Company

How Hyperresearch handles your data

Hyperresearch reads public web pages, sends text to model providers, and stores what it read in your workspace. This page states what that means in practice: what the fetch lane will and will not do, how one workspace is kept out of another, who else processes your data, how long it is kept, and which assurances we cannot give yet. Everything here matches the Privacy Policy and the Terms, which are the binding documents.

Hyperresearch is based at 1001 S. Main St., Suite 500, Kalispell, MT 59901, United States; the legal entity behind it is listed on About. Security and privacy correspondence goes to support@hyperresearch.ai and a person reads it.

What the fetch lane does, and what it refuses to do

The pipeline fetches public pages, logged out. It never signs in to anything. It holds no customer credentials for third-party sites, because there is nowhere to put them. It does not solve CAPTCHAs and no CAPTCHA-solving vendor is integrated.

Fetching is a ladder. It checks your workspace vault first, then tries a direct fetch, then asks Unpaywall, Europe PMC and CORE for a legally open-access copy of any DOI, then Cloudflare Browser Rendering, then Firecrawl in plain and stealth modes. When every rung fails, the run does not guess and does not escalate privileges. It raises a human escalation: the run pauses with the URL and the reason, categorised as bot_wall, login_wall, captcha or paywall, and you resolve it by uploading the document, pasting the text, draining it with your own browser, or abandoning that source. Progress on the rest of the run is preserved while it waits.

Site operators get three commitments. robots.txt is recorded on every fetch and enforced for discovery fetches and for workspaces set to strict. A shared denylist covers financial institutions, government login portals, health portals, adult sites, data brokers, and anything a vendor refuses; a workspace can narrow that list but can never widen it. Per-domain concurrency limits inside the engine hold each workspace to a small number of simultaneous requests against any one host. Every fetch is attributable to a workspace, a run, a ladder rung and a vendor request id, so a complaint can be answered with a list. To be added to the denylist, write to support@hyperresearch.ai.

Fetched content is treated as untrusted data

The pipeline reads attacker-controllable pages and hands them to models that have tools. That is the central risk in this product and it is handled structurally rather than by asking a model to be careful.

Every fetched body is wrapped in an <untrusted-source> fence with a hardened preamble before it reaches any model or MCP client, and forged fence tags inside a body are neutralised regardless of case or whitespace. Tool allowlists are enforced per role by the orchestrator, not by prompt: a fetcher cannot call the artifact editor and a patcher cannot call the fetcher, so an injected instruction asking for a tool the role does not have fails closed. Tool arguments are schema-validated. URLs passed to the fetcher must be http or https and must resolve to public addresses, with private, link-local and cloud metadata ranges refused and DNS rebinding checked at connect time. Drafts and the synthesiser write to fixed artifact paths, so no model chooses a file path. Citation numbers and wikilinks are resolved by the engine, never by concatenating model output into a path. Your question is stored verbatim and repeated to every role, so a page cannot change the question.

In the console and in the vault, a source’s body is displayed inside a visible untrusted-source fence. That is deliberate. It is the source’s own words, and the interface says so.

Tenant isolation

Workspace identity comes from the API key, never from the request body. Every Durable Object, every storage prefix, every vector namespace and every database query is keyed by the workspace id derived from the authenticated key. Service bindings between Workers pass the authenticated context, and no Worker trusts a workspace id supplied in a header from outside.

Containers are shared compute and hold no tenant state. They receive bodies, return results, and keep no per-tenant files beyond the request. Raw PDFs are written to storage by the orchestrator, not by the container. Signed download URLs are prefixed by workspace and expire after about an hour.

The verification API enforces the same rule. An anonymous demo submission cannot reference a vault note_id at all; that field is refused outright.

Keys, scopes and connections

API keys are 32 random bytes. We store a salted SHA-256 hash plus a short non-secret prefix for lookup, which means we cannot read your key back, only revoke it. A key is shown once. Each key carries its own scopes, records a last-used timestamp, rotates with a 24-hour overlap, and revokes instantly through a revocation list checked on every request.

Scopes are runs:read, runs:write, vault:read, vault:write, verify, mcp and admin. An agent authorised over MCP through the browser consent screen gets read-only scopes by default; write access and metered actions such as verify require a separate grant, and the consent screen names the client, the scopes requested and the vault being granted. Every connection is listed with its client, scopes and timestamps, and can be revoked.

Provider keys, vendor keys, Stripe secrets and webhook signing secrets live in a secrets store and are bound only to the Workers that need them. Enterprise bring-your-own-key credentials are stored as gateway provider keys under a per-workspace gateway, so our own gateway logs never see them.

