Privacy Policy
Last updated: August 22, 2026
HiveMinded ("we", "us", or the "Service") is operated by HiveMinded, Inc. We respect your privacy and have built this Service so you stay in control of your family's data. This page explains what we collect, why, and what choices you have.
1. Information we collect
- Account information: name, email, optional phone number, hashed password (or Apple/OAuth subject), profile photo URL.
- Family data you create: events, chores, allowances, meals, grocery lists, photos, documents, sticky notes, messages, and related metadata. This data is scoped to your family and is never shared with other families.
- Health and medical information: optional, and only what you choose to enter. This can include allergies, medications, conditions, blood type, doctor and insurer details, insurance policy, group and subscriber numbers, photos of insurance cards, appointment dates, visit notes and diagnoses, emergency contacts, and the equivalent records for pets. On care appointments and visits, the provider's name and phone number and your free-text notes and diagnoses are encrypted with AES-256-GCM before they are written to the database. The remaining health fields — allergies, medications, conditions, blood type, emergency contacts, and insurance card details — are stored without that field-level encryption and are protected by account and family access controls. We do not connect to Apple Health, Google Fit, or any wearable, and we do not collect biometric data.
- Children's data: parents may add child profiles (name, age, optional photo) for chore assignment, allowance tracking, and chat. If a parent chooses to give a child their own login, we store a parent-chosen username and a hashed PIN — never an email address or phone number for that child — along with a record of which parent gave consent and when. We do not advertise to children, do not sell their data, and do not allow children to share data outside their own family. (See COPPA section below.)
- Usage telemetry: minimal anonymous request logs (timestamp, route, status code) for security and reliability. No third-party analytics SDKs ship in the production app.
- Payment information: processed by Stripe. We store only the transaction id, last-four of the card, and brand. We never receive the full card number.
- Push notifications: if you opt in, we store the browser-issued endpoint URL so we can deliver alerts. You can revoke at any time from your device settings or the Account page.
- Location: optional. If you enable Location Sharing, the app stores the most recent latitude/longitude per family member. You can disable this at any time.
2. How we use information
- To provide the Service — render your calendar, deliver messages, run AI assistants, etc.
- To send transactional email/SMS you have explicitly enabled (digest, reminders, invites).
- To process subscription payments and respond to refund requests.
- To detect and prevent abuse (rate limits, bot detection, audit log).
We do not sell personal information. We do not run third-party advertising in the app.
3. AI features
When you use AI features (meal suggestions, chore tips, etc.), the relevant prompt and necessary context are sent to our AI provider (currently OpenAI) under a no-training data agreement. Your data is not used to train external models.
Your Care & Health records are never part of that context — no AI feature reads them. The one exception is what you supply yourself: if you paste health details into an AI chat or upload a medical document for import, that text is sent to the AI provider like any other prompt.
4. Children's privacy (COPPA)
HiveMinded is intended for parents to use with their family, and children never sign up on their own. A parent creates a child's profile, and may also give that child a login from inside the family: the parent chooses a username and a PIN, and must affirm parental consent before the login is created. We record which parent gave that consent and when.
Logins created this way hold no email address and no phone number, and a child's account is blocked from adding either one later. We do not knowingly collect personal information from children outside the parent-managed family context, and we never require a child to provide more information than the feature needs.
Parents can review, modify, or delete their child's data, reset the PIN, or remove the login entirely at any time from the Account → Family Members page. To ask what we hold about your child, or to withdraw consent, email privacy@hiveminded.app.
Outside the United States: some countries set an age of digital consent higher than 13 — up to 16 in parts of the EU. Where that applies, a parent or guardian must create and manage the account for anyone below that age, using the parent-provisioned login described above.
5. Data sharing
We share data only with the service providers required to operate the Service:
- Stripe — payment processing
- Resend — transactional email
- Twilio — transactional SMS (optional)
- OpenAI — AI features (no training)
- Hosting — Replit Deployments / Cloudflare
We do not share data with advertisers, data brokers, or any third party for marketing purposes.
Health and medical information is not shared with any of these providers other than the hosting and storage infrastructure the Service runs on. It is never sent to our AI provider, never included in an email or SMS, and never used for marketing. Appointment reminders you mark private appear in the app under a neutral "Health reminder" label, so the detail is not exposed on a lock screen.
6. Your rights
- Access / Export: download a complete JSON copy of your family's data from Account → Data & Privacy → Export My Data.
- Delete: permanently delete your account and (if you are the last family member) all family data from Account → Data & Privacy → Delete My Account. (See section 7 for full details.)
- Correct: edit any field directly in the app.
- Restrict / Object: contact us at privacy@hiveminded.app.
7. How to delete your account
You can permanently delete your HiveMinded account and all associated personal data at any time. There are two ways:
- From inside the app or website: sign in, then go to Account → Data & Privacy → Delete My Account. Confirm with your password. Your account is anonymized within 24 hours and removed from backups within 30 days.
- If you cannot sign in: email privacy@hiveminded.app from the address on your account with the subject line "Delete my account". We respond within 5 business days and complete deletion within 30 days.
If you are the family administrator and the last remaining adult on the account, deleting your account also deletes all shared family data (events, chores, messages, photos, etc.). Other family members will be notified by email at least 7 days before final deletion so they can export their data.
8. Mobile app permissions
On iOS and Android, the HiveMinded mobile app may request these device permissions, all of which are optional:
- Location (when in use): only if you enable Location Sharing or arrival/departure alerts. We do not track your location in the background.
- Photo library: only when you tap "attach photo" for a chore, memory, or message. We never scan your library otherwise.
- Camera: only when you tap "take photo". The image is uploaded only when you confirm.
- Notifications: only if you opt in. You can change this at any time in your device settings or in the in-app Notification Settings screen.
9. Security
Passwords are hashed with bcrypt. All traffic is TLS 1.2+. Sessions use HTTP-only secure cookies with same-site protection. Database access is restricted to the application service account and is regionally redundant.
10. Retention
We keep your data as long as your account is active. After deletion, your record is anonymized within 24 hours and removed from backups within 30 days.
11. International users, lawful bases, and GDPR rights
The Service is hosted in the United States. By using HiveMinded you consent to the transfer of your data to the U.S. We honor data-subject requests from any jurisdiction.
If you are in the UK, the EU, or another region with comparable law, these are the lawful bases we rely on under Article 6 of the GDPR:
- Performance of a contract — running your account and delivering the core Service: your calendar, chores, lists, messages, and the family data you create.
- Consent — optional features you switch on yourself: location sharing, push notifications, SMS, and any health or medical records you choose to enter. Health data is special-category data under Article 9 and is processed only on your explicit consent; you can withdraw it by deleting those records or your account.
- Legitimate interests — keeping the Service secure and reliable: rate limiting, abuse and bot detection, audit logging, and minimal request logs. We keep this data minimal and balance it against your rights.
- Legal obligation — retaining billing and tax records for as long as the law requires.
For a child, the lawful basis is the consent of the holder of parental responsibility, captured at the moment the parent creates the child's login.
You have the right to access, correct, delete, restrict, or object to our processing, and the right to data portability — the in-app JSON export satisfies that. You may also lodge a complaint with your local supervisory authority. To exercise any of these rights, email privacy@hiveminded.app.
12. Changes
When we make a material change, we'll notify you in-app and via email. The "Last updated" date at the top of this page always reflects the current version.
13. Contact
Questions? Email privacy@hiveminded.app. Mail: HiveMinded, Inc., 1 Hive Lane, Wilmington, DE 19801, USA.