1. Introduction & Scope
Welcome to Hive ("we," "us," "our," or the "Platform"). This Privacy Policy describes how Hive Technologies ("Hive," the "Company," "we," "us," or "our") collects, uses, stores, shares, and protects information when you use our website at https://hivechat.online (the "Website"), our web application, and any related services, features, content, or applications (collectively, the "Service" or "Platform").
This Privacy Policy applies to all users of the Service, including without limitation users who are browsers, contributors, content creators, community members, chatters, callers, or any other users of the Platform. By accessing or using Hive, you acknowledge that you have read, understood, and agree to be bound by the terms of this Privacy Policy.
We are committed to protecting your privacy and providing a safe, positive experience for all our users, especially our younger users. We believe in transparency and want you to understand exactly what data we collect and how it is used.
This Privacy Policy should be read in conjunction with our Terms of Service, which govern your use of the Platform. Together, these documents form the complete agreement between you and Hive regarding your use of the Service.
Important: If you do not agree to this Privacy Policy, please do not access or use the Service. Your continued use of the Service after the posting of this Privacy Policy constitutes your acceptance of the updated terms.
This policy applies to information we collect:
- On the Hive website and web application
- In email, text, and other electronic messages between you and Hive
- Through mobile and desktop applications you download from the Service
- When you interact with our advertising and third-party applications
- When you participate in communities, send messages, make calls, or engage with other users
2. Who We Are
Hive is a social community platform designed to connect teens through shared interests, communities, real-time messaging, and multimedia communication. Our platform enables users to:
- Create and join interest-based communities
- Send text messages, images, videos, audio files, and other media in community channels
- Send direct (private) messages to other users
- Make voice and video calls with other users
- Create rich, customizable profiles
- Follow hashtags and discover content across communities
- Build friendships and social connections
- Participate in a gamified rank and progression system
- Use AI-powered tools for content discovery and assistance
Company Name: Hive Technologies
Website: https://hivechat.online
Contact Email: privacy@hivechat.online
Data Protection Officer: dpo@hivechat.online
3. Age Requirements & COPPA Compliance
Hive is designed for users aged 13 and older. We are committed to complying with the Children's Online Privacy Protection Act (COPPA), the General Data Protection Regulation (GDPR), and all other applicable laws regarding the collection of data from minors.
3.1 Minimum Age Requirement
You must be at least 13 years of age to create an account and use Hive. We do not knowingly collect personal information from children under the age of 13. If we become aware that we have collected personal information from a child under the age of 13 without verification of parental consent, we will take steps to remove that information from our servers.
3.2 Age Verification During Registration
During the onboarding process, we require all users to provide their date of birth. This information is used solely for age verification purposes to ensure compliance with COPPA and to provide age-appropriate experiences. Your date of birth is:
- Verified against the minimum age requirement (13 years)
- Used to apply age-appropriate privacy defaults for users under 18
- Stored securely and not shared with other users
- Retained for the lifetime of your account for compliance purposes
3.3 Parental Rights
Parents and legal guardians have the right to:
- Review the personal information collected from their child
- Request the deletion of their child's personal information
- Refuse to allow further collection of their child's information
- Contact us at any time to exercise these rights
If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@hivechat.online and we will promptly investigate and take appropriate action.
3.4 Age-Gated Features
Certain features may have additional age restrictions. For example, users under 16 may have different default privacy settings than users 16 and older, in compliance with GDPR Article 8 and applicable national implementations.
4. Information We Collect
We collect information in several ways as you use Hive. The types of information we collect can be broken down into the following categories:
- Account Information: Data you provide when creating an account
- Profile Information: Data you provide to customize your profile
- Content You Create: Messages, posts, media, and other content
- Communication Data: Direct messages, calls, and conversations
- Usage Data: Information about how you interact with the Platform
- Device Data: Information about the device and browser you use
- Location Data: Approximate location information
- Third-Party Data: Information from connected services
We will always clearly indicate which information is required and which is optional. You have choices about the information you provide, and you can update or delete your information at any time through your account settings.
