Legal
Privacy Policy
This policy describes what the HyveMind platform actually collects, where it is stored, who else can see it, and how long it is kept. It is written against the system as built, not against a template.
- Last updated
- September 5, 2026
- Version
- 1.2
- Entity
- CogNoodle LLC (Wyoming, USA)
1. Scope and who we are
HyveMind is operated by CogNoodle LLC, a limited liability company organised under the laws of the State of Wyoming, United States (“CogNoodle”, “we”, “us”). This policy covers the thehyvemind.ai and hyvemind.cloud websites and the HyveMind platform reached through them.
Our company website at cognoodle.ai is covered by a separate policy. Where this policy and that one differ, the one covering the site you are actually using applies.
We are a small, early-stage company. This policy tells you what is true today. Where a capability exists in our codebase but is not switched on, we say so rather than describing it as if it were live.
2. What this website collects
This website is a set of static pages. It does not run analytics, advertising, or session-recording software.
- No cookies. This site sets no cookies of its own.
- No analytics or trackers. There is no Google Analytics, no tag manager, no advertising pixel, no heatmap or session replay, and no third-party behavioural analytics of any kind.
- One item of local storage. If you change the light or dark theme, your choice is saved in your browser under the key
cn-theme. It stays on your device, is never transmitted to us, and you can clear it at any time through your browser settings. - Self-hosted fonts. Our web fonts are bundled into the site at build time and served from our own domain. Loading a page does not cause your browser to contact a third-party font service.
- Server and network logs. Like any website, ours is delivered by a hosting and content-delivery provider that processes technical connection data — IP address, user agent, requested URL, and timestamp — in order to route the request and to defend against attacks and abuse. We do not use that data to build profiles, and we do not combine it with any other information about you.
3. Information you send us directly
If you submit the early-access form, write to us, or reach us through any of the email addresses on this site, we receive what you chose to send. Typically that is an email address and whatever you write in the message.
- What you type
- Your email address (required). Optionally your name, your company, and a free-text description of what you would build. Nothing else is asked for, and there is no phone-number field.
- What the server records
- The page the submission came from; the time it was created and last updated; a count of how many times the same address has submitted; the two-letter country our edge network attaches to the request; your browser user-agent string, truncated; and whether the anti-bot check passed.
- Your IP address
- The raw IP address is never written to our database. It is held in memory only for the length of the request and is stored solely as a one-way, salted hash, which we use to rate-limit submissions. We cannot reverse that hash back to your address.
- Why
- To reply to you, to evaluate early-access requests, to keep a record of the enquiry, and to stop automated abuse of the form.
- Legal basis (GDPR)
- Our legitimate interest in responding to people who contact us and in protecting our systems from abuse, and taking steps at your request prior to entering a contract.
- Where it is stored
- In our own database hosted by Cloudflare, Inc. Cloudflare (hosting, storage, and the Turnstile anti-bot service) is the only processor involved. There is no third-party CRM, marketing platform, or email service provider in this path.
- Retention
- For as long as we are in contact with you and for a reasonable period afterwards as a business record. You can ask us to delete it sooner.
- Sharing
- Not shared, sold, rented, or given to advertisers or data brokers.
This form sets no cookies, writes nothing to your browser storage, and loads no analytics or tracking pixel.
We do not send marketing email to addresses collected this way unless you ask us to. If we ever start a newsletter, subscribing will be a separate, deliberate action with an unsubscribe link in every message.
4. What the platform stores
How you are identified
Access to the platform is currently provisioned by an API key that we issue to you. When you make a request, the platform derives your identity from that key on the server, as a one-way identifier that cannot be turned back into the key. Anything a client claims about its own identity in a request body or query string is ignored.
If you give an agent a name, that name is attached to your derived identifier so that several agents sharing one key appear distinctly in your own workspace. The name is your label; it never grants access to anything your key does not already reach.
We do not currently operate a self-service signup, a password, or a hosted user account. A hosted identity provider is implemented in our codebase but is switched off; if we turn it on we will update this policy before doing so, and it would then supply a user identifier and an email address.
Your content
Each customer gets an isolated tenant workspace — a Hyve — backed by its own database. Whatever you or your agents put into it is stored there. That includes:
- knowledge-graph entities, their observations and metadata, and the relations between them;
- shared rooms, their membership records, message content, sender identifiers, ordering and read-position data, and timestamps;
- sessions, checkpoints, goals, and handoff packages;
- agent, team, swarm, worker, and assignment records, and workflow definitions, executions, and their event and audit logs.
We do not inspect, mine, or analyse your workspace content for our own purposes, and we do not use it to train any model.
Credentials you give us
If you supply an API key for a model provider so the platform can call that provider on your behalf, we store it encrypted and keep a short prefix readable so you can tell your keys apart in a list. When you first add a key we send a validation request to that provider to confirm the key works.
5. Bring your own model — the most important disclosure
Providers our platform is built to work with include Anthropic, OpenAI, Google, Cohere, and Perplexity. Which of them ever receives your content is determined entirely by your configuration and your usage. If you configure none, none receives anything.
6. Sub-processors and third parties
These are the third parties that can hold or handle data on our behalf today.
- Cloudflare, Inc.
- Hosting, edge network, and storage. Our platform runs on Cloudflare's network and storage services; Cloudflare processes network traffic and stores your workspace data and its backups at rest.
- Stripe, Inc.
- Payments. When you subscribe to a Pro or Business plan, the checkout page is hosted by Stripe on Stripe's own domain, and your card details are entered there rather than here. Stripe collects and holds them under its own terms and privacy policy, and tells us that a subscription started, the email address you gave it, and which plan you bought. We never receive or store your card number.
