Privacy, plainly explained
Privacy Policy
HISTI is designed so your check-in answers, optional recipient label, progress, and score stay in your browser. The current check-in does not upload that state to an HISTI application server.
Effective September 14, 2026
1. Scope
This policy explains the privacy practices of the HISTI website and check-in at histi.ocharlotted.com. It distinguishes information kept in your browser from ordinary technical information processed when a website is delivered over the internet.
2. Check-in data stays on your device
HISTI processes the check-in in your browser. The current app may store these items in localStorage so you can resume or review the check-in:
- recipient type and the optional private recipient label, if you enter one;
- selected answers, answer statuses, category-skip choices, and current question;
- accessibility/preferences used by the check-in; and
- the current result plus up to 12 locally saved result snapshots.
This check-in state is not submitted to an HISTI application server. It stays in the browser profile/device where you use HISTI unless you explicitly export or share it yourself.
3. No cookies
HISTI does not set or use cookies for the current website or check-in. HISTI does not use advertising cookies, analytics cookies, or tracking cookies.
HISTI does use localStorage for local progress and result history. localStorage is browser storage, but it is not a cookie. You can inspect or clear it using HISTI’s controls or your browser’s site-data tools.
4. The optional fill-in box
The check-in has one optional free-text field: a private label for the person or audience you have in mind. You can leave it blank or use a nickname. Do not enter a real name if you do not want that name stored locally in your browser.
The current app writes that optional label only into local browser storage. Its Content Security Policy blocks the page’s connection APIs, and the app has no endpoint that submits the label.
Server-retention policy for fill-in text: 0 minutes. If a current or future HISTI-controlled application handler ever receives content from a fill-in field, HISTI’s policy is to discard that field content immediately and not persist it in HISTI application storage. The current check-in does not send the field in the first place.
5. What ordinary website hosting can see
Loading any website requires ordinary network requests for files such as HTML, JavaScript, CSS, the logo, and the static question catalogue. HISTI is hosted on Vercel, so hosting infrastructure may process technical request information such as:
- IP address and approximate network information;
- browser/device and protocol information;
- requested URL/static file;
- request time, response status, and security/diagnostic information.
Those ordinary hosting requests are separate from the check-in state. HISTI does not place your answers, optional recipient label, progress, or score into those requests.
Vercel’s own handling of infrastructure information is described in the Vercel Privacy Notice.
6. No analytics, ads, or third-party runtime trackers
The current check-in does not load an analytics SDK, advertising tracker, remote font service, or third-party tracking script. It uses system fonts and same-origin static assets.
The production browser policy sets connect-src 'none' and form-action 'none', blocking the normal page APIs used for fetch/XHR/WebSocket/EventSource/sendBeacon connections and form submissions.
7. Exporting your data
You can use Export my data in the check-in footer. The export is created locally in your browser and can include the two HISTI local-storage records used for progress and saved results.
HISTI provides multiple methods so one browser feature is not required:
- Download JSON — saves a local file;
- Copy JSON — copies the export to your clipboard when browser permission allows it;
- View raw data — shows the export in a selectable read-only text area for manual copying.
If those controls cannot be used, you can inspect the same local storage through your browser’s developer/site-storage tools.
8. Deleting your local HISTI data
Use Reset inside HISTI to remove the HISTI progress and saved-result keys from the current browser profile. As an alternative method, clear site data for histi.ocharlotted.com using your browser settings.
Because HISTI does not receive the check-in state, HISTI cannot remotely retrieve or delete data that exists only in your browser.
9. Local retention
Local HISTI progress remains in the browser until you reset it, clear site data, or the browser/device removes it. Saved result history is limited by the app to the most recent 12 completed-result snapshots.
Local browser storage is not a secure vault. Anyone with access to your unlocked browser profile/device may be able to inspect it. On a shared device, consider exporting what you want to keep and then resetting HISTI.
10. Sharing a result
Sharing is optional. If you press Share, HISTI creates the result image/text locally and asks the browser or operating system to share it to a destination you choose. If native sharing is unavailable, HISTI may download the generated image locally instead.
Once you choose another app, service, or person as the destination, that destination’s privacy practices apply.
11. Age policy
The main HISTI check-in is not intended for users under age 13. HISTI does not ask for a date of birth and does not create an age profile. A separate children’s version is coming soon.
If you are under 13, please wait for the children’s version rather than using the main check-in.
12. Your choices and rights inside HISTI
- keep real private information to yourself;
- leave the optional private label blank;
- refuse any question;
- skip sensitive Categories C and D from their warning screens;
- go back, stop, review, export, or reset;
- keep your result private or share it only when you choose.
13. Alternative methods
HISTI is designed so privacy controls do not depend on one single UI path:
- Export: download, clipboard, raw-text view, or browser site-storage tools.
- Delete: HISTI Reset or browser “clear site data.”
- Review: use Review in the result screen or inspect the local export.
- Do not provide text: leave the optional recipient label blank.
- Do not answer sensitive questions: refuse individual questions or skip eligible sensitive sections.
14. Privacy and security verification
The check-in includes a privacy-proof panel that checks its visible CSP, same-origin runtime resources, HISTI local-storage keys, and whether any cookies are visible to the page. You can also inspect the public source in the HISTI repository.
No technical control can make a general-purpose browser or device perfectly secure. HISTI’s design reduces data transmission rather than promising absolute security.
15. Changes to this policy
This policy may change when HISTI’s features, hosting, privacy controls, or service providers change. The effective date at the top identifies the current version.
16. Contact
A dedicated HISTI contact email is being set up and will be published here once available.
Do not send check-in answers, optional private labels, passwords, codes, account details, or other sensitive information by email.