Privacy Policy
Last updated: August 23, 2026
- No sale or advertising profilesWe do not sell personal information or use API activity for targeted advertising.
- No training on customer inputsHivewire does not use customer inputs to train AI models. Customer-facing OpenRouter requests use providers that do not retain or train on those inputs.
- Operational loggingWe retain request metadata—not raw API-key secrets—to meter credits, secure the Service, and troubleshoot failures.
- Service providers process dataAWS, Cloudflare, Stripe, RevenueCat, OpenRouter, model providers, Google, Google Ads, and PostHog perform specific functions described below.
1. Introduction
This Privacy Policy explains how Hivewire, LLC ("Hivewire," "we," "us," or "our") collects, uses, discloses, and retains personal information when you visit hivewire.ai, create a developer account, use the Hivewire REST API or MCP server, or contact us (collectively, the "Service"). The Service is for users who are at least 18 years old.
Our primary application records are stored in the United States. Cloud and service providers may process information in other countries where they operate.
2. AI Processing & Training
Hivewire does not use customer queries, channel descriptions, feedback, or other customer inputs to train AI models. Customer-facing routes and personalized newsletter generation may send query or channel text through OpenRouter to a model provider for classification or a generated response. These requests require zero-data-retention endpoints and exclude providers that collect prompt data. The eligible model provider may vary by task or availability.
Search and relevance routes send text directly to the Google Gemini API to create embeddings. If that service is unavailable, we may send the same text through OpenRouter to a zero-data-retention Gemini embedding endpoint. Google's paid-service terms state that prompts and responses are not used to improve its products; Google may retain direct requests for a limited period for abuse monitoring and legal compliance. Do not submit passwords, payment-card data, protected health information, or other highly sensitive personal information to the Service.
Before processing a free-text topic-profile request, we send the text to OpenAI's moderation endpoint to detect prohibited content. OpenAI states that API inputs are not used to train its models by default. Its current endpoint-specific data-control table lists no abuse-monitoring or application-state retention for moderation requests.
3. Data We Collect
3.1 Account and authentication data: We collect your name, email address, account identifier, login method, and acceptance of the Terms and this Policy. If you choose Google or Apple sign-in, we receive the account information that provider makes available. Authentication tokens are stored server-side; the browser receives an opaque session identifier.
3.2 Billing data: Stripe collects payment-card and billing details directly. We receive and retain customer, subscription, transaction, plan, and entitlement identifiers needed to manage billing. RevenueCat processes subscription and entitlement events. Hivewire does not receive or store full payment-card numbers.
3.3 API usage metadata: For authenticated API calls we record a request identifier, source IP address, timestamp, endpoint, response status, latency, account identifier, API-key identifier, and plan. Access logs contain a key identifier, not the raw API-key secret. We also maintain monthly and per-endpoint credit counters.
3.4 Customer inputs and configuration: Depending on the route, we process search terms, topic-profile text, channel names and descriptions, selected topics, filters, and channel feedback. Channel configuration and feedback remain associated with your account so the channel can operate. Standard API access logs do not include request bodies.
3.5 Website, session, and connected-app data: We process network and request information made available by Cloudflare, essential cookie identifiers, OAuth client names and redirect addresses, authorization records, and consent records needed to sign you in or connect an MCP client.
3.6 Communications: If you contact us, we collect your email address, the contents of the message, and any diagnostic information you provide.
3.7 Product analytics: We send limited account events—such as signup, plan changes, and purchases—to PostHog using an identifier derived with a salt that rotates daily. We also send plan and account-age categories. We do not use PostHog to build advertising audiences or a cross-day behavioral profile from these events.
3.8 Advertising measurement: We use the Google Ads tag to measure whether an advertisement leads to a verified developer account. Google may receive the page URL, referrer, browser and device information, IP-derived location, Google ad-click identifiers, the conversion event, and a random transaction identifier used to prevent duplicate counting. We do not send an email address, API activity, channel configuration, or Customer Input with this event. We have disabled ad-personalization signals and do not use the tag for remarketing audiences.
4. Cookies
We use essential cookies for sign-in state, redirects, security checks, and your authenticated session. These include short-lived OAuth state and nonce cookies and HttpOnly session identifiers.
With permission where required, the Google Ads tag uses optional first-party cookies to connect an ad click with a later verified signup. In the EEA, United Kingdom, and Switzerland, we do not load the Google tag unless you allow advertising measurement. If location cannot be determined, we also ask first. Our hw_ads_consent cookie stores your choice for 180 days. Use the "Cookie settings" control to change it.
