1. Introduction
HiveBase, Inc. ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the HiveBase platform and its integrations with workplace applications including Slack, Zoom, Google Calendar, Gmail, GitHub, Linear, Asana, ClickUp, Notion, Coda, HubSpot, Attio, Ramp, and others.
By using HiveBase, you agree to the data practices described in this policy. Please read it carefully.
2. Information We Collect
2.1 Information You Provide
- Account registration data (name, work email address, company name, role)
- Workspace configuration and preferences
- Integration credentials and OAuth access tokens
- Payment information (processed by Stripe — we do not store card numbers)
- Support and feedback communications
2.2 Data Accessed Through Integrations
When you authorize an integration, we access data from that platform to the extent necessary to provide the features you use:
- Email content and metadata (Gmail)
- Calendar events and attendee information (Google Calendar)
- Meeting recordings and transcripts (Zoom)
- Messages and channel activity (Slack)
- Repository activity, pull requests, issues, and commit metadata (GitHub)
- Task and project data (Linear, Asana, ClickUp, Jira)
- CRM records (HubSpot, Attio)
- Financial transaction metadata (Ramp)
- Document content (Notion, Coda)
Extract and expire: For most integration content (emails, messages, meeting transcripts), we process the raw content to extract structured intelligence (facts, signals, entities, tasks) and then expire the underlying raw content. Your workspace Brain retains extracted intelligence — not raw third-party content — reducing your long-term data footprint.
2.3 Usage and Behavioral Data
- Feature usage patterns and interaction frequencies
- AI decision feedback signals (e.g., whether you acted on a triage recommendation, reprioritized an AI-scored task, or corrected a signal) — used as described in Section 4
- Session and device information (browser type, IP address, timestamps)
- Error logs and performance data
3. How We Use Your Information
3.1 Service Delivery
- Processing signals, generating tasks, and extracting insights within your workspace
- Running AI agents and orchestrating workflows on your behalf
- Generating meeting notes, email drafts, project plans, and other AI outputs
- Synchronizing data across your connected integrations
- Personalizing your experience based on your workspace's accumulated Brain
3.2 Platform Improvement (anonymized aggregates)
We use anonymized, aggregated operational patterns to improve platform defaults, calibrate AI scoring models, and generate industry benchmarks. This never includes your Customer Content or identifying information. See Section 4 for details and opt-out options.
3.3 Communications
- Service notifications and updates
- Product announcements (with opt-out available)
- Responses to support requests
4. Data Tiers — Your Controls
We operate a three-tier data framework that gives you clear controls over how your data is used beyond service delivery:
Tier 0 — Service Delivery
What: Your data is used to operate the Service for you.
Control: Required for Service use. Cannot be opted out of while an active subscriber.
Cross-customer protection: Your data never leaves your workspace boundary for the benefit of other customers.
Tier 1 — Platform Analytics (Opt-out available)
What: Anonymized, aggregated operational patterns (e.g., "median signal-to-action conversion rate for Series A SaaS companies is X%"). No Customer Content. No identifying information.
Purpose: Improve platform defaults, calibrate AI models, generate anonymized industry benchmarks.
Control: Opt out at any time in workspace settings → Privacy.
Tier 2 — AI Improvement Program (Explicit opt-in only)
What: Anonymized AI decision feedback signals (e.g., triage accept/reject, task reprioritization, signal corrections). Not the content of emails or messages — only the decision outcome.
Purpose: Improve AI classifiers and routing models shared across the platform.
Incentive: Work Unit credit discount for participating workspaces.
Control: Explicit opt-in required in workspace settings → AI Improvement Program. Withdraw at any time; previously contributed data excluded from future training runs upon request.
