Hammer Labs HL-PRV-001 1 SHEET
PRIVACY

What this site measures

Written to be checked rather than agreed to. Everything below can be verified from the page source, the network tab, or the open repositories this is built from. Last changed September 8, 2026.

01

This site

Pages are static and served from Firebase Hosting. There are no advertising trackers, no third-party embeds beyond the ones named here, and no cookies set by this site itself.

Mixpanel is loaded and records page views and clicks. Session recording is off: no replay of your visit is captured or stored, at any sampling rate. What a click records is the fact that something was clicked and roughly where, never its contents. Text and element attributes are masked at the library level, so the words on a button, the text you type and everything you enter into a form stay out of it. It records the page you are on, a randomly assigned identifier, and what your browser reports about itself. It honours Do Not Track.

Two named events are sent deliberately rather than inferred: choosing a code and a payer in the rate widget, and clicking an email address or a repository link. Both carry what was chosen or which link it was, and nothing about you. Visits from our own machines and from preview deployments are not recorded here at all, which is a measurement decision rather than a privacy one, but the effect is the same.

Fonts come from Google Fonts, which sees your address when a font is fetched.

02

The agent

The agent at /ask/ runs as a separate service and is shown here in a frame. What you type goes to that service, to Google's Gemini on Vertex AI, and to the Hammer world your question is answered from. Conversations are stored so that a follow-up can refer to the question before it.

It sets one cookie for a guest identity, and a second, encrypted, if you sign in. The encrypted one carries your access token to the world; the service keeps no copy of it. Both are marked Secure and partitioned, so the copy set inside this page's frame is separate from the one set on the agent's own address.

Do not paste anything about a patient into it. It is a demonstration over published records and carries no agreement covering personal health information.

03

The two forms

The assessment enquiry and the monthly vintage note post to the same service the agent runs on, and each is stored in its own table. We keep what you typed, the address to reply to, and the campaign parameters that were in the link you arrived on, so we know which piece of writing brought you here. No cookie is set by either form and neither is shared with an email or advertising platform.

The monthly note goes out to the address you gave and carries a way to stop. Write to hello@hammer.ai to have either record deleted.

04

Signing in

Sign-in is handled by WorkOS AuthKit, which holds your account and issues the token the agent forwards. This site never sees a password. The number of questions you have asked is counted against your account identifier so a daily limit can be applied.

05

Asking for a copy, or deletion

Write to hello@hammer.ai and say which address you signed in with. Conversations and counters tied to it will be sent to you or deleted.

The plugin's own privacy note, covering what the installed world receives, is in the plugin repository.

← Hammer Labs Docs →