Privacy policy
Last updated: 6 September 2026. ManyFails is operated by Phil in the United Kingdom.
Operating the site
We process requests to serve pages, prevent abuse and investigate errors. Application logs contain a request ID, method, URL path, time and, for API handlers, response status and duration. They exclude request bodies, query strings, cookies and authorization headers. Our hosting proxy also processes your IP address. Rate limiting keeps hashed IP addresses and, when keys are available, hashed API keys in temporary server memory for the configured request window.
Analytics
Nothing you type into Idea Check is stored by ManyFails: no idea text in our database, logs, URLs or analytics events. Text is sent to the configured embedding and Claude providers to process the check. We keep an IP hash for anonymous checks or a hash of the API-key identifier for authenticated REST and MCP checks, plus the UTC date and daily count. Anonymous callers share three checks per IP; API keys use their plan’s allowance. Expired counters are removed on the next check. Idea Check events contain only the matched cluster, similarity, warning-sign count and channel. Click and export events identify public entries, never your idea. Citation downloads contain public citations only.
Analytics is not enabled in this version. When introduced, we plan to use PostHog EU, hosted in the European Union, through our own /ingest path. The planned events are page views and navigation, card views and share clicks, archive filters, pattern views, searches (query length and result count, not query text), Idea Check use and result clicks, newsletter and submission completion, MCP tool use, citation exports and internal publishing actions. Event properties describe pages, categories, counts and performance, not the text of your ideas or submissions.
The planned setup is anonymous and cookieless, with no session recordings or advertising profiles. This policy will be updated before analytics, accounts or public forms go live, including any choices required for those features.
Retention and access
Our operating retention schedule is 30 days for request and proxy logs and encrypted backups, 12 months for security and editorial audit records, and 12 months for planned analytics events. Model spending records contain provider totals, tokens and cost, without prompts or user identifiers. Public sources and correction history remain available while relevant to the archive. Records needed to resolve a dispute may be retained until that dispute is resolved.
Access to operational records is restricted to the operator and service providers needed to run the site. Resend delivers operational alert emails containing error counts or spending totals. We do not sell personal information.
Privacy and corrections
For privacy requests, contact phil.bird@gmail.com. You can request access, correction or deletion of personal information we hold. For a factual correction or takedown, identify the entry and disputed claim and provide supporting evidence. We aim to review these complaints within 48 hours, temporarily unpublish or correct credible disputed material while checking it, and record corrections in the public changelog.