5. Google API Services — Limited Use Disclosure
HiveBase's use of information received from Google APIs (including Gmail and Google Calendar APIs) is subject to the Google API Services User Data Policy, including the Limited Use requirements. We adhere to the following restrictions:
- Use is limited to providing or improving user-facing features — Google user data is used only to deliver features you have authorized (email triage, task generation, calendar context) and not for any unrelated purpose
- No advertising use — Google user data is not used to serve advertisements or develop advertising profiles
- No data sale or brokering — Google user data is never sold or transferred to data brokers
- No AI training on Google data — Google user data is not used to develop, improve, or train generalized AI or ML models (including Tier 2 AI Improvement Program)
- Restricted third-party transfer — Google user data is shared with third parties only as necessary to provide the Service (e.g., AI inference providers), with your consent, or as required by law
- Human access restrictions — We do not permit humans to read your Gmail content except: (a) for security investigations, (b) to comply with applicable law, or (c) at your explicit written request for support purposes
6. Data Sharing and Disclosure
We do not sell your personal information. We may share your information with:
- AI model providers (OpenAI, Anthropic, Google, and others) — to process your requests and generate outputs. These providers are contractually bound to data protection standards and do not use your data to train their general models.
- Infrastructure and service providers — cloud hosting (Supabase, Vercel, Railway), analytics (PostHog), error monitoring (Sentry), and payment processing (Stripe)
- Third-party integrations you authorize — data flows back to platforms you explicitly connect
- Legal authorities — when required by law, court order, or to protect our legal rights
- Business transfers — in the event of a merger, acquisition, or sale of assets, with notice to users and continued protection under this policy or a materially equivalent one
7. Data Security
We implement appropriate technical and organizational measures to protect your information, including:
- Encryption of data in transit (TLS) and at rest (AES-256)
- Row-level security and access controls enforced at the database layer
- OAuth token storage with scoped permissions and revocation capability
- Regular security assessments and dependency audits
- Workspace isolation — each organization's data is logically separated
No system is perfectly secure. In the event of a data breach that affects your personal information, we will notify you as required by applicable law.
8. Data Retention
We retain your personal information and workspace data for as long as your account is active or as needed to provide services. Specifically:
- Active workspace data — retained throughout your subscription
- Raw integration content — processed and expired per the extract-and-expire pattern; typically not retained beyond the processing window
- Extracted Brain intelligence — retained as long as your workspace is active, or until you delete it
- Account data after termination — retained for 30 days to allow data export, then deleted
- Tier 1 aggregates — retained indefinitely in anonymized form
- Tier 2 training data — excluded from future training runs within 30 days of opt-out request
You may request deletion of your workspace data at any time by contacting team@hivebase.ai.
9. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access — request a copy of personal information we hold about you
- Correction — correct inaccurate or incomplete data
- Deletion — request deletion of your personal information and workspace data
- Portability — receive your data in a structured, machine-readable format
- Objection / restriction — object to or restrict certain processing activities
- Withdraw consent — opt out of Tier 1 analytics or withdraw from the Tier 2 AI Improvement Program at any time
GDPR (EEA/UK) and CCPA (California) residents: You have additional rights under applicable law. To exercise any rights, contact us at team@hivebase.ai. We will respond within 30 days.
10. Children's Privacy
The Service is not directed to individuals under 18. We do not knowingly collect personal information from minors. If you believe a minor has provided us with personal information, please contact us and we will promptly delete it.
11. International Data Transfers
HiveBase is based in the United States. If you access the Service from outside the US, your information may be transferred to, stored, and processed in the US. For users in the EEA or UK, we rely on Standard Contractual Clauses (SCCs) as the legal mechanism for cross-border transfers where applicable.
12. Changes to This Policy
We may update this Privacy Policy from time to time. For material changes, we will notify you via email or in-product notification at least 30 days before the change takes effect. The "Last Updated" date at the top of this page reflects the most recent revision. Continued use of the Service after the notice period constitutes acceptance.
13. Contact Us
For privacy questions, requests, or concerns, contact us at:
team@hivebase.ai
HiveBase, Inc.
For GDPR-related inquiries, please include "GDPR Request" in the subject line.