1. Introduction
HiveBase, Inc. ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the HiveBase platform and its integrations with workplace applications including Slack, Zoom, Google Calendar, Gmail, Google Search Console, GitHub, Linear, Asana, ClickUp, Notion, Coda, HubSpot, Attio, Ramp, and others.
By using HiveBase, you agree to the data practices described in this policy. Please read it carefully.
2. Information We Collect
2.1 Information You Provide
- Account registration data (name, work email address, company name, role)
- Workspace configuration and preferences
- Integration credentials and OAuth access tokens
- Payment information (processed by Stripe — we do not store card numbers)
- Support and feedback communications
2.2 Data Accessed Through Integrations
When you authorize an integration, we access data from that platform to the extent necessary to provide the features you use:
- Email content and metadata (Gmail)
- Calendar events and attendee information (Google Calendar)
- Search queries, pages, clicks, impressions, and site-property metadata (Google Search Console)
- Meeting recordings and transcripts (Zoom)
- Messages and channel activity (Slack)
- Repository activity, pull requests, issues, and commit metadata (GitHub)
- Task and project data (Linear, Asana, ClickUp, Jira)
- CRM records (HubSpot, Attio)
- Financial transaction metadata (Ramp)
- Document content (Notion, Coda)
Extract and expire: For most integration content (emails, messages, meeting transcripts), we process the raw content to extract structured intelligence (facts, signals, entities, tasks) and then expire the underlying raw content. Your workspace Brain retains extracted intelligence — not raw third-party content — reducing your long-term data footprint.
2.3 Usage and Behavioral Data
- Feature usage patterns and interaction frequencies
- AI decision feedback signals (e.g., whether you acted on a triage recommendation, reprioritized an AI-scored task, or corrected a signal) — used as described in Section 4
- Session and device information (browser type, IP address, timestamps)
- Error logs and performance data
3. How We Use Your Information
3.1 Service Delivery
- Processing signals, generating tasks, and extracting insights within your workspace
- Running AI agents and orchestrating workflows on your behalf
- Generating meeting notes, email drafts, project plans, and other AI outputs
- Synchronizing data across your connected integrations
- Personalizing your experience based on your workspace's accumulated Brain
3.2 Platform Improvement (anonymized aggregates)
We use anonymized, aggregated operational patterns to improve platform defaults, calibrate AI scoring models, and generate industry benchmarks. This never includes your Customer Content or identifying information. See Section 4 for details and opt-out options.
3.3 Communications
- Service notifications and updates
- Product announcements (with opt-out available)
- Responses to support requests
4. Data Tiers — Your Controls
We operate a three-tier data framework that gives you clear controls over how your data is used beyond service delivery:
Tier 0 — Service Delivery
What: Your data is used to operate the Service for you.
Control: Required for Service use.
Cross-customer protection: Your data never leaves your workspace boundary for the benefit of other customers.
Tier 1 — Platform Analytics (Opt-out available)
What: Anonymized, aggregated operational patterns. No Customer Content. No identifying information.
Purpose: Improve platform defaults, calibrate AI models, generate anonymized industry benchmarks.
Control: Opt out at any time in workspace settings → Privacy.
Tier 2 — AI Improvement Program (Explicit opt-in only)
What: Anonymized AI decision feedback signals (triage accept/reject, task reprioritization, signal corrections). Not the content of emails or messages.
Incentive: Work Unit credit discount for participating workspaces.
Control: Explicit opt-in required. Withdraw at any time; previously contributed data excluded from future training runs upon request.
5. Google API Services — Limited Use Disclosure
HiveBase's use of information received from Google APIs (including Gmail and Google Calendar APIs) is subject to the Google API Services User Data Policy, including the Limited Use requirements. We adhere to the following restrictions:
- Use is limited to providing or improving user-facing features — Google user data is used only to deliver features you have authorized and not for any unrelated purpose
- No advertising use — Google user data is not used to serve advertisements or develop advertising profiles
- No data sale or brokering — Google user data is never sold or transferred to data brokers
- No AI training on Google data — Google user data is not used to develop, improve, or train generalized AI or ML models (including Tier 2)
- Restricted third-party transfer — Google user data is shared with third parties only as necessary to provide the Service, with your consent, or as required by law
- Human access restrictions — We do not permit humans to read your Gmail content except for security investigations, legal compliance, or at your explicit request
6. Data Sharing and Disclosure
We do not sell your personal information. We may share your information with:
- AI model providers (OpenAI, Anthropic, Google, and others) — to process your requests. These providers do not use your data to train their general models.
- Infrastructure and service providers — cloud hosting, analytics (PostHog), error monitoring (Sentry), and payment processing (Stripe)
- Third-party integrations you authorize — data flows back to platforms you explicitly connect
- Legal authorities — when required by law or court order
- Business transfers — in the event of a merger or acquisition, with notice to users
7. Data Security
We implement appropriate technical and organizational measures to protect your information, including:
- Encryption of data in transit (TLS) and at rest (AES-256)
- Row-level security and access controls enforced at the database layer
- OAuth token storage with scoped permissions and revocation capability
- Regular security assessments and dependency audits
- Workspace isolation — each organization's data is logically separated
8. Data Retention
We retain your data as follows:
- Active workspace data — retained throughout your subscription
- Raw integration content — processed and expired per the extract-and-expire pattern; not retained beyond the processing window
- Extracted Brain intelligence — retained while your workspace is active, or until you delete it
- Account data after termination — retained for 30 days for export, then deleted
- Tier 1 aggregates — retained indefinitely in anonymized form
- Tier 2 training data — excluded from future training runs within 30 days of opt-out request
9. Your Rights
Depending on your jurisdiction, you may have the right to access, correct, delete, or port your personal information, object to or restrict certain processing, and withdraw consent at any time. GDPR (EEA/UK) and CCPA (California) residents have additional rights under applicable law.
To exercise any rights, contact us at team@hivebase.ai. We will respond within 30 days.
10. Changes to This Policy
We may update this Privacy Policy from time to time. For material changes, we will notify you via email or in-product notification at least 30 days before the change takes effect. Continued use of the Service after the notice period constitutes acceptance.
11. Contact Us
For privacy questions, requests, or concerns:
team@hivebase.ai
HiveBase, Inc.