5. Information You Provide Directly
5.1 Account Registration Information
When you create a Hive account, we collect the following required information:
| Data Field | Type | Purpose | Retention |
|---|---|---|---|
| Username | Text (3-50 characters) | Unique identifier, displayed publicly | Account lifetime |
| Email Address | Email format | Account verification, authentication, communications | Account lifetime |
| Password | Hashed (bcrypt, 12 rounds) | Account security, authentication | Account lifetime (hashed only) |
| Date of Birth | Date | Age verification, COPPA/GDPR compliance | Account lifetime |
Password Security: Your password is never stored in plain text. We use bcrypt with 12 rounds of salting to hash your password before storage. Even our employees cannot see your password. We strongly recommend choosing a unique, strong password that you do not use on other websites or services.
5.2 Registration Metadata
During registration, we automatically collect the following metadata for security purposes:
| Data Field | Type | Purpose | Retention |
|---|---|---|---|
| Registration IP Address | IPv4/IPv6 | Fraud prevention, security logging, abuse detection | Indefinite |
| User-Agent String | Text | Browser/device identification, security logging | Indefinite |
5.3 Profile Information
After creating your account, you may choose to provide the following optional profile information during onboarding or at any time through your settings:
| Data Field | Type | Visibility | Purpose |
|---|---|---|---|
| Profile Picture | Image (Base64/URL) | Public | Identity, recognition |
| Display Name | Text (up to 50 chars) | Public | Shown instead of username |
| Bio | Text | Public | Personal description |
| About Me | Long text | Public | Extended profile section |
| Status | Text (up to 100 chars) | Public | Current mood/status message |
| Pronouns | Text (up to 50 chars) | Public | Gender pronoun display |
| Website | URL (up to 255 chars) | Public | External link on profile |
| Country | Text (up to 100 chars) | Public | Location display |
| Language | Text (up to 50 chars) | Public | Preferred language |
| Timezone | Text (up to 50 chars) | Private | Time-based features |
| Interests | Array of text tags | Public | Interest discovery |
| Hobbies | Array of text tags | Public | Hobby display |
| Education | Text (up to 255 chars) | Public | Education info |
| Occupation | Text (up to 255 chars) | Public | Work info |
| Favorite Emoji | Text (up to 50 chars) | Public | Profile decoration |
| Favorite Quote | Long text | Public | Profile quote |
| Social Links | JSON object | Public | External social media links |
5.4 Profile Customization Data
You may also provide the following customization data to personalize your profile's appearance:
- Profile Banner: A banner image displayed at the top of your profile
- Accent Color: Your preferred theme color (default: #6C63FF)
- Profile Theme: Dark or light theme preference
- Profile Frame: Decorative frame around your avatar
- Profile Nameplate: Decorative element below your name
- Profile Effect: Animated effect on your profile
- Profile Ring: Animated ring effect around your avatar
- Profile Music: Background music file for your profile (audio file URL)
- Profile Music Title & Artist: Metadata for your profile music
- Chat Text Color: Custom color for your chat messages
- Chat Text Font: Custom font for your chat messages
- Username Color: Custom color for your displayed username
- Profile Font: Custom font used on your profile page
5.5 Privacy & Notification Settings
You have control over various privacy settings, including:
- Profile Visibility: Who can view your full profile (public, friends only, private)
- DM Privacy: Who can send you direct messages (everyone, friends only, nobody)
- Mention Preferences: Who can @mention you (everyone, friends only, nobody)
- Friend Request Settings: Who can send you friend requests (everyone, friends only)
- Online Status Visibility: Whether other users can see when you are online
- Last Seen Visibility: Whether other users can see your last activity time
- Chat Permissions: Who can message you in communities
- Profile View Permissions: Who can view your full profile details
- Tagging Permissions: Whether you can be tagged in messages
- Reaction Permissions: Whether others can react to your messages
- Notification Preferences: Granular control over push, email, and sound notifications
6. Information Collected Automatically
When you access or use Hive, we automatically collect certain information about your device and your use of the Service. This information is collected using cookies, web beacons, pixel tags, and other tracking technologies.
