HINDSIGHTBack to explorer
Effective August 23, 2026

Privacy, terms, and funding policy

Hindsight is a public-record research explorer. Public browsing requires no account. These terms explain the optional identity and payment features and distinguish source data, deterministic calculations, and AI-assisted synthesis.

Public sources and AI

Government, company, political-figure, and drug records come from the public agencies linked beside each record. Hindsight does not use AI to invent source observations: government and company outcome scores are calculated in code from the published agency values. Gemini performs disclosed, build-time editorial synthesis and three-pass evidence review against each approved source ledger; the evidence-consensus score is then calculated in code from those structured AI judgments. Human-review status is shown on every seeded brief, and no human review is implied when the record says it is not recorded.

Information we process

Public browsing creates ordinary request logs handled by Cloudflare. If you sign in to sponsor research, Google provides your account identifier, name, and email. Hindsight stores the research topic, optional question and claims, payment status, and Stripe transaction identifiers. Card details are entered on Stripe and never pass through Hindsight.

When you open a drug record, Hindsight sends the generic name to openFDA through its Cloudflare Worker and temporarily caches the public response. The FDA receives Hindsight's request rather than a browser-direct request containing your IP address. Following a raw-source or DailyMed link leaves Hindsight and is governed by that provider's policies.

Coverage and freshness

Hindsight is a curated public beta, not a comprehensive catalog or a live causal model. The manifest records each source's retrieval time, weekly refresh cadence, and stale deadline. Government and company outcomes describe observations during a term or reporting period; they do not prove that an official or company caused the result.

Purpose, retention, and deletion

Identity connects a funded request to its supporter, receipt, and research queue. Request content and direct identifiers are retained while the request is active and ordinarily for no more than 24 months. A daily retention job pseudonymizes older content. Limited payment identifiers and status may remain where reasonably needed for accounting, fraud prevention, disputes, or legal obligations.

Signed-in supporters can use “Delete my data” in the funding panel to pseudonymize their stored Hindsight request content immediately. This does not delete records independently retained by Google, Stripe, Cloudflare, or public-source providers.

Funding terms and refunds

A $1 sponsorship supports independent research into the submitted topic. It does not buy publication, priority, a deadline, or a predetermined conclusion. Submitted claims are leads rather than accepted facts. Stripe handles payment and sends the definitive payment receipt.

If a duplicate or mistaken payment occurs, contact support within 14 days. Refunds are available before a request is marked fulfilled; later requests are reviewed based on work already completed and applicable law. A failed or cancelled Checkout is not charged.

Security and service limits

Hindsight uses secure HTTP-only session cookies, signed Stripe webhooks, request throttling, and least-privilege Cloudflare bindings. No system is perfectly secure. The service and its public-record summaries are provided for research and informational purposes, not medical, legal, investment, or voting advice.

Contact

For privacy, deletion, support, or refund questions, email danielfugere28@gmail.com. Include the Stripe receipt identifier when asking about a payment; never send card details.