HiveBoss.ai
Legal · Buzzy Media LLC

Privacy Policy

Effective: June 19, 2026  ·  Operated by Buzzy Media LLC  ·  Questions: privacy@hiveboss.ai

This is the full legal Privacy Policy governing Buzzy Media LLC's collection, use, and disclosure of your information when you use HiveBoss. Our Privacy & Data Commitment describes what we actually believe and practice, in plain language. Both documents are true. In the event of a conflict between them, this Policy governs.

1

Scope of This Policy

This Privacy Policy applies to all services, websites, and applications operated by Buzzy Media LLC under the HiveBoss brand (collectively, the "Services"), including hiveboss.ai and any associated desktop or mobile applications. It applies to all individuals who access or use the Services, including workspace owners, Members, Beekeepers, and any other authorized users (collectively, "Users").

This Policy does not apply to third-party applications, AI model providers, or external services that you may connect to HiveBoss. Those providers operate under their own terms and privacy policies.

Use of the Services is also governed by our Terms of Service. Capitalized terms not defined here have the meanings given in the Terms of Service.

2

Key Definitions

  • Hive: your workspace on the HiveBoss platform.
  • Bee: an AI agent configured within your Hive (Intern, Employee, or Contractor type).
  • Customer Data: content you and your team create, upload, or generate within your Hive, including messages, files, Context Graph nodes, Marching Orders, HiveReports, and Bee outputs.
  • Account Information: information you provide when registering or managing your account (name, email, organization, billing details).
  • Usage Data: metadata generated when you interact with the Services (log data, feature usage, session data, Honey transaction records).
  • Personal Data: any information relating to an identified or identifiable individual.
  • Connected Service: a third-party application (such as Gmail, Google Drive, or Slack) that you authorize to connect to your Hive via OAuth or API credentials.
  • Derived Content: summaries, extractions, embeddings, notes, action items, drafts, or other outputs that a Bee generates from Connected Service Data and that you direct HiveBoss to save into your Hive.

3

Information We Collect

3.1 Account Information. When you create a Hive or register for the Services, you provide us with information such as your name, email address, organization name, and password. Customers on paid plans provide billing information (credit card or ACH details), which is processed by our payment processor and not stored on our servers in full.

3.2 Customer Data. You and your authorized teammates submit Customer Data to the Services in the course of using HiveBoss, including context nodes, Marching Orders, Bee task inputs and outputs, HiveReports, uploaded files, and communications within the platform. We process Customer Data exclusively on your behalf, as a data processor, to operate and deliver the Services. We do not read, analyze, mine, or otherwise use Customer Data for our own purposes. For organization-controlled Hives, the customer organization is the controller of the Customer Data submitted to that Hive; Buzzy Media LLC is the processor.

3.3 Usage Data. We automatically collect certain information when you access or use the Services:

  • Log data: IP address, browser type and version, pages visited, time and date of access, referring URLs, and error logs.
  • Device data: device type, operating system, unique device identifiers, and crash reports.
  • Platform metadata: which features you use, how Bees are invoked, Honey consumption amounts and timestamps, and integration events.
  • Location data: approximate location derived from IP address, used for security and localization purposes only.

3.4 Communications. If you contact us by email, support ticket, or other means, we collect the contents of that communication and any information you choose to provide.

3.5 Connected Services. If you connect a third-party service to your Hive via OAuth or API, HiveBoss receives only the data necessary to execute the specific task a Bee is performing on your behalf. Google user data is governed separately by Section 7. The lifecycle of data accessed through any Connected Service (including what is temporarily processed, what becomes Derived Content, and what is deleted on disconnection) is described in Section 8.

4

How We Use Information

We use Account Information and Usage Data for the following purposes:

To provide and operate the Services. This includes account management, feature delivery, Honey ledger tracking, Bee orchestration, and technical support. This is our primary use and the reason the data exists.

To improve and develop the Services. We use aggregate and anonymized Usage Data to understand how HiveBoss is used, identify pain points, and prioritize product development. We do not use Customer Data for this purpose.

To communicate with you. We send transactional and administrative communications (account confirmations, billing receipts, security notices, policy updates). We may also send product updates and feature announcements. You may opt out of non-essential communications at any time.

