Privacy Policy
Published: October 6, 2026 · Version: privacy-2026-10-06.r1
This Privacy Policy describes how HiveLuma ("HiveLuma," "we," "us," or "our") collects, uses, discloses, and otherwise processes information in connection with your access to and use of the HiveLuma platform and related services (collectively, the "Service").
1. Information We Collect
In the course of providing the Service, we may collect the following categories of information:
- Account information. This may include your name, business email address, login credentials, and other account registration information.
- Billing and transaction information. This may include subscription status, plan selection, billing address details, and transaction metadata processed through our authorized payment service providers. We use Stripe for card processing; HiveLuma does not store full payment card numbers.
- Customer data. This includes data, URLs, prompts, queries, files, text, inputs, and other materials submitted by you or your organization in connection with your use of the Service.
- Usage and technical information. This may include IP address, browser type, device information, operating system, referral source, session activity, page interactions, and other diagnostic or log data relating to how the Service is accessed and used.
- AI input and output data. We may process prompts, URLs, queries, instructions, generated outputs, reports, and other related interaction data in order to operate the Service and return analytics, visibility insights, rankings, recommendations, and related outputs.
- Policy acceptance. We save the accepted Terms and Privacy versions, your account reference, a server-set UTC time and a short description of where you accepted them. We do not add your IP address or browser user-agent to this evidence. New versions add a record, not replace one. We do not invent prior acceptance for existing accounts.
- Support messages. If you report a problem, we may send your message, account contact information and a cleaned page path to our support notification service. Do not send passwords or API keys. Copies held by email or support services are outside an in-app report deletion.
2. How We Use Your Information
We may use collected information to:
- Provide, operate, maintain, support, and improve the Service.
- Generate analytics, rankings, reports, recommendations, schema-related outputs, and other Service features.
- Process transactions and administer subscriptions, plan access, and billing.
- Communicate with you regarding account activity, updates, support matters, and security or administrative notices.
- Monitor usage, troubleshoot issues, enforce our terms, and detect, investigate, or prevent fraud, abuse, misuse, or unauthorized activity.
- Comply with legal obligations and protect the rights, property, and safety of HiveLuma, our users, and third parties.
3. Aggregated Analytics and Service Improvement
We use Customer Data and Service interaction data to operate, maintain, secure, and improve the Service while it remains within the applicable retention period. Raw or joinable scan targets, URLs, prompts, queried topics, and outputs are customer content, not anonymous analytics, and are purged under the retention and account-deletion rules below. We may retain genuinely de-identified aggregate statistics that cannot reasonably be linked back to you, your organization, or a customer resource. We do not sell personally identifiable information to third parties.
4. Information Sharing and Disclosure
We may disclose information in the following circumstances:
- Service providers. We may share information with vendors, contractors, and service providers that perform services on our behalf, including cloud hosting providers, infrastructure vendors, payment processors, analytics providers, customer support tools, and AI or model providers. To perform a requested scan or tool run, HiveLuma may send relevant submitted inputs and public-page content to supported AI providers. Different providers may receive different inputs. Their own policies govern provider-held copies, retention and training. We do not promise provider-side deletion or a single data-use rule for every provider.
- Legal compliance and protection. We may disclose information where we believe such disclosure is necessary or appropriate to comply with applicable law, regulation, legal process, or governmental request, or to protect the rights, safety, property, or security of HiveLuma, our users, or others.
- Business transactions. We may disclose information in connection with an actual or proposed merger, acquisition, financing, reorganization, sale of assets, bankruptcy, dissolution, or similar corporate transaction.
- With your direction or consent. We may disclose information where you request, instruct, or otherwise consent to the disclosure.
5. Data Security
We implement commercially reasonable technical, administrative, and organizational safeguards designed to protect information against unauthorized access, loss, misuse, or alteration. Such measures may include access controls, authentication safeguards, encrypted transmission, and secure handling of sensitive credentials such as connected API keys. However, no method of transmission over the internet and no method of electronic storage is completely secure, and therefore we cannot guarantee absolute security.
6. Data Retention
We retain saved customer report content in accordance with the retention period associated with your plan: Starter 30 days, Pro 60 days, Growth 90 days, and Enterprise 365 days. Upgrades may extend still-existing artifacts; downgrades and billing-status changes do not shorten an established expiry. Expired terminal customer artifacts are purged. Explicit account deletion may remove content sooner.
Public Page Scan results are kept for up to 30 days after they are ready. Linked identifiable lead and event information is kept for up to 90 days from creation. New scans may use external AI providers. We may reuse a saved result without another AI call. Consent evidence shares the public lead/event lifecycle; no separate longer-lived consent archive is currently implemented. Pseudonymous identifiers that can still be linked to a person are not anonymous data.
Deletion removes eligible HiveLuma-held content. Required billing/security evidence and some shared-workspace records may remain. Downloads, external/provider copies, infrastructure logs and backups are not erased by this request. Billing shutdown or content removal may remain pending. Policy-acceptance records are removed when account deletion completes; required financial records may retain a replaced account reference. Report deletion alone does not remove account-level acceptance records.
Saved BYOK keys are encrypted and require eligible plan access to use. They remain until that access actually ends, including before a scheduled cancellation takes effect. Eligible-plan changes preserve them. Loss of BYOK access deletes saved keys; later access requires entering them again. We save limited BYOK usage records to enforce the 1,000-run workspace billing-period limit, not provider prompts or key values in those usage records. When account deletion also removes its workspace, that workspace's quota history is removed. Shared-workspace records may remain. An ordinary quota-history retention duration is still under review; it is not claimed to match report expiry or to be erased by report deletion.
7. International Data Transfers
Your information may be transferred to, processed in, and stored in jurisdictions other than your own, including jurisdictions where data protection laws may differ from those in your province, state, or country of residence. By using the Service, you acknowledge and consent to such transfers, processing, and storage, subject to applicable law.
8. Your Rights
Depending on your jurisdiction and subject to applicable law, you may have the right to request access to, correction of, deletion of, or restriction of the processing of your personal information. You may also have the right to withdraw consent in certain circumstances. To make such a request, please contact us using the contact information set out below. We may need to verify your identity before responding to your request.
9. Cookies and Analytics
Analytics is optional. Your choice is saved in this browser, not as an account-wide preference. Use Analytics preferences to choose Allow or Do not allow. “Do not allow” stops future HiveLuma-triggered analytics in this browser, including after refresh. It does not erase data already received by Google or another analytics provider. Sensitive password/reset/verification and private link-access routes remain excluded.
We use Google Analytics to help measure traffic, understand usage behavior, and improve the Service. Google Analytics may collect information such as IP address, browser type, device information, pages visited, session duration, and related usage data in accordance with Google's own privacy practices. More information about Google's privacy practices is available at Google's Privacy Policy.
You may be able to control cookies through your browser settings, including by deleting or blocking certain cookies. You can also opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on. Please note that disabling cookies or similar technologies may affect the functionality of certain parts of the Service.
We do not use cookies for third-party advertising and do not sell your personal information to third parties.
10. Children's Privacy
The Service is intended for business users and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will take reasonable steps to delete that information.
11. Contact Us
If you have questions about this Privacy Policy or our data practices, you may contact us at:
Email: privacy@hiveluma.com
12. Policy updates
When required versions change, signed-in product use pauses until you explicitly accept them. You can still log out, recover or secure your account, request deletion, or contact support. Declining does not record acceptance. Each published version has a fixed document link so you can see what was accepted.