A redaction layer strips anything resembling a bearer token, API key, webhook secret, provider key or signed URL before it can reach a log line. Operational logs carry identifiers only: request id, account id, workspace id, run id, method, path, status and our error codes. They do not carry your question, your report, request bodies, your email address, your IP address or your user agent.

Spend caps

Every workspace has a spend cap and threshold notifications. Prices are shown on the control that starts the work, so the price is the confirmation and there is no separate spend dialog. Runs are a flat price per run and verification is per checked pair, both charged against the same cap. Internally, per-vendor global caps sit at 80% of contract, so no single workspace can exhaust a vendor for everyone else. A stolen key can still spend, which is why keys are per-scope, revocable instantly, and carry a last-used timestamp you can check.

Retention, export and deletion

We would rather tell you what the code does than quote a schedule it does not implement.

Data Retention today
Reports, run artifacts, vault notes, fetched source text and raw bytes Kept until you delete the note or the workspace. There is no automatic expiry today and no storage lifecycle rule
Verification inputs, meaning a document you submitted plus its sources Deleted 7 days after the job finishes unless you asked us to keep it. The receipt is kept
The run index and launch parameters, which include your verbatim question Kept indefinitely today, including after the workspace’s content is deleted. This is a known gap
Usage ledger, invoice mirrors, refunds and credits At least 7 years. These are the records an invoice dispute or a tax authority is answered from
Audit log Readable for the workspace’s audit window, 365 days by default, configurable between 30 days and 10 years. The window clamps what the API returns; rows are not yet deleted when they age out
Console sessions Expire 14 days after last use and 30 days after sign-in at the latest. Expired rows are not yet purged
Rate-limit and idempotency records Minutes to 24 hours, by their own expiry
Server logs Cloudflare Workers Logs retention. We have not pinned a period in our configuration, so we do not state one

You can do these yourself right now: export the vault as a tar.gz of Markdown (on pay as you go the archive leaves out raw files and assets older than 180 days and model-call logs older than 30 days; they stay stored and readable), download any report as Markdown or PDF, export the workspace audit log as NDJSON, delete individual vault notes, see and revoke every API key and agent connection, ask for a copy of everything we hold about you across workspaces — which we assemble and hand back as a download link good for 24 hours — and close the account, which schedules the deletion 14 days out and can be cancelled from the same screen inside those 14 days.

You have to ask us for these: correction of your account record, and deletion of a single workspace. The API can delete a workspace; the console cannot yet. Email support@hyperresearch.ai from the address on the account. We aim to respond within 30 days and to complete a confirmed deletion within 14 days, the same window the self-service route uses.

Deleting a workspace erases its vault database, its embeddings and every stored object under its prefix, including reports, notes, fetched source text, raw bytes and exports, and revokes its keys. It leaves behind, in the control database, the workspace tombstone and metadata rows: the run index and its launch parameters, the usage ledger, the audit log, verification records and fetch-job parameters. A deletion handled by support removes those rows too. Automating that is on the list.

The two halves of your identity are one deletion either way round: deleting your Clerk sign-in identity closes your account here as well, and closing your account here deletes your Clerk user when the deletion completes. A closure that arrives from Clerk gets no 14-day window, because the identity you would sign in with to cancel it is the thing that has just stopped existing.

Subprocessors

Each of these processes data for us, and each gets the minimum the job needs. This table is copied from the Privacy Policy, which is the canonical version.

Platform and account

Subprocessor What it does What reaches it
Cloudflare, Inc. (US) All hosting and storage: Workers, D1, R2, Durable Objects, Vectorize, KV, Queues, Workflows, Containers, Browser Rendering, Workers AI for vault-search embeddings, AI Gateway, DNS, CDN and WAF. Its resolver also checks every URL we are about to fetch, which is how the pipeline is stopped from being pointed at a private network. Turnstile guards the public demo Everything stored, plus every URL the pipeline resolves
Clerk, Inc. (US) Sign-in and identity for the console Your email address and its verification status, your chosen sign-in factor, and Clerk’s own sign-in telemetry
Stripe, Inc. (US) Payments, subscriptions, Checkout, the Customer Portal, invoicing and tax Your email address, your card details entered on Stripe’s own pages, usage meter events in cents, and invoice records. Card numbers never touch our servers
Resend Transactional email: run, billing and account notices The recipient’s email address and the notice content

Model inference

Every model call except the direct Meta fallback leaves through Cloudflare AI Gateway, which holds the provider keys. We send no telemetry about you with it beyond a run id. The model chain runs through OpenRouter, with Meta called directly as a fallback, and the run page shows the model ids used for each role.

