Privacy Policy
How we collect, use, store, share, and protect information when you use the Hone Studio platform.
1. Information We Collect
Hone Labs LLC (“Hone Labs,” “we,” “us,” or “our”) operates the Hone Studio platform (“Platform”). We built Hone Studio for organizations that handle sensitive institutional data, including higher education institutions subject to FERPA. Our data practices reflect that responsibility: we minimize what we collect, we don’t sell data, and we give institutions full control over their information.
Information You Provide
| Category | Examples | Purpose |
|---|---|---|
| Account information | Email address, name (from OAuth profile) | Authentication, account management |
| Organizational content | Documents, knowledge base entries, conversation messages, research projects | Core Platform functionality |
| Feedback and support | Messages to support channels | Responding to requests, improving Platform |
Information Generated
| Category | Examples | Purpose |
|---|---|---|
| AI-generated content | Draft documents, extracted facts, research summaries | Core AI-assisted features |
| Embeddings | Vector representations of document text | Semantic search |
| Usage metadata | Feature usage, token consumption, API call logs | Operation, billing, quality monitoring |
Collected Automatically
| Category | Examples | Purpose |
|---|---|---|
| Analytics | Page views, feature interactions (via Vercel Analytics) | Understanding usage, improving experience |
| Performance data | Page load times, Core Web Vitals | Maintaining performance |
| Error data | Error stack traces (PII scrubbed), performance traces | Diagnosing and fixing bugs |
| Server logs | IP addresses, request timestamps | Security monitoring, abuse prevention |
We do NOT collect: Social Security numbers, financial account numbers or payment card data, biometric data, health or medical records, precise geolocation data, or data from children under 13 (see Section 9).
2. How We Use Information
We use information only for the purposes below. We do not sell, rent, or trade your information.
| Purpose | Legal Basis | Data Used |
|---|---|---|
| Provide the Platform | Contract performance | Account info, organizational content, AI-generated content |
| Process AI requests | Contract performance | Document text, conversation history, knowledge base content |
| Maintain security | Legitimate interest | Server logs, authentication data, error data |
| Improve the Platform | Legitimate interest | Aggregated analytics, performance data, error reports |
| Communicate with you | Contract performance | Email address (notifications, magic link auth) |
| Comply with law | Legal obligation | As required by applicable law |
3. Data Isolation and Multi-Tenancy
Each client organization operates on fully isolated infrastructure and their data is strictly isolated:
- Separate infrastructure per client — Each client has a dedicated Supabase project (independent database, auth, and storage), a dedicated Railway backend deployment, and a dedicated Vercel frontend deployment with its own domain. There is no shared database, application server, or frontend between clients.
- Separate database schemas — Within each client’s Supabase project, data resides in dedicated, client-prefixed database tables. There is no shared data pool between clients.
- Row-Level Security (RLS) — Database-level policies enforce that queries can only return data belonging to the requesting client’s workspace.
- Separate storage — Uploaded files are stored in client-specific storage buckets.
- No cross-client data access — It is architecturally impossible for one client’s users to access another client’s data through the Platform — both at the infrastructure level (separate deployments) and the application level (prefixing, RLS, bucket isolation).
For comprehensive details, see our Security Practices page.
5. Data Retention
| Category | Retention Period |
|---|---|
| Organizational content | Contract duration + 30-day export window |
| Account data | Account lifetime + 30-day grace period |
| Usage logs | 1 year |
| Error reports | 90 days |
| Server logs | 30 days |
| Database backups | 7 days (Supabase Pro plan) |
Accidental deletion protection: Every deletion in the Platform goes through a soft-delete pipeline. If data is deleted by mistake, it can be recovered within 30 days.
Contract Termination Timeline
Days 1–30
Data remains available for export only (no new processing)
Day 30
All data soft-deleted, user access revoked
Day 60
Permanent deletion of all data
Day 90
All copies confirmed erased, including backup rotation (7-day retention, Supabase Pro plan)
Upon request
Written certification of complete deletion provided
6. Data Security
We protect your data through multiple layers of security:
- Encryption at rest — AES-256 encryption (AWS KMS managed keys)
- Encryption in transit — TLS 1.2+ for all connections, HSTS enforced
- Authentication — JWT-based with algorithm confusion prevention; API keys with bcrypt hashing and constant-time comparison
- Access control — Email/domain allowlisting, Row-Level Security on all database tables (defense-in-depth; primary authorization via application layer), workspace-scoped permissions
- Rate limiting — Redis-backed rate limiting to prevent abuse and resource exhaustion
- Input validation — Parameterized queries (SQL injection prevention), Pydantic model validation, SSRF protection
- Security headers — Full suite including X-Frame-Options, Content-Security-Policy, X-Content-Type-Options
- Monitoring — Error monitoring with PII scrubbing, application performance monitoring
- CI/CD security — Automated linting, type checking, and testing on every code change
For comprehensive details, see our Security Practices page.
