← Back to Hipppo

Privacy Policy

Last updated: August 29, 2026

This Privacy Policy describes Our policies and procedures on the collection, use and disclosure of Your information when You use the Service and tells You about Your privacy rights and how the law protects You.

We use Your Personal Data to provide and improve the Service. By using the Service, You agree to the collection and use of information in accordance with this Privacy Policy.

Interpretation and Definitions

Interpretation

The words whose initial letters are capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.

Definitions

For the purposes of this Privacy Policy:

  • Account means a unique account created for You to access our Service or parts of our Service.
  • Affiliatemeans an entity that controls, is controlled by, or is under common control with a party, where “control” means ownership of 50% or more of the shares, equity interest or other securities entitled to vote for election of directors or other managing authority.
  • Company(referred to as either “the Company”, “We”, “Us” or “Our” in this Privacy Policy) refers to Save Everything. Feed Hippo., the controller of Your Personal Data, contactable at support@feedhipppo.com
  • Cookies are small files that are placed on Your computer, mobile device or any other device by a website, containing the details of Your browsing history on that website among its many uses.
  • Country refers to: United States.
  • Device means any device that can access the Service such as a computer, a cell phone or a digital tablet.
  • Personal Data(or “Personal Information”) is any information that relates to an identified or identifiable individual. We use “Personal Data” and “Personal Information” interchangeably unless a law uses a specific term.
  • Service refers to the Website, the Hipppo web application at app.feedhipppo.com, the Hipppo Chrome browser extension, the Hipppo Figma plugin, the Hipppo MCP server and agent connections, tokens You mint for other clients such as the iOS shortcut, and shared board links You publish.
  • Service Provider means any natural or legal person who processes the data on behalf of the Company. It refers to third-party companies or individuals employed by the Company to facilitate the Service, to provide the Service on behalf of the Company, to perform services related to the Service or to assist the Company in analyzing how the Service is used.
  • Usage Data refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).
  • Website refers to Hipppo, accessible from https://feedhipppo.com.
  • You means the individual accessing or using the Service, or the company, or other legal entity on behalf of which such individual is accessing or using the Service, as applicable.

Collecting and Using Your Personal Data

Types of Data Collected

Personal Data

While using Our Service, We may ask You to provide Us with certain personally identifiable information that can be used to contact or identify You. Personally identifiable information may include, but is not limited to:

  • Email address

User-Saved Content

When You use the Service to save content, We collect the following data that You explicitly submit:

  • Saved items— URLs, page titles, descriptions, thumbnails, screenshots, and image files that You choose to save using Hipppo. This content is stored privately in Your account by default. You may choose to publish a board as a shareable link; doing so makes the items on that board, and the board’s title, viewable by anyone who has the link, until You turn the link off. Shared boards may display a saved screenshot or other media, but they do not expose page-reconstruction packages.
  • Page captures — When You choose Capture Page, Hipppo stores a screenshot and may also store visible page text, page structure, layout, styles, typography, and asset references. We do not include raw HTML, scripts, or runtime form, password, autofill, or editable-field values. Screenshots and visible text can still contain sensitive information. Page-reconstruction packages remain private and are not included in shared boards.
  • Metadata — titles, descriptions, domain names, and preview images automatically extracted from pages You save.
  • Organizational data — board names and tag names You create to organize Your saved items.

Usage Data

Usage Data is collected automatically when using the Service.

Usage Data may include information such as browser type, browser version, the pages of our Service that You visit, the time and date of Your visit, the time spent on those pages, unique device identifiers and other diagnostic data. Our analytics provider may use Your Device's Internet Protocol address briefly for geographic enrichment and bot detection, then discards the address rather than storing it with Your analytics events.

We may also collect information that Your browser sends whenever You visit Our Service or when You access the Service by or through a mobile device.

Tracking Technologies and Cookies

We use Cookies and similar tracking technologies to track the activity on Our Service and store certain information. Tracking technologies We use include beacons, tags, and scripts to collect and track information and to improve and analyze Our Service.

Cookies can be “Persistent” or “Session” Cookies. Persistent Cookies remain on Your personal computer or mobile device when You go offline, while Session Cookies are deleted as soon as You close Your web browser.

