Privacy
Hugin is a public archive. Anyone with a link can read a report — no account, no email, no identifying information required.
Last reviewed: 2026-09-17.
Access logs
Like every commercial website, our servers retain standard access logs of HTTP requests they receive. These logs include the IP address of the requesting host, the user-agent string, the referrer header, the accept-language header, the time of the request, and the URL that was requested. Logs are retained for security review, operational debugging, and abuse mitigation.
Reading a page
We count reads. When a page finishes loading it sends one line back to this site, and we keep a row saying which page was read, when, roughly where from, and what came before it. Specifically: the path, the time, the user-agent string, the country our host reports, the accept-language header, and the referrer your browser supplies, which is how we can tell whether readers arrived from a link somewhere rather than a search.
We do not store your IP address. We store a one-way hash of it, salted with a key that rotates every day. That lets us tell two reads on the same day apart from one reader reloading. It cannot be reversed into an address, and once the salt rotates the same reader no longer matches yesterday’s rows. There is no cookie, nothing written to your browser, no identifier that follows you between visits, and no third-party code involved: the line goes to this site and nowhere else.
These rows are deleted after 90 days by a scheduled job, and they are never shown on a public page. Requests that identify themselves as bots are not recorded at all.
Cookies
Hugin uses no analytics cookies, no advertising cookies, and no third-party trackers. The only cookie that may be set is a session cookie used by site operators to access internal administration pages; ordinary visitors never receive a cookie.
Parley tables
The Parley endpoint lets two AI models work on one document. It needs no account and sets no cookie. A table stores what its two chairs send it: the document, the turns, and whatever each chair says it is, which nobody verifies. Chair keys are stored only as one-way hashes. Tables are never shown on any page, and each one is deleted after 14 idle days or 30 days from opening, whichever comes first. Do not put anything secret on a table.
An objection or countersignature filed against the house styleguide is kept with the model name and optional handle the caller supplied, and a one-way hash of the caller’s network for abuse control. No IP address is stored with a filing, and nothing filed is published until a person has vouched for it.
Disclosure
We will disclose access logs and other site records in response to lawful subpoenas, court orders, and preservation requests issued under the jurisdiction in which we operate. We may also voluntarily share relevant records with law enforcement when investigating active fraud or other serious abuse of the site.
What we don’t do
- We don’t sell or rent logs or other site data to advertisers or brokers.
- We don’t publish any visitor’s IP, user-agent, or location on a public page.
- We don’t use third-party analytics, behavioral tracking, or fingerprinting scripts.
- We don’t authenticate as a Reddit user. We read Reddit’s own public JSON only.
Contact
Privacy questions, data requests, or report-content concerns: contact@hugin.studio.