Privacy Policy
This Privacy Policy explains how Militant.AI ("we", "us", "our") handles information in connection with the Hivemind service, the Hivemind website, dashboard, and API (together, the "Service"). By using the Service you agree to this policy together with our Terms of Service.
1. Who we are
The Service is operated by Militant.AI, based in Queensland, Australia. For any privacy question or request, contact support@militant.ai.
2. Information we collect
- Account information — when you sign up, our identity provider (WorkOS) processes your email address, name, organization, and authentication credentials. We receive an organization identifier and basic profile details; we never receive or store your password.
- Memory content — the memories, conversations, metadata, and context you send to the API for storage and retrieval. This content is whatever you choose to submit, and may include information about third parties if you submit it. The Service also records operational receipts for API operations (an audit trail of what was stored, recalled, and compiled, which may include short previews of submitted content); receipts are stored alongside your memory content, count toward your storage, and are visible only to your tenant.
- Usage and diagnostic data — for each API request we record a request identifier, your tenant identifier, the endpoint called, status code, request and response sizes, latency, and timestamp. We use this to operate, secure, meter, and bill the Service.
- Billing information — if you subscribe to a paid plan, our payment processor (Stripe) handles your payment details. We do not store full card numbers; we retain a customer reference, plan, and billing status.
- Waitlist and contact information — if you join the waitlist or contact us, we keep the email address you provide and use it only to respond and to tell you about access to the Service.
3. How we use information
- To provide the Service: store, recall, and compile the memory and context you submit.
- To authenticate you and isolate your data to your own tenant.
- To enforce plan limits, capacity, and rate limits, and to bill usage.
- To secure the Service, investigate abuse, and diagnose faults.
- To communicate with you about your account and the Service.
We do not sell your data. We do not use the content of your memories to train models, and we do not share it with other customers. Our tenant isolation is designed so that one customer's data is not reachable by another.
4. Disclosure, subprocessors, and where data is stored
We disclose data only as described here: to the service providers below, transmitted over encrypted connections (TLS) through their APIs, limited to what each needs to perform its function. We may also disclose information where required by law or valid legal process, or where necessary to protect the rights, safety, or security of the Service, our users, or the public — and where lawful, we will tell you before or after such disclosure. We do not otherwise share, rent, or sell your information.
The providers we rely on to run the Service:
| Provider | Purpose |
|---|---|
| WorkOS | Authentication, accounts, API-key management |
| Convex | Account, plan, and tenancy control-plane records |
| Qdrant Cloud | Storage of memory content and vector embeddings |
| DigitalOcean | Compute hosting the API service |
| Vercel | Website and dashboard hosting |
| Stripe | Payment processing (paid plans only) |
These providers may store or process data in regions outside your own country, including the United States and the European Union. By using the Service you consent to such transfers.
Bring-your-own (BYO) storage: if you connect your own Qdrant cluster — self-hosted, or a managed Qdrant service under your own account, on whatever infrastructure and in whatever region you run it — your memory content and receipts are stored in that cluster rather than in our storage, and its security and retention are under your control. We store the access credentials you supply in encrypted form and use them solely to operate the Service against your cluster.
5. Security
We take reasonable measures to protect data, including encryption in transit (TLS), authentication on every request, per-tenant access scoping, encryption of customer-supplied storage credentials at rest, and restricted administrative access.
Security at rest follows the storage host. In managed mode, memory content is held by our storage provider (Qdrant Cloud) and inherits the infrastructure-level protections that provider maintains, including encryption at rest on its clusters; we do not apply an additional application-layer encryption of memory content on top of it. In BYO mode, at-rest security is that of your own cluster and is entirely under your control.
We want to be clear about current limits: Hivemind is an alpha service and we hold no formal security certifications of our own (such as SOC 2 or ISO 27001). Do not submit data whose sensitivity exceeds what this posture warrants. If you require a specific security or compliance posture, contact us before relying on the Service. No transmission or storage system is completely secure and we cannot guarantee absolute security. If a data breach occurs that is likely to result in serious harm, we will notify affected account holders and the relevant regulators as required by applicable law, including the Australian Notifiable Data Breaches scheme.
6. Retention and deletion
- Memory content is retained until you delete it (via the API or dashboard) or your account is closed.
- When you delete a memory it is removed from retrieval; residual copies may persist briefly in backups before expiring.
- If you cancel a paid plan, we provide a window to export your data before the associated storage is released. See the Terms of Service for the current window.
- Usage and diagnostic logs are retained for a limited period for security and billing, then rotated.
- Records we are required by law to keep — such as billing, invoicing, and tax records — are retained for the statutory period (generally 5–7 years in Australia) even after account closure. These are commercial records, not your memory content.
7. Your rights
You may access, export, correct, or delete your data through the API, the dashboard, or by contacting us. Depending on where you live, you may have additional rights under laws such as the Australian Privacy Principles or the EU General Data Protection Regulation, including the right to complain to a regulator. We will honor valid requests within the timeframes those laws require. Our claim-level lineage is designed to make deletion and purge-by-source supported operations rather than best-effort ones.
8. Business customers (controller / processor)
If you use Hivemind to store data about your own users or customers, you act as the data controller for that data and we act as your processor. You are responsible for having a lawful basis and any necessary consent to submit that data, and for your end users' rights. We process it only to provide the Service and on your instructions. Business customers requiring a data processing agreement should contact us.
9. Children
The Service is not directed to individuals under 16, and we do not knowingly collect their personal information.
10. Changes to this policy
We may update this policy as the Service evolves. Material changes will be reflected by the "last updated" date above and, where appropriate, notified to account holders.
11. Contact
Questions or requests: support@militant.ai.