Privacy
Last updated 2026-09-17. Plain English, no lawyer-speak. Questions: hello@hackhopper.com.
What loads when you visit
The page itself, its fonts, and the site's own code come from hackhopper.com. Two other kinds of requests happen on every visit, signed in or not: Google Fonts (for the typefaces) and the hackathon cover-art hosts (Devpost, MLH, Luma CDNs) for the images on each card — both send your browser's IP address and user agent to those services, the same as any website using web fonts or hotlinked images. Neither is an ad, a tracker, or an analytics pixel: we don't run any of those, and no code we wrote sends your data anywhere for tracking purposes. The library that talks to our database (supabase-js) is a file we host ourselves (site/vendor/) — it is not fetched from a CDN at runtime, so signing in doesn't add a new third party to trust, only a new same-origin request to Supabase.
Browsing doesn't require an account
You can look at the whole list, search, filter, and open a hackathon's own site without ever signing in — none of that reaches our servers. Saving a hackathon, marking it registered/attending/attended, and logging a project all require an account (so your list can follow you to your other devices), and each of those actions prompts you to sign in the first time.
If you sign in
We store: your email address or GitHub id, your avatar URL, a handle we generate (or pull from GitHub), a private calendar-subscription link, and the hackathon list + project log you build up — hosted on Supabase (Postgres) in the US. Every request to Supabase happens only because you signed in; nothing is sent there before that. This browser also keeps a local copy of your list (hackhopper.v1) purely as a cache for fast loading and offline use — it's cleared automatically when you sign out or sign into a different account, and "Export my log" downloads it as a backup any time. Signing in only syncs your data across devices; it does not make anything public by itself.
What's public
Nothing, unless you turn on "Make my profile public" (phase 2, not live yet). When that ships, the exact list that becomes visible will be: your handle, display name, school, avatar, bio, hackathons you've attended or are going to, your non-draft projects (name, repo, demo, outcome — never your private notes), and accepted teammates. Today, in phase 1, there is no public profile at all — your saved list, drafts, tags, and notes are not exposed to anyone but you.
What we never do
We don't sell or share your data, run ads, or use analytics cookies or tracking pixels. There's no page-view tracking of any kind today — if that ever changes it'll be cookieless (e.g. Plausible) and it'll be its own decision, not bundled in quietly.
Delete everything, or take it with you
Delete: account menu → "Account settings" → Danger zone → "Delete account", type your handle (or DELETE) to confirm. This is immediate and irreversible — your profile, hackathon list, and projects are gone from our servers. Signing in again afterward starts a brand-new, empty account.
Export: "Export my log" downloads everything as a JSON file any time you're signed in.
Calendar link: your calendar-subscription link (Account settings → Your data) is private to you — "Reset link" invalidates the old one immediately if you ever shared it by mistake.
Age
HackHopper's audience is college students, but the site is public. You must be 13 or older to create an account (GitHub's and Supabase's terms require it). We don't collect a date of birth or run an age gate beyond asking — collecting less is the point.