Your data

Privacy & data

Last updated 5 October 2026.

The short version

  • You can use HIBN without an account, and without giving your name or your email address.
  • When you run a check, we store the setup you chose, the AI’s reply exactly as you pasted it, and the score. We also store the country and city estimated from your connection, or the location you chose instead.
  • A result opens only in the browser that ran the check, while its key lasts, or in your account once the result is there. We publish totals and medians from Quick and Deep checks. We never publish a result or a reply.
  • A result that isn’t in an account can be opened until your browser’s key expires. The key lasts 90 days from the day it is made, and new checks don’t extend it. A daily clean-up then removes the reply, the detail of each question, the city and anything you typed for Other. We keep the score, the rest of the setup, the country and the dates.
  • You can delete any finished result you can still open, and any check you started and didn’t finish. You can download what is linked to your browser or your account.
  • HIBN runs on Cloudflare. Sign-in, if you choose it, is by Google.
  • For any question or request about your data, write to privacy@haveibeennerfed.ai.

Who we are

HIBN is run by BEMA Labs Pty Ltd, trading as Have I Been Nerfed?, based in New South Wales, Australia. On this page, “we” means that company.

HIBN is for people aged 18 and over.

What we collect, and why

When you start a check

  • The setup you choose: provider, app, model and level, and anything you type when you choose Other. If you say whether you used a new conversation and whether memory was on, we record that too. We show it on your result, use it to decide whether two checks can be compared, and group checks by it in Analytics.
  • Your location: the country and city that our host, Cloudflare, estimates from your connection. If you change the location or choose not to say, we store only your choice. We use the country to count Quick and Deep checks by country in Analytics. The city is stored with your result. It is shown on your result page and is never published.
  • A browser key: a random value kept in a cookie. A result that isn’t in an account opens only in a browser that holds the key. We make the key the first time you start a check or save a pack while signed out. We store a one-way hash of the key, not the key itself.
  • The time the check started.

The questions you copy go to your AI’s provider when you send them. They begin with a line that names haveibeennerfed.ai and, for a pack, the pack’s title. HIBN itself sends no part of a check to any AI provider.

When you get your result

  • The AI’s reply, exactly as you pasted it, and a fingerprint (SHA-256) of the text. We use the reply to score your check and to show it back to you.
  • What you tell us about missing answers: that the AI refused, or that it didn’t answer.
  • Your stopwatch time, if you used the stopwatch.
  • The result: the outcome and question score for each question, and the score. We also store the versions of the questions and the scoring code, and the time you finished the check.

While the reply is in the box, the page sends it to our server to look for the answer labels. We don’t keep that copy. We store the reply when you choose “Get my result”.

A reply can hold anything the AI wrote. If your app uses memory or custom instructions, that can include details about you. Read the reply before you paste it. If it holds personal details, don’t paste it. Turn off memory in your app if you can, and run a new check. After you get your result, you can’t edit the reply, but you can delete the result.

If you sign in with Google

We ask Google to confirm who you are and for the name on your Google profile. Google gives us an identifier for your account, and we store it. We show the name on your Account page while you’re signed in. We keep it only with that sign-in: signing out removes it at once, and otherwise it goes with the sign-in’s record. Google also sends your first and last names and a link to your profile picture, and we don’t keep them. We don’t ask Google for your email address.

We keep a record of each sign-in attempt and each signed-in session until a daily clean-up deletes it, normally within 3 days. A record holds the times, what the sign-in was for and whether it finished. A signed-in session’s record also holds the name on your Google profile until you sign out. For a save, it also holds the references of the result and of our record of your browser key. It holds the reference of the account, and one-off security codes.

If you publish a Custom Pack, we store the display name you choose and show it as the author. We store it with your account and with each pack you publish. Publishing again under a new name doesn’t change packs already published. The name stays with a pack after you make it private or delete it. It also stays in the “Based on” line of copies other people made. To have it removed, write to privacy@haveibeennerfed.ai. We then remove it from your account, from your packs and from the “Based on” line of copies, and your published packs become private.

A result you save to an account keeps a note of the browser key that ran it. That note links your account to our record of that key, and so to the other checks run with that key. The note stays in the deletion record if you delete the result.

Google learns that you signed in to HIBN. Google’s own privacy policy covers what Google does with that.

If you write a Custom Pack or send feedback

For a pack, we store the title, the description, the questions, the expected answers and the matching rules.

For feedback, we store the topic, your message, the time and the page you sent it from. If you give your name or email address, we store them with the message. We use the email address only to reply to that message. If you came from a result or a pack, we also store its reference. We also store a one-off code from your browser, so that a message sent twice is stored once.

We send a copy of each message, with the name and email address if you gave them, to our support email address, which is a company email inbox. Cloudflare sends the copy. We review messages there, and if you gave an email address we reply as soon as we can. We keep them in line with the company’s email retention policy. We don’t record which browser or account sent feedback. If the feedback carries a result’s reference, that reference leads to the result. If you put an email address in the message, we store it as part of the message.

