Privacy Policy

Last updated: 7 August 2026

1. Who we are

This Privacy Policy explains how HyperStore ("we", "us", "our") handles personal data when you use store.hypergpt.ai, our directory of AI applications. HyperStore is operated by Decentralogic Ltd, the controller responsible for the personal data described here.

You can reach us about anything in this policy at [email protected].

Our main site publishes its own policy at hypergpt.ai/privacy-policy. This one covers store.hypergpt.ai.

2. Browsing without an account

You can browse and search the whole directory without an account. If you do that, we do not collect your name or email — but the third-party services in section 5 still operate, and section 7 explains the choice you have over them.

3. If you create an account

Accounts are optional and only unlock saving apps to your own list. We hold:

  • Your email address, which identifies the account and signs you in.
  • Your name, if you choose to give one — it is optional and only shown in the interface.
  • Your password, stored only as a bcrypt hash. We never hold the password itself.
  • Your Google account identity, only if you choose to sign in with Google instead of a password.
  • The apps you save, so your list persists between visits.
  • A sign-in session cookie that keeps you signed in. It contains a signed token, not your password.
  • Account creation and last sign-in times, for security and account housekeeping.

4. If you contact us or submit a listing

  • Contact form — we receive your name, email and message, and keep them until the request is resolved and for a reasonable period afterwards.
  • Submit an AI app — we receive the applicant name and email you give us along with the details of the app being submitted, so we can review it and come back to you about it.

Both are voluntary. We use these details to answer you and for nothing else.

5. What is collected automatically

  • Google Analytics, via Google Tag Manager — device and browser information, approximate location derived from your IP address, pages viewed and the referring page, for audience measurement.
  • Microsoft Clarity — interaction recordings: clicks, scrolling, mouse movement and a replay of your session, to understand how pages are used.
  • Google AdSense and its ad partners — advertising identifiers and ad interactions, to serve and measure ads.
  • A pseudonymous visitor identifier recorded when you click through from an article to an external app, so we can measure which recommendations are useful.
  • Search terms entered in the site search, kept as aggregate counts only with no identifier attached, so we can see what people look for and fill gaps in the catalogue.
  • Google's Consent Management Platform — your consent choice, so we can remember what you agreed to.

We do not sell personal data.

6. Cookies, advertising and analytics

This site is funded by advertising, served through Google AdSense. Google and its ad partners may set cookies to select and measure ads. Where you have consented, ads may be personalised — selected using a profile built from your activity across sites. Where you have not consented, Google serves limited ads, selected without using information stored on your device.

We use Google Analytics for aggregate audience statistics and Microsoft Clarity for session replay and heatmaps. When you have not consented, both operate in a restricted mode: Clarity sets no cookies and treats each page view separately, and Analytics sends only cookieless signals.

Strictly necessary cookies — your sign-in session, your language choice, your light/dark preference and your consent record — are always set, because the site cannot work without them.

7. How we ask for your consent

If you visit from the European Economic Area, the United Kingdom or Switzerland, you will see a consent message before advertising and analytics cookies are used. It is served by Google’s Consent Management Platform, certified under the IAB Europe Transparency & Consent Framework (TCF) v2.2. You can accept, refuse, or open Manage options to choose purposes and vendors individually.

Refusing is free and always available. If you refuse, the site keeps working; you will still see ads, but they will not be personalised.

Changing your mind. You can reopen the consent message at any time from the privacy settings link in the site footer, or by clearing this site’s cookies. Withdrawing consent does not affect processing that already happened while consent was in place.

Outside the EEA, the UK and Switzerland this consent message is not shown, and the services described above operate under the rules of your local jurisdiction.

8. Legal bases (EEA, UK and Switzerland)

  • Contract — running your account and saving your list, when you have one.
  • Consent — advertising cookies, personalised advertising, analytics and session replay. Withdrawable at any time.
  • Legitimate interests — answering your messages, reviewing listing submissions, keeping the site secure and available, and understanding aggregate demand where that does not require consent. We balance this against your rights and use the least intrusive option we can.

Some vendors listed in the consent message rely on legitimate interests for certain purposes. You can object to that in Manage options.

9. Who receives your data

  • Google (advertising, analytics, tag management, consent management, and Google sign-in if you use it) — see policies.google.com/privacy and business.safety.google/adscookies.
  • Microsoft (Clarity) — see privacy.microsoft.com/privacystatement.
  • Google's certified ad partners — the full, current list is shown inside the consent message under List of partners. It is maintained by IAB Europe and changes over time, which is why we link to it rather than reproduce it.
  • Cloudflare — serves and protects this site, and hosts our image CDN.
  • Railway — hosts the application and its database.

We do not share your account email, contact message or listing submission with advertisers.

10. Leaving the site

HyperStore is a discovery layer. When you follow a link to an external app or website, that destination’s own privacy policy applies. We do not control what they collect, and we are not responsible for it.

11. International transfers

These providers are based outside the EEA and may process data in the United States and elsewhere. Where personal data is transferred out of the EEA, the UK or Switzerland, they rely on legal transfer mechanisms including the European Commission’s Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.

12. How long data is kept

  • Account data — until you ask us to delete the account. Deleting it also deletes your saved apps.
  • Contact messages and listing submissions — until resolved, then for a reasonable period as a record.
  • Outbound click records — kept in pseudonymous form for traffic analysis.
  • Search terms — aggregate counts, kept indefinitely; they contain no identifier.
  • Analytics and advertising data — per the retention set by Google and Microsoft.
  • Your consent choice — up to 13 months, then you will be asked again.

13. Your rights

If you are in the EEA, the UK or Switzerland you have the right to access, rectify, erase, restrict or object to processing of your personal data, and to data portability. Where processing is based on consent, you may withdraw it at any time.

To exercise these rights, contact us at [email protected]. You also have the right to complain to your local data protection authority.

For data collected directly by Google and Microsoft under their own policies, requests are often fastest handled with them — the links in section 9 include their request forms.

14. Blockchain and Web3

Some parts of the HyperGPT ecosystem involve blockchain technology. Anything recorded on a public blockchain is public and permanent by design, and outside our control. Browsing HyperStore does not require any blockchain interaction.

15. Security

We take reasonable technical and organisational steps to protect the platform — passwords are hashed, sessions are signed, and traffic is encrypted in transit. No online service can be guaranteed completely secure, and we ask you to use a strong, unique password.

16. Children

This site is not directed at children under 16 and we do not knowingly collect their personal data.

17. Changes to this policy

We may update this policy as the site or the services it uses change. The "Last updated" date at the top shows the current version.

18. Contact

HyperStore, operated by Decentralogic Ltd[email protected]