  • Necessary / Essential Cookies — Session Cookies administered by Us. These Cookies are essential to provide You with services available through the Website and to enable authentication. Without these Cookies, the services that You have asked for cannot be provided.
  • Functionality Cookies — Persistent Cookies administered by Us. These Cookies allow Us to remember choices You make when You use the Website, such as remembering your login state.
  • Attribution Cookies — A Persistent Cookie administered by Us that records how You first arrived: the campaign and source parameters in the link You followed, the referring website address, and the first page You landed on. It is written once on Your first visit and is not updated on later visits. We use it to understand which channels bring people to Hipppo. It contains no personal information and no content from Your library.

Chrome Browser Extension

The Hipppo Chrome extension allows You to save content directly from any webpage. The extension requests the following browser permissions, each used only for the specific purpose described:

  • activeTab — Reads the URL, title, and visible area of the tab You are currently viewing, and captures a screenshot, only when You explicitly click the Hipppo extension icon or a save button. This permission is never activated passively.
  • tabs — Used to send save instructions to the active page and to capture screenshots when You trigger a save action. The extension does not read or log the URLs of tabs You are not actively saving.
  • storage — Uses chrome.storage.local to store a cache of Your account state, Your blocked-sites list, and temporary recovery data for an interrupted page capture. Browser-managed cookies authenticate requests to Hipppo. The extension does not store an authentication token in chrome.storage.local. Recovery data stays on Your device while the extension completes or recovers the save, and is removed after completion or when an expired session is processed.
  • contextMenus— Adds “Save to Hipppo” options to the browser right-click menu so You can save a page, link, image, or selected text without opening the extension popup.
  • alarms — Runs a periodic background task approximately every 30 minutes to refresh Your blocked-sites list from Hipppo servers, so that sites You block are kept up to date even when the popup is closed. No page content or browsing data is collected during this sync.
  • Access to all websites (http://* and https://*) — Required to inject the Hipppo save overlay on pages You visit and read the current page when You choose a save action. The overlay may inspect the element under Your pointer locally so its save controls can appear. Hipppo does not upload or retain that content unless You choose to save it.

Data sent to Our servers — When You choose a save action, the extension sends the page URL, page title, metadata, and the screenshot, image, or page content needed for that save. Capture Page sends a screenshot and, when available, the page-reconstruction data described above over HTTPS to private Hipppo storage. The background settings sync does not send page content.

What the extension does NOT do:

  • We do not track Your browsing history.
  • We do not upload or retain content from pages You visit unless You explicitly save something from them.
  • We do not inject ads or modify the content of pages You visit.
  • We do not sell or share Your data with advertisers or data brokers.

AI Analysis of Your Saves

Hipppo uses AI to make Your library findable. Shortly after You save an item, We send that item to two providers: Anthropic, which generates a short taste note and descriptive tags, and Voyage AI, which turns it into a search embedding — a numeric vector that lets You search by meaning. Both results are stored with the item in Your library.

  • What is sent — the saved image or screenshot as raw bytes, plus the page title, description, and source domain. Nothing that identifies You personally is included in the request: no email address, no account identifier, no board or tag names, and no other item from Your library.
  • What comes back — a short descriptive note and a set of tags, validated on Our servers before being stored.
  • Not used for training— Your content is not used to train Anthropic’s or Voyage’s models, or Ours.
  • Some saves skip the vision step — for kinds We do not analyse visually (video, links, PDFs, and text-only social posts), no image is sent; those items get a text-only embedding so they remain searchable.
  • Automated, and imperfect — these notes and tags are generated automatically without human review and can be wrong. They are organisational metadata, not a statement of fact. They do not produce any legal or similarly significant effect for You, and no decision about You is made on the basis of them.
  • Deleting the item deletes them — notes and tags are stored on the item and are removed when You delete it.
  • Lawful basis — performance of Our contract with You: organising saved items is the Service You signed up for. Email support@feedhipppo.com if You have questions about this processing.

Agent Connections (MCP)

You can connect an AI client — such as Claude or ChatGPT — to Your Hipppo library through Our MCP server. This happens only when You complete the authorisation step yourself.

