Privacy
What huggingbay.xyz collects (first-party privacy-preserving analytics, request contact emails with 30-day retention), how long it is kept, and where the machine-readable data policy lives.
What this site collects
huggingbay.xyz uses first-party, privacy-preserving traffic measurement only. There are no third-party trackers or analytics scripts, and no data is sold or shared with advertisers. Public rollups expose no raw IP addresses, visitor keys, user agents, or referrers. When authenticated trusted Cloudflare ingress supplies a valid country code, Hugging Bay stores only that coarse two-letter country code inside the existing access, page, or download event record for aggregate regional measurement; missing, invalid, or untrusted values are ignored. No city, coordinate, locale, referrer, or new IP data is recorded for this purpose, and country codes are not exposed in public rollups. The field follows the retention of the event row it accompanies; structured access rows are pruned after 30 days, and no separate country history is created. The live measurement statement is published in the privacy block of /api/traffic.
The visitor cookie
To count returning readers rather than repeat visits, this site sets one first-party cookie named hb_visitor. It holds a random opaque token — not your IP address, name, or email — and it is stored only after being hashed, so page and action event records never contain the raw cookie value. The cookie is HttpOnly and SameSite=Lax, is sent only to huggingbay.xyz, is never readable by JavaScript or any third party, and carries no advertising or cross-site identifier.
It lasts up to 13 months (390 days) from the last visit. It is used for aggregate product measurement only — how many distinct people use a feature, and whether they come back. It is never used to authenticate you or to make an access decision.
The same hashed analytics visitor key may also be combined with an experiment ID in a deterministic server-side hash to choose a product variant before the page renders. This creates no additional cookie or identifier. Exposure and named goal actions use the existing first-party product event stream. A reload may write another raw exposure event; experiment reports deliberately count only the visitor's earliest exposure for that experiment.
Two separate identities are in play, and they are deliberately not the same thing. The long-lived cookie above is the analytics identity. Rate limits, review interactions, and other abuse controls continue to use a short-lived key derived from a daily salted hash of coarse request attributes, which rotates every day and is never stored in the cookie.
To opt out, send DNT: 1, Sec-GPC: 1, or X-Hugging-Bay-No-Record: 1; read-only audits may instead add audit=1 or telemetry=off to the URL. Hugging Bay records no page, action, download, transfer, conversion, or access telemetry for those requests and acknowledges the choice with X-Hugging-Bay-No-Record: honored. DNT and GPC also prevent the hb_visitor analytics cookie and expire any existing one. A separate daily rotating key may still be used for necessary rate limits and abuse controls; it is not used as fallback measurement.
Contact data and retention
If you submit a catalog, mirror, or source request with a contact email, the private contact field is retained for 30 days and then redacted; the public request, status, dedupe, refusal, and moderation evidence remains without it. Account sign-in uses email magic links: your email address is used to send the sign-in link and operate your account, and is not exposed on public surfaces.
Machine-readable policies
Task execution data handling is governed by Bay Run's published data policy. Agents and auditors should read the machine-readable documents directly: data-policy.json, assurance.json, and security.txt.
Contact
Privacy questions, data-rights requests, and security reports: security@huggingbay.xyz.
Open interactive page