Privacy Policy

Last updated: August 7, 2026

1. Scope & Roles

This Privacy Policy explains how Hiveflow, Inc. ("Hiveflow", "we") handles personal information in connection with the Hiveflow platform.

  • Account & website data: for information we collect about our account holders and website visitors, Hiveflow acts as the data controller.
  • Customer content: for data our customers submit into their workflows ("Customer Content"), the customer is the controller and Hiveflow acts as a data processor, processing it solely under the customer's instructions and the applicable Data Processing Agreement (DPA).

2. Information We Collect

  • Account information (name, email address, and, where provided, phone number)
  • Authentication data (hashed passwords, OAuth identifiers)
  • Usage data, logs and analytics
  • Device and browser information
  • Cookies and similar technologies (see our Cookie Policy)
  • Customer Content processed on the customer's behalf within workflows, per the DPA

3. How We Use Your Information

  • To provide, operate and secure our AI workflow orchestration platform
  • To communicate with you about your account and our services
  • To improve our services, subject to the limitation below
  • To detect, prevent and respond to security incidents and fraud
  • To comply with legal obligations

We do not use Customer Content to train foundation or machine-learning models. Customer Content is processed only to deliver the service as configured by the customer.

4. Information Sharing & Subprocessors

We do not sell your personal information. We share information only:

  • With subprocessors that help operate the platform (infrastructure, storage and AI model providers), under contractual confidentiality and security obligations. See AI model providers below for how content is shared with AI services, and the current full list at our Trust Center.
  • To comply with legal obligations or lawful requests
  • To protect the rights, safety and security of Hiveflow, our customers and the public
  • In connection with a merger, acquisition or asset sale, subject to this policy

5. AI Model Providers

Hiveflow builds and runs automations using large language models. To do that, we send parts of your content to the AI provider you select. This section explains exactly what is sent, to whom, and what happens to it.

What we send

  • The messages you write to Genius and to your agents, including the conversation history needed for context
  • Files you attach to those conversations (documents, spreadsheets, images), and text extracted from them
  • The content your flows process at run time — for example the body of an email a flow was built to summarize, or a record a flow was built to classify
  • The configuration of the flow or agent being executed, such as its instructions and the description of the tools it may call

We do not send your account credentials, payment details, or the credentials of your connected integrations to AI providers.

Who we send it to

Content is sent from Hiveflow's servers to the provider selected for each flow or agent. You choose the provider and the model, and you can change or remove them at any time. Depending on that choice, the recipient may be:

  • OpenAI (OpenAI, L.L.C.)
  • Anthropic (Anthropic PBC)
  • Google (Gemini and Vertex AI)
  • Microsoft (Azure OpenAI Service)
  • Amazon Web Services (Bedrock)
  • Groq, Mistral AI, Perplexity, Friendli and Hugging Face

If you supply your own API key for a provider, content is sent to that provider under your own agreement with them. The current, authoritative list of subprocessors is maintained at our Trust Center.

How it is used, and how long it is kept

  • Content is sent for one purpose only: to produce the output your flow, agent or conversation asked for.
  • It is not used to train foundation or machine-learning models, neither by Hiveflow nor by our AI providers. We contract with these providers on terms that exclude training on customer content.
  • It is not sold, and it is not shared for advertising or advertising measurement.
  • Providers may retain content briefly for abuse monitoring under their own terms. We require subprocessors to offer confidentiality and security protections equivalent to those described in this policy.
  • Conversations and flow results are stored in your Hiveflow workspace until you delete them, or until your account is deleted.

Your consent and control

In the Hiveflow mobile apps we ask for your explicit permission before any content is sent to an AI provider, and nothing is sent until you agree. You can withdraw that permission at any time in Settings → Privacy → AI data sharing. On the web you control it by choosing which flows and agents to run, and which provider each one uses. Withdrawing consent or removing the provider stops further processing; it does not undo processing already carried out.

6. Data Security

We apply technical and organizational measures appropriate to the risk, including:

  • Encryption in transit (TLS 1.2+) and encryption of sensitive data at rest (AES-256-GCM)
  • Multi-tenant isolation across the data, API and real-time layers
  • Role-based access control, MFA and server-side session revocation
  • Isolated code execution (micro-VMs) and centralized logging with security alerting

We will notify affected customers of a personal-data breach without undue delay and, where applicable, within 72 hours of becoming aware. Further detail is available in our Trust Center.

7. Data Retention & Deletion

We retain personal information for as long as your account is active or as needed to provide the service, then delete or anonymize it. On termination, Customer Content is deleted within 30 days, subject to legal retention requirements and the DPA. Enterprise customers may configure specific retention periods.

8. International Transfers

Hiveflow is based in the United States and may process information in the U.S. and other countries where our subprocessors operate. Where required, we rely on appropriate transfer mechanisms (such as Standard Contractual Clauses or documented consent). Data residency options are available for enterprise customers.

9. Your Rights

Depending on your location, you may have the following rights. To exercise them, contact privacy@hiveflow.ai. Where Hiveflow acts as processor, we will refer requests to the relevant customer (controller).

  • GDPR (EEA/UK): access, rectification, erasure, restriction, portability and objection.
  • CCPA/CPRA (California): to know, delete, correct, and opt out of "sale"/"sharing", note we do not sell personal information, without discrimination.
  • LFPDPPP (Mexico): ARCO rights, Acceso, Rectificación, Cancelación y Oposición, and revocation of consent.
  • Opt out of marketing communications at any time.

10. Children's Privacy

Hiveflow is not directed to children and is intended for use by individuals of legal age. We do not knowingly collect personal information from children.

11. Google API Services & Limited Use

Hiveflow lets you connect your Google account (for example Gmail, Google Sheets, Google Docs, Google Slides, Google Drive and Google Calendar) so that your own workflows can read and write data on your behalf, strictly according to the automations you configure.

Hiveflow's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use and transfer of raw or derived user data received from Google Workspace APIs likewise adheres to that policy, including its Limited Use requirements.

In particular:

  • We only use Google user data to provide and improve the user-facing features you explicitly configure in your workflows (e.g., reading an incoming email to log it into a spreadsheet you chose).
  • We do not transfer Google user data to third parties except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition with prior notice.
  • We do not use Google user data for advertising, and we do not sell it.
  • No humans read your Google user data unless you give us explicit permission (e.g., a support request), it is required for security purposes or to comply with the law, or the data has been aggregated and anonymized.
  • Google Workspace data is not used to develop, improve, or train generalized artificial intelligence or machine learning models. Where a workflow you configure sends specific content to an AI model to perform the task you requested, that content is used solely to execute your workflow.
  • OAuth tokens are stored encrypted (AES-256) and you can revoke Hiveflow's access at any time from your Google Account settings or by disconnecting the integration inside Hiveflow.

12. Changes & Contact

We may update this policy from time to time; material changes will be posted here with a revised date. Questions or requests: privacy@hiveflow.ai. For a Data Processing Agreement, contact security@hiveflow.ai.

Usuarios en México (LFPDPPP): consulta nuestro Aviso de Privacidad y los Términos y Condiciones.