Privacy Policy
Effective 11 August 2026
This summary is for orientation only. The numbered sections below are the agreement; where the two differ, the sections govern.
01Who we are, and which hat we are wearing
Honey Nudger Inc. operates DeepSieve. This policy explains what personal data we handle, why, and what you can do about it.
The distinction that governs everything below is which role we are in, because our obligations differ:
- We are the controller for data about our own users and visitors — your account, your billing details, how you use the product, and your messages to support. See what we collect through your rights.
- We are a processor for the research you direct. You choose the subject, the schema and the schedule; we execute it and store the result in your workspace. You are the controller of that data, and personal data in research results covers what that means — including for people who appear in your results and never signed up for anything.
Contact for privacy questions, data-subject requests and Data Processing Agreements: support+deepsieve@honeynudger.ai.
If you need our registered postal address for a formal notice, ask at support+deepsieve@honeynudger.ai and we will provide it.
02What we collect about you
| Category | What it is | Where it comes from |
|---|---|---|
| Identity and account | Name, work email, organisation, role, and the identity provider you signed in with. | You, and WorkOS when you sign in through SSO. |
| Billing | Plan, credit balance, invoices, transaction history, and the last four digits and brand of your card. We never receive or store your full card number. | You, via Stripe; usage rating via Metronome. |
| Product usage | Runs started, reports created, API calls, feature usage, timestamps, and errors. | Generated as you use the Service. |
| Technical | IP address, browser and device type, and request logs — kept for security, abuse prevention and debugging. | Automatically, when you connect. |
| Communications | Support messages, and delivery events for the transactional email we send you. | You, and Resend. |
| Research content | Your prompts, seed lists, Blueprints and results. Treated as your confidential data, not as data about you. | You, and the public web sources a run reads. |
We do not collect sensitive personal information as that term is defined by California law for the purpose of inferring characteristics about you, and we do not ask for government identifiers, precise geolocation, biometrics or health data.
03Why we use it, and our legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Provide the Service, run research you request, and store your results | Performance of a contract |
| Take payment, rate usage, issue invoices and chase unpaid amounts | Performance of a contract; legal obligation |
| Send transactional email — receipts, billing notices, retention and deletion warnings | Performance of a contract; legal obligation |
| Keep the Service secure: authentication, abuse and fraud prevention, logging | Legitimate interests in operating a secure service |
| Understand aggregate usage to fix bugs and improve the product | Legitimate interests in improving our service |
| Product and marketing email that is not transactional | Consent — withdraw it at any time via the unsubscribe link |
| Comply with law, respond to lawful requests, and defend claims | Legal obligation; legitimate interests |
04We do not train models on your data, and we do not sell it
Your Blueprints, prompts, research and exports are never used to train models — ours or a provider’s. We send prompts to model providers under zero-retention terms where the provider offers them.
We do not sell personal information, and we do not share it for cross-context behavioural advertising — as those terms are defined by the California Consumer Privacy Act. We have not done so in the preceding twelve months. There is no “Do Not Sell or Share My Personal Information” link on this site because there is nothing for it to switch off.
We do not use your personal data to make decisions about you by automated means that produce legal or similarly significant effects.
07How long we keep it
- Research and workspace data — for as long as your account is active. After cancellation you keep read-only access for one year, and we email you at closure and again 90, 30 and 7 days before deletion. At the end of the window the workspace and its contents are deleted, irreversibly.
- Account and identity data — for as long as the account exists, then deleted with the workspace.
- Billing records — kept for as long as tax and accounting law requires, typically seven years, even after deletion of the rest.
- Security and request logs — a short rolling window, then discarded.
- Backups — age out on their own schedule after deletion, rather than being edited in place.
08How we protect it
TLS 1.2 or better in transit, AES-256 at rest for the database, object storage and backups. Hosting is on AWS in private subnets behind a web application firewall. Access is role-scoped, and API keys can carry their own run and spend budgets so an integration can never exceed what you minted it for.
Every workspace is a separate database schema and the search path is set per transaction, so isolation between tenants is enforced by the database rather than by a query filter someone has to remember to write.
No system is perfectly secure. Our current certification status — including what is complete and what is in progress — is published without a sales call in our Trust Center. If you believe you have found a vulnerability, write to support+deepsieve@honeynudger.ai.
09Personal data that appears in research results
This section is specific to what DeepSieve does, and it matters more than anything else on this page.
The Service researches the public web. Depending on what you ask it to research, results may contain personal data about identifiable people — executives, founders, authors, public officials — who have no relationship with us and never agreed to anything.
For that data, you are the controller and we are your processor. You decide the subject matter and the schema; we execute the run under your instructions. That allocation has consequences you should be clear about before you point the product at people:
- You need a lawful basis for collecting it, and you are responsible for identifying one.
- Where the law requires notice to people whose data you collect indirectly (GDPR Art. 14), that obligation is yours.
- You must not use the Service to build surveillance profiles, re-identify de-identified data, or make employment, credit, housing, insurance or similar decisions about people. Our Terms prohibit all of it.
- A Data Processing Agreement is included on Pro and Enterprise, and available on Starter by asking us. No sales call either way.
If you are a person who has found your own data in someone’s DeepSieve dataset, write to support+deepsieve@honeynudger.ai. We will route your request to the customer who controls it, and we will assist them in responding as the law requires. Where we hold the data as a processor we cannot unilaterally delete a customer’s records, but we will not ignore you and we will tell you what we did.
10Your rights
Depending on where you live, you have some or all of the following rights over personal data we hold about you as a controller:
- Know and access — what we hold, where it came from, why we have it, and who we disclosed it to.
- Correct — fix data that is wrong or incomplete.
- Delete — have it erased, subject to records we must keep by law.
- Port — receive it in a portable format. Your research data is exportable as CSV, JSON or NDJSON from the product at any time, with citations intact.
- Object and restrict — object to processing based on legitimate interests, or ask us to restrict it while a dispute is resolved.
- Withdraw consent — where we rely on consent, withdraw it without affecting what came before.
- Opt out of sale or sharing — we do neither, so there is nothing to opt out of.
- Non-discrimination — exercising these rights will never cost you a worse price or a worse service.
Write to support+deepsieve@honeynudger.ai to exercise any of them. We will verify your identity against the account, respond within the statutory window — 30 days under GDPR, 45 days under California law, extendable where the law allows and we tell you — and we will not charge you for it. An authorised agent may act for you with written permission. If we refuse a request we will say why, and you may appeal by replying to our response.
EU/UK residents: you may also complain to your local supervisory authority, or to the UK Information Commissioner’s Office. We would rather you came to us first.
11International transfers
We host in the United States by default; regional (EU) hosting is available on Enterprise plans. If you are outside the US, using the Service involves transferring your data to the US. Where we transfer personal data out of the EEA or the UK, we rely on the European Commission’s Standard Contractual Clauses and the UK Addendum, together with the technical measures described above.
12Children
DeepSieve is a business product and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, tell us at support+deepsieve@honeynudger.ai and we will delete it.
13Changes to this policy
We review this policy at least annually and update it when our practices change. If a change is material we will notify you by email or in the Service before it takes effect, and the effective date at the top of this page will change.
Honey Nudger Inc. · Privacy questions and data-subject requests: support+deepsieve@honeynudger.ai · Terms of Service · Trust Center