Subprocessor What it does What reaches it
OpenRouter, Inc. (US) Inference for every pipeline role The prompts for each step, meaning your question and the source text the step works on, and the completions; the model providers behind OpenRouter receive what OpenRouter forwards: Meta (the muse-spark contributor model) for every role; Anthropic, PBC (US; Claude Opus 5.5) for the final edit of a Light report, and for the plan, the rulings on disputed points, the writing and an error check of a Deep report, which means Anthropic receives the evidence a Deep run gathered (the text of the sources it read, cut to fit the model’s input limit) in order to write the report; and OpenAI (US) in two cases: GPT-6.1 Sol when Claude Opus declines a step or fails to write a Deep report, in which case it receives the same input, and GPT-6 Luna as a last-resort fallback when the Meta model cannot be reached
Meta Fallback inference when the Meta model cannot be reached through OpenRouter: the same model, called directly The prompts and completions of the calls that fall back

We do not use your content to train models. We run no models of our own. Your question and the source text go to the providers above under their paid API terms in order to generate your report. We do not license your content to anyone for training and we do not analyse your research across customers. For the providers reached through OpenRouter, the commitment is OpenRouter’s and the underlying provider’s, and we cannot promise you more than the strongest commitment they make to us.

Research: search, fetching and scholarly lookup

Subprocessor What it does What reaches it
Firecrawl Primary web search, and fetching and extracting page text, including its stealth proxy for pages that block ordinary fetches Search queries a pipeline step generated from your question, and the URLs to fetch
Parallel Web Systems, Inc. (US) Fallback web search when Firecrawl search fails The same search queries
Exa Labs, Inc. (US) Neural search for the adversarial lens, when that lens is switched on The same search queries
OpenAlex (OurResearch, US), Crossref, Unpaywall (OurResearch), Europe PMC (EMBL-EBI, UK), CORE (Open University, UK), doi.org (International DOI Foundation) Scholarly metadata, DOI resolution, retraction flags, and finding a legally open-access copy of a paywalled paper DOIs and scholarly search strings derived from your question. No account data
GitHub, Inc. (US), Stack Exchange, Inc. (US), Algolia (the Hacker News search API) Discovering primary and community sources Search terms derived from your question
X (the official X API) Searching posts on X when a question turns on what people said Search terms derived from your question
SEC EDGAR (U.S. Securities and Exchange Commission) Full-text search of company filings, and Form D notices Search terms derived from your question

Search and scholarly vendors receive machine-generated queries, which are derived from your question and are often close to it. Model providers receive your question itself. The websites the pipeline reads are not subprocessors, but worth saying: they see an ordinary HTTP request from Cloudflare’s network carrying the URL and our user agent, not your account.

There is no analytics vendor and no error-tracking vendor in the codebase. The one advertising network is Google Ads, which receives only a click ID, an event name, a time and a price, sent from our server when an account that came from a Google ad signs up, starts its first run or pays for its first run. There is no ad pixel or Google tag on the site. Anthropic and OpenAI are reached only through OpenRouter, as the model inference table says. We will update the table before adding a subprocessor that touches customer content, and material additions go to account owners.

Reporting a vulnerability

Send it to support@hyperresearch.ai with enough detail to reproduce it. There is no dedicated security address and no formal disclosure policy or bounty yet; when there is, it will be published here. Please do not test against other customers’ workspaces, and please give us a chance to fix it before publishing.

What we do not offer yet

Stated honestly, because a procurement review will find these anyway.

  • No SOC 2 report. There is no Type I or Type II report today and we are not naming a date. The audit log, per-key scopes and tenant isolation described above were built to be auditable, and readiness work is planned, not done.
  • No data residency guarantee. Everything runs on Cloudflare’s global network and may be processed in any region Cloudflare operates in. Cloudflare’s own certifications and its data processing addendum, including EU standard contractual clauses, apply to that processing. Cloudflare jurisdiction restrictions are an Enterprise conversation; ask before you sign up.
  • No Data Processing Addendum on the shelf. If you are embedding Hyperresearch in your own product, you are likely a controller and we are likely your processor, and that relationship needs a DPA with standard contractual clauses and subprocessor flow-down. Ask us and we will work through it.
  • No EU, UK or Swiss representative. If you are there and need a local representative, write to us and we will handle your request directly.
  • No console control for workspace deletion. The API deletes a workspace; the console cannot yet, so ask support@hyperresearch.ai and we will do it. Account closure and the subject access export are both self-service now — closure schedules the deletion 14 days out and the export hands back a link good for 24 hours.
  • No automatic expiry of stored content. Nothing ages out by itself. Delete what you do not want kept.
  • No arbitration clause, which is a deliberate choice rather than an omission, and is stated in the Terms.

Updated 2026-10-02