Last updated: 2026-07-14

Privacy Policy

This Privacy Policy describes how Brightwing Systems, LLC ("we", "us", or "our") collects, uses, and protects information when you use HumanGated ("the Service") available at humangated.ai. By using the Service, you agree to the collection and use of information in accordance with this policy.

1. Information We Collect

Prototype content

When you upload a prototype, we collect the HTML file you submit along with the metadata you provide (a display name and the reviewer allowlist — email domains and addresses).

Data received via AI coding tools

HumanGated is designed to be driven by AI coding agents (such as Claude Code, Codex, or Gemini CLI). When you upload through an agent, the upload payload — the HTML file and its metadata — is sent from your machine to our API. We receive and store only that payload. We do not receive, access, or store your conversations with the agent.

Owner tokens and accounts

Owners are identified by an access token, which can be minted without providing any personal information. If you claim a token for recovery, we collect the email address you provide.

Reviewer identity

Reviewers self-assert an email address once per browser. We use it to check the prototype's allowlist, to attribute feedback, and we remember it in a signed cookie so it doesn't need to be re-entered.

Feedback data

When a reviewer leaves feedback, we collect the note and its type, threaded replies, the on-page anchors that position the pin (CSS selectors, text snippets), an optional screenshot of the annotated region of the rendered prototype, and capture context (page URL, viewport size, browser user-agent).

Usage data

We collect standard server logs (IP addresses, browser type, pages visited, timestamps) to operate the Service and prevent abuse, including short-lived rate-limit counters keyed by IP address.

Cookies

We use only essential and functional cookies:

We do not use analytics, advertising, or third-party tracking cookies.

2. Legal Basis for Processing

We process your personal information on the following legal bases:

3. How We Use Your Information

4. Data Sharing

We do not sell your personal information. Prototypes are private by default: a prototype is reachable only through its unguessable link, by reviewers whose email matches its allowlist, and only until it expires. An owner may deliberately make an individual prototype public — an explicit, per-prototype choice that lets anyone with the link view it (they still enter an email, which we use only to attribute their feedback). Feedback is visible to the prototype's owner and to that prototype's reviewers. Beyond that, we share information only in the following circumstances:

5. Data Retention

Every prototype is retained for a flat 30 days from upload, after which its link stops resolving. For 14 days after expiry, the stored content and feedback are kept so the owner can still pull past feedback or re-open the link; after that grace period they are permanently deleted — the prototype, every stored version, all feedback, and all screenshots. Owners can also permanently delete any prototype immediately, at any time, via the dashboard or API. Deletion requests for other stored data are honored within 30 days, except where retention is required by law. The reviewer-identity cookie expires after about 90 days. Server logs are kept for a limited period for security and operations.

6. International Data Transfers

Our servers are located in the United States. If you access the Service from outside the United States, your information may be transferred to, stored, and processed there. By using the Service, you consent to the transfer of your information as described in this policy. We take appropriate measures to ensure your data is treated securely regardless of where it is processed.

7. Data Security

We implement industry-standard security measures to protect your information, including encryption in transit (TLS), signed cookies, access controls, and regular backups. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

8. Your Rights

Owners may:

Reviewers may request access to or deletion of feedback attributed to their email address by contacting privacy@brightwingsystems.com.

California residents (CCPA)

If you are a California resident, you have the right to know what personal information we collect, use, and disclose; to request deletion of your personal information; and to opt out of the sale of your personal information. We do not sell your personal information. To exercise these rights, contact us at privacy@brightwingsystems.com. We will not discriminate against you for exercising any of these rights.

European Economic Area, UK, and Swiss residents (GDPR)

If you are located in the EEA, UK, or Switzerland, you have the right to access your personal data; rectify inaccurate data; request erasure of your data; restrict or object to processing; request data portability; and lodge a complaint with your local data protection supervisory authority. To exercise these rights, contact us at privacy@brightwingsystems.com.

9. Children's Privacy

The Service is intended for users aged 13 and older. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us at privacy@brightwingsystems.com and we will take steps to delete it promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. Your continued use of the Service after changes constitutes acceptance of the revised policy.

11. Contact Us

If you have questions about this Privacy Policy, contact us at privacy@brightwingsystems.com.