To enforce our policies and protect the Services. We may process information to detect fraud, prevent abuse, investigate violations of our Terms of Service, and protect the security and integrity of the platform.

To comply with legal obligations. We may process or disclose information as required by applicable law. See Section 11 for our specific position on law enforcement requests.

What we never do
We do not use Customer Data to train AI models, ours or anyone else's. We do not analyze your content to derive insights for sale or licensing. We do not use your data for advertising. Our business model is subscription revenue. Your data is not part of it.

5

How We Share and Disclose Information

We do not sell your Personal Data or Customer Data. We do not license it or share it with third parties for their commercial use. We share information only in the following circumstances:

5.1 With your direction. When you or an authorized workspace administrator configures an integration, grants access to a teammate, or exports data, we act on those instructions.

5.2 With service providers. We engage a limited number of third-party vendors who process information on our behalf to support infrastructure, billing, security, and communications (e.g., cloud hosting, payment processing, email delivery). These vendors are bound by data processing agreements that restrict their use of your information to the specific services they provide to us.

5.3 With AI model providers. When a Bee executes a task, content from your Hive context may be transmitted to third-party AI providers. This is described in detail in Section 6. This is an operational necessity of the platform and not a sale or disclosure for external purposes.

5.4 During a corporate transaction. If Buzzy Media LLC is involved in a merger, acquisition, asset sale, bankruptcy, or similar transaction, Customer Data and Account Information may be transferred as part of that transaction, subject to confidentiality obligations. We will notify affected users as required by applicable law.

5.5 Aggregated or de-identified data. We may share aggregated, anonymized data (e.g., platform-wide usage statistics) that cannot reasonably be used to identify any individual or organization.

5.6 Legal and safety disclosures. See Section 11 for our specific policy on government and law enforcement requests. We will also disclose information when necessary to prevent imminent harm to persons or property.

5.7 Professional advisers. We may share information with our legal counsel, accountants, auditors, and insurers as necessary for them to provide professional services to us, subject to confidentiality obligations.

6

Third-Party AI Providers

HiveBoss routes Bee task execution through one or more third-party AI model providers. When a Bee runs, content from your Context Graph and task input may be transmitted to the applicable provider as part of the API request. This is fundamental to how the platform operates.

We do not have control over AI providers' data practices beyond what their published terms permit. Your use of the Services constitutes acknowledgment that data may flow to these providers under those terms.

"Not used for training" is not the same as "not retained." Some AI providers retain API inputs and outputs for limited periods to support abuse monitoring, security, or service reliability, even when their terms prohibit training on customer content. We select providers whose API terms prohibit training on customer content by default, and we do not opt into provider training or feedback programs using your data.

Google user data accessed through Gmail or Google Drive is governed by Section 7 and is not used to train any AI provider's models.

7

Google User Data

If you choose to connect a Google account to HiveBoss, you authorize us to access certain data from your Google account through Google APIs. We request only the access needed to provide the features you enable, and you can review or revoke this access at any time at myaccount.google.com/permissions.

Gmail access. When you connect Gmail, we request the narrowest scopes required for the features you enable:

  • View your email messages and settings (gmail.readonly), to allow a Bee to read a specific email thread or message that you have explicitly directed it to process, such as summarizing a thread, extracting action items, or drafting a reply. HiveBoss does not scan your inbox continuously or read mail outside of a task you initiate.
  • Send email on your behalf (gmail.send), to allow a Bee to send an email after you have reviewed and approved it as part of a workflow. No email is sent from your account without a task explicitly authorized by you or a workspace administrator you have delegated.
  • Manage drafts and send emails (gmail.compose), to allow a Bee to create a draft in your Gmail inbox for your review before sending. Drafts appear in your Gmail Drafts folder and are not delivered until you send them.

Google Drive access. When you connect Google Drive, we request the narrowest scopes required for the features you enable:

  • View and manage Google Drive files that you have opened or created with HiveBoss (drive.file), to allow a Bee to read, summarize, extract from, or otherwise process specific files that you have explicitly selected or shared with HiveBoss. HiveBoss does not access files in your Drive that you have not selected or shared with the application.
  • Where a feature you enable requires broader read access (for example, ingesting a collection of files into your Context Graph), HiveBoss may request view-only access to your Drive files (drive.readonly). When a broader scope is requested, the Google consent screen will display the specific scope before you authorize it.

