Company
How Hyperresearch handles your data
Hyperresearch reads public web pages, sends text to model providers, and stores what it read in your workspace. This page states what that means in practice: what the fetch lane will and will not do, how one workspace is kept out of another, who else processes your data, how long it is kept, and which assurances we cannot give yet. Everything here matches the Privacy Policy and the Terms, which are the binding documents.
Hyperresearch is based at 1001 S. Main St., Suite 500, Kalispell, MT 59901, United States; the legal entity behind it is listed on About. Security and privacy correspondence goes to support@hyperresearch.ai and a person reads it.
What the fetch lane does, and what it refuses to do
The pipeline fetches public pages, logged out. It never signs in to anything. It holds no customer credentials for third-party sites, because there is nowhere to put them. It does not solve CAPTCHAs and no CAPTCHA-solving vendor is integrated.
Fetching is a ladder. It checks your workspace vault first, then tries a direct fetch, then asks Unpaywall, Europe PMC and CORE for a legally open-access copy of any DOI, then Cloudflare Browser Rendering, then Firecrawl in plain and stealth modes. When every rung fails, the run does not guess and does not escalate privileges. It raises a human escalation: the run pauses with the URL and the reason, categorised as bot_wall, login_wall, captcha or paywall, and you resolve it by uploading the document, pasting the text, draining it with your own browser, or abandoning that source. Progress on the rest of the run is preserved while it waits.
Site operators get three commitments. robots.txt is recorded on every fetch and enforced for discovery fetches and for workspaces set to strict. A shared denylist covers financial institutions, government login portals, health portals, adult sites, data brokers, and anything a vendor refuses; a workspace can narrow that list but can never widen it. Per-domain concurrency limits inside the engine hold each workspace to a small number of simultaneous requests against any one host. Every fetch is attributable to a workspace, a run, a ladder rung and a vendor request id, so a complaint can be answered with a list. To be added to the denylist, write to support@hyperresearch.ai.
Fetched content is treated as untrusted data
The pipeline reads attacker-controllable pages and hands them to models that have tools. That is the central risk in this product and it is handled structurally rather than by asking a model to be careful.
Every fetched body is wrapped in an <untrusted-source> fence with a hardened preamble before it reaches any model or MCP client, and forged fence tags inside a body are neutralised regardless of case or whitespace. Tool allowlists are enforced per role by the orchestrator, not by prompt: a fetcher cannot call the artifact editor and a patcher cannot call the fetcher, so an injected instruction asking for a tool the role does not have fails closed. Tool arguments are schema-validated. URLs passed to the fetcher must be http or https and must resolve to public addresses, with private, link-local and cloud metadata ranges refused and DNS rebinding checked at connect time. Drafts and the synthesiser write to fixed artifact paths, so no model chooses a file path. Citation numbers and wikilinks are resolved by the engine, never by concatenating model output into a path. Your question is stored verbatim and repeated to every role, so a page cannot change the question.
In the console and in the vault, a source’s body is displayed inside a visible untrusted-source fence. That is deliberate. It is the source’s own words, and the interface says so.
Tenant isolation
Workspace identity comes from the API key, never from the request body. Every Durable Object, every storage prefix, every vector namespace and every database query is keyed by the workspace id derived from the authenticated key. Service bindings between Workers pass the authenticated context, and no Worker trusts a workspace id supplied in a header from outside.
Containers are shared compute and hold no tenant state. They receive bodies, return results, and keep no per-tenant files beyond the request. Raw PDFs are written to storage by the orchestrator, not by the container. Signed download URLs are prefixed by workspace and expire after about an hour.
The verification API enforces the same rule. An anonymous demo submission cannot reference a vault note_id at all; that field is refused outright.
Keys, scopes and connections
API keys are 32 random bytes. We store a salted SHA-256 hash plus a short non-secret prefix for lookup, which means we cannot read your key back, only revoke it. A key is shown once. Each key carries its own scopes, records a last-used timestamp, rotates with a 24-hour overlap, and revokes instantly through a revocation list checked on every request.
Scopes are runs:read, runs:write, vault:read, vault:write, verify, mcp and admin. An agent authorised over MCP through the browser consent screen gets read-only scopes by default; write access and metered actions such as verify require a separate grant, and the consent screen names the client, the scopes requested and the vault being granted. Every connection is listed with its client, scopes and timestamps, and can be revoked.
Provider keys, vendor keys, Stripe secrets and webhook signing secrets live in a secrets store and are bound only to the Workers that need them. Enterprise bring-your-own-key credentials are stored as gateway provider keys under a per-workspace gateway, so our own gateway logs never see them.
A redaction layer strips anything resembling a bearer token, API key, webhook secret, provider key or signed URL before it can reach a log line. Operational logs carry identifiers only: request id, account id, workspace id, run id, method, path, status and our error codes. They do not carry your question, your report, request bodies, your email address, your IP address or your user agent.
