Legal

Privacy Policy

Last updated: July 9, 2026

This Privacy Policy explains how Hyve Applied Intelligence LLC ("HyveAI," "we," "us") collects, uses, shares, and protects personal information when you visit hyveappliedintelligence.com, use our client portal at app.hyveappliedintelligence.com, interact with a HyveAI-powered chat widget, or otherwise use the HyveAI platform (collectively, the "Service").

Two roles. For data about our customers and visitors to our marketing site, HyveAI acts as a data controller. For data that our customers submit into the Service about their own end users (documents, chat transcripts, feedback), HyveAI acts as a data processor on the customer's behalf — that relationship is governed by our Data Processing Addendum.

1. Information We Collect

1.1 Information you provide

  • Account information: name, email address, password hash, organization name, role, phone, timezone.
  • Billing information: handled by our payment processor (Stripe) — we store a customer ID and subscription metadata; we do not store full card numbers on our servers.
  • Content you upload: documents, URLs, and metadata ingested into your knowledge base.
  • Support communications: messages you send us via email or in-product forms.

1.2 Information collected automatically

  • Usage data: pages visited, actions taken, session duration, approximate location derived from IP.
  • Device data: browser type and version, operating system, screen size, referring URL.
  • Log data: IP address, timestamps, request metadata, error traces (scrubbed of sensitive fields such as auth headers).
  • Cookies & local storage: authentication tokens, session state, and preferences. See Cookies below.

1.3 End-user chat data

When a visitor uses a HyveAI chat widget embedded on a customer site, HyveAI processes the question, generated response, similarity scores, and basic session metadata on behalf of the customer that operates that widget. We do not directly collect names, email addresses, or identifiers from widget users unless the customer explicitly enables a lead-capture form, in which case the submitted details are routed to the operating customer.

2. How We Use Information

  • To provide, operate, secure, and support the Service, including authenticating accounts, applying rate limits, and preventing abuse.
  • To process payments and manage subscriptions via our payment processor.
  • To communicate about Service availability, billing, security, and policy updates.
  • To send product updates and marketing, only where you have opted in or where permitted by law. You can unsubscribe at any time.
  • To comply with legal obligations and enforce our agreements.

We describe our AI-specific data-use commitments using the following categories:

  • Customer Data (the documents, prompts, and conversations Customer or its end users submit) is used only to provide, secure, support, and troubleshoot that Customer's own instance of the Service.
  • Usage Metrics (aggregated technical metrics such as response latency, error rates, and request volume) may be used to operate, monitor, and improve the Service generally, including for reliability, abuse prevention, and billing.
  • De-Identified / Aggregated Data may be used for analytics or product improvement only where it cannot reasonably be used to identify Customer, an end user, or the content of any specific document or conversation.
  • Model Training: we do not use Customer Data to train or fine-tune any AI model — for our own use or for any third party — unless Customer gives explicit written opt-in for a specific, described training use.

We do not sell or share personal information, as those terms are defined under the CCPA.

3. Legal Bases (EEA/UK)

If you are in the European Economic Area, the United Kingdom, or Switzerland, we process personal data on the following legal bases:

  • Performance of a contract — to deliver the Service you requested.
  • Legitimate interests — to operate, secure, and improve the Service, provided those interests are not overridden by your rights.
  • Consent — for optional cookies and marketing.
  • Legal obligation — to comply with tax, accounting, and other laws.

4. Subprocessors & Third-Party Services

We engage trusted third parties to host and operate the Service. Each is bound by contractual confidentiality and security obligations. We describe them below by category and purpose rather than naming each vendor on this page, so this section stays accurate as vendors change; the current, named list is maintained in our Data Processing Addendum, Annex I, which we are contractually obligated to keep accurate and to update with advance notice. We separate subprocessors that are required to operate the Service for every customer from those engaged only when a customer enables the related optional feature.

Required subprocessors

Category Purpose Region
AI model provider LLM inference and text embeddings United States
Vector database provider Vector database for retrieval-augmented generation United States
Payment processor Payment processing and subscription billing United States
Application monitoring provider Application error and performance monitoring United States
Dedicated-server hosting provider Compute, storage, reverse proxy, and encrypted backups for the core platform Europe
Email delivery provider Transactional and alert email delivery United States / Europe

Optional subprocessors (engaged only if you enable the related feature)

Category Purpose Region
Small-language-model fine-tuning provider Optional small-language-model fine-tuning and hosting United States
Team messaging / alerting provider Operational alerts and customer integrations, where enabled United States
SMS delivery provider SMS delivery, for customers using the SMS channel United States

This list does not include the social media platforms you may connect as a Connected Account — those are addressed separately in Section 13 (Connected Social Accounts), since you connect and control those accounts directly. We will provide advance notice (generally at least 14 days) before engaging a new subprocessor that materially changes how we process personal data, consistent with the notice provisions of our Data Processing Addendum, which maintains the current subprocessor list in its Annex I.