  • What We store — the authorisation grant and access tokens for that connection, the name the client registered under, and the time it was last used. We do not store the conversations You have with the AI client.
  • What leaves Hipppo — Connecting a client does not automatically export Your library or page-reconstruction packages. When a connected client reads Your library, only the items, notes, tags, board names, and page-capture sections it requests are transmitted to that client. From that point the content is handled by the operator of that client under their own privacy policy, and We have no visibility into or control over it. Connect only clients You trust.
  • Revocation — You can revoke a connection at any time from Your account page, which invalidates its tokens. Revocation stops future access; it cannot recall content a client already retrieved.
  • Retention — revoked or expired tokens and grants are deleted. Tokens You mint for other clients (for example the iOS shortcut) are stored only as a one-way hash and are deleted when You revoke them or delete Your account.

Shared Board Links

Publishing a board creates a secret link that lets anyone holding it view that board’s title and items without signing in. Your name and email address are not shown on a shared board.

We ask search engines not to index shared board URLs, but a link You hand out can be forwarded, and content viewed while a link was live may have been copied. Turning a link off permanently invalidates that URL — re-sharing generates a new one — and it takes effect immediately.

Use of Your Personal Data

The Company may use Personal Data for the following purposes:

  • To provide and maintain our Service, including to monitor the usage of our Service.
  • To manage Your Account: to manage Your registration as a user of the Service.
  • For the performance of a contract: the development, compliance and undertaking of the purchase contract for the products, items or services You have purchased or of any other contract with Us through the Service.
  • To contact You: To contact You by email regarding updates, security notices, or informative communications related to the Service.
  • To manage Your requests: To attend and manage Your requests to Us.
  • For business transfers: We may use Your Personal Data to evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of Our assets.
  • For other purposes: We may use Your information for purposes such as data analysis, identifying usage trends, and to evaluate and improve our Service.

We may share Your Personal Data in the following situations:

  • With Service Providers:We may share Your Personal Data with Service Providers to monitor and analyze the use of our Service and to process payments. See the “Third-Party Service Providers” section below for details.
  • For business transfers: We may share or transfer Your Personal Data in connection with any merger, sale of Company assets, financing, or acquisition of all or a portion of Our business to another company.
  • With Your consent: We may disclose Your Personal Data for any other purpose with Your consent.

Third-Party Service Providers

We use the following third-party services. Each acts as a data processor on our behalf and is subject to its own privacy policy:

  • Vercel (Vercel Inc.) — application hosting and content delivery. Every request to the Service passes through Vercel, which processes Your IP address, request headers, and URLs in short-lived operational logs to serve the Service and protect it from abuse. Vercel Privacy Policy
  • Supabase (Supabase Inc.) — authentication, database, and file storage. Supabase processes Your email address, saved items, uploaded images, and all other account data. Servers are located in the United States. Supabase Privacy Policy
  • Stripe (Stripe, Inc.) — payment processing for paid subscriptions. Stripe collects and processes Your payment card information, billing address, and transaction history. We never see or store Your full card number. Stripe Privacy Policy
  • Anthropic(Anthropic PBC) — AI analysis of saved items. When You save an item, We send the item’s image bytes and its page metadata (title, description, and source domain) to Anthropic’s API to generate taste notes and descriptive tags. We do not send Your email address, account identifier, or any other account data with the request, and We do not send signed URLs — only the bytes themselves. Anthropic does not use API inputs or outputs to train its models. Anthropic Privacy Policy
  • Voyage AI— search embeddings. So that You can search Your library by meaning rather than by exact words, We send the same saved image bytes and text (title, description, and source domain) to Voyage’s API, which returns a numeric vector stored alongside the item. The words You type into search are also sent, as text only. As with Our AI analysis, no email address or account identifier accompanies the request. Voyage AI Privacy Policy
  • Resend (Resend, Inc.) — transactional email delivery. Resend processes Your email address and the contents of messages We send You or that You send Us through the in-app feedback form. Resend Privacy Policy
  • Loops (Loops, Inc.) — lifecycle email delivery. For accounts enrolled after this service is activated, Loops processes Your email address and account identifier, plus bounded milestones recording whether You have saved, connected an agent, or received useful agent output. It does not receive saved content, URLs, notes, tags, or agent requests. We do not override an unsubscribe when updating these milestones, and We delete the Loops contact before We delete Your account. Loops Privacy Policy
  • PostHog (PostHog, Inc.) — product analytics. On the Hipppo app, We send sanitized browser pageviews containing the page origin and path, device and browser information, and explicit product events from the browser and server. Query strings and page fragments are removed from analytics URLs. Client IP addresses may be used briefly for geographic enrichment and bot detection, then are discarded rather than stored with analytics events. We use PostHog session replay to understand navigation, friction, and failures in the Service. Replays may include pages, interface content, cursor movement, clicks, and navigation. Text entered into form inputs is masked in the browser before it is sent. Browser console-log capture, network request or response content, and broad automatic interaction event capture remain disabled. PostHog does not sell personal data. PostHog Privacy Policy
  • Sentry (Functional Software, Inc.) — error monitoring and performance tracking. Sentry automatically captures error logs, stack traces, and device/browser metadata when the Service encounters an unexpected error. This data is used solely to identify and fix bugs. Sentry Privacy Policy

