Privacy Policy

Last updated: July 8, 2026

TL;DR
  • We don't use cookies
  • We don't track individual users
  • We don't store your API request content
  • We collect only what's needed for rate limiting and requested follow-up
  • We use Cloudflare Analytics (privacy-first, no cookies)

1. Introduction

HUMMBL ("we", "us", "our") operates the hummbl.io website and the HUMMBL Base120 API. This Privacy Policy explains what data we collect, how we use it, and your rights.

2. Data We Collect

2a. API Usage Data (Automatic)

When you make API requests, we automatically collect:

  • IP address or IP-derived key (used for rate limiting, abuse prevention, and aggregate analytics; retained for up to 30 days in operational stores)
  • Request timestamp (for rate limit window calculation)
  • Request path and method (for routing; not logged)

Read-only API request bodies are processed in-memory. For assessment, checkout, and other explicitly submitted forms, we store the submitted email and assessment data for follow-up, delivery, and audit receipts as described below.

2b. Website Analytics (Cloudflare Web Analytics)

Our website uses Cloudflare Web Analytics, which:

  • Does NOT use cookies
  • Does NOT track individual users
  • Does NOT collect personal information
  • Collects only aggregate page view data (page URL, referrer, country, browser type)
  • Is privacy-first by design (no cross-site tracking)

More info: cloudflare.com/web-analytics

2c. Data You Provide Voluntarily

If you use a HUMMBL assessment, checkout, or report recovery form, we collect the email address and consent metadata you submit so we can send assessment reports, checkout links, or report recovery access. Assessment emails are retained for up to 24 months unless a longer retention period is required for billing, tax, security, or dispute records. Checkout and recovery emails are retained for the duration needed to provide the requested service. If you contact us via our scheduling link (cal.com), that interaction is governed by Cal.com's privacy policy.

The contact form (if present) accepts name, email, message, and optional company/project type. Contact-form submissions are logged to D1 for audit receipts and rate-limited by IP hash in KV. Contact-form data is retained for up to 24 months unless a longer retention period is required.

3. Data We Do NOT Collect

  • No cookies (zero cookies, ever)
  • No personal identification information beyond what you submit voluntarily
  • No email addresses unless you submit a form or contact us
  • No tracking pixels or behavioral trackers (Cloudflare Web Analytics is used for aggregate, cookie-free metrics — see sections 4 and 5)
  • No cross-site tracking
  • No fingerprinting
  • No advertising IDs

4. How We Use Data

  • IP addresses: Rate limiting only (100 req/min per IP). Stored in Cloudflare Workers memory during the rate limit window (~60 seconds), then discarded.
  • Analytics: Understanding aggregate traffic patterns (which pages are popular, geographic distribution). No individual user tracking.
  • Submitted emails: Sending the newsletter, requested assessment reports, checkout/service messages, or report recovery links you asked to receive.

5. Data Storage & Security

  • API: Runs on Cloudflare Workers (edge computing). No persistent database stores user data.
  • Website: Hosted on Cloudflare Pages. Static files only.
  • Rate limit data: In-memory on Cloudflare Workers. Automatically evicted after the rate limit window (~60 seconds).
  • Rate-limit records: IP hash stored in Cloudflare KV for rate limiting. Retained for up to 30 days.
  • Assessment emails: Retained for up to 24 months unless a longer retention period is required for billing, tax, security, or dispute records.
  • Checkout and recovery emails: Retained for the duration needed to provide the requested service (typically 24 months).
  • Contact-form submissions: Logged to Cloudflare D1 for audit receipts. Retained for up to 24 months unless a longer retention period is required.
  • No data is sold. Data is processed by HUMMBL and by infrastructure/service providers needed to deliver the requested service.

6. Security Pipeline

Our API includes a 5-layer security pipeline that processes inputs in real-time:

  • Prompt injection detection
  • PII detection and redaction
  • Input sanitization

If PII is detected in your input, it is flagged in the response but NOT stored or logged.

7. Third-Party Services

Service Purpose Privacy Policy
Cloudflare Workers API hosting cloudflare.com/privacypolicy
Cloudflare Pages Website hosting cloudflare.com/privacypolicy
Cloudflare Web Analytics Aggregate analytics cloudflare.com/web-analytics
Cloudflare D1 Contact-form and assessment data storage cloudflare.com/privacypolicy
Cloudflare KV Rate-limit storage (IP hash) cloudflare.com/privacypolicy
Cloudflare Turnstile Bot protection (assessment forms) cloudflare.com/privacypolicy
Resend Email delivery (reports and service messages) resend.com/privacy
Cal.com Meeting scheduling (optional) cal.com/privacy
HUMMBL API Newsletter, assessment, checkout, and report recovery forms This policy

8. Children's Privacy

The Service is not directed at children under 13. We do not knowingly collect data from children.

9. Your Rights

You may request access, correction, deletion, or unsubscribe for personal data you submitted through HUMMBL forms. Use any unsubscribe link in a newsletter or contact us through the privacy contact below.

For EU/UK users (GDPR): Our lawful basis for processing IP addresses is legitimate interest (rate limiting to prevent abuse). Our lawful basis for newsletter and assessment email follow-up is consent or, for paid reports and service messages, contract necessity.

For California users (CCPA): We do not sell personal information. We do not share personal information for targeted advertising.

10. Contact-Form Policy Ownership

The contact form (if present) serves both HUMMBL business inquiries and personal-site messages. Contact-form data is governed by this HUMMBL privacy policy regardless of the inquiry type.

11. Changes to This Policy

We may update this Privacy Policy. Changes will be reflected in the "Last updated" date. Material changes will be noted in our changelog.

12. Contact

For privacy questions, contact us at cal.com/hummbl/30min.