates, timestamps, and Stripe Customer, Checkout, payment, and invoice references. Stripe, not Hype Star, handles full payment-card or bank details.

Permanent basic inclusion does not require payment information and does not create a Stripe Customer, Checkout Session, payment method, or order. We record the canonical project key needed to prevent duplicate profiles. If a separate founding or paid enhancement exists, we also retain its status and entitlement dates. No owner identity is required for basic submission.

Newsletter signup is optional, unchecked by default, and separate from project submission, ownership, accounts, and payment. Entering an address does not create an account or project listing. We send the newsletter only after the one-time confirmation capability is used.

We do not need sensitive personal information to create a project profile. Please do not submit government identifiers, financial account credentials, health information, private login details, or other unnecessary sensitive information.

03

Public and owner-supplied sources.

We collect information directly from you, from your interaction with Hype Star, from a project owner or representative, and from publicly available project pages or approved sources and APIs. We may seed an unclaimed profile with public project information and a source link so authorized representatives can discover, correct, claim, or remove it.

The analyzer fetches only the submitted public homepage, checks robots instructions, and may extract structured data, title, meta description, headings, canonical URL, icons, and Open Graph fields. A separately isolated, network-restricted editorial process may capture a fixed-viewport screenshot of that public page. The public analyzer itself does not render untrusted pages. Analyzer results begin as private review artifacts. After editorial review, a limited public-homepage screenshot may be displayed as an independent directory preview without waiting for an ownership claim.

For an optional richer detail section, an operator may review visible text on one or more official project pages and store the exact evidence needed to audit the paraphrase. The source fetch is restricted to approved public HTTPS project hosts. Evidence excerpts and integrity hashes are private review material, not public profile copy.

04

Why we use information.

  • Provide, curate, categorize, review, publish, and maintain project profiles and links.
  • Verify, date, audit, correct, replace, expire, or retire optional source-backed profile detail sections while preserving an attributable review history.
  • Create and preserve dated unpaid editorial spotlights from reviewed public project information.
  • Create private analyzer drafts and communicate about submissions, claims, corrections, removal, or support.
  • Prevent duplicate project profiles, operate permanent basic inclusion, administer separate enhancement dates, and verify people who later request management or paid controls.
  • Estimate active and daily visitors, deduplicate profile views and outbound clicks, report basic referral, copy, and completed native-share interactions to listing managers, and understand whether submission and supporter tools work.
  • Authenticate customers, protect listing controls, and operate, troubleshoot, secure, and improve the website, API, database, storage, and shared-account system.
  • Process listing and featured-placement purchases, maintain transaction records, prevent fraud, and meet legal obligations.
  • Send a requested newsletter confirmation, maintain a suppression-safe contact list, deliver the weekly editorial email to confirmed subscribers, document consent and withdrawal, and prevent newsletter abuse.
  • Protect Hype Star, users, listed projects, rights holders, and the public; investigate misuse; and respond to lawful requests.

Where a legal basis is required, these uses rely as applicable on performing or preparing to perform a contract with you, Hype Star’s legitimate interests in operating a safe and useful directory, your consent, and compliance with legal obligations. You may withdraw consent for future processing where consent is the basis.

05

A profile is public; review materials are not.

Published project profiles may show the project name, domain, website link, category, editorial or owner-controlled description, tags, public source information, claim status, disclosed sponsored position, a reviewed public-homepage screenshot, and owner-approved brand assets. Public profile information can be indexed, copied, or reshared by other people and search engines.

A current source-backed detail section may publicly show its reviewed label and paraphrase, official source URL and locator, position, publication date, source capture date, latest successful check date, and automatic validity deadline. The supporting evidence excerpt, body and evidence hashes, check failures, prior revisions, and reviewer or retirement operator identifiers are not exposed through the website, open API, MCP, or agent skill.

Published weekly spotlights may show the issue title and summary, project names and reading order, editor notes, and the source-capture date used at publication. This is public project and editorial information; subscriber addresses, account details, payment records, and private review artifacts are not included. An embedded public profile may independently show its factual supporter-link status, but that status is not stored as selection evidence or used to choose or order an issue.

The free submission path collects a public project URL, selected kind/category, source metadata, and ordinary abuse-prevention data; it does not require an account, contact email, or payment identity. Public metadata may seed a private listing draft, and that draft becomes public only after accuracy and safety review. A contact or verification email is collected only if someone separately chooses to claim or pay for a listing and is not published unless they choose to include it. Raw logo candidates and internal source traces remain private during review. Project representatives and rights holders can request correction, replacement, or removal of a displayed public-page screenshot.

Newsletter addresses, confirmation state, consent records, and provider identifiers are not published or exposed through project profiles, the open API, MCP, or agent skill. Hype Star does not publish a subscriber count until it can be calculated from confirmed database records and labeled with a date.

06

When information is disclosed.

  • Public directory: approved profile information is disclosed as described above.
  • Infrastructure providers: hosting, PostgreSQL database, private asset storage, email delivery, security, and similar vendors may process information to provide services to Hype Star.
  • Newsletter delivery: after confirmation, we send the address and current subscribe or unsubscribe state to Resend so it can deliver email and maintain bounce, complaint, and suppression controls. A provider subscribe signal cannot create Hype Star consent.
  • Payment provider: information is sent to Stripe only when a verified owner explicitly starts or manages an available paid purchase, including for checkout, receipts, invoice history, saved payment-method controls, and Stripe-hosted billing management. Basic directory inclusion is not sent to Stripe.
  • Legal and safety: information may be disclosed when reasonably necessary to comply with law, enforce terms, investigate fraud or abuse, or protect rights and safety.
  • Business change: information may be transferred as part of a financing, reorganization, sale, merger, or similar transaction, subject to appropriate confidentiality and notice where required.