6.1 Log Data
Our servers automatically record information ("Log Data") that your browser sends whenever you visit the Website. Log Data may include:
- Your Internet Protocol (IP) address
- Browser type and version
- Operating system
- Referring/exit pages and URLs
- Date and time of your visit
- Time spent on pages
- Pages viewed and links clicked
- Screen resolution and window size
- Language preferences
- Hardware model and carrier information (for mobile devices)
6.2 Device Information
We collect information about the device you use to access Hive, including:
- Device type (desktop, mobile, tablet)
- Operating system and version
- Browser type and version
- Screen resolution
- Device identifiers (where available)
- Mobile network information
- Device language settings
- Time zone
6.3 Usage Information
We collect information about your use of the Service, including:
- Features you use and actions you take
- Communities you join, visit, or interact with
- Messages you send, view, or react to
- Calls you initiate, answer, or participate in
- Time and duration of your activities
- Search queries you enter
- Content you upload or share
- Notifications you receive and interact with
- Settings you change
- Errors and crashes you encounter
7. Device & Browser Information
We collect detailed information about the device and browser you use to access Hive. This includes:
7.1 Browser Fingerprinting
We may collect a combination of browser attributes to create a device identifier for security and fraud prevention purposes. This may include browser type, installed fonts, screen resolution, timezone, language settings, and other attributes. This information helps us detect and prevent unauthorized access, account takeover, and other security threats.
7.2 Hardware Information
When you use voice or video calling features, we may collect information about your device's hardware capabilities, including:
- Camera and microphone availability
- Screen sharing capabilities
- Network connection type (WiFi, cellular, ethernet)
- Bandwidth estimates for call quality optimization
This information is used solely to optimize your calling experience and is not shared with third parties.
7.3 Software Information
We may collect information about the software and applications installed on your device that could interact with Hive, including:
- Operating system version
- Browser plugins and extensions
- Installed fonts (for rendering optimization)
- Graphics capabilities (for video call optimization)
8. Usage & Activity Data
We track how you interact with the Platform to improve your experience and our services. This includes:
8.1 Community Activity
- Communities you are a member of
- Communities you visit or browse
- Messages you send in community channels
- Reactions you add to messages
- Messages you reply to
- Files and media you upload to communities
- Calls you participate in within communities
- Hand raises during calls
- Mute/camera toggle states during calls
8.2 Direct Messaging Activity
- Conversations you participate in
- Messages you send and receive
- Read receipts (when you read a message)
- Media you share in direct messages
- Calls you make or receive via direct messages
8.3 Social Activity
- Friend requests you send, receive, accept, or decline
- Users you block or unblock
- Hashtags you follow
- Notifications you receive and interact with
- Profile views (if you choose to make this visible)
8.4 AI Assistant Usage
If you use our AI assistant feature ("Bee"), we track:
- Number of AI requests you make per day
- Daily usage limits (based on your rank level)
- Topics and queries you ask about
- AI responses provided to you
This data is used to manage usage limits, improve AI responses, and prevent abuse. AI request data is retained for the purpose of improving service quality.
9. Location Information
We collect and use location information in the following ways:
9.1 Approximate Location
We derive your approximate location from your IP address. This is used for:
- Content moderation and enforcement of regional laws
- Language and timezone recommendations
- Analytics and service improvement
- Security and fraud prevention
We do not collect or store your precise GPS location unless you explicitly grant permission through your device's location services.
9.2 Self-Reported Location
You may voluntarily provide your country and timezone in your profile settings. This information is:
- Stored on your profile and visible according to your privacy settings
- Used for time-based features and notifications
- Used for regional content recommendations
- Not verified for accuracy
9.3 IP Address Location
Your IP address is used to determine your approximate geographic location (city/country level). This information is:
- Used for security monitoring and fraud detection
- Used to enforce regional content policies
- Logged at registration and during login for security purposes
- Not shared with other users
- Retained for the lifetime of your account for security auditing
10. Cookies & Similar Technologies
10.1 What Are Cookies
Cookies are small text files that are placed on your device when you visit a website. They are widely used to make websites work more efficiently and to provide information to website owners.
10.2 How We Use Cookies
We use cookies and similar technologies for the following purposes:
- Authentication: To keep you signed in and maintain your session
- Security: To detect unauthorized access and protect your account
- Preferences: To remember your settings and preferences
- Analytics: To understand how you use the Platform and improve our services
- Performance: To optimize loading times and resource usage
10.3 Types of Cookies We Use
| Cookie Type | Purpose | Duration |
|---|---|---|
| Essential Cookies | Required for the Service to function (authentication, security) | Session / 7 days |
| Functional Cookies | Remember your preferences and settings | 30 days |
| Analytics Cookies | Help us understand usage patterns | 90 days |
10.4 Managing Cookies
You can control and manage cookies through your browser settings. Most browsers allow you to:
- View and delete cookies
- Block third-party cookies
- Block all cookies (though this may affect functionality)
- Set cookie preferences per website
Please note that disabling certain cookies may impair the functionality of the Service.
