Legal
Privacy policy
You should be able to read this in one sitting and know exactly what we hold on you, who can see it, and how. So here it is.
The short version.
- What you know lives in a store that is yours alone. One per account, nobody else's in it.
- Other people read of you only through an audience you set. Anything an audience doesn't name is not shared.
- A thing an audience keeps back never reaches the model. It isn't hidden by an instruction; it isn't there.
- Every answer your page gives is logged for you: who asked, through which audience, what was drawn on.
- Nothing you put in trains anything. No advertising trackers; the one count of visits we keep sets no cookie and knows no one.
What we hold
Your account. Your email address, a name if you gave one, a hash of your password if you set one, the sessions you're signed in on with the browser each was opened from, when you agreed to the terms and which version, and your mail preferences. If you sign in with Google or LinkedIn we keep the identifier they hand us and the picture they publish, which becomes your face until you change it. We never see their password and they never see yours. If the link you first arrived by said where it was posted, or you came from another site, the account keeps that one word (see cookies, below).
What you know. Everything you put into your store: things you typed, answers you gave the interview, entries from a LinkedIn export you chose to import (read in your browser; the file itself is never sent to us), pictures you attached, replies you wrote in a space, and things an assistant you connected proposed and you confirmed. Each carries a name, a source and the date it was observed. Nothing is rewritten in place: a new version supersedes the old, and the old stays as history you can read and remove.
Your page and its settings. Your page's name and address, your face and banner, how it speaks, each audience and what it allows, the invites you issued (as a hash, never the key itself; who redeemed each and when), and the assistants you connected and what each may do.
Activity. For every question your page answers: when, through which audience, the question as it was asked, the answer, which of your things it drew on and how much of each, and how many were kept back as a count. Asking needs an account, so a question carries the asker's name and account, or, through an invite, the invite's name. Someone who opens your profile without signing in is logged too, with no name: only a one-way hash of their network address, used to limit how often one address may read.
What you asked. The questions you put to other people's pages, with the answers you were given, so you can find them again. The answers you chose to save.
Who you follow, and what you're in. The pages you follow, the spaces you joined and your role in each, the companies you administer or belong to and the domains they proved.
Mail we sent you. Which digests and notices went out and when, so we never send the same one twice.
Visits to your page. A number per day: how many people and how many robots (search engines, AI assistants, link previews) opened your page, and what kind of place they came from. Nothing about who any of them were. Only you see it, on Activity (a company's admins, for a company's page); it is kept for 400 days and goes with your page.
Operations. Request logs and traces that say a route was slow or failed. They carry ids and timings, not the contents of what you know or anyone's question. An operator's console shows the registry, never a store, a question or an answer, and every action an operator takes is logged with a reason.
Cookies and storage. One cookie holds your session while you're signed in. One lives for ten minutes while a Google or LinkedIn sign-in completes, then is gone. If you arrived from a link that named where it was posted, or from another site, one cookie keeps that one word (say, “linkedin.com”) for thirty days, and an account you make in that time records it, so we know which places are worth writing in. It holds no id and nothing about what you read. Your browser keeps your theme choice, a draft of the guided start, and a question you carried from one page to another; none of that leaves your browser. Pages are counted with Cloudflare Web Analytics: which address was opened, how fast it loaded, the site that linked here, and the country and kind of browser. It sets no cookie, keeps no address and builds no profile of anyone. There is no advertising or third-party tracker on this site.
About other people
People who ask. A question is logged for the page's owner with the asker's name, because asking needs an account; a question through an invite is logged under the invite's name. Reading a page needs no account, and a signed-out visitor who opens a profile is logged with no name. The asker sees their own question and the answer they were given; nothing else about anybody.
People you invite. When you mail an invite or a question to someone, we hold their email address for that purpose: to send one mail, to know when the link was opened, and to tell you when they answered. The mail names you as the sender and carries a way to stop.
People named in what you know. If you store something about another person, you are responsible for having the right to. The terms forbid storing what isn't yours to share, and we will remove such a thing on a well-founded report.
Who sees it, and how
Your audiences. A person asks; your page answers from the things the audience they're in allows, at the level it allows. In full means what you stored. Roughly means a coarser version made by fixed code, never by a model.Yes or no means "there is something on this" and nothing else. Hidden means it is never loaded into the answer at all. A page in draft answers nobody. Money and health are never an audience topic: nothing about either is stored, and the engine refuses to release anything under those names whatever an audience says.
The model. To turn allowed things into an answer, we send those things, the question and, if the asker gave one, a short phrase about their situation to a model through OpenRouter, by way of Cloudflare's AI Gateway. The model receives what the audience allowed and nothing else; it does not receive kept-back things with an instruction to ignore them, because an instruction is not a boundary. When an audience allows nothing for a question, no model is called. We also send each thing you store, each picture you upload and each question you ask to a small model that screens it for content the terms forbid; it returns a verdict and keeps nothing. OpenRouter and the model provider behind it process this for the duration of a request under terms that exclude training.
Us. We don't read what you know except to handle a report, fix a problem you asked us to look at, or comply with the law, and we tell you when we do.
Nobody else. We don't sell, share or license anything here to anyone, and we don't advertise.
If the law requires. We disclose what a court or a public authority lawfully compels us to, no more, and we tell you unless we are forbidden to.
Where it lives
On Cloudflare's network, which runs in many countries; your data may be stored and processed outside the country you live in. What you know sits in a storage object that belongs to your account alone; the registry, Activity and everything shared across people sit in a database; pictures in object storage; sessions and mail on the same platform. Cloudflare's AI Gateway keeps a record of each model request so we can see spend and failures; that record holds what the audience allowed, and only that. OpenRouter, in the United States, routes model requests to the model's provider. Traces of requests go to Honeycomb and carry ids and timings.
How long
For as long as your account exists, plus the history you chose to keep. Delete your account and we delete the account, what you know and its history, your pages, audiences, invites, connections, Activity, saves, follows, memberships, interview questions, pictures and mail records; your replies in rooms are blanked, and your name leaves other people's logs and rooms, which otherwise stay because they belong to those people. The one-way hash that limits how often an open-web asker may ask is not tied to an account and expires on its own.
Your rights, and how to use them
- See it. Everything we hold about you is on screen: What you know, Who can ask, Activity, and what you asked. If you want it as a file, write to us and you'll have it within thirty days.
- Fix it. Edit or remove any thing you know from your console; your name from Page; your face and banner too.
- Delete it. From the Page tab of Me, "Delete your account": type your address and password, confirm the link we mail you while signed in, and everything above is erased at once. No waiting period. If you cannot sign in, write to hello@humblekind.co from your account's address.
- Stop the mail. Every digest and notice carries a link that turns it off in one click, and Activity has the same control.
- Complain. To us first, please; and you may also complain to the privacy authority where you live, in Quebec the Commission d'accès à l'information, elsewhere in Canada the Office of the Privacy Commissioner or your province's commissioner.
Children
This service is for people 18 and older. We do not knowingly hold an account for anyone younger; tell us and it is erased.
Changes
If this policy changes in a way that matters to you, you'll be asked to agree before going on, and you'll hear about it by email first when we have a confirmed address.
Also worth reading: the terms.