🔒 Privacy Policy

Your Data, Your Control

At hk3k, privacy isn't just a policy—it's part of who we are. We're building personalized AI that works for you, never at your expense. That means your knowledge is yours alone, and our job is to protect it while giving you full control every step of the way.

Last updated: January 15, 2025

Quick Privacy Summary (Plain Language)

We keep things simple: your data is yours, not ours. We don't sell it, we don't train AI on it without your permission, and we protect it with strong security (AES-256 + TLS 1.3). You can export or delete your data anytime, and if you leave, we'll remove it from our systems within 90 days. We only share data with trusted providers (like Stripe for payments or AWS for hosting) to keep hk3k running. No tracking cookies, no ads, no surprises.

Our Privacy Commitment

hk3k was created with a simple principle: your knowledge and data belong only to you. We don't sell your information, and we never use your personal data to train AI without your explicit permission.

Our goal isn't to exploit your data—it's to empower you with tools that are private, personalized, and trustworthy. That's how we make AI feel less like a risk, and more like a true partner.

100%
Data Ownership
0
Data Sales
256-bit
Encryption

1. Information We Collect

When you use hk3k, you choose what to share. We collect only the information needed to deliver a secure, personalized AI experience:

Account Information

  • • Email address for account creation and communication
  • • Name (optional, for personalization)
  • • Payment information (processed securely through Stripe—never stored by us)

Knowledge Data

  • • Text and content you choose to save
  • • URLs of pages where content was captured
  • • Tags and categories you create
  • • Notes and annotations you add

Usage Information

  • • Features you use and how often
  • • Search queries (anonymized)
  • • Performance metrics to improve the service

Integration Data

  • • Notion workspace information (with your permission)
  • • OAuth tokens for authorized integrations
  • • Database schemas for field mapping

2. How We Use Your Information

To Provide Our Service

We process and store your captured knowledge, generate AI-powered insights, synchronize with your integrations, and deliver search results.

To Improve hk3k

We analyze usage patterns (anonymized), fix bugs, improve performance, and develop new features—never training AI models on your personal data.

To Communicate With You

We send important service updates, respond to support requests, share optional product news (with consent), and provide security alerts when necessary.

To Support Research & Analytics

We may use anonymized and aggregated data (which cannot identify you) to improve system performance and guide research. This data is never shared in a form that can be linked back to you.

3. How We Protect Your Data

Technical Safeguards

  • • 256-bit AES encryption at rest
  • • TLS 1.3 encryption in transit
  • • Secure cloud infrastructure (AWS)
  • • Regular security audits
  • • Automated backups

Access Controls

  • • JWT authentication
  • • Two-factor authentication (optional)
  • • Role-based access for teams
  • • Regular access reviews
  • • Secure API endpoints

4. Data Sharing & Third Parties

We Never Sell Your Data

Your personal information and knowledge are never sold, rented, or traded to third parties.

Limited Sharing Scenarios

  • Service Providers: We work with trusted partners (e.g., Stripe for payments, AWS for hosting) who process data on our behalf under strict confidentiality agreements.
  • AI Processing: When you use AI features, queries are processed through OpenAI or similar providers. We never send personally identifiable information with these requests.
  • Legal Requirements: If disclosure is required by law, we'll notify you unless prohibited.
  • Your Consent: With your explicit permission for integrations or features.

5. Your Rights & Controls

You Can Always:

  • ✓ Access all your stored data
  • ✓ Export your data in common formats
  • ✓ Delete specific memories or all data
  • ✓ Update your personal information
  • ✓ Control integration permissions
  • ✓ Opt out of optional communications

GDPR & CCPA Rights:

  • ✓ Right to be informed
  • ✓ Right to access
  • ✓ Right to rectification
  • ✓ Right to erasure
  • ✓ Right to data portability
  • ✓ Right to object

Global Privacy Controls

We honor browser-based privacy signals such as Global Privacy Control (GPC). If your browser sends such a signal, we treat it as an opt-out request for non-essential data processing.

6. Cookies & Tracking

We use only the minimal cookies required for hk3k to function smoothly:

  • • Authentication cookies → Keep you logged in securely
  • • Preference cookies → Save settings (like dark mode)
  • • Security cookies → Prevent fraud and protect your account

We do not use tracking cookies or advertising cookies. We do not share data with advertising networks.

7. Data Retention

Active Accounts: Data kept as long as your account is active.

Deleted Data: Removed from active systems immediately, and erased from backups within 30 days.

Account Closure: Personal data deleted within 90 days (unless legally required).

Inactive Accounts: Accounts that remain inactive for more than 3 years may be permanently deleted to protect your privacy.

8. Children's Privacy

hk3k is not intended for children under 13 in the U.S. or under the minimum digital consent age in other regions (e.g., 16 in the EU). We do not knowingly collect personal data from children below these ages.

For children above the age of digital consent:

  • • Parental or guardian consent is required for account creation or use of the Service
  • • Personal data of minors is collected only as needed to provide the Service and never for marketing or AI training without parental consent
  • • Some data may be shared with trusted service providers (e.g., payment processing, cloud hosting) solely to enable functionality

Parents or guardians can:

  • • Review their child's data
  • • Request deletion of any personal data associated with the child by contacting privacy@hk3k.ai

We employ reasonable technological safeguards to:

  • • Prevent underage children from accessing parts of our Service where personal data is collected
  • • Restrict children from participating in forums, newsletters, contests, or other community interactions without parental oversight

If we become aware that a child has provided personal data without parental consent, we delete the information promptly and notify the parent or guardian where possible.

9. International Data Transfers

Your data may be processed in the U.S. or in other countries where our providers operate. We use safeguards like standard contractual clauses and adequacy decisions to protect your rights.

10. Changes to This Policy

If we make material changes, you'll be notified at least 30 days before they take effect (via email or in-app). Continuing to use hk3k after changes means you accept the updated policy.

Contact Us

Questions or concerns about your privacy? We'd love to hear from you.

Email: privacy@hk3k.ai

Because privacy should never be a mystery.