10.5 Local Storage
We use browser local storage to:
- Store your authentication token (hive_token)
- Store your user profile data (hive_user)
- Maintain your session state
- Cache data for offline access
Local storage data remains on your device until you clear it or delete your account.
11. How We Use Your Information
We use the information we collect for the following purposes:
11.1 To Provide and Maintain the Service
- Create and manage your account
- Authenticate your identity and maintain your session
- Enable messaging, calling, and other core features
- Display your profile to other users
- Facilitate community membership and participation
- Process and deliver your messages and media
- Enable voice and video calling features
11.2 To Improve and Optimize the Service
- Analyze usage patterns to improve features
- Identify and fix bugs and errors
- Optimize performance and loading times
- Develop new features based on user behavior
- Conduct A/B testing and experiments
- Improve AI moderation accuracy
11.3 To Protect Users and the Platform
- Detect and prevent fraud, spam, and abuse
- Enforce our Terms of Service and Community Guidelines
- Protect against unauthorized access and security threats
- Monitor for suspicious activity and account takeovers
- Respond to legal requests and comply with applicable laws
- Verify age and enforce age restrictions
11.4 To Communicate With You
- Send account-related notifications (security alerts, password resets)
- Send service updates and announcements
- Respond to your support requests and inquiries
- Send notification preferences you have enabled
- Send marketing communications (with your consent where required)
11.5 For Personalization
- Customize your experience based on your preferences
- Recommend communities and content based on your interests
- Personalize your profile and chat appearance
- Adjust notification timing based on your timezone
12. Legal Bases for Processing (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data based on the following legal grounds under the General Data Protection Regulation (GDPR):
12.1 Consent
We process certain data based on your explicit consent, which you provide when:
- Creating an account and agreeing to this Privacy Policy
- Opting in to marketing communications
- Enabling optional features that require data processing
- Granting location access on your device
You may withdraw your consent at any time by adjusting your settings or contacting us.
12.2 Contractual Necessity
We process data necessary to fulfill our contract with you (the Terms of Service), including:
- Account creation and management
- Providing core Service features (messaging, calling, communities)
- Processing payments (for premium features, if applicable)
- Customer support
12.3 Legitimate Interests
We process data based on our legitimate interests, including:
- Fraud prevention and security monitoring
- Analytics and service improvement
- Enforcing our Terms of Service
- Preventing abuse and protecting users
- Infrastructure monitoring and optimization
We balance these interests against your rights and freedoms to ensure they do not override your privacy.
12.4 Legal Obligations
We may process data to comply with legal obligations, including:
- Responding to valid legal requests from authorities
- Maintaining records required by law
- Protecting our legal rights
- Complying with tax and financial regulations
13. AI-Powered Content Moderation
Hive uses artificial intelligence to help maintain a safe and positive community environment. This section describes how our AI moderation system works and what data it processes.
13.1 How AI Moderation Works
Our AI moderation system analyzes messages sent in community channels to detect potentially harmful content, including:
- Spam: Repetitive or automated-looking messages
- Toxicity: Hate speech, harassment, bullying, or abusive language
- Scams: Phishing attempts, fraudulent links, or deceptive content
- Inappropriate Content: Content that violates our Community Guidelines
- Self-Harm: Content promoting self-harm or suicide
- Sexual Content: Sexually explicit or inappropriate material
13.2 What Data the AI Processes
When AI moderation is active in a community, the following data may be processed:
- The full text of messages sent in the community
- The sender's user ID and username
- The community ID and channel context
- Historical message patterns for the user
- Message timing and frequency
13.3 How the AI Analysis Works
Our AI moderation uses a locally-hosted large language model (LLM) running on our own infrastructure. The analysis process:
- Message text is sent to our local AI service (Ollama running a qwen2.5:3b model)
- The AI analyzes the message for potential policy violations
- The AI returns a classification (spam, toxicity, scam, etc.) with a severity score
- If the severity exceeds the community's configured threshold, an action is taken
- Actions may include: allowing the message, warning the user, auto-deleting the message, or muting the user
- The analysis results are logged for moderation review
Important: Our AI moderation runs entirely on our own servers. Message data is not sent to external AI services like OpenAI, Google, or other third-party AI providers.
