Legal

Privacy policy

Effective & last updated: 10 October 2026 · Version 1.0 · Next scheduled review: 10 October 2027

This policy covers US federal and state law (including COPPA and CCPA/CPRA), the UK GDPR, the EU GDPR and global best practice.

1. Who we are

AI Memory Vault is a product of Hushkey Labs, Inc., a Delaware corporation ("Hushkey Labs", "we", "us" or "our"). We operate the AI Memory Vault platform, including our mobile applications, web application and browser extension (together, the "Service"), and this website.

Contact: hello@hushkey.io
Business address: to be published on completion of our US incorporation.

2. What this policy covers

This Privacy Policy explains how we collect, use, store and protect your personal data when you use our Service or this website. It applies to all users globally, with specific provisions for users in the United States (including California), the United Kingdom and the European Economic Area (EEA).

3. The data we collect

3.1 Data you provide directly

  • Account registration information (email address)
  • Content you upload to your vault (documents, photos, notes, voice memos, files)
  • Passkey authentication credentials (stored locally on your device — never on our servers)
  • Communications you send us (support requests, feedback)

3.2 Data we collect automatically

  • Device type, operating system and app version
  • Usage metadata (feature interactions, session duration — never content)
  • Error logs and crash reports (anonymised)
  • IP address (used for security and fraud prevention only)

3.3 Data we do not collect

  • The contents of your vault are end-to-end encrypted. We cannot read, access or analyse your stored data.
  • We do not sell your data. Ever.
  • We do not use your vault content to train AI models.
  • We do not use third-party advertising trackers.

4. How we use your data

We use your data only to:

  • Provide, maintain and improve the Service
  • Authenticate your identity securely via passkey
  • Send transactional communications (account alerts, security notifications)
  • Respond to your support requests
  • Comply with legal obligations
  • Detect and prevent fraud or security threats

We do not use your personal data for targeted advertising.

5. Legal basis for processing (UK & EU users)

Under the UK GDPR and EU GDPR, we process your data on the following legal bases:

PurposeLegal basis
Providing the ServicePerformance of a contract (Art. 6(1)(b))
Security & fraud preventionLegitimate interests (Art. 6(1)(f))
Legal complianceLegal obligation (Art. 6(1)(c))
Marketing communications and the waitlistConsent (Art. 6(1)(a))
Replying to messages you send usLegitimate interests (Art. 6(1)(f))

6. Data storage & security

Encryption: all vault content is encrypted using AES-256-GCM before it leaves your device. Your encryption keys are derived from your passkey credentials and are never transmitted to or stored on our servers.

Servers: the Service's infrastructure is hosted on AWS (Amazon Web Services); the hosting region will be listed here before the Service launches. We use industry-standard security controls including encryption in transit (TLS 1.3), encryption at rest, access control and regular security audits.

Passkey authentication: we use WebAuthn/FIDO2 passkey technology. Your biometric data and device credentials never leave your device. We store only a public key credential — not your password or biometric.

Retention: we retain your account data for as long as your account is active. Vault content is deleted within 30 days of account deletion. Anonymised usage logs may be retained for up to 12 months.

7. Data sharing

We do not sell, rent or trade your personal data. We share data only with:

  • Service providers who help us operate the platform (for example, AWS for infrastructure), under strict data processing agreements
  • Law enforcement or regulators, only when required by law and to the minimum extent required
  • You, when you explicitly grant AI agents permissioned, scoped, time-limited access to your vault

8. Your rights

US users (California — CCPA/CPRA)

  • Right to know what personal data we collect and how it is used
  • Right to delete your personal data
  • Right to opt out of the sale of personal data (we do not sell data)
  • Right to non-discrimination for exercising your rights
  • Right to correct inaccurate personal data

UK & EU users (UK GDPR / EU GDPR)

  • Right of access (Article 15)
  • Right to rectification (Article 16)
  • Right to erasure — the "right to be forgotten" (Article 17)
  • Right to restriction of processing (Article 18)
  • Right to data portability (Article 20)
  • Right to object (Article 21)
  • Right to withdraw consent at any time

All users

  • Right to close your account and have your data deleted
  • Right to export your vault data

To exercise any of these rights, email hello@hushkey.io or use our contact form. We will respond within 30 days (UK/EU: within one month, as required by the GDPR).

9. Children's privacy (COPPA — US)

Our Service is not directed at children under the age of 13 (or under 16 for users in the EEA/UK). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us immediately at hello@hushkey.io and we will delete it.

10. International data transfers

We are based in the United States. If you are located in the UK or EEA, your data may be transferred to and processed in the US. We comply with applicable data transfer mechanisms, including Standard Contractual Clauses (SCCs), as required under the UK GDPR and EU GDPR.

11. AI agents & third-party access

When you choose to grant an AI agent access to your vault:

  • Access is scoped (you choose what the agent can see)
  • Access is time-limited (you set the duration)
  • All access is logged in your audit trail
  • You can revoke access at any time
  • The agent receives only the data you explicitly permit

We are not responsible for how third-party AI agents use data you choose to share with them.

12. Cookies & tracking

This website does not set cookies or store anything on your device for visitors. The Service's web application uses only essential cookies required for authentication and security. We do not use advertising cookies or cross-site tracking.

13. Changes to this policy

We will notify you of material changes by email or in-app notification at least 14 days before they take effect. Your continued use of the Service after that date constitutes acceptance of the updated policy. This policy is reviewed at least once a year; the next scheduled review is 10 October 2027.

14. Contact & complaints

Data controller: Hushkey Labs, Inc., a Delaware corporation
Email: hello@hushkey.io
Address: to be published on completion of our US incorporation
EU representative: to be appointed before we offer the Service in the EU (GDPR Article 27)
UK representative: to be appointed before we offer the Service in the UK (UK GDPR Article 27)

UK users: you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
EU users: you have the right to lodge a complaint with your local supervisory authority (for example, the CNIL in France, the BfDI in Germany or the DPC in Ireland).

15. This website and the waitlist

Before the Service launches, this website collects a small amount of information so we can run the waitlist and reply to you:

  • Waitlist: your email address and, if you choose to give them, your name, what best describes you and what you'd use AI Memory Vault for.
  • How you found us: the form you used, the page that referred you, any campaign tags in the link you clicked (for example, which post you came from) and your country (worked out from your connection; we do not store your IP address).
  • Contact form: your name, email address, optional company name, topic and message.
  • Support chat: the questions you type into the chat assistant and its answers (kept so we can improve our answers), and — if you choose "Talk to a human" — your name, email and the chat transcript so our team can reply.
  • Abuse prevention: a one-way hash of your IP address, stored with submissions so we can detect spam.

Please don't share passwords, payment details or sensitive personal data in the chat. Some chat questions are answered by an AI model provided by Anthropic, which processes the conversation on our behalf to generate a reply and does not use it to train its models.

This information is stored by our website providers — Vercel (hosting) and Supabase (database) — and, if we send you a confirmation email, Resend (email delivery). We keep waitlist details until the Service launches and you've received your invite, or until you ask us to remove you; contact messages are kept for up to 24 months. To leave the waitlist, email hello@hushkey.io from the address you signed up with.