5. International Transfers

HyveAI operates infrastructure in Europe and processes data through US-based subprocessors. Where personal data is transferred outside your region, we rely on appropriate safeguards such as the Standard Contractual Clauses published by the European Commission.

6. Data Retention

  • Account data: retained while the account is active and for a reasonable period afterwards for legitimate business purposes (legal obligations, dispute resolution, security).
  • Customer Data (documents, chat logs): retained according to the customer's configuration. Customer Data is deleted from active production systems within 30 days after account termination.
  • Logs and security telemetry: retained for up to 30 days by default.
  • Backups: encrypted database backups containing Customer Data are isolated from ordinary use and are overwritten in the ordinary course of HyveAI's backup rotation (a 7-day / 4-week / 3-month rolling schedule), unless retention is required by law or needed for security, fraud-prevention, or dispute-resolution purposes.

7. Security

We implement administrative, technical, and physical safeguards designed to protect personal data, including:

  • encryption in transit (TLS) for all external traffic;
  • industry-standard credential hashing and secure token storage for passwords and API keys;
  • multi-factor authentication for administrative access to production systems;
  • role-based, least-privilege access controls limiting who can access personal data and production infrastructure;
  • rate limiting and monitoring to help detect and prevent abuse;
  • encrypted backups; and
  • a documented security-incident response process, including the breach-notification commitments in our Data Processing Addendum.

No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security. We will notify affected individuals and/or regulators of a data breach involving personal data as required by applicable law — including, for Arizona residents, in accordance with Ariz. Rev. Stat. § 18-545. We may update our security controls from time to time as threats, technology, and best practices evolve.

8. Your Rights

Depending on where you live, you may have rights to access, correct, delete, port, restrict, or object to the processing of your personal data, and to withdraw consent where processing is based on consent. To exercise any of these rights, contact loren@hyveappliedintelligence.com. We will respond within the timeframes required by applicable law.

If you are an end user of a HyveAI customer's chat widget and wish to exercise your rights in relation to that chat history, please contact the operator of the site where you used the widget — they are the data controller for that interaction.

California residents: see Section 9 (California Privacy Rights) below for CCPA-specific rights and our Notice at Collection.

9. California Privacy Rights (CCPA/CPRA)

This section supplements the rest of this Privacy Policy and applies to California residents, as required by the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA"). It serves as our Notice at Collection.

9.1 Categories of Personal Information We Collect

Category Collected? Source Purpose Shared With Retention
Identifiers (name, email, phone, account ID) Yes Directly from you (account/customer) Login, billing, support Payment processor, hosting provider, email provider Account lifetime + a reasonable period required by law
Internet or other electronic network activity Yes Automatically, from your use of the Service Security, fraud prevention, product analytics Hosting and monitoring providers Up to 30 days by default (see Data Retention)
Commercial information (subscription/billing history) Yes From you and our payment processor Payment processing, renewals, accounting Payment processor Term of account + tax/accounting record-retention period
Customer content (documents, chat transcripts, uploaded files) Yes Directly from you or your end users Providing the RAG/chat/knowledge-base Service you configure AI inference, vector-database, and hosting subprocessors (see Subprocessors) Per your configuration; deleted from active production systems within 30 days after account termination. Encrypted backups are isolated from ordinary use and overwritten in the ordinary course of HyveAI's backup rotation unless retention is legally required or needed for security, fraud-prevention, or dispute-resolution purposes.
Sensitive personal information (e.g. if you choose to upload it within documents) Only if you include it in uploaded content You (Customer-controlled) Processed only to the extent needed to provide the Service you configure; not used by HyveAI to infer characteristics about you Same subprocessors that process the surrounding document, per your configuration Per your configuration; deleted from active production systems within 30 days after account termination. Encrypted backups are isolated from ordinary use and overwritten in the ordinary course of HyveAI's backup rotation unless retention is legally required or needed for security, fraud-prevention, or dispute-resolution purposes.

We collect this information for the business and commercial purposes described in Section 2 (How We Use Information) above.