13.4 AI Moderation Logs
AI moderation decisions are logged with the following information:
- Message ID and sender user ID
- Full text of the analyzed message
- AI response and classification
- Action taken (allow, warn, delete, mute, review, reply)
- Severity score
- Category of violation
- Timestamp of analysis
These logs are retained indefinitely for moderation review, policy enforcement, and AI model improvement.
13.5 Community AI Settings
Community administrators can configure AI moderation settings, including:
- Whether AI moderation is enabled
- Whether auto-delete is enabled for flagged messages
- Spam detection threshold (number of messages before detection)
- Toxicity threshold (0.0 to 1.0)
- Auto-mute duration for violations
- Maximum warnings before escalation
14. How We Share Your Information
We value your privacy and do not sell your personal information to third parties. However, we may share your information in the following circumstances:
14.1 With Other Users
The following information is visible to other users based on your privacy settings:
- Username and display name
- Profile picture and banner
- Bio and about me section
- Public profile fields (pronouns, interests, hobbies, etc.)
- Online status and last seen (if enabled)
- Community memberships
- Messages you send in community channels
- Reactions you add to messages
14.2 Within Communities
When you join a community, other members of that community can see:
- Your username and profile picture
- Your messages in community channels
- Your participation in community calls
- Your membership in the community
14.3 With Service Providers
We may share information with trusted service providers who assist us in operating the Platform, including:
- Cloudflare: Content delivery, security, and file storage (R2)
- Hosting Providers: Server infrastructure and database hosting
- Analytics Providers: Usage analytics and performance monitoring
These service providers are contractually obligated to protect your information and use it only for the purposes we specify.
14.4 For Legal Reasons
We may disclose your information if required to do so by law or in response to valid requests by public authorities, including:
- Court orders or subpoenas
- Government or law enforcement requests
- To protect our legal rights or the rights of others
- To prevent fraud or illegal activity
- To protect the safety of our users or the public
14.5 Business Transfers
In the event that Hive is involved in a merger, acquisition, or sale of all or a portion of its assets, your information may be transferred as part of that transaction. We will notify you of any such change in ownership or control of your personal information.
14.6 With Your Consent
We may share your information for purposes not described in this policy with your explicit consent.
15. Third-Party Service Providers
We work with the following third-party service providers to operate and improve Hive:
15.1 Cloudflare, Inc.
- Service: Content Delivery Network (CDN), DDoS protection, file storage
- Data Shared: IP addresses, request metadata, uploaded files
- Purpose: Website performance, security, and file hosting (R2 storage)
- Privacy Policy: https://www.cloudflare.com/privacypolicy/
15.2 Google Fonts
- Service: Web font delivery
- Data Shared: IP address, browser user-agent, requested font files
- Purpose: Typography and design consistency
- Privacy Policy: https://policies.google.com/privacy
15.3 Google reCAPTCHA (if applicable)
- Service: Bot detection and abuse prevention
- Data Shared: IP address, browser behavior, interaction patterns
- Purpose: Prevent automated abuse of forms
- Privacy Policy: https://policies.google.com/privacy
15.4 Ollama (Local AI Service)
- Service: Local AI inference for content moderation
- Data Shared: Message text for analysis (processed locally on our servers)
- Purpose: AI-powered content moderation
- Data Location: Our own infrastructure (not a third-party cloud service)
We regularly review our service providers' privacy practices to ensure they maintain adequate protections for your data.
16. Cloudflare & Infrastructure
Hive uses Cloudflare for content delivery, security, and file storage. Here's how Cloudflare handles your data:
16.1 CDN & Security
When you access Hive, your connection is routed through Cloudflare's global network. Cloudflare may process:
- Your IP address
- Browser type and version
- Requested URLs and headers
- Cookies set by Hive
- Referring URLs
Cloudflare uses this data to provide CDN services, DDoS protection, and web application firewall (WAF) functionality.
16.2 Cloudflare R2 Storage
We use Cloudflare R2 for file storage, including:
- Profile pictures and banners
- Message attachments (images, videos, audio, files)
- Profile music files
- Community icons and media
Files stored in R2 are accessible via URLs that do not contain personally identifiable information. Old files are deleted when replaced or when you delete your account.