How we use it. We use Google user data only to provide and improve user-facing features that you initiate within HiveBoss. We do not use Google user data for advertising, and we do not sell it.

How we store and share it. We store Google user data only as long as needed to provide the feature you enabled. We do not share it with third parties except as necessary to provide that feature, to comply with applicable law, or with your direction. When Google user data is transmitted to an AI model provider to execute a task you initiated, that transfer is limited to the data necessary for the task and is subject to the no-training commitments in Section 6. If you disconnect your Google account, we delete the associated Google user data from production systems within 30 days. Derived Content that you saved into your Hive is governed by Section 8.

Human access. We do not allow humans to read your Google user data except: (a) with your explicit consent; (b) where necessary for security purposes, such as investigating abuse; (c) to comply with applicable law; or (d) where the data has been aggregated and anonymized such that it no longer identifies you.

AI and machine learning. We do not use Google user data to develop, improve, or train generalized or non-personalized AI or machine learning models.

Google API Limited Use
HiveBoss's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

8

Connected Service Data Lifecycle

This section explains what happens to data that HiveBoss accesses through a Connected Service. The same lifecycle applies to Gmail, Google Drive, Slack, and any other Connected Service you authorize.

Temporary processing. When you direct a Bee to act on Connected Service Data (for example, summarize a specific email thread, extract information from a specific Drive file, or draft a Slack reply), HiveBoss temporarily retrieves and processes only the data necessary to complete that task. We do not continuously scan a Connected Service unless a feature you have specifically enabled requires it, and any such ongoing access is disclosed in-product before you enable the feature.

Derived Content. If you direct HiveBoss to save the output of a task into your Hive (for example, by adding a summary to your Context Graph, generating a HiveReport, or storing an extracted note), that saved output becomes Derived Content and is treated as Customer Data. Derived Content is retained according to your workspace settings and the retention provisions in Section 9.

Disconnection. Disconnecting a Connected Service revokes HiveBoss's access tokens and deletes any temporarily stored Connected Service Data from production systems within 30 days. Disconnection does not automatically delete Derived Content that you previously saved into your Hive. To delete Derived Content, delete it through your Hive controls or contact us at privacy@hiveboss.ai.

Residual copies. Residual copies of Connected Service Data and Derived Content in backup systems are purged within 90 days of deletion from production.

9

Data Retention

We retain Customer Data in accordance with your account settings and our operational requirements to deliver the Services. You may configure retention settings for certain data types within your Hive.

If you close your account, your Customer Data is deleted from production systems within 30 days. Residual copies in backup systems are purged within 90 days of deletion from production. After deletion, we will not be able to recover your data.

We retain Account Information and Usage Data for as long as necessary to fulfill the purposes described in this Policy, to comply with legal obligations, resolve disputes, and enforce our agreements. We may retain de-identified or aggregated Usage Data indefinitely.

HiveReports and Honey transaction records are retained for the life of your account and for a minimum of 12 months following account closure to support billing dispute resolution and audit obligations.

10

Security

We implement and maintain technical and organizational security measures appropriate to the sensitivity of the information we process. Our practices include:

  • Encryption of Customer Data in transit (TLS 1.2+) and at rest (AES-256).
  • Access controls enforced at the node level within the Context Graph, aligned with the permission model you configure for your Hive.
  • Logical isolation between organizations: Customer Data for one Hive is not accessible to any other Hive.
  • Internal access to Customer Data restricted to personnel who require it to provide support or maintain the platform, and only as authorized by you.

No system connected to the internet can guarantee absolute security. We encourage you to use strong, unique credentials and report any suspected security issues to hello@hiveboss.ai.

12

Age Limitations

The Services are not directed to, and we do not knowingly collect Personal Data from, individuals under the age of 16. If you believe a minor under 16 has provided Personal Data to us, contact us at privacy@hiveboss.ai and we will take steps to delete that information.

