Privacy Policy
Last updated: July 8, 2026
- We don't use cookies
- We don't track individual users
- We don't store your API request content
- We collect only what's needed for rate limiting and requested follow-up
- We use Cloudflare Analytics (privacy-first, no cookies)
1. Introduction
HUMMBL ("we", "us", "our") operates the hummbl.io website and the HUMMBL Base120 API. This Privacy Policy explains what data we collect, how we use it, and your rights.
2. Data We Collect
2a. API Usage Data (Automatic)
When you make API requests, we automatically collect:
- IP address or IP-derived key (used for rate limiting, abuse prevention, and aggregate analytics; retained for up to 30 days in operational stores)
- Request timestamp (for rate limit window calculation)
- Request path and method (for routing; not logged)
Read-only API request bodies are processed in-memory. For assessment, checkout, and other explicitly submitted forms, we store the submitted email and assessment data for follow-up, delivery, and audit receipts as described below.
2b. Website Analytics (Cloudflare Web Analytics)
Our website uses Cloudflare Web Analytics, which:
- Does NOT use cookies
- Does NOT track individual users
- Does NOT collect personal information
- Collects only aggregate page view data (page URL, referrer, country, browser type)
- Is privacy-first by design (no cross-site tracking)
More info: cloudflare.com/web-analytics
2c. Data You Provide Voluntarily
If you use a HUMMBL assessment, checkout, or report recovery form, we collect the email address and consent metadata you submit so we can send assessment reports, checkout links, or report recovery access. Assessment emails are retained for up to 24 months unless a longer retention period is required for billing, tax, security, or dispute records. Checkout and recovery emails are retained for the duration needed to provide the requested service. If you contact us via our scheduling link (cal.com), that interaction is governed by Cal.com's privacy policy.
The contact form (if present) accepts name, email, message, and optional company/project type. Contact-form submissions are logged to D1 for audit receipts and rate-limited by IP hash in KV. Contact-form data is retained for up to 24 months unless a longer retention period is required.
3. Data We Do NOT Collect
- No cookies (zero cookies, ever)
- No personal identification information beyond what you submit voluntarily
- No email addresses unless you submit a form or contact us
- No tracking pixels or behavioral trackers (Cloudflare Web Analytics is used for aggregate, cookie-free metrics — see sections 4 and 5)
- No cross-site tracking
- No fingerprinting
- No advertising IDs
4. How We Use Data
- IP addresses: Rate limiting only (100 req/min per IP). Stored in Cloudflare Workers memory during the rate limit window (~60 seconds), then discarded.
- Analytics: Understanding aggregate traffic patterns (which pages are popular, geographic distribution). No individual user tracking.
- Submitted emails: Sending the newsletter, requested assessment reports, checkout/service messages, or report recovery links you asked to receive.
5. Data Storage & Security
- API: Runs on Cloudflare Workers (edge computing). No persistent database stores user data.
- Website: Hosted on Cloudflare Pages. Static files only.
- Rate limit data: In-memory on Cloudflare Workers. Automatically evicted after the rate limit window (~60 seconds).
- Rate-limit records: IP hash stored in Cloudflare KV for rate limiting. Retained for up to 30 days.
- Assessment emails: Retained for up to 24 months unless a longer retention period is required for billing, tax, security, or dispute records.
- Checkout and recovery emails: Retained for the duration needed to provide the requested service (typically 24 months).
- Contact-form submissions: Logged to Cloudflare D1 for audit receipts. Retained for up to 24 months unless a longer retention period is required.
- No data is sold. Data is processed by HUMMBL and by infrastructure/service providers needed to deliver the requested service.
6. Security Pipeline
Our API includes a 5-layer security pipeline that processes inputs in real-time:
- Prompt injection detection
- PII detection and redaction
- Input sanitization
If PII is detected in your input, it is flagged in the response but NOT stored or logged.
7. Third-Party Services
| Service | Purpose | Privacy Policy |
|---|---|---|
| Cloudflare Workers | API hosting | cloudflare.com/privacypolicy |
| Cloudflare Pages | Website hosting | cloudflare.com/privacypolicy |
| Cloudflare Web Analytics | Aggregate analytics | cloudflare.com/web-analytics |
| Cloudflare D1 | Contact-form and assessment data storage | cloudflare.com/privacypolicy |
| Cloudflare KV | Rate-limit storage (IP hash) | cloudflare.com/privacypolicy |
| Cloudflare Turnstile | Bot protection (assessment forms) | cloudflare.com/privacypolicy |
| Resend | Email delivery (reports and service messages) | resend.com/privacy |
| Cal.com | Meeting scheduling (optional) | cal.com/privacy |
| HUMMBL API | Newsletter, assessment, checkout, and report recovery forms | This policy |
8. Children's Privacy
The Service is not directed at children under 13. We do not knowingly collect data from children.
9. Your Rights
You may request access, correction, deletion, or unsubscribe for personal data you submitted through HUMMBL forms. Use any unsubscribe link in a newsletter or contact us through the privacy contact below.
For EU/UK users (GDPR): Our lawful basis for processing IP addresses is legitimate interest (rate limiting to prevent abuse). Our lawful basis for newsletter and assessment email follow-up is consent or, for paid reports and service messages, contract necessity.
For California users (CCPA): We do not sell personal information. We do not share personal information for targeted advertising.
10. Contact-Form Policy Ownership
The contact form (if present) serves both HUMMBL business inquiries and personal-site messages. Contact-form data is governed by this HUMMBL privacy policy regardless of the inquiry type.
11. Changes to This Policy
We may update this Privacy Policy. Changes will be reflected in the "Last updated" date. Material changes will be noted in our changelog.
12. Contact
For privacy questions, contact us at cal.com/hummbl/30min.