This is the full legal Privacy Policy governing Buzzy Media LLC's collection, use, and disclosure of your information when you use HiveBoss. Our Privacy & Data Commitment describes what we actually believe and practice, in plain language. Both documents are true. In the event of a conflict between them, this Policy governs.
This Privacy Policy applies to all services, websites, and applications operated by Buzzy Media LLC under the HiveBoss brand (collectively, the "Services"), including hiveboss.ai and any associated desktop or mobile applications. It applies to all individuals who access or use the Services, including workspace owners, Members, Beekeepers, and any other authorized users (collectively, "Users").
This Policy does not apply to third-party applications, AI model providers, or external services that you may connect to HiveBoss. Those providers operate under their own terms and privacy policies.
Use of the Services is also governed by our Terms of Service. Capitalized terms not defined here have the meanings given in the Terms of Service.
3.1 Account Information. When you create a Hive or register for the Services, you provide us with information such as your name, email address, organization name, and password. Customers on paid plans provide billing information (credit card or ACH details), which is processed by our payment processor and not stored on our servers in full.
3.2 Customer Data. You and your authorized teammates submit Customer Data to the Services in the course of using HiveBoss, including context nodes, Marching Orders, Bee task inputs and outputs, HiveReports, uploaded files, and communications within the platform. We process Customer Data exclusively on your behalf, as a data processor, to operate and deliver the Services. We do not read, analyze, mine, or otherwise use Customer Data for our own purposes. For organization-controlled Hives, the customer organization is the controller of the Customer Data submitted to that Hive; Buzzy Media LLC is the processor.
3.3 Usage Data. We automatically collect certain information when you access or use the Services:
3.4 Communications. If you contact us by email, support ticket, or other means, we collect the contents of that communication and any information you choose to provide.
3.5 Connected Services. If you connect a third-party service to your Hive via OAuth or API, HiveBoss receives only the data necessary to execute the specific task a Bee is performing on your behalf. Google user data is governed separately by Section 7. The lifecycle of data accessed through any Connected Service (including what is temporarily processed, what becomes Derived Content, and what is deleted on disconnection) is described in Section 8.
We use Account Information and Usage Data for the following purposes:
To provide and operate the Services. This includes account management, feature delivery, Honey ledger tracking, Bee orchestration, and technical support. This is our primary use and the reason the data exists.
To improve and develop the Services. We use aggregate and anonymized Usage Data to understand how HiveBoss is used, identify pain points, and prioritize product development. We do not use Customer Data for this purpose.
To communicate with you. We send transactional and administrative communications (account confirmations, billing receipts, security notices, policy updates). We may also send product updates and feature announcements. You may opt out of non-essential communications at any time.
To enforce our policies and protect the Services. We may process information to detect fraud, prevent abuse, investigate violations of our Terms of Service, and protect the security and integrity of the platform.
To comply with legal obligations. We may process or disclose information as required by applicable law. See Section 11 for our specific position on law enforcement requests.
HiveBoss routes Bee task execution through one or more third-party AI model providers. When a Bee runs, content from your Context Graph and task input may be transmitted to the applicable provider as part of the API request. This is fundamental to how the platform operates.
We do not have control over AI providers' data practices beyond what their published terms permit. Your use of the Services constitutes acknowledgment that data may flow to these providers under those terms.
"Not used for training" is not the same as "not retained." Some AI providers retain API inputs and outputs for limited periods to support abuse monitoring, security, or service reliability, even when their terms prohibit training on customer content. We select providers whose API terms prohibit training on customer content by default, and we do not opt into provider training or feedback programs using your data.
Google user data accessed through Gmail or Google Drive is governed by Section 7 and is not used to train any AI provider's models.
If you choose to connect a Google account to HiveBoss, you authorize us to access certain data from your Google account through Google APIs. We request only the access needed to provide the features you enable, and you can review or revoke this access at any time at myaccount.google.com/permissions.
Gmail access. When you connect Gmail, we request the narrowest scopes required for the features you enable:
gmail.readonly), to allow a Bee to read a specific email thread or message that you have explicitly directed it to process, such as summarizing a thread, extracting action items, or drafting a reply. HiveBoss does not scan your inbox continuously or read mail outside of a task you initiate.gmail.send), to allow a Bee to send an email after you have reviewed and approved it as part of a workflow. No email is sent from your account without a task explicitly authorized by you or a workspace administrator you have delegated.gmail.compose), to allow a Bee to create a draft in your Gmail inbox for your review before sending. Drafts appear in your Gmail Drafts folder and are not delivered until you send them.Google Drive access. When you connect Google Drive, we request the narrowest scopes required for the features you enable:
drive.file), to allow a Bee to read, summarize, extract from, or otherwise process specific files that you have explicitly selected or shared with HiveBoss. HiveBoss does not access files in your Drive that you have not selected or shared with the application.drive.readonly). When a broader scope is requested, the Google consent screen will display the specific scope before you authorize it.How we use it. We use Google user data only to provide and improve user-facing features that you initiate within HiveBoss. We do not use Google user data for advertising, and we do not sell it.
How we store and share it. We store Google user data only as long as needed to provide the feature you enabled. We do not share it with third parties except as necessary to provide that feature, to comply with applicable law, or with your direction. When Google user data is transmitted to an AI model provider to execute a task you initiated, that transfer is limited to the data necessary for the task and is subject to the no-training commitments in Section 6. If you disconnect your Google account, we delete the associated Google user data from production systems within 30 days. Derived Content that you saved into your Hive is governed by Section 8.
