Back to HQ

Privacy Policy

How HQ collects, uses, stores and protects your data.

Effective 4 August 2026

1. Who we are

HQ ("HQ", "we", "us") provides an AI operating layer at joinhq.net: private workspaces where you create and work alongside AI workers. This policy explains what personal data we handle and why. It is maintained by the HQ team and updated as the product changes.

2. Data we collect

  • Account data — your name, email address, profile photo and authentication identifiers. If you sign in with Google or Apple, we receive only your basic profile and email from that provider; we never receive your password.
  • Workspace content — the spaces, AI workers, instructions, notes, lists, messages and files you create in HQ.
  • Billing data — plan, seat count, subscription status and renewal dates. Card details are handled entirely by Stripe; HQ never sees or stores your card number.
  • Usage data — AI request counts, token usage, feature interactions, and technical logs such as timestamps and error reports, used to run and improve the service.

3. How we use your data

We use your data to operate your account and workspaces, run AI requests you initiate, enforce fair-use and plan limits, take payment, provide support, keep the service secure, and improve HQ. We do not sell your personal data, and we do not use your workspace content to train third-party foundation models.

4. AI processing

When you send a message to an AI worker, the relevant prompt, instructions and context are transmitted to our AI model providers to generate a response. Providers process this data to return a result and are contractually restricted from using it to train their models. You should not enter data you are not permitted to share with a third-party processor.

5. Storage and security

Workspace records are stored in a managed Postgres database with row-level security, so data is readable only by members of the workspace it belongs to. Files and images are stored in object storage and served through short-lived signed URLs rather than being embedded in the database. Data is encrypted in transit and at rest. Access to production systems is restricted to authorised personnel.

6. Sharing and processors

We share data only with the processors needed to run HQ: our cloud hosting and database provider, our AI model providers, and Stripe for payments. We may also disclose data where required by law. We do not share your workspace content with other customers.

7. Retention and deletion

We keep your data for as long as your account is active. When you delete a space, worker or file it is removed from your workspace and purged from backups on our standard backup cycle. When you close your account, personal data is deleted, except records we must keep for legal, tax or accounting purposes.

8. Your rights

Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to or restrict processing, and to complain to your data protection regulator. You can update most profile data directly in HQ, or contact us to make a request.

9. Cookies

HQ uses essential cookies and local storage to keep you signed in and remember preferences such as light or dark mode. We do not use advertising cookies.

10. Children

HQ is not intended for people under 16 and we do not knowingly collect their data.

11. Changes and contact

We will update this page when our practices change, and the effective date above will change with it. For any privacy question or request, contact us at privacy@joinhq.net.