Privacy Policy
Last updated: August 14, 2026
Summary
HUMMBL is open source governance infrastructure for agentic AI. We do not run advertising. We do not sell your data. We do not use third-party analytics trackers. This page describes what limited data we process and your rights.
1. Data We Collect
1.1 Data you provide
If you contact us (email, GitHub issues, social media), we receive the information you choose to share: your name, email address, and message content. We use this solely to respond to your inquiry.
1.2 Automatically collected data
Our website is hosted on Cloudflare Pages. Cloudflare may process server-level logs (IP addresses, request timestamps, user agent strings) as part of standard web infrastructure operations. We do not control or access these logs directly. See Cloudflare's Privacy Policy for details.
1.3 Newsletter and assessment email follow-up
If you subscribe to our newsletter or request an assessment email follow-up, we collect your email address and consent timestamp. Submitted emails are retained for up to 24 months. You may request access, correction, deletion, or unsubscribe at any time. The lawful basis for newsletter and assessment email follow-up is consent (GDPR Art. 6(1)(a)). You can withdraw consent by unsubscribing via the link in any email or by contacting us via GitHub Issues.
1.4 MCP server usage
Our public MCP server (mcp-public.hummbl.io) processes
tool requests (model lookups, searches, recommendations). These
requests contain the query text you send to the server. We do not log
or store individual queries. We do not associate queries with personal
identifiers. The server does not require authentication or user
accounts.
1.5 Data we do NOT collect
- No analytics or tracking scripts (no Google Analytics, no Plausible, no Fathom)
- No advertising cookies or pixels
- No user accounts or profiles on this website
- No individual MCP query logging
- No sale of data to third parties
2. How We Use Data
- To respond to inquiries you initiate
- To operate and maintain the website and MCP servers
- To monitor aggregate, anonymized service health (uptime, error rates)
- To improve the Base120 mental model library (the model content is public and open source)
3. Legal Basis (GDPR)
For users in the European Economic Area, our processing of limited personal data is based on:
- Legitimate interests (Art. 6(1)(f)) — operating a public website and responding to inquiries
- Consent (Art. 6(1)(a)) — when you voluntarily contact us
4. Your Rights
You have the right to:
- Request access to your personal data
- Request correction or deletion of your personal data
- Request restriction of processing
- Object to processing based on legitimate interests
- Request data portability
- Withdraw consent at any time
- Lodge a complaint with your local data protection authority
To exercise any of these rights, contact us at GitHub Issues or the email listed in the GitHub organization.
5. Cookies
This website does not set cookies. Cloudflare may set essential
infrastructure cookies (e.g., __cf_bm for bot management)
that are necessary for the site to function. These are not controlled
by us and cannot be used for tracking.
6. Third-Party Services
- Cloudflare — web hosting, CDN, DNS. See Cloudflare Privacy Policy.
- GitHub — source code hosting, issue tracking. See GitHub Privacy Statement.
We do not embed third-party advertising trackers or invasive analytics. This site loads Cloudflare Web Analytics (a privacy-first, cookie-less beacon) solely for aggregate pageview and performance measurement.
7. Data Retention
We do not maintain databases of user personal data. Inquiry emails are retained in our email system for as long as needed to respond and for a maximum of 12 months thereafter. Cloudflare infrastructure logs are retained according to Cloudflare's policies.
8. Children's Privacy
Our website and services are not directed to children under 13 (or the applicable age in your jurisdiction). We do not knowingly collect personal data from children.
9. Changes to This Policy
We may update this policy from time to time. Changes will be posted on this page with an updated "Last updated" date. The source for this page is available on GitHub.
10. Contact
Questions about this privacy policy can be directed to GitHub Issues. For privacy-specific requests, reference "Privacy Request" in your issue title.