5. How We Use Your Data
- Provide, authenticate, personalize, and maintain the Service.
- Process Customer Inputs and return the requested Output.
- Meter credits, enforce rate limits, and manage subscriptions.
- Detect abuse, investigate failures, and protect accounts and infrastructure.
- Send transactional messages, security notices, billing notices, and API deprecation notices.
- Understand signup and subscription outcomes using limited product analytics.
- Measure whether Google advertisements lead to verified developer accounts.
- Comply with law and enforce our agreements.
6. Sharing Your Information
We do not sell personal information or share it for cross-context behavioral advertising. We disclose information to the following service-provider categories for the stated purposes:
- Amazon Web Services, including Cognito — account authentication, databases, API hosting, and operational logs.
- Cloudflare — website and Worker hosting, DNS, security, caching, and OAuth storage.
- Stripe and RevenueCat — checkout, subscription billing, customer portal, and plan entitlements.
- OpenRouter and routed model providers — classification, generated responses, and backup embedding processing for customer-facing routes that process free text. We restrict these requests to zero-data-retention providers that do not collect prompt data.
- Google Gemini — primary embedding processing for routes that process free text.
- Google Ads — conversion measurement for verified developer-account signups. Ad-personalization signals and remarketing audiences are disabled.
- OpenAI — moderation of free-text topic-profile requests before further processing.
- PostHog — limited, pseudonymous signup and subscription analytics.
- Google or Apple — authentication, only when you choose that sign-in provider.
- Professional advisers and authorities — when reasonably necessary for legal advice, compliance, fraud prevention, safety, or a valid legal request.
We may also disclose information in connection with a merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality protections and applicable law.
7. Data Retention
- Account data: retained while the account is active. An account-deletion request enters a 30-day waiting period, and signing in during that period cancels the request. After the waiting period, we delete the account records covered by our deletion process. Billing, security, usage, dispute, and legally required records may be retained for the periods described below or as otherwise necessary.
- API-key records: active keys remain usable until you revoke them. We do not store the raw secret after it is issued. Key identifiers and related security or metering records may be retained after revocation.
- Sessions and OAuth records: retained from a few minutes to 90 days depending on whether the record is a sign-in request, authorization code, session, refresh token, client registration, or consent record.
- API access logs and credit counters: retained for up to 90 days.
- Channel configuration and feedback: retained until you delete the channel or our account-deletion process removes the associated records.
- Billing and transaction records: retained for as long as needed to administer the subscription and meet tax, accounting, dispute, and legal obligations.
- Support communications: retained for as long as needed to resolve the request and maintain an appropriate support and security record.
- AI-provider records: OpenRouter and its routed model providers do not retain the content of restricted customer-facing requests, including backup embedding requests. OpenRouter retains non-content request metadata. Google may retain inputs sent directly to its paid Gemini API for a limited period for abuse monitoring and legal compliance.
- Advertising measurement: our consent-choice cookie remains for 180 days unless you clear it or change your choice. Google processes conversion and ad-click records under its Google Ads data terms and the retention settings for our advertising account. Hivewire does not keep a separate copy of the Google tag's raw browser data.
8. Your Privacy Rights
You may ask us to provide a copy of your personal information or to correct or delete it. Depending on where you live and which law applies to Hivewire, you may have additional privacy rights. We do not sell personal information or use it for targeted advertising.
Submit a request to privacy@hivewire.ai. We will verify the request using information associated with your account and respond within the period required by applicable law. An authorized agent may submit a request for you if the agent provides proof of authority and we can verify your identity. We may retain information where needed for security, billing records, legal obligations, or disputes. You can reject or change optional Google Ads measurement through the "Cookie settings" control.
9. Data Security
We use HTTPS/TLS in transit, encryption in primary cloud storage, hashed API-key storage, short-lived authorization codes, and access controls intended to limit access to people and systems that need it. No security measure eliminates all risk.
10. Age Restriction
The Service is not offered to anyone under 18. We do not knowingly collect account information from a person under 18. If you believe a minor has created an account, contact privacy@hivewire.ai.
11. Changes to This Policy
We may update this Privacy Policy as our practices or legal obligations change. We will post the revised version and change the "Last updated" date. If a change materially expands how we use previously collected personal information, we will provide additional notice or obtain consent when required.
12. Contact
Privacy: privacy@hivewire.ai
General support: support@hivewire.ai