13

Cookies and Tracking

We use cookies and similar technologies for the following purposes only:

  • Essential operation: session management, authentication tokens, routing to your Hive, and security controls. These cannot be disabled without impairing core platform function.
  • Preference memory: storing your display and notification preferences across sessions.
  • Aggregate analytics: understanding overall usage patterns and platform performance using anonymized, non-identifiable data. We do not use third-party advertising networks or behavioral tracking tools.

We do not use tracking cookies for advertising. We do not build behavioral profiles for sale or license. We do not use third-party retargeting pixels.

You can configure cookie preferences through your browser settings. Disabling essential cookies will impair your ability to use the platform.

14

International Data Transfers

HiveBoss is operated from the United States. If you access the Services from outside the United States, your information may be transferred to, stored, and processed in the United States and in other countries where our service providers maintain infrastructure.

For Users in the European Economic Area (EEA), the United Kingdom, or Switzerland, we rely on Standard Contractual Clauses approved by the European Commission (and their UK equivalents) as the legal mechanism for transferring Personal Data outside the EEA and UK. A copy of our data processing addendum incorporating these clauses is available upon request at privacy@hiveboss.ai.

15

Your Rights

Depending on your jurisdiction, you may have the following rights with respect to your Personal Data:

  • Access: the right to request a copy of the Personal Data we hold about you.
  • Correction: the right to request correction of inaccurate Personal Data.
  • Deletion: the right to request deletion of your Personal Data, subject to legal retention requirements.
  • Portability: the right to receive your data in a structured, machine-readable format.
  • Objection: the right to object to processing based on our legitimate interests.
  • Restriction: the right to request restriction of processing in certain circumstances.
  • Withdrawal of consent: where we rely on consent, the right to withdraw it at any time.

You can exercise many of these rights directly within your account settings or by exporting your data through the platform. For requests that cannot be fulfilled through account settings, contact us at privacy@hiveboss.ai. We will respond within 30 days, or as required by applicable law. We may ask you to verify your identity before processing a request.

Workspace Administrators. If your Hive is administered by your employer or another organization, that organization is the controller of the Customer Data within that Hive. Privacy requests relating to Customer Data should generally be directed to that organization, and we will support the organization in responding as required by applicable law.

16

California Privacy Rights (CCPA / CPRA)

This section applies to California residents and supplements the rest of this Policy. Under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), California residents have additional rights regarding their Personal Information.

Categories of Personal Information collected: We collect identifiers and contact information; commercial information (billing and subscription data); internet or electronic network activity information (Usage Data); approximate geolocation (from IP); and inferences drawn from the above to operate and improve the Services.

Business purposes for collection: As described in Section 4 of this Policy.

We do not sell Personal Information. We do not share Personal Information for cross-context behavioral advertising.

California rights: California residents may request to know the categories and specific pieces of Personal Information we have collected, request deletion, request correction, opt out of any future sale (none currently occurs), and not be discriminated against for exercising these rights.

To submit a California rights request, contact us at privacy@hiveboss.ai. We will verify your identity using information associated with your account. You may designate an authorized agent to submit a request on your behalf; authorized agents must provide written authorization.

If you would like to exercise a Global Privacy Control, we honor GPC signals received by our web properties as an opt-out of sale and sharing under CPRA.

17

Changes to This Policy

We may update this Privacy Policy from time to time as the Services evolve, as legal requirements change, or as we refine our data practices. We will post the updated Policy at this URL and update the effective date.

If we make changes that materially affect your privacy rights (such as a change to how we use Customer Data, a new category of sharing, or a change to our law enforcement disclosure policy), we will provide advance notice via email to your registered address and/or through a notice within the platform, no less than 14 days before the change takes effect. Your continued use of the Services after that notice period constitutes acceptance of the updated Policy.

18

Contacting Us

For any questions, concerns, or requests related to this Privacy Policy or our data practices:

Privacy & data questions: privacy@hiveboss.ai
All other inquiries: hello@hiveboss.ai

Mailing address:
Buzzy Media LLC
Attn: Privacy
150 Country Estates Circle, Suite 110
Reno, Nevada 89511

We aim to respond to all privacy-related inquiries within 5 business days and to fulfill requests within 30 days, or within the timeframe required by applicable law.