Last updated: 2026-07-14
Privacy Policy
This Privacy Policy describes how Brightwing Systems, LLC ("we", "us", or "our") collects, uses, and protects information when you use HumanGated ("the Service") available at humangated.ai. By using the Service, you agree to the collection and use of information in accordance with this policy.
1. Information We Collect
Prototype content
When you upload a prototype, we collect the HTML file you submit along with the metadata you provide (a display name and the reviewer allowlist — email domains and addresses).
Data received via AI coding tools
HumanGated is designed to be driven by AI coding agents (such as Claude Code, Codex, or Gemini CLI). When you upload through an agent, the upload payload — the HTML file and its metadata — is sent from your machine to our API. We receive and store only that payload. We do not receive, access, or store your conversations with the agent.
Owner tokens and accounts
Owners are identified by an access token, which can be minted without providing any personal information. If you claim a token for recovery, we collect the email address you provide.
Reviewer identity
Reviewers self-assert an email address once per browser. We use it to check the prototype's allowlist, to attribute feedback, and we remember it in a signed cookie so it doesn't need to be re-entered.
Feedback data
When a reviewer leaves feedback, we collect the note and its type, threaded replies, the on-page anchors that position the pin (CSS selectors, text snippets), an optional screenshot of the annotated region of the rendered prototype, and capture context (page URL, viewport size, browser user-agent).
Usage data
We collect standard server logs (IP addresses, browser type, pages visited, timestamps) to operate the Service and prevent abuse, including short-lived rate-limit counters keyed by IP address.
Cookies
We use only essential and functional cookies:
protopeek_sessionid— session management (signed-in owners only)protopeek_csrftoken— CSRF protectionprotopeek_reviewer— the signed reviewer-identity cookie (~90 days)
We do not use analytics, advertising, or third-party tracking cookies.
2. Legal Basis for Processing
We process your personal information on the following legal bases:
- Contract performance: to provide the Service you have requested, including hosting prototypes, gating access, and delivering feedback
- Legitimate interest: to operate, maintain, and improve the Service, detect abuse, and ensure security
- Consent: where required by applicable law, such as for optional communications
3. How We Use Your Information
- To host prototypes and serve them to their invited reviewers
- To gate access against each prototype's allowlist and attribute feedback to its author
- To return feedback to the prototype's owner, including through the API
- To communicate with you about the Service (e.g., security alerts, updates)
- To respond to support requests
- To detect and prevent fraud, abuse, or security incidents
4. Data Sharing
We do not sell your personal information. Prototypes are private by default: a prototype is reachable only through its unguessable link, by reviewers whose email matches its allowlist, and only until it expires. An owner may deliberately make an individual prototype public — an explicit, per-prototype choice that lets anyone with the link view it (they still enter an email, which we use only to attribute their feedback). Feedback is visible to the prototype's owner and to that prototype's reviewers. Beyond that, we share information only in the following circumstances:
- Service providers: we use third-party providers to operate the Service, bound to access data only as necessary to perform their functions. These include our cloud hosting provider (Hetzner).
- Legal requirements: we may disclose information if required by law, subpoena, or other legal process.
- Business transfers: if Brightwing Systems, LLC is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.
5. Data Retention
Every prototype is retained for a flat 30 days from upload, after which its link stops resolving. For 14 days after expiry, the stored content and feedback are kept so the owner can still pull past feedback or re-open the link; after that grace period they are permanently deleted — the prototype, every stored version, all feedback, and all screenshots. Owners can also permanently delete any prototype immediately, at any time, via the dashboard or API. Deletion requests for other stored data are honored within 30 days, except where retention is required by law. The reviewer-identity cookie expires after about 90 days. Server logs are kept for a limited period for security and operations.
6. International Data Transfers
Our servers are located in the United States. If you access the Service from outside the United States, your information may be transferred to, stored, and processed there. By using the Service, you consent to the transfer of your information as described in this policy. We take appropriate measures to ensure your data is treated securely regardless of where it is processed.
7. Data Security
We implement industry-standard security measures to protect your information, including encryption in transit (TLS), signed cookies, access controls, and regular backups. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. Your Rights
Owners may:
- Deactivate a prototype or let its link expire at any time, via the dashboard or API
- Permanently delete a prototype — its content and all associated feedback — at any time, via the dashboard or API, effective immediately
- Revoke or rotate access tokens at any time
- Request a copy or deletion of stored data by contacting privacy@brightwingsystems.com
Reviewers may request access to or deletion of feedback attributed to their email address by contacting privacy@brightwingsystems.com.
California residents (CCPA)
If you are a California resident, you have the right to know what personal information we collect, use, and disclose; to request deletion of your personal information; and to opt out of the sale of your personal information. We do not sell your personal information. To exercise these rights, contact us at privacy@brightwingsystems.com. We will not discriminate against you for exercising any of these rights.
European Economic Area, UK, and Swiss residents (GDPR)
If you are located in the EEA, UK, or Switzerland, you have the right to access your personal data; rectify inaccurate data; request erasure of your data; restrict or object to processing; request data portability; and lodge a complaint with your local data protection supervisory authority. To exercise these rights, contact us at privacy@brightwingsystems.com.
9. Children's Privacy
The Service is intended for users aged 13 and older. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us at privacy@brightwingsystems.com and we will take steps to delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. Your continued use of the Service after changes constitutes acceptance of the revised policy.
11. Contact Us
If you have questions about this Privacy Policy, contact us at privacy@brightwingsystems.com.