16.3 Cloudflare Workers
We may use Cloudflare Workers for serverless computing. Workers may process requests on Cloudflare's edge network, but do not store personal data beyond what is necessary for request processing.
17. File Storage & Uploads
When you upload files to Hive, they are stored on our Cloudflare R2 infrastructure. Here's what you need to know about file uploads:
17.1 Types of Uploads
- Profile Pictures: Your avatar image
- Profile Banners: Your profile banner image
- Message Attachments: Files shared in community channels or DMs (images, videos, audio, documents)
- Profile Music: Audio files for your profile background music
17.2 File Metadata Stored
For each uploaded file, we store:
- Original filename
- File size (in bytes)
- MIME type (e.g., image/jpeg, video/mp4)
- Image/video dimensions (width and height)
- Audio/video duration
- Storage key (unique identifier)
- Public URL for accessing the file
- Thumbnail URL (for videos and larger files)
17.3 File Retention
- Profile pictures and banners are retained until you replace or delete them
- Message attachments are retained indefinitely unless deleted by the sender or a moderator
- Profile music files are retained until you replace or delete them
- When you delete your account, all your uploaded files are permanently deleted
17.4 File Visibility
- Profile pictures and banners are public (visible to all users)
- Message attachments are visible to members of the community or DM conversation
- Profile music is public (visible on your profile)
- Uploaded files may be accessible via direct URL by anyone who has the link
18. Direct Messages & Private Communications
Hive provides direct messaging (DM) functionality for private conversations between users. Here's how we handle your private communications:
18.1 How DMs Work
- DMs are private conversations between two users
- Only you and the other participant(s) can see your DMs
- DMs are stored on our servers for delivery and history
- Read receipts track when each participant has read the messages
18.2 What We Can See
While DMs are private between users, certain metadata is available to Hive for:
- Delivery: Routing messages between participants
- Security: Detecting spam, abuse, or policy violations
- Support: Resolving user-reported issues
- Legal: Responding to valid legal requests
We do not routinely read the content of your direct messages. However, messages may be reviewed if:
- A user reports a message for policy violations
- We receive a valid legal request (court order, subpoena)
- We reasonably believe there is an imminent threat to safety
- The message triggers our automated spam or abuse detection systems
18.3 DM Privacy Controls
You control who can send you DMs through your privacy settings:
- Everyone: Any user on Hive can send you DMs
- Friends Only: Only users you've accepted as friends can DM you
- Nobody: No one can send you DMs
18.4 DM Data Retention
- DMs are retained for the lifetime of the conversation
- Deleting a conversation removes it from your view
- Read receipt data is retained for 30 days
- When you delete your account, all your DMs are permanently deleted
19. Voice & Video Calls
Hive supports voice and video calling using WebRTC (Web Real-Time Communication) technology. Here's how calls work and what data is involved:
19.1 How Calls Work
- Calls use peer-to-peer WebRTC connections where possible
- Signaling (call setup, offer/answer exchange) is routed through our servers
- Audio and video streams are transmitted directly between participants when possible
- Community calls support up to 5 participants; DM calls support up to 2
19.2 Call Data We Collect
When you participate in a call, we record:
- Call start and end timestamps
- Call type (voice or video)
- Call participants
- Community or DM conversation the call belongs to
- Mute and camera toggle states
- Hand raise events
19.3 Call Content
Audio and video streams during calls are transmitted via WebRTC and are not recorded or stored by Hive. Once a call ends, the audio/video content is gone. We only retain the call metadata listed above.
19.4 Call Signaling Data
During call setup, the following data is transmitted through our servers:
- SDP (Session Description Protocol) offers and answers
- ICE (Interactive Connectivity Establishment) candidates
- Call state changes (join, leave, mute, camera toggle)
This data is used solely for establishing and managing the call and is not stored beyond the duration of the call.
19.5 Call System Messages
When a call is started, a system message is posted to the relevant community channel or DM conversation indicating that a call was initiated. This message includes:
- The username of the call initiator
- The call type (voice or video)
- A clickable link to join the call
20. Public Profiles & Community Content
20.1 Public Profiles
Your profile may be visible to other users depending on your privacy settings. By default, the following information is public:
- Username
- Profile picture
- Display name
- Bio and about me
- Pronouns
- Interests and hobbies
- Social links
- Country
- Member since date
- Rank
- Community memberships
You can control your profile visibility through your privacy settings:
- Public: Anyone can view your full profile
- Friends Only: Only friends can view your full profile
- Private: Nobody can view your full profile
20.2 Community Content
Content you post in community channels is visible to all members of that community. This includes:
- Text messages
- Images, videos, and other media
- Reactions and replies
- File attachments
Community content may be indexed by search engines unless the community has opted out of indexing.