Spend caps
Every workspace has a spend cap and threshold notifications. Prices are shown on the control that starts the work, so the price is the confirmation and there is no separate spend dialog. Runs are a flat price per run and verification is per checked pair, both charged against the same cap. Internally, per-vendor global caps sit at 80% of contract, so no single workspace can exhaust a vendor for everyone else. A stolen key can still spend, which is why keys are per-scope, revocable instantly, and carry a last-used timestamp you can check.
Retention, export and deletion
We would rather tell you what the code does than quote a schedule it does not implement.
| Data | Retention today |
|---|---|
| Reports, run artifacts, vault notes, fetched source text and raw bytes | Kept until you delete the note or the workspace. There is no automatic expiry today and no storage lifecycle rule |
| Verification inputs, meaning a document you submitted plus its sources | Deleted 7 days after the job finishes unless you asked us to keep it. The receipt is kept |
| The run index and launch parameters, which include your verbatim question | Kept indefinitely today, including after the workspace’s content is deleted. This is a known gap |
| Usage ledger, invoice mirrors, refunds and credits | At least 7 years. These are the records an invoice dispute or a tax authority is answered from |
| Audit log | Readable for the workspace’s audit window, 365 days by default, configurable between 30 days and 10 years. The window clamps what the API returns; rows are not yet deleted when they age out |
| Console sessions | Expire 14 days after last use and 30 days after sign-in at the latest. Expired rows are not yet purged |
| Rate-limit and idempotency records | Minutes to 24 hours, by their own expiry |
| Server logs | Cloudflare Workers Logs retention. We have not pinned a period in our configuration, so we do not state one |
You can do these yourself right now: export the vault as a tar.gz of Markdown (on pay as you go the archive leaves out raw files and assets older than 180 days and model-call logs older than 30 days; they stay stored and readable), download any report as Markdown or PDF, export the workspace audit log as NDJSON, delete individual vault notes, see and revoke every API key and agent connection, ask for a copy of everything we hold about you across workspaces — which we assemble and hand back as a download link good for 24 hours — and close the account, which schedules the deletion 14 days out and can be cancelled from the same screen inside those 14 days.
You have to ask us for these: correction of your account record, and deletion of a single workspace. The API can delete a workspace; the console cannot yet. Email support@hyperresearch.ai from the address on the account. We aim to respond within 30 days and to complete a confirmed deletion within 14 days, the same window the self-service route uses.
Deleting a workspace erases its vault database, its embeddings and every stored object under its prefix, including reports, notes, fetched source text, raw bytes and exports, and revokes its keys. It leaves behind, in the control database, the workspace tombstone and metadata rows: the run index and its launch parameters, the usage ledger, the audit log, verification records and fetch-job parameters. A deletion handled by support removes those rows too. Automating that is on the list.
The two halves of your identity are one deletion either way round: deleting your Clerk sign-in identity closes your account here as well, and closing your account here deletes your Clerk user when the deletion completes. A closure that arrives from Clerk gets no 14-day window, because the identity you would sign in with to cancel it is the thing that has just stopped existing.
Subprocessors
Each of these processes data for us, and each gets the minimum the job needs. This table is copied from the Privacy Policy, which is the canonical version.
Platform and account
| Subprocessor | What it does | What reaches it |
|---|---|---|
| Cloudflare, Inc. (US) | All hosting and storage: Workers, D1, R2, Durable Objects, Vectorize, KV, Queues, Workflows, Containers, Browser Rendering, Workers AI for vault-search embeddings, AI Gateway, DNS, CDN and WAF. Its resolver also checks every URL we are about to fetch, which is how the pipeline is stopped from being pointed at a private network. Turnstile guards the public demo | Everything stored, plus every URL the pipeline resolves |
| Clerk, Inc. (US) | Sign-in and identity for the console | Your email address and its verification status, your chosen sign-in factor, and Clerk’s own sign-in telemetry |
| Stripe, Inc. (US) | Payments, subscriptions, Checkout, the Customer Portal, invoicing and tax | Your email address, your card details entered on Stripe’s own pages, usage meter events in cents, and invoice records. Card numbers never touch our servers |
| Resend | Transactional email: run, billing and account notices | The recipient’s email address and the notice content |
Model inference
Every model call except the direct Meta fallback leaves through Cloudflare AI Gateway, which holds the provider keys. We send no telemetry about you with it beyond a run id. The model chain runs through OpenRouter, with Meta called directly as a fallback, and the run page shows the model ids used for each role.
