What The Hackathon Playbook collects, why, and where it goes. Plain English, no surprises.
Last updated: September 14, 2026
The Hackathon Playbook (the website at thehackathonplaybook.dev, the "Site") is run by Bill Zhang ("we", "us", or "our"). This policy explains what the Site collects, why, which services receive it, and what choices you have.
The short version:
This policy works alongside our Terms of Service. For any question or request about your data, email billzhangsc@gmail.com.
We use two analytics tools to learn how the Site is used, so we can fix what is confusing and write more of what is useful.
Vercel Web Analytics counts page views, so we can see which pages are popular.
PostHog records how people use the Site. It captures:
PostHog gives your browser a random ID so it can tell repeat visits apart. We never give PostHog your name or email address, and we do not build a profile of who you are. PostHog also receives your IP address as part of each request, as any web service does.
PostHog also records session replays, which are playbacks of how a page was scrolled and clicked, including the text shown on the page and the page's technical console messages. They help us find the spots where readers get stuck. Anything you type into a form field is masked in replays, and the AI chat window is left out of them entirely.
The Site has an AI assistant ("Ask the Playbook") and, on the cheat sheet, an AI prompt finder. Here is what happens when you use them.
What you send: for the chat, the recent conversation (up to the last 10 messages). For the prompt finder, the one sentence you type. If you open the chat from a page's Ask the Playbook option, it also sends that page's address so the answer can focus on it.
OpenAI writes the answers. It receives your messages, the parts of the Site that match your question, and our instructions to the model. We send these requests with OpenAI's response storage turned off. To find the matching parts of the Site, your last few chat questions may also be sent to OpenAI's embeddings service. OpenAI's own API data policies apply to everything it receives.
We keep a record of each request in FireTrace, the tracing service we use to review AI answers. A record holds your messages, the answer, which pages of the Site were used as sources, the model, token counts, estimated cost, timings, and whether the request succeeded. For the chat, it also holds the page you opened it from (if any) and a random conversation ID. It does not include your IP address, and it is not linked to your name, email, or any account.
We use these records to find weak answers, fill gaps in the content, and improve the assistant.
The conversation ID is created in your browser tab and groups the turns of one conversation together. It is not tied to your name, email, or any account. Closing the tab or clicking Clear conversation discards it, and your next conversation gets a new one.
If you rate an answer with the thumbs up or thumbs down button, we add that rating to the answer's record in FireTrace.
Your conversation is also saved in your browser tab so it survives moving between pages. It is deleted when you close the tab or click Clear conversation.
Because conversations are stored, please do not paste passwords, API keys, personal information, or anything confidential into the chat.
AI tools can search the Site through our public MCP server (a standard way for AI agents to use outside tools). If your browser has built-in agent support, the Site offers it some of the same tools. When an agent searches, the search text may be sent to OpenAI's embeddings service to find matching sections.
We do not store those searches, and they are not sent to FireTrace. Agents that use the chat directly are handled the same way as the AI chat above.
To keep the AI features and the MCP server from being abused, we count requests from each IP address over a rolling 10-minute window. The chat, answer ratings, the prompt finder, and the MCP server each have their own limit.
Those counts are stored in Upstash, a hosted Redis database, under a key that contains your IP address. Each key deletes itself 10 minutes after your last counted request. If Upstash cannot be reached, the count is kept in our server's memory instead, which is cleared when the server restarts.
Upstash also holds running totals of AI tokens used across the whole Site each day and each month. Those totals contain no personal data.
The newsletter form keeps its own anti-spam counts, described in the Newsletter section above.
The Site is hosted on Vercel. Like any web host, Vercel receives your IP address, your browser details, and the address of each page you request, because that is how pages get delivered. Vercel keeps its own logs to run and secure its platform.
Our own server code adds only operational messages to those logs, such as token counts for AI requests and error details when something fails. It does not log your chat messages.
These services receive data from the Site. Each one has its own privacy policy.
Links to other sites, including affiliate links, take you to services with their own privacy policies.
Anything else is kept only as long as needed to run the Site, and deleted on request.
We do not currently respond to Do Not Track or Global Privacy Control browser signals.
The Site is not directed at children under 13, and we do not knowingly collect personal information from them. If you think a child under 13 has given us personal information, for example by subscribing to the newsletter, email us and we will delete it.
We may update this policy as the Site changes. When we do, we will revise the "Last updated" date at the top of this page. For significant changes, we may also post a notice on the Site.
For questions or requests about this policy or your data, email billzhangsc@gmail.com.