9.2 We Do Not Sell or Share Personal Information

We do not sell or share personal information, as those terms are defined under the CCPA. We have not sold or shared personal information in the preceding 12 months, and we do not have actual knowledge of selling or sharing the personal information of minors under 16.

9.3 Your CCPA Rights

If you are a California resident, you have the right to:

  • Know what personal information we have collected about you, including the categories of sources, purposes, and third parties;
  • Delete personal information we have collected from you, subject to certain exceptions;
  • Correct inaccurate personal information;
  • Opt out of the sale or sharing of personal information (not applicable — we do not sell or share);
  • Limit the use and disclosure of sensitive personal information to what is necessary to provide the Service (we do not use sensitive personal information for any purpose beyond what you configure); and
  • Non-discrimination — we will not discriminate against you for exercising any of these rights.

To exercise these rights, contact us as described in Section 8 (Your Rights) or Section 15 (Contact). We will verify your request using information you provide and respond within the timeframe required by the CCPA. You may designate an authorized agent to make a request on your behalf, subject to our ability to verify that authorization.

10. Cookies

We use strictly necessary cookies and local storage to keep you signed in, to maintain session state, and to remember your preferences. We do not use third-party advertising cookies. Where required, we will ask for your consent before setting any non-essential cookies.

11. Children

The Service is not directed to children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will promptly delete it.

12. Changes to this Policy

We may update this Privacy Policy from time to time. Material changes will be notified by email and/or in-product notice. The "Last updated" date at the top reflects the most recent revision.

13. Connected Social Accounts

The Service allows Customer to connect its own social media accounts — currently supporting Meta (Facebook and Instagram), LinkedIn, X (Twitter), TikTok, and Google / YouTube — so that Customer can authorize HyveAI to publish content on Customer's behalf to Customer's own pages, profiles, or channels ("Connected Accounts").

HyveAI uses Connected Account data only to authenticate the account, display connected-account status within the Service, and publish content expressly configured, scheduled, or approved by Customer. HyveAI does not sell Connected Account data, use it for advertising, or use it to train AI models. Customer may revoke access at any time, and HyveAI will delete stored access tokens promptly after disconnection, except where retention is legally required.

The table below lists the specific OAuth scopes requested for the publishing capabilities described above, based on each platform's own current developer documentation. Platforms periodically rename, split, or deprecate scopes; the scopes actually requested at any given time are shown on that platform's own consent screen when Customer connects an account, and control if they differ from this table.

Platform Exact OAuth Scope / Permission Why Needed Optional?
Meta (Facebook Pages) pages_show_list List the Facebook Pages the user manages, so Customer can choose which Page to connect Required
Meta (Facebook Pages) pages_manage_posts Publish, edit, and delete posts on the connected Page Required
Meta (Facebook Pages) pages_read_engagement Read basic engagement metrics to display publish status in the Service Optional
Meta (Instagram) instagram_basic Read the connected Instagram account's basic profile information Required
Meta (Instagram) instagram_content_publish Publish images and video to the connected account Required
LinkedIn w_organization_social Publish posts on behalf of the connected Company Page Required
LinkedIn r_organization_social Read the organization's existing posts to display publish status Optional
X (Twitter) tweet.write Publish posts from the connected account Required
X (Twitter) users.read Identify the connected account (display name and handle) Required
X (Twitter) offline.access Issue a refresh token so the connection persists without repeated re-authentication Required
X (Twitter) tweet.read Read the account's own posts to display publish status Optional
TikTok video.publish Publish video content to the connected account Required
TikTok user.info.basic Identify the connected account (display name) Required
Google / YouTube https://www.googleapis.com/auth/youtube.upload Upload video content to the connected channel Required
Google / YouTube https://www.googleapis.com/auth/youtube.readonly Read the channel's existing videos to display publish status Optional
  • Storage: access tokens are encrypted at rest and are never displayed in full within the Service after the initial connection.
  • Retention: tokens are retained only for as long as the Connected Account remains connected, and are deleted promptly (generally within 24 hours) after Customer disconnects the account.
  • Revocation & deletion: Customer may disconnect any Connected Account at any time from within the Service, or directly from that platform's own app/connection settings. See our Data Deletion Instructions for the full process, including for Meta (Facebook/Instagram) accounts.
  • Scope: HyveAI does not use Connected Account access to read, collect, or analyze Customer's broader social graph, private messages, or followers/connections, beyond what is strictly required to publish the content types Customer enables. The exact permissions requested are shown on each platform's own consent screen at the time Customer connects the account.
  • Platform terms: Customer's use of each connected platform remains subject to that platform's own terms of service, developer policies, and — for Google — the Google API Services User Data Policy, including its Limited Use requirements. HyveAI is not responsible for content once it has been published to a third-party platform at Customer's direction.