Human access. We do not allow humans to read your Google user data except: (a) with your explicit consent; (b) where necessary for security purposes, such as investigating abuse; (c) to comply with applicable law; or (d) where the data has been aggregated and anonymized such that it no longer identifies you.
AI and machine learning. We do not use Google user data to develop, improve, or train generalized or non-personalized AI or machine learning models.
This section explains what happens to data that HiveBoss accesses through a Connected Service. The same lifecycle applies to Gmail, Google Drive, Slack, and any other Connected Service you authorize.
Temporary processing. When you direct a Bee to act on Connected Service Data (for example, summarize a specific email thread, extract information from a specific Drive file, or draft a Slack reply), HiveBoss temporarily retrieves and processes only the data necessary to complete that task. We do not continuously scan a Connected Service unless a feature you have specifically enabled requires it, and any such ongoing access is disclosed in-product before you enable the feature.
Derived Content. If you direct HiveBoss to save the output of a task into your Hive (for example, by adding a summary to your Context Graph, generating a HiveReport, or storing an extracted note), that saved output becomes Derived Content and is treated as Customer Data. Derived Content is retained according to your workspace settings and the retention provisions in Section 9.
Disconnection. Disconnecting a Connected Service revokes HiveBoss's access tokens and deletes any temporarily stored Connected Service Data from production systems within 30 days. Disconnection does not automatically delete Derived Content that you previously saved into your Hive. To delete Derived Content, delete it through your Hive controls or contact us at privacy@hiveboss.ai.
Residual copies. Residual copies of Connected Service Data and Derived Content in backup systems are purged within 90 days of deletion from production.
We retain Customer Data in accordance with your account settings and our operational requirements to deliver the Services. You may configure retention settings for certain data types within your Hive.
If you close your account, your Customer Data is deleted from production systems within 30 days. Residual copies in backup systems are purged within 90 days of deletion from production. After deletion, we will not be able to recover your data.
We retain Account Information and Usage Data for as long as necessary to fulfill the purposes described in this Policy, to comply with legal obligations, resolve disputes, and enforce our agreements. We may retain de-identified or aggregated Usage Data indefinitely.
HiveReports and Honey transaction records are retained for the life of your account and for a minimum of 12 months following account closure to support billing dispute resolution and audit obligations.
We implement and maintain technical and organizational security measures appropriate to the sensitivity of the information we process. Our practices include:
No system connected to the internet can guarantee absolute security. We encourage you to use strong, unique credentials and report any suspected security issues to hello@hiveboss.ai.
When we receive a request for user information from a government agency, law enforcement entity, or any other authority:
The Services are not directed to, and we do not knowingly collect Personal Data from, individuals under the age of 16. If you believe a minor under 16 has provided Personal Data to us, contact us at privacy@hiveboss.ai and we will take steps to delete that information.
HiveBoss is operated from the United States. If you access the Services from outside the United States, your information may be transferred to, stored, and processed in the United States and in other countries where our service providers maintain infrastructure.
For Users in the European Economic Area (EEA), the United Kingdom, or Switzerland, we rely on Standard Contractual Clauses approved by the European Commission (and their UK equivalents) as the legal mechanism for transferring Personal Data outside the EEA and UK. A copy of our data processing addendum incorporating these clauses is available upon request at privacy@hiveboss.ai.
Depending on your jurisdiction, you may have the following rights with respect to your Personal Data:
You can exercise many of these rights directly within your account settings or by exporting your data through the platform. For requests that cannot be fulfilled through account settings, contact us at privacy@hiveboss.ai. We will respond within 30 days, or as required by applicable law. We may ask you to verify your identity before processing a request.
Workspace Administrators. If your Hive is administered by your employer or another organization, that organization is the controller of the Customer Data within that Hive. Privacy requests relating to Customer Data should generally be directed to that organization, and we will support the organization in responding as required by applicable law.
This section applies to California residents and supplements the rest of this Policy. Under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), California residents have additional rights regarding their Personal Information.
Categories of Personal Information collected: We collect identifiers and contact information; commercial information (billing and subscription data); internet or electronic network activity information (Usage Data); approximate geolocation (from IP); and inferences drawn from the above to operate and improve the Services.
Business purposes for collection: As described in Section 4 of this Policy.
We do not sell Personal Information. We do not share Personal Information for cross-context behavioral advertising.
California rights: California residents may request to know the categories and specific pieces of Personal Information we have collected, request deletion, request correction, opt out of any future sale (none currently occurs), and not be discriminated against for exercising these rights.
To submit a California rights request, contact us at privacy@hiveboss.ai. We will verify your identity using information associated with your account. You may designate an authorized agent to submit a request on your behalf; authorized agents must provide written authorization.
If you would like to exercise a Global Privacy Control, we honor GPC signals received by our web properties as an opt-out of sale and sharing under CPRA.
We may update this Privacy Policy from time to time as the Services evolve, as legal requirements change, or as we refine our data practices. We will post the updated Policy at this URL and update the effective date.
If we make changes that materially affect your privacy rights (such as a change to how we use Customer Data, a new category of sharing, or a change to our law enforcement disclosure policy), we will provide advance notice via email to your registered address and/or through a notice within the platform, no less than 14 days before the change takes effect. Your continued use of the Services after that notice period constitutes acceptance of the updated Policy.
For any questions, concerns, or requests related to this Privacy Policy or our data practices:
Privacy & data questions: privacy@hiveboss.ai
All other inquiries: hello@hiveboss.ai
Mailing address:
Buzzy Media LLC
Attn: Privacy
150 Country Estates Circle, Suite 110
Reno, Nevada 89511
We aim to respond to all privacy-related inquiries within 5 business days and to fulfill requests within 30 days, or within the timeframe required by applicable law.