Last updated: 2026-07-14

Privacy Policy

This Privacy Policy describes how Brightwing Systems, LLC ("we", "us", or "our") collects, uses, and protects information when you use HumanGated ("the Service") available at humangated.ai. By using the Service, you agree to the collection and use of information in accordance with this policy.

1. Information We Collect

Prototype content

When you upload a prototype, we collect the HTML file you submit along with the metadata you provide (a display name and the reviewer allowlist — email domains and addresses).

Data received via AI coding tools

HumanGated is designed to be driven by AI coding agents (such as Claude Code, Codex, or Gemini CLI). When you upload through an agent, the upload payload — the HTML file and its metadata — is sent from your machine to our API. We receive and store only that payload. We do not receive, access, or store your conversations with the agent.

Owner accounts and tokens

Owners create an account by verifying an email address through a magic link — no password is created or stored. We collect the email address and the display name you provide; the display name appears on the review requests you send. Each machine you link is identified by its own revocable access token.

Reviewer identity

Reviewers self-assert an email address once per browser. We use it to check the prototype's allowlist, to attribute feedback, and we remember it in a signed cookie so it doesn't need to be re-entered.

Feedback data

When a reviewer leaves feedback, we collect the note and its type, threaded replies, the on-page anchors that position the pin (CSS selectors, text snippets), an optional screenshot of the annotated region of the rendered prototype, and capture context (page URL, viewport size, browser user-agent).

Review requests and the activity record

When an owner asks someone to review something, we store the request and what happened to it: who was asked (their email address), what they were asked, which version they were shown, when it was sent, delivered and opened, what they decided, their answer in their own words, and the IP address the answer came from.

This record is kept indefinitely, and that is deliberate. Its entire purpose is to answer "who approved this, and when" long after the fact — for an owner, a client, or an auditor. A record with holes in it would not do that. It survives the prototype it was about, and it survives someone leaving the organisation they were in. See §5 and §8.

Organisations

Owners on a Team plan share one record. Work written while you are a member of an organisation is visible to everyone else in it, and stays visible to them if you leave — that is what the organisation is paying for. Work you did before you joined, or after you leave, is not shared with them.

Branding you upload

Owners on a paid plan may upload a logo to appear on their review pages. We resize and re-encode it, store the result, and serve it publicly on those pages. Do not upload an image containing personal or confidential information.

Usage data

We collect standard server logs (IP addresses, browser type, pages visited, timestamps) to operate the Service and prevent abuse, including short-lived rate-limit counters keyed by IP address.

Cookies

We use only essential and functional cookies:

We do not use advertising or third-party tracking cookies, and we do not sell or share data with advertisers.

We use a self-hosted, cookieless analytics tool (Umami) on our own marketing and signed-in pages to count visits. It sets no cookies, assigns no persistent identifier, and sends nothing to a third party. It is never loaded on a review page. Reviewers did not sign up for anything and cannot opt out of something they never chose, so the pages they see carry no analytics at all.

2. Legal Basis for Processing

We process your personal information on the following legal bases:

3. How We Use Your Information

4. Data Sharing

We do not sell your personal information. Prototypes are private by default: a prototype is reachable only through its unguessable link, by reviewers whose email matches its allowlist, and only until it expires. An owner may deliberately make an individual prototype public — an explicit, per-prototype choice that lets anyone with the link view it (they still enter an email, which we use only to attribute their feedback). Feedback is visible to the prototype's owner and to that prototype's reviewers. Beyond that, we share information only in the following circumstances:

5. Data Retention

Every prototype is retained for 30 days, after which its link stops resolving. The 30 days run from upload and restart whenever a new version is published, or whenever the owner extends it on a paid plan — so something in active use stays available and something nobody has touched does not. For 14 days after expiry, the stored content and feedback are kept so the owner can still pull past feedback or bring the link back; after that grace period they are permanently deleted — the prototype, every stored version, all feedback, and all screenshots. Owners can also permanently delete any prototype immediately, at any time, via the dashboard or API.

The activity record is kept indefinitely. Deleting a prototype removes its content, its versions, its feedback and its screenshots; the record that it was shared, who was asked about it and what they decided remains, because that record is the thing the Service exists to produce. It includes the reviewer's email address and the IP their answer came from. If you would rather it did not, §8 explains how to ask us to remove it.

Deletion requests for other stored data are honored within 30 days, except where retention is required by law. The reviewer-identity cookie expires after about 90 days. Server logs are kept for a limited period for security and operations.

6. International Data Transfers

Our servers are located in the United States. If you access the Service from outside the United States, your information may be transferred to, stored, and processed there. By using the Service, you consent to the transfer of your information as described in this policy. We take appropriate measures to ensure your data is treated securely regardless of where it is processed.

7. Data Security

We implement industry-standard security measures to protect your information, including encryption in transit (TLS), signed cookies, access controls, and regular backups. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

8. Your Rights

Owners may:

Reviewers may request access to, or deletion of, anything attributed to their email address — feedback, review requests they were sent, and the activity record of their answers — by contacting privacy@brightwingsystems.com. You do not need an account to ask, and you never needed one to be included.

Where erasing an entry would destroy a record an owner relies on, we will tell you what we propose to do rather than quietly refuse: normally that means removing your email address and IP address and leaving the fact that an answer was given, so the owner keeps a record with a hole where you used to be rather than no record at all.

California residents (CCPA)

If you are a California resident, you have the right to know what personal information we collect, use, and disclose; to request deletion of your personal information; and to opt out of the sale of your personal information. We do not sell your personal information. To exercise these rights, contact us at privacy@brightwingsystems.com. We will not discriminate against you for exercising any of these rights.

European Economic Area, UK, and Swiss residents (GDPR)

If you are located in the EEA, UK, or Switzerland, you have the right to access your personal data; rectify inaccurate data; request erasure of your data; restrict or object to processing; request data portability; and lodge a complaint with your local data protection supervisory authority. To exercise these rights, contact us at privacy@brightwingsystems.com.

9. Children's Privacy

The Service is intended for users aged 13 and older. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us at privacy@brightwingsystems.com and we will take steps to delete it promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. Your continued use of the Service after changes constitutes acceptance of the revised policy.

11. Contact Us

If you have questions about this Privacy Policy, contact us at privacy@brightwingsystems.com.