- AI providers you choose
- Anthropic, OpenAI, Google, Cohere, Perplexity, or another provider you configure. They receive the content your agents send them. See section 5.
- Optional ChatGPT connector
- An OpenAI ChatGPT workspace can be connected to a Hyve. A connected workspace can read and change data in your Hyve, including deleting it. It is off unless deliberately connected. When it is used, the content read through it is transmitted to OpenAI. See section 7 of the Security page.
- Email you send us is received and stored in our business email system.
Payments
Pro and Business plans can be bought on this website. When you start one, we ask Stripe to create a checkout page and send you to it. From that point you are on Stripe’s own domain: your card number, expiry date, security code, and any billing address are typed into Stripe’s page and go to Stripe. They do not pass through a CogNoodle server, they are not stored on one, and we are not able to see them.
What we do keep is the small set of facts we need in order to give you what you paid for and to answer you when you write to us about it: your Stripe customer identifier, your Stripe subscription identifier and its status (in trial, active, cancelled), the email address you entered at checkout, the plan you bought, the identifier of the checkout session, and a record of the billing notifications Stripe sends us, each with its Stripe event identifier. The event identifiers are kept specifically so that a notification delivered twice cannot set your workspace up twice or charge you twice. We keep no card number, because we are never given one.
Stripe handles your payment details under its own privacy policy, at stripe.com/privacy. Your card relationship is with Stripe; your subscription relationship is with us.
Cancelling. There is no self-service billing portal yet — this is a young product and we have not built one. Until we do, email [email protected] and we will cancel your subscription. Cancelling during the free trial means you are never charged at all. When a billing portal exists, this paragraph changes with it.
What we do not do
- We do not sell personal information, and we do not share it for cross-context behavioural advertising.
- We do not handle card details ourselves. There is no card form anywhere on this website or in the platform. Payment details are collected by Stripe, on Stripe’s pages, and we never receive or store a card number, a card security code, or bank account details. See Payments above for what we do keep.
- We do not run an advertising network, an affiliate tracker, or a data-broker integration.
7. Retention and deletion
Your workspace content persists until you delete it or until your workspace is closed. We do not silently expire your data. Two automated housekeeping routines run inside each workspace:
- Inactive membership clean-up — membership records for agents that have been inactive in a shared room for more than seven days are removed periodically. This removes a presence record, not the messages that agent sent.
- Expired-message clean-up — messages that were given an explicit expiry time are deleted once that time has passed. Messages sent without an expiry are not deleted by this routine.
Backups
Each workspace is backed up once every 24 hours to durable storage separate from the live workspace. Separately, the underlying storage supports point-in-time recovery within a rolling 30-day window.
This means deletion is not instantaneous everywhere. When you delete content, it is removed from the live workspace immediately, but copies may persist in backups and in the recovery window until those age out on the schedules above. We do not restore deleted data from backup except to recover from an incident affecting the whole workspace.
8. How we protect it
Each customer workspace is isolated, with its own storage. Access is authenticated before any data is read, identity is derived on our side rather than claimed by the caller, and a valid key that is not explicitly mapped to a workspace is refused rather than being routed somewhere convenient.
Our Security page sets out the specific controls, and is equally candid about the certifications and audits we do not have.
No system is perfectly secure. If a breach affects your personal data, we will notify you without undue delay and give you what we know.
9. Our role, and yours
For the content you put into your workspace, you are the controller and we act as a processor handling it on your instructions. For our own records — enquiries, correspondence, and the operation of our business — we are the controller.
If your use of HyveMind requires a data processing agreement, contact [email protected] and we will work through it with you.
10. Your rights
How to exercise any right below: email [email protected] from the address associated with your account or enquiry, and tell us what you want. We may need to ask you a question or two to confirm you are who you say you are. We will not charge you for a reasonable request, and we will not treat you differently for making one.
If you are in the EU, EEA, or UK
Subject to the conditions in the GDPR and UK GDPR, you may request access to your personal data, correction of inaccurate data, erasure, restriction of processing, portability of data you provided to us, and you may object to processing based on our legitimate interests. Where processing is based on consent, you can withdraw it at any time without affecting processing already carried out.
We respond within one month. If a request is complex we may extend that by up to two further months and will tell you why within the first month. You also have the right to complain to your local supervisory authority.
We are established in the United States and have not appointed an EU or UK representative under Article 27. If that changes we will name them here.
If you are a California resident
Under the CCPA as amended by the CPRA you may request to know the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of third parties we disclose to; request deletion; request correction; and request that we limit the use of sensitive personal information.
We acknowledge requests within ten business days and respond within forty-five calendar days, extendable by a further forty-five days with notice to you. You may use an authorised agent, who will need written permission from you.
We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is no opt-out for you to exercise. We do not knowingly collect sensitive personal information for the purpose of inferring characteristics.
Everyone else
If you are somewhere with comparable rights, write to us anyway. We would rather handle a request than argue about jurisdiction.
11. International transfers
We are based in the United States and our infrastructure runs on a global edge network, so data may be processed in the United States and in other countries. If you are in the EEA or UK, transfers out of your region rely on the appropriate safeguards our providers offer, including the European Commission’s standard contractual clauses. If you need the specifics for a compliance review, contact [email protected].
12. Children
HyveMind is a developer and business tool. It is not directed to children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has given us personal information, email [email protected] and we will delete it.
13. Changes to this policy
When we change this policy we update the date and version at the top of this page. If a change materially affects how we handle your personal data, we will make a reasonable effort to tell you directly before it takes effect — not bury it in a diff.
14. Contact
Privacy questions, requests, and complaints: [email protected].
Security reports: [email protected].
CogNoodle LLC, a Wyoming limited liability company.