On every visit

Cloudflare receives your network address (IP address) to deliver the site. We don’t store the address itself. To limit abuse, we use a secret key to turn it into a code that changes every day. For each hour, we count your requests of each kind against that code. Because we hold that key, the code could be matched to an address while the counts exist. A daily clean-up deletes the counts, normally within 26 hours.

Each page you open receives Cloudflare’s estimate of your country and city, so that the home page can show it. We store the estimate only when you start a check and leave the location as it is.

The logs our code writes hold the time, the kind of request and whether it worked. They hold no replies and no network addresses. Cloudflare keeps them for up to 7 days. Cloudflare keeps its own records as our host.

What we don’t collect

We don’t ask for your phone number or payment details. The feedback form asks for your name and email address, and both are optional. If you sign in with Google, we hold the name on your Google profile while you’re signed in. We hold a name if you choose one as a display name. We hold an email address if you give one with feedback, write one in a message or email us. A reply, a pack or a name you type can also contain personal details, if you or the AI put them there. We can’t see your AI account, your other chats or your app’s settings. We know only the setup you tell us.

How we learn from use

We count how many checks are started and finished, and how many browsers or accounts ran checks on 2 or more days. We count how often public packs are run by other people, and what feedback is about. These counts come from the records described above. A check you delete still counts as started, and as finished if it was, for up to 30 days after it was started.

We also use Cloudflare Web Analytics to count visits to our pages. A small script from Cloudflare runs on each page and reports the page’s address, the site that linked you to it, your browser, device type and country, and how quickly the page loaded. It sets no cookie and stores nothing on your device. We see only totals, not a record of what any one person did.

Who can see what

You. A result you ran while signed out opens only in the browser that ran it, and only while that browser’s key lasts. A result in an account opens only while you are signed in to that account, in any browser. Once you save a result to an account, the browser’s key no longer opens it. That is what “Private” means on a result and in My Results: no other visitor can open it. The address of a result page contains the result’s reference, and the reference alone does not open the result.

Everyone. Quick and Deep checks that have a score are counted in Analytics. Analytics shows the exact number of those checks. It lists each country that has at least 1 check, with the count as a range. For a setup with at least 20 checks, it shows the count as a range. It also shows the median score, unless the setup includes Unknown. Checks with Other anywhere in the setup are not listed by setup. Those 20 checks can come from a few people, or from 1. It never shows a single result, a reply or a city. Custom Pack checks are never counted in Analytics. A pack’s page shows how many finished checks have used it: “fewer than 10”, then the exact number. A check you delete, or one we leave out, is not counted.

Everyone, if you publish a pack. They see its title, description and questions, your display name, its version, and the date and time it last changed. They also see how often it has been run. The expected answers and the matching rules are shown to you and to no other visitor.

Our service providers. Cloudflare hosts HIBN and its database, counts page visits, and delivers feedback to our support inbox. Google handles sign-in, if you use it.

We may leave a check out of Analytics, for example if it looks automated or abusive. You keep your result.

How long we keep it

  • A result in your account (saved there, or started while signed in). It has no set end date. You can delete it at any time.
  • A result not saved to an account. You can open it until your browser’s key expires. The key is made the first time you start a check or save a pack while signed out. It lasts 90 days and is not renewed. A daily clean-up then removes the reply and its fingerprint, and the outcome of each question, normally within a day. It also removes what you told us about missing answers, the stopwatch time, the city, and anything you typed for Other. We keep the score and the count of fully correct questions, or the reason a check has no score. We also keep the rest of the setup, the dates, and which questions and scoring code were used. We keep the country, whether it was estimated or chosen by you. These have no set end date, and the record stays linked to our record of your browser key. A Quick or Deep check with a score still counts in Analytics, and a pack check still counts in the pack’s run count.
  • If you clear your cookies, the key is gone. You can then no longer open, download or delete those results. We still hold them in full until the 90 days end, and then remove the same parts. After a key has expired or been cleared, the next check you start, or pack you save, while signed out makes a new key. The new key lasts 90 days and doesn’t open the old results.
  • A check you started and didn’t finish. It holds no reply. We keep its setup, including anything you typed for Other, its location, its start time and its link to your browser key or your account. You can delete it from My Results while you can open it there. If you started it while signed out, a daily clean-up removes its city and anything you typed for Other once your browser’s key expires, normally within a day, as it does for a finished result. We keep the rest with no set end date. To have one deleted after that, write to privacy@haveibeennerfed.ai.
  • A result you delete. We erase it from the live database at once and keep a deletion record, with no set end date. See “Deleting a result” below.
  • Your account. We keep the identifier Google gave us, and your display name if you chose one, until you ask us to delete them. See “Ask us” below.
  • The name on your Google profile. Only while you’re signed in. Signing out removes it at once. Otherwise a daily clean-up deletes it with the sign-in’s record, normally within 3 days.
  • Your browser key. The cookie expires after 90 days. We keep our record of the key, which is an ID, a hash and 2 dates, with no set end date.
  • Custom Packs. A pack stays on HIBN until you delete it. After that, nobody can open its page or start a new check with it. A check that someone started before you deleted it still shows the questions and can still be finished. After you delete it, its title, its version number and your display name still show on results that used it. Its title and your display name stay in the “Based on” line of copies. Copies that other people made keep the questions they copied. If you make the pack private, other people can no longer open its page or start a new check with it. A check they had already started can still be finished. We keep every version of its title, description, questions and expected answers, with no set end date, whether or not a result used it. A pack made without an account can be opened only until that browser’s key expires. After that, it can’t be opened or deleted from the site, and we keep it with no set end date.
  • Feedback. A daily clean-up deletes it, with any name and email address you gave, once it is 365 days old, normally within a day of that. The copy in the company email inbox is kept in line with the company’s email retention policy.
  • Sign-in records. A daily clean-up deletes them, normally within 3 days.
  • Request counts. A daily clean-up deletes them, normally within 26 hours.
  • Moderation records. When we leave a check out of Analytics, hide a pack or mark feedback as handled, we make a record. It says what we did, when and who did it, and holds the reference of the check, pack or feedback. For a check or a pack, it also says why. We keep these records with no set end date, even if you later delete the result or the pack.
  • The database history kept by Cloudflare. Up to 30 days. See “Backups” below.