7. Your Rights and Choices
Data Export
You may request a complete export of your organization’s data at any time. Exports include all uploaded documents (original files), generated documents, knowledge base content, conversation history, research projects, and workspace structure. Exports are delivered in JSON format (structured data) and original format (uploaded files) within 15 business days. For exports exceeding 100GB, we will provide a delivery timeline within 3 business days of the request.
Data Deletion
You may request deletion of specific data or all data at any time:
- Send a written request to privacy@honelabs.dev
- We confirm the scope within 2 business days
- Soft deletion within 5 business days (data becomes invisible in the Platform)
- 30-day grace period (cancellable — in case of accidental deletion)
- Permanent deletion after grace period
- Written certification of deletion provided upon request
Account Closure
Contact your organization’s administrator to request account deprovisioning, or contact us directly at privacy@honelabs.dev.
Communication Preferences
The Platform sends only transactional communications (magic link authentication emails, account notifications). We do not send marketing emails.
8. FERPA Compliance
For higher education clients that designate Hone Labs as a “school official” under FERPA (20 U.S.C. § 1232g):
- Legitimate educational interest — We access education records only to provide the contracted Platform services
- Direct control — The institution controls which users have access and what data is uploaded
- No re-disclosure — We do not disclose education records to any third party except our sub-processors, who are bound by the same restrictions
- No use beyond purpose — Education records are used solely for the contracted service — never for marketing, profiling, or product development
- AI provider protections — All AI providers do not use education records for training. Zero-retention agreements are confirmed with Google and Perplexity, and requested from Anthropic and Cohere
- Data return and deletion — Upon contract termination, education records are returned (via data export) and deleted per the timeline in Section 5
- Breach notification — In the event of unauthorized disclosure of education records, we notify the institution within 24 hours per our Incident Response Plan
We do not condition the provision of services on a student or parent waiving FERPA rights.
9. Children's Privacy
Hone Studio is designed for institutional use by authorized adult users. We do not knowingly collect personal information directly from children under the age of 13. The Platform is not directed at children.
If education records pertaining to students under 13 are included in content uploaded by an institution, that data is processed solely under the institution’s authority as part of the contracted service, subject to the same protections described in Section 8.
If we become aware that we have collected personal information directly from a child under 13 without appropriate consent, we will delete that information promptly. If you believe we have collected such information, please contact us at privacy@honelabs.dev.
10. State Privacy Law Compliance
New York Education Law 2-d
For New York education institution clients: Hone Labs maintains practices designed to meet NY Education Law § 2-d requirements for third-party contractors handling student data. We maintain data security and privacy standards consistent with NIST Cybersecurity Framework guidelines, limit data use to the contracted educational purpose, and will not sell or release student data or teacher/principal data for commercial purposes.
California (SOPIPA)
Hone Labs does not use student information to target advertising, create profiles for non-educational purposes, sell student information, or disclose student information except as permitted under SOPIPA (SB 1177). The Platform is designed solely for the institutional purposes contracted by the client.
Rhode Island
For Rhode Island institution clients: We comply with Rhode Island’s Identity Theft Protection Act (R.I. Gen. Laws § 11-49.3) regarding breach notification requirements. In the event of a security breach involving personal information of Rhode Island residents, we will notify affected individuals and the Rhode Island Attorney General as required by law.
12. International Data
All Platform data is processed and stored in the United States. If you are accessing the Platform from outside the United States, your information will be transferred to and processed in the United States.
For clients requiring specific data residency arrangements, please contact us at privacy@honelabs.dev to discuss options.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last Updated” date at the top of this policy. For changes that affect how we handle client data, we will provide at least 30 days’ advance notice via email to client administrators. For changes required by law, we will implement them as required and notify clients as soon as practicable.
14. Contact Us
For privacy questions, data requests, or concerns:
- Email: privacy@honelabs.dev
- AI Ethics: ai@honelabs.dev
- Security: security@honelabs.dev
Mailing Address:
Hone Labs LLC
Berkshires, MA