Skip to content

Privacy & data handling

You test business-sensitive things here — unreleased copy, product pages, concepts. This explains, in plain terms, what happens to that content.

What we collect

The content you submit to test — pasted text, page content, uploaded images, and, for task studies, the target website URL — plus the study settings you choose (persona, cohort size, research question). For your account: your email and, if you sign in with Google, your name and avatar. We also keep operational logs (who did what, and when) for security and troubleshooting.

How your content is used

To run your study, your content is sent to our AI provider (Anthropic) to generate the simulated cohort’s reactions and the collated summary. That is the only purpose it is used for. Anthropic does not train its models on content sent through its API, and we never repurpose your content to train, fine-tune, or improve any model. For task studies, the study also opens the target website you specify in an isolated browser to let the cohort attempt the task; it will not follow links off that site, and never submits payment or login details.

Where it’s stored

Your studies and their results are stored in our database (Supabase, hosted in the EU), encrypted at rest. Uploaded images live in a private storage bucket, reachable only through short-lived signed links. All traffic is encrypted in transit (TLS). Each workspace’s data is isolated from every other workspace.

Who processes it

We rely on a small set of infrastructure providers (“subprocessors”) to run the product. Content only reaches those needed to do so:

  • Anthropicruns the simulated cohort and summary — does not train on your content
  • Supabasedatabase, file storage, and sign-in
  • Netlifyhosts the web app
  • Fly.ioruns studies in the background
  • Resendsends account and invite emails

Retention & deletion

Your studies stay until you delete them. You can export any study, and you can ask us to delete your content or your whole account — we’ll remove it from our database and file storage. Our AI provider may briefly retain API content for its own safety and abuse monitoring under its policy; it is not used for training and ages out.

Security

Encryption at rest and in transit; per-workspace isolation; strict controls on the addresses a study may reach (no internal or private networks); and an append-only audit trail of security-relevant actions. We’re building toward formal SOC 2 assurance.

Your choices

You can access and export your studies at any time, and request deletion of your content or account. For any privacy question, or to exercise these rights, contact us at sparebrain@hereinthehive.com.

Last updated 2026-07-17