The launch version does not use personal information to sell it or share it for cross-context behavioral advertising. If that practice changes, we will update this Policy and provide any notice and controls required before the change applies.

07

Privacy-minded traffic measurement.

For the public traffic counter, Hype Star combines the requesting IP address and user agent with a secret salt and purpose label using a one-way keyed hash. The traffic hash rotates daily, so it is not a durable cross-day identifier. The database stores the hash, day, first- and last-seen times, and a view count. Known bots, previews, prefetches, and similar non-human requests are excluded where detected.

The same approach creates purpose-separated daily hashes to deduplicate profile views, badge or profile-link copies, and clicks to a listed project within a 30-minute window and to rate-limit analyzer, listing-creation, and account-email requests. Newsletter request, confirmation, and unsubscribe attempts use the same purpose-separated abuse-prevention approach. Security rate-limit hashes use the network address without the user-agent component. Hype Star does not use these hashes to follow you across unrelated websites or build an advertising profile. Ordinary hosting and security logs may still briefly contain network information according to provider configuration.

Growth-event records use a fixed event vocabulary and controlled labels. They do not store arbitrary analytics properties, full page or referrer URLs, account identifiers, or clipboard contents. Known bots, preview and prefetch requests, Global Privacy Control, and Do Not Track requests are excluded from these counters where detected. Manager reports describe dated estimated interactions, not unique people.

This code does not set advertising or third-party analytics cookies. Customer login uses a secure, HTTP-only, first-party session cookie; Stripe may use its own necessary technologies only when you visit its hosted Checkout or billing pages for an optional paid purchase, under Stripe's policies.

08

Retention and security follow the purpose.

We retain information only while reasonably needed to operate the directory and its counters, review and maintain a profile, provide requested services, document transactions or consent, resolve disputes, prevent abuse, and meet legal obligations. Daily traffic records may be retained to support the lifetime aggregate counter; the rotating hash prevents the counter from using one durable identifier across days. Analyzer jobs and private artifacts may be retained through moderation, rights review, and related disputes.

Raw growth events, outbound-click events, and security rate-limit events are scheduled for deletion after 90 days. The public traffic counter remains separate: daily records may be retained to support its stated lifetime aggregate, while its visitor hash rotates each day.

A newsletter confirmation capability expires after 48 hours and can be used once. Expired confirmation rows are scheduled for deletion after an additional 30 days. Never-confirmed pending subscriber rows are scheduled for deletion after 30 days when no valid capability remains. Minimal signed-webhook receipts are scheduled for deletion after 90 days. Confirmed, unsubscribed, suppressed, and consent-event records may be kept while needed to deliver the requested email, honor opt-outs and complaints, prove consent or withdrawal, resolve disputes, and meet legal duties.

Retention periods vary because the service is pre-launch and the purpose and legal requirements differ by record. When information is no longer reasonably needed, we delete or de-identify it, subject to backup cycles and lawful preservation requirements.

We use administrative and technical safeguards appropriate to the information, including access controls, hashed tokens and visitor identifiers, private review storage, request limits, and network protections. No system is completely secure, so we cannot guarantee absolute security.

Source-backed detail records may be retained while a section is current and afterward as reasonably needed to document editorial review, corrections, retirements, source disputes, and integrity checks. Public validity deadlines control display, not automatic deletion of the private audit trail. When those operational, rights, dispute, and legal purposes no longer apply, the records are deleted or de-identified subject to backup cycles and lawful preservation.

09

Your choices and privacy rights.

You may ask to access, correct, delete, or receive a copy of personal information about you, or to object to or restrict certain processing, where applicable law provides that right. You may also request ownership review, a factual correction, asset replacement, or removal of a project profile. Email hello@hypestar.org with enough detail to locate the relevant information.

We may need to verify your identity, authority, or relationship to a listed project before acting. An authorized agent may submit a request where law permits, and we may ask for proof of authorization. You may appeal a denied privacy request by replying to our decision. You will not receive discriminatory treatment for exercising an applicable privacy right.

Every newsletter includes an unsubscribe method. Using it updates Hype Star first, before provider synchronization is attempted. You may also withdraw newsletter consent or request help at hello@hypestar.org. Unsubscribing from the newsletter does not pause or remove a project listing or account, and changing a listing does not subscribe or unsubscribe an address.

Because the launch version does not sell personal information or use it for cross-context behavioral advertising, an opt-out preference signal does not change those practices. If Hype Star later performs processing covered by such a signal, we will honor it as required. You may also complain to your local privacy or data protection authority.

10

Visitors may be in different countries.

Hype Star and its infrastructure providers may process information in countries other than the one where you live. Privacy laws and government-access rules can differ. Where applicable law requires safeguards for a transfer, we will use an approved legal mechanism or another lawful basis.

11

Hype Star is not directed to children.

The service is not directed to children under 13, and we do not knowingly collect their personal information. If you believe a child under 13 has provided personal information, contact us so we can review and delete it as appropriate.

12

Policy updates and contact.

We may update this Policy as Hype Star launches accounts, payments, mobile clients, or new measurement tools. We will post the revised Policy with a new effective date and provide additional notice when required by law. Material changes apply prospectively unless law permits otherwise.

Privacy questions, requests, and profile correction or removal requests: hello@hypestar.org.