| Subprocessor | What it does | What reaches it |
|---|---|---|
| OpenRouter, Inc. (US) | Inference for every pipeline role | The prompts for each step, meaning your question and the source text the step works on, and the completions; the model providers behind OpenRouter receive what OpenRouter forwards: Meta (the muse-spark contributor model) for every role; Anthropic, PBC (US; Claude Opus 5.5) for the final edit of a Light report, and for the plan, the rulings on disputed points, the writing and an error check of a Deep report, which means Anthropic receives the evidence a Deep run gathered (the text of the sources it read, cut to fit the model’s input limit) in order to write the report; and OpenAI (US) in two cases: GPT-6.1 Sol when Claude Opus declines a step or fails to write a Deep report, in which case it receives the same input, and GPT-6 Luna as a last-resort fallback when the Meta model cannot be reached |
| Meta | Fallback inference when the Meta model cannot be reached through OpenRouter: the same model, called directly | The prompts and completions of the calls that fall back |
We do not use your content to train models. We run no models of our own. Your question and the source text go to the providers above under their paid API terms in order to generate your report. We do not license your content to anyone for training and we do not analyse your research across customers. For the providers reached through OpenRouter, the commitment is OpenRouter’s and the underlying provider’s, and we cannot promise you more than the strongest commitment they make to us.
Research: search, fetching and scholarly lookup
| Subprocessor | What it does | What reaches it |
|---|---|---|
| Firecrawl | Primary web search, and fetching and extracting page text, including its stealth proxy for pages that block ordinary fetches | Search queries a pipeline step generated from your question, and the URLs to fetch |
| Parallel Web Systems, Inc. (US) | Fallback web search when Firecrawl search fails | The same search queries |
| Exa Labs, Inc. (US) | Neural search for the adversarial lens, when that lens is switched on | The same search queries |
| OpenAlex (OurResearch, US), Crossref, Unpaywall (OurResearch), Europe PMC (EMBL-EBI, UK), CORE (Open University, UK), doi.org (International DOI Foundation) | Scholarly metadata, DOI resolution, retraction flags, and finding a legally open-access copy of a paywalled paper | DOIs and scholarly search strings derived from your question. No account data |
| GitHub, Inc. (US), Stack Exchange, Inc. (US), Algolia (the Hacker News search API) | Discovering primary and community sources | Search terms derived from your question |
| X (the official X API) | Searching posts on X when a question turns on what people said | Search terms derived from your question |
| SEC EDGAR (U.S. Securities and Exchange Commission) | Full-text search of company filings, and Form D notices | Search terms derived from your question |
Search and scholarly vendors receive machine-generated queries, which are derived from your question and are often close to it. Model providers receive your question itself. The websites the pipeline reads are not subprocessors, but worth saying: they see an ordinary HTTP request from Cloudflare’s network carrying the URL and our user agent, not your account.
There is no analytics vendor and no error-tracking vendor in the codebase. The one advertising network is Google Ads, which receives only a click ID, an event name, a time and a price, sent from our server when an account that came from a Google ad signs up, starts its first run or pays for its first run. There is no ad pixel or Google tag on the site. Anthropic and OpenAI are reached only through OpenRouter, as the model inference table says. We will update the table before adding a subprocessor that touches customer content, and material additions go to account owners.
Reporting a vulnerability
Send it to support@hyperresearch.ai with enough detail to reproduce it. There is no dedicated security address and no formal disclosure policy or bounty yet; when there is, it will be published here. Please do not test against other customers’ workspaces, and please give us a chance to fix it before publishing.
What we do not offer yet
Stated honestly, because a procurement review will find these anyway.
- No SOC 2 report. There is no Type I or Type II report today and we are not naming a date. The audit log, per-key scopes and tenant isolation described above were built to be auditable, and readiness work is planned, not done.
- No data residency guarantee. Everything runs on Cloudflare’s global network and may be processed in any region Cloudflare operates in. Cloudflare’s own certifications and its data processing addendum, including EU standard contractual clauses, apply to that processing. Cloudflare jurisdiction restrictions are an Enterprise conversation; ask before you sign up.
- No Data Processing Addendum on the shelf. If you are embedding Hyperresearch in your own product, you are likely a controller and we are likely your processor, and that relationship needs a DPA with standard contractual clauses and subprocessor flow-down. Ask us and we will work through it.
- No EU, UK or Swiss representative. If you are there and need a local representative, write to us and we will handle your request directly.
- No console control for workspace deletion. The API deletes a workspace; the console cannot yet, so ask support@hyperresearch.ai and we will do it. Account closure and the subject access export are both self-service now — closure schedules the deletion 14 days out and the export hands back a link good for 24 hours.
- No automatic expiry of stored content. Nothing ages out by itself. Delete what you do not want kept.
- No arbitration clause, which is a deliberate choice rather than an omission, and is stated in the Terms.
Updated 2026-10-02
