Privacy policy.
Our business is building systems that live in your storage, on your machine. That shapes everything on this page: we collect little, and your workspace data mostly never touches us.
1. What we collect
- Site forms. When you fill out a form on this site (an application, the readiness check, a resource request), we collect what you type: typically your name, email, and your answers.
- Checkout data. Purchases run through Stripe. We receive your name, email, what you bought, and payment status. Your card number goes to Stripe, never to us.
- Acceptance records. When you accept our purchase terms and complete the data-ownership attestation, we store that acceptance with your email and a timestamp.
- Intake submissions. To build your workspace, you send us intake material: answers about your role, methodology, and voice, and any files you choose to upload. This is the most sensitive thing we hold, and sections 4 and 6 cover how we limit and retire it.
- Support email. If you email us, we keep the thread so we can help you.
- Site analytics. We use Vercel's privacy-focused analytics to count visits and page views. We do not run advertising trackers.
2. What we use it for
One purpose: selling, building, delivering, and maintaining your workspace, and supporting you afterward. We do not use your data for advertising. We send operational email about your order and, if you opt in, occasional product email you can leave with one click.
3. Who processes it
We use a short list of service providers. Each sees only what its job requires.
| Processor | What it does for us |
|---|---|
| Anthropic | Runs Claude for build and maintenance work and processes Cowork sessions through the account and plan used for that session. Anthropic's handling is governed by that account's plan, settings, and terms. |
| Stripe | Payment processing and checkout. Holds your card details; we never see them. |
| Dropbox | Buyer-owned workspace storage. Your root lives in your own account; we hold scoped membership to its System subfolder only, as described in section 4. |
| Supabase | Stores intake submissions, readiness-check results, and terms-acceptance records. |
| Resend | Sends our transactional email (order confirmations, delivery notices). |
| Vercel | Hosts this website and provides its analytics. |
| Google Workspace | Our email and internal documents, including support threads you send us. |
If this list changes, we update this page before the new processor touches client data.
4. The folder-access model
Your workspace is a folder in your own storage account. You own it. You control who is in it. We are not a hosting company holding your data; we are a builder with a narrow, visible key.
- Our standing access is limited to the managed System area of your workspace: skills, templates, and the guide. That is how updates reach you.
- Your deal data, transcripts, and client files sit outside that area. We do not have standing access to them.
- For a refresh, you can grant broader access. It is scoped to the job, time-boxed, logged, and revoked when the refresh is done.
- Heavy business data (CRM exports, email history) loads directly into your folder on your machine during the install call. It does not pass through our systems and is never stored on our side.
5. What we never do
- We never sell your data. Not to brokers, not to "partners", not to anyone.
- We never use your data to train public AI models.
- We never use one client's data for another client. Your workspace is built from your material and our own templates, nothing else.
6. Retention and deletion
Our defaults:
- Intake submissions and uploads: deleted from our systems within 90 days after your delivery is accepted. If you are on maintenance, we keep only what the service needs, and delete the rest on the same schedule.
- Readiness-check and terms-acceptance records: kept for as long as we could need to prove the terms of your purchase.
- Payment records: kept as required by tax and accounting law.
- Support email: kept while you are a client, deleted on request.
Deletion on request: email hello@humnminds.ai and we will delete the personal data we hold about you, except records we are legally required to keep. We confirm when it is done. Your own workspace is untouched by any of this; it is yours and lives in your storage.
7. Your choices and rights
- Ask us what we hold about you, and we will tell you.
- Ask us to correct it or delete it.
- Leave any marketing email with one click.
- Remove our membership from your workspace folder at any time. Updates stop; your ownership does not.
8. Contact
TGAI LLC dba HUMN Minds, Washington, USA.
Email: hello@humnminds.ai
If we change this policy, we update the date at the top and keep prior versions available on request.
HUMN