14. Federation Program (Political Vertical)

Certain HyveAI products in our political vertical (currently FieldIQ and Lidy) support an optional Federation program. Federation lets participating facilities contribute to and benefit from network-wide intelligence without exposing their underlying records to other participants. Federation is off by default for every facility and has two independent layers of opt-in.

14.1 Aggregate Signal Participation. A facility administrator may opt the facility into the aggregate signal layer. Once enabled, HyveAI computes de-identified, aggregate metrics from that facility's activity — such as topic engagement, query volume, knowledge-base gap patterns, and outcome or sentiment distributions — classified against a fixed, Hyve-maintained topic taxonomy so results are comparable across facilities.

Suppression controls. HyveAI applies suppression controls designed to prevent aggregate signal outputs from identifying or reasonably inferring any individual, facility, household, voter, donor, constituent, or participating organization. An aggregate signal is only computed, stored, or disclosed where it satisfies all of the following, enforced at the database level where noted:

  • at least five (5) participating facilities contribute to the metric (enforced at the database level);
  • a minimum number of underlying individuals or events contribute to the metric, so a small facility's activity cannot dominate or be isolated from the result;
  • a minimum time-window size, to prevent point-in-time inference;
  • no single contributing facility's activity represents a disproportionate share of the underlying result; and
  • no geography, topic, or segment narrow enough to create a reasonable risk of identifying a specific facility or person.

HyveAI will not publish or disclose an aggregate signal if the sample size, geography, time window, topic, or contribution distribution creates a reasonable risk of re-identification — for example, a rare topic, a small sample, or a sensitive category is suppressed rather than disclosed. No aggregate signal can be traced back to, or reveal the underlying records of, any single facility.

Aggregate signals may be made available, at an aggregation granularity appropriate to the buyer's contract, to separately contracted signal-layer customers (for example, candidates, campaigns, or state party organizations purchasing rollup intelligence). Signal-layer buyers never receive raw records, individual voter or constituent data, or facility-identifying detail — signal-layer buyers receive only de-identified, aggregate outputs and are contractually prohibited from attempting to re-identify any facility, individual, voter, donor, constituent, or underlying record.

14.2 Knowledge-Base Sharing (Additional, Separate Opt-In). Independently of, and in addition to, aggregate signal participation, a facility may separately choose to mark specific knowledge-base entries as visible to other participating facilities in the network, so that another facility's AI agent can retrieve and reference that entry when answering its own end users. This is opt-in per document — enabling aggregate signal participation under Section 14.1 does not, by itself, make any knowledge-base content visible to other facilities. A facility can revoke a document's shared status at any time; doing so stops the document from being included in new retrieval going forward, but removal from the underlying shared search index is not necessarily instantaneous and may take some time to fully propagate. Content already retrieved and returned to an end user by another facility before revocation is part of that facility's own historical records and is not retroactively deleted from them.

14.3 Leaving the Network. If a facility disables Federation, it stops contributing new aggregate signal, and any knowledge-base entries it had shared stop being included in new cross-facility retrieval going forward, subject to the propagation timing described in Section 14.2 — this is not necessarily instantaneous. Aggregate signals already computed and incorporated into network-wide metrics before the facility left are retained, because they never contained that facility's identifiable raw data to begin with and cannot be reconstructed to reveal it.

14.4 Consent Record. HyveAI records the date and the authorized user who enabled Federation for a facility, and will honor a facility administrator's instruction to disable Federation, or to un-share a knowledge-base entry, at any time, subject to Section 14.2.

14.5 Political Coordination Risk. Facilities participating in Federation may include competing or otherwise unaffiliated political campaigns, committees, or organizations. HyveAI does not evaluate, and does not represent, that a facility's participation in Federation — including its receipt of aggregate signal or shared knowledge-base content — complies with campaign-finance coordination, disclosure, or related rules in any jurisdiction. Each facility is solely responsible for determining whether its own participation is lawful under rules applicable to it. HyveAI reserves the right to restrict, segment, or exclude a facility from a Federation, or from specific Federation content, where HyveAI reasonably believes doing so is necessary to address a coordination, legal, or compliance concern.

15. Contact

Hyve Applied Intelligence LLC
Email: loren@hyveappliedintelligence.com
Website: hyveappliedintelligence.com