should() Privacy Policy
This policy covers should(), run by HyperMindZ: what we collect, what we keep, who processes it, and how to get it deleted. It sits alongside the Terms.
1. What we collect
- Account: your name, email and sign-in identity (for example GitHub), the use case you give when you request access, and the terms version you accepted, with the time and IP address.
- Decisions: for each decision, a sha256 hash of the question and context (not the text), the outcome, confidence, model, cost, latency and time. The raw context is stored only if you opt in.
- Sources you reference: the link, the revision and a fingerprint (hash) of the text read. For decisions made with a judgment, also the extracted field values, where each came from, and the file title. We never store the document itself. Uploaded files are read for one decision and discarded.
- Connections: the access tokens for accounts you connect, encrypted at rest, and a log of each read (who, which key, which source, when; no content).
- What you give us: outcomes, corrections, test cases and judgments you create.
- Usage: request counts, spend and rate-limit counters.
2. How we use it
To run the service: answer your decisions, show you your history and evidence, enforce limits and spend caps, keep the service secure, and contact you about your account. We don’t sell your data, don’t use it for advertising, and don’t use it to train models.
Aggregate analysis. HyperMindZ staff analyze usage across accounts to operate and improve should(): which templates and judgments are used, outcome and escalation rates, confidence, engines, cost, latency, and which kinds of sources are read. This uses the decision records above (which hold a hash of each question, never its text) and the judgments you define. It never uses document content, which we don’t store. Results are looked at in aggregate. We look at one account’s judgments only to support that account, to investigate abuse or a security issue, or for billing.
3. Where your content goes: model providers
To decide, should() sends the question and the relevant context (including passages read from your sources) through OpenRouter to a model provider. We ask for zero data retention and no training in our OpenRouter account settings and on each request, and route only to providers that say they meet those settings.
We rely on those providers’ published policies in good faith, and we cannot guarantee them. We can’t audit a provider’s systems. OpenRouter states that its zero-retention listings reflect providers’ own representations. Where a provider’s documents disagree, we say so here. As of the date below:
- OpenRouter says it doesn’t store prompts or outputs unless a customer opts into logging (we don’t), and doesn’t train on them.
- TypeSafe AI (Jev) is listed by OpenRouter and Cloudflare as zero data retention and says it doesn’t train on inputs. Its own terms also describe zero retention as an enterprise option and reserve rights to derive telemetry and to monitor abuse. We have asked TypeSafe to confirm in writing how traffic from OpenRouter is handled, and we will update this section when it answers.
- OpenAI models are reached only through Microsoft Azure endpoints that OpenRouter lists as zero retention. OpenAI’s own endpoint, which keeps abuse-monitoring logs for up to 30 days, is excluded by our settings.
If we learn a provider doesn’t meet the settings we rely on, we stop sending it data and update this policy.
4. Service providers (sub-processors)
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Clerk | Sign-in, accounts and API keys | Name, email, sign-in identity, API key metadata | United States |
| Neon | Database | Account records, decision records (hashes, outcomes, provenance), usage and spend | United States (AWS us-east-1) |
| Vercel | Hosting and request logs | Requests in transit, operational logs without context content | United States |
| OpenRouter | Routes each decision to a model provider | The question and context of a decision, in transit | United States |
| TypeSafe AI (Jev) | Decision model, via OpenRouter | The question and context of a decision | United States |
| Microsoft Azure (OpenAI models) | Language-model engine for some judgments, condensing and extraction, via OpenRouter | The question, context and relevant passages of a decision | United States or EU |
5. Accounts you connect
- Google Workspace: drive.file: only the files you pick with should(). should() reads a file only when you (or a key or agent you allowed) ask for a decision or open a preview.
- A connection is yours alone; colleagues in your organization can’t use it. Disconnect under Keys & connections to revoke our access at the provider.
- should()’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
6. How long we keep it
- Decision records, their provenance and extracted values, and the source-read log: 13 months, then deleted.
- Connection tokens: until you disconnect, or your account is removed.
- Account and access records: while your account exists.
- Uploaded files and source content: not kept.
7. Your choices and rights
You can see your decisions in the app, disconnect sources, revoke keys, and ask us to export or delete your data. Email contactus@hypermindz.ai. Where local law gives you further rights (for example under GDPR or California law), contact us at the same address.
8. Security and location
Connection tokens are encrypted at rest; access is limited to what each feature needs. Data is processed in the United States (and the EU for some Azure endpoints).
9. Changes and contact
We update this policy when our processing or providers change. The date is below. Questions: contactus@hypermindz.ai.
Version v1.1 · last updated 2026-09-28