Deleting a result

When you delete a result, we erase its content from the live database at once. That covers the reply and its fingerprint, the scores and the detail of each question, and what you told us about missing answers. It also covers the stopwatch time, the setup and the location. The result stops counting in Analytics at once.

We keep a short deletion record, so that the result can’t come back or count in Analytics again. It holds the result’s reference, which question set and scoring code it used, and the browser or account it belonged to. For a result saved to an account, it also names the browser key that ran the check. It holds the times the check was started, finished and deleted, and the time the clean-up removed the reply, if it did. It also says whether we had left the check out of Analytics. Your data download shows the record, apart from 3 internal fields that it names.

Backups

Cloudflare keeps a history of the database for up to 30 days, so that HIBN can be recovered after a failure. Data you delete stays in that history for up to 30 days after you delete it.

If we ever restore an earlier copy, we close the site first. We copy every deletion record out of the current database, and then restore the earlier copy. Then we apply those deletions again and confirm them before the site reopens.

A restore has limits. If the current database can’t be read at all, we take the deletion records from the latest copy we can read. A result you deleted after that copy can’t be deleted again, so it would come back. A deletion we made because you asked us to is applied again even then: we keep our own list of those deletions, apart from the database. A restore applies again the deletion of results, what the daily clean-up removes when a key expires, and the deletions we made because you asked us to. It applies again nothing else that you removed or changed. A pack that you deleted or made private after the restored copy was taken would come back as it was. So would a check we left out of Analytics, or a pack we hid, in that time. Anything added after the restored copy was taken is lost, including new results, packs, accounts and feedback. A result you saved to an account in that time goes back to the browser that ran it. If that browser’s key has expired or its cookies were cleared, nobody can open the result, and the clean-up removes its reply. Everyone is signed out.

Replies removed when a browser key expires also stay in that history for up to 30 days. They are removed again before a restored copy reopens.

Cookies and browser storage

HIBN sets up to 3 cookies. Each is needed for the site to work.

CookieWhat it doesHow long it lasts
__Host-hibn_gHolds your browser key, so that this browser can open its results.90 days
__Host-hibn_sKeeps you signed in.Up to 12 hours
__Host-hibn_oCarries a Google sign-in from start to finish.10 minutes

Your browser also keeps your last setup on your own device, including anything you typed for Other. It stays until you clear your browser’s data. For a check in progress, your browser keeps the reply you have pasted and your stopwatch time. It keeps them until you get your result or close the tab. It also keeps a one-off code while a check is starting.

Our service providers

Cloudflare hosts HIBN, runs its database, estimates your location from your connection and counts visits to our pages. Cloudflare works in many countries, so your data may be stored or handled outside Australia.

Google handles sign-in, if you choose to sign in. That happens on Google’s own pages.

Your choices

  • Location. On the home page or a pack’s page, before you start a check, you can change the location or choose not to say. That choice covers that check only. Your result and Analytics then show your choice, and we store only your choice, not the estimate. “Check again (same setup)” uses the same choice as the check it repeats.
  • Delete a result. Open it and choose “Delete result”. To delete a check you didn’t finish, choose “Delete” beside it in My Results.
  • Download your data. Use “Download my data” in My Results. The file holds what is linked to your browser or your account, and a list at its end names what it leaves out. It is saved on your device and holds your replies. After your browser’s key expires, the download no longer includes that browser’s records.
  • Sign out at any time. Signing out ends your session in that browser.
  • Ask us. To have your account and every result in it, a check you didn’t finish, or your display name deleted, write to privacy@haveibeennerfed.ai. Include the “id” shown under “browser” or “account” in your data download, and for a check, the check’s “id” as well. Without these, we can’t tell which records are yours. We act on a request within 30 days. Download your data before your browser’s key expires: after that, the download no longer shows that id.

Terms · About