20.3 Content Removal
You can delete your own messages at any time. Community moderators can also remove messages that violate community guidelines. However, deleted content may still exist in backups or caches for a limited time.
21. Real-Time Presence & Activity Status
Hive tracks and displays certain real-time information about your activity:
21.1 Online Status
Your online status (online/offline) is visible to other users based on your settings. This status is updated when:
- You connect to the Service
- You disconnect from the Service
- You are inactive for an extended period
21.2 Last Seen
Your "last seen" timestamp indicates when you were last active on the Platform. This is updated each time you interact with the Service.
21.3 Current Activity
Other users may be able to see:
- Which community you are currently viewing
- Whether you are in a voice/video call
- Whether you have your microphone or camera muted
21.4 Presence Controls
You can control your visibility through settings:
- Show Online Status: Toggle whether others see your online status
- Show Last Seen: Toggle whether others see your last activity time
22. Notifications
22.1 Types of Notifications
Hive may send you notifications for:
- New direct messages
- Mentions in community channels
- Friend requests
- Community activity (new members, announcements)
- Call invitations
- System announcements and security alerts
22.2 Notification Delivery
Notifications may be delivered via:
- In-App Notifications: Displayed within the Hive interface
- Push Notifications: Sent to your device (if enabled)
- Email Notifications: Sent to your registered email (if enabled)
- Sound Notifications: Audio alerts for new messages (if enabled)
22.3 Notification Controls
You have granular control over notifications through your settings. You can enable or disable:
- Message notifications
- Mention notifications
- Friend request notifications
- Community notifications
- Push notifications
- Email notifications
- Sound notifications
22.4 Notification Retention
Notifications are automatically deleted after 30 days. You can also manually delete individual notifications or mark all as read.
23. Data Retention & Deletion
23.1 How Long We Keep Your Data
| Data Type | Retention Period |
|---|---|
| Account Information | Until account deletion |
| Profile Information | Until account deletion |
| Community Messages | Indefinite (until deleted by user/moderator) |
| Direct Messages | Until conversation deletion or account deletion |
| Call Metadata | Indefinite |
| File Uploads | Until deleted by user or account deletion |
| AI Moderation Logs | Indefinite |
| Notifications | 30 days (auto-deleted) |
| Read Receipts (DMs) | 30 days |
| Registration IP & User-Agent | Account lifetime |
| Login History | Account lifetime |
| Server Logs | 90 days |
| Analytics Data | 12 months (anonymized after 6 months) |
23.2 Data Deletion on Account Removal
When you delete your account, we permanently delete or anonymize:
- Your profile information
- Your username (released for potential reuse after 30 days)
- Your profile picture and banner
- Your messages in community channels (anonymized, not deleted, to preserve conversation context)
- Your direct messages (deleted)
- Your uploaded files
- Your friend list
- Your notification settings
- Your call history
Note: Some data may be retained in backups for up to 90 days after deletion, after which it is permanently purged.
24. Data Security
We take the security of your personal information seriously and implement appropriate technical and organizational measures to protect it against unauthorized access, alteration, disclosure, or destruction.
24.1 Technical Measures
- Encryption in Transit: All data transmitted between your device and our servers is encrypted using TLS (Transport Layer Security)
- Encryption at Rest: Sensitive data is encrypted when stored on our servers
- Password Hashing: Passwords are hashed using bcrypt with 12 rounds of salting
- JWT Authentication: Secure token-based authentication with configurable expiration
- Rate Limiting: Protection against brute force attacks and abuse
- Input Validation: All user inputs are sanitized and validated
- SQL Injection Protection: Parameterized queries prevent SQL injection attacks
- XSS Protection: Content Security Policy and input sanitization
- CSRF Protection: Token-based protection against cross-site request forgery
24.2 Organizational Measures
- Access to user data is limited to authorized personnel on a need-to-know basis
- Regular security audits and vulnerability assessments
- Employee training on data protection and security practices
- Incident response procedures for data breaches
- Regular backup and disaster recovery testing
24.3 