Supabase, Stripe, Anthropic, Voyage AI, PostHog, Sentry, Resend, Loops, and Vercel all process data on servers in the United States. If We add or replace a provider that processes Your Personal Data, We will update this list and the “Last updated” date before the change takes effect.

Retention of Your Personal Data

The Company will retain Your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use Your Personal Data to the extent necessary to comply with our legal obligations, resolve disputes, and enforce our legal agreements and policies.

  • Account information — retained for the duration of your account relationship plus up to 24 months after account closure.
  • Saved items — retained for as long as Your account is active. You can delete individual saves at any time. Deleting an item removes its library record. Account deletion removes all associated library records.
  • Usage Data / analytics — up to 12 months from the date of collection.
  • Error logs — up to 90 days, as retained by Sentry per their default configuration.
  • Uploaded images and screenshots — retained with the item they belong to. Deleting the item or the account deletes the stored files.
  • Page-reconstruction packages — retained with the item they belong to. Deleting the item or the account removes the library record and stops new package uploads. Any remaining package files in private storage are removed after active upload grants expire.
  • Access tokens and agent connections — deleted when You revoke them or delete Your account.
  • Feedback You send Us — retained while We work through it. If You delete Your account, We keep the message itself but delete the email address it came from and the screenshot attached to it, so the feedback no longer identifies You.
  • Backups — deleted content may persist in encrypted routine backups until they rotate, within 30 days of deletion. Backups are used only to restore the Service after a failure.
  • Billing records — held by Stripe for as long as tax and financial-record law requires, independently of the retention periods above.

Usage Data is retained in accordance with the periods described above, and may be retained longer only where necessary for security, fraud prevention, or legal compliance.

Transfer of Your Personal Data

Your information, including Personal Data, is processed at the Company's operating offices and in any other places where the parties involved in the processing are located. This information may be transferred to — and maintained on — computers located outside of Your state, province, country or other governmental jurisdiction where the data protection laws may differ from those of Your jurisdiction.

The Company will take all steps reasonably necessary to ensure that Your data is treated securely and in accordance with this Privacy Policy and no transfer of Your Personal Data will take place to an organization or a country unless there are adequate controls in place.

If You are in the EEA, the United Kingdom, or Switzerland, Your Personal Data is transferred to the United States. Those transfers rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum where applicable) in Our agreements with each provider listed above, or on a provider’s certification under the EU-US Data Privacy Framework where it holds one. You may request details of the safeguards that apply by emailing support@feedhipppo.com.

Delete Your Personal Data

You have the right to delete or request that We assist in deleting the Personal Data that We have collected about You.

You may delete individual saved items at any time from within Your Hipppo library. You can also delete Your entire account yourself, without contacting Us, from Your account page. Deleting Your account immediately removes Your account record, every saved item, board, tag, and AI-generated note, every shared board link, and every agent connection and access token. Uploaded images and screenshots are deleted with the account. Any remaining page-reconstruction package files are removed after active upload grants expire. It cannot be undone, so export anything You want to keep first.

Deleting Your Hipppo account does not by itself cancel a paid subscription — cancel it from the Stripe Customer Portal first. Stripe retains billing and transaction records independently of Us for as long as tax and financial-record law requires.

If You would rather We do it, or if You want a copy of Your data first, email support@feedhipppo.com.

Please note that We may need to retain certain information when We have a legal obligation or lawful basis to do so.

Disclosure of Your Personal Data

Business Transactions

If the Company is involved in a merger, acquisition or asset sale, Your Personal Data may be transferred. We will provide notice before Your Personal Data is transferred and becomes subject to a different Privacy Policy.

Law Enforcement

Under certain circumstances, the Company may be required to disclose Your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency).

Other Legal Requirements

The Company may disclose Your Personal Data in the good faith belief that such action is necessary to:

  • Comply with a legal obligation
  • Protect and defend the rights or property of the Company
  • Prevent or investigate possible wrongdoing in connection with the Service
  • Protect the personal safety of Users of the Service or the public
  • Protect against legal liability

Lawful Basis for Processing (GDPR)

If You are located in the European Economic Area (EEA) or United Kingdom, We process Your Personal Data under the following lawful bases under GDPR Article 6:

  • Contract performance (account & saved items) — email address and saved content are processed to provide the Service You signed up for.
  • Contract performance (payments) — payment data is processed by Stripe to fulfill Your subscription.
  • Legitimate interest — Usage Data and error logs are processed to maintain, secure, and improve the Service, provided those interests are not overridden by Your rights.
  • Consent — where We ask for it explicitly, for example before sending You a message You opted into. We do not run advertising, cross-site tracking, or profiling cookies, so there is no consent banner; the analytics described above run under legitimate interest and honour Do Not Track in the browser.

Your Privacy Rights

EEA / UK residents (GDPR)

You have the right to:

  • Access the Personal Data We hold about You
  • Correct inaccurate Personal Data
  • Request erasure of Your Personal Data
  • Restrict or object to processing of Your Personal Data
  • Data portability — receive Your data in a structured, machine-readable format
  • Withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal

Access, correction, and erasure can be exercised directly in the product: Your library shows everything We hold about Your saves, individual items are editable and deletable, and Your account page deletes the account outright. For portability — a machine-readable copy of Your account data and saved items — or for any other request, email support@feedhipppo.com from the address on Your account. We acknowledge within two business days and respond within 30 days, free of charge.

You also have the right to lodge a complaint with Your local data protection supervisory authority. We would appreciate the chance to address Your concern first.

California residents (CCPA)

We do not sell Your personal information. Under the California Consumer Privacy Act (CCPA), California residents also have the right to:

  • Know what Personal Data We collect, use, disclose, or sell
  • Delete Personal Data We have collected from You
  • Non-discrimination for exercising Your CCPA rights

To submit a CCPA request, email support@feedhipppo.com with the subject line “CCPA Request”.

Analytics opt-out

PostHog browser collection respects the Do Not Track setting. Enabling Do Not Track suppresses browser-side PostHog collection in supported browsers and does not affect the functionality of the Service. It is not an account-level opt-out and does not suppress limited server-side product events generated when the Service completes actions You request.

Security of Your Personal Data

The security of Your Personal Data is important to Us, but remember that no method of transmission over the Internet, or method of electronic storage is 100% secure. While We strive to use commercially reasonable means to protect Your Personal Data, We cannot guarantee its absolute security.

Data is encrypted in transit. Saved images and screenshots are held in a private store and served only through short-lived signed links, and access to Your library is enforced per-account at the database level.

If something goes wrong: if We become aware of a breach affecting Your Personal Data, We will notify You by email without undue delay, and will notify the relevant supervisory authority within 72 hours where the law requires it.

Children's Privacy

Our Service does not address anyone under the age of 16. We do not knowingly collect personally identifiable information from anyone under the age of 16. If You are a parent or guardian and You are aware that Your child has provided Us with Personal Data, please contact Us. If We become aware that We have collected Personal Data from anyone under the age of 16 without verification of parental consent, We take steps to remove that information from Our servers.

Links to Other Websites

Our Service may contain links to other websites that are not operated by Us. If You click on a third party link, You will be directed to that third party's site. We strongly advise You to review the Privacy Policy of every site You visit. We have no control over and assume no responsibility for the content, privacy policies or practices of any third party sites or services.

Changes to this Privacy Policy

We may update Our Privacy Policy from time to time. We will notify You of any changes by posting the new Privacy Policy on this page. We will let You know via email and/or a prominent notice on Our Service, prior to the change becoming effective and update the “Last updated” date at the top of this Privacy Policy.

You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.

Contact Us

This Privacy Policy is part of our Terms of Service.

If You have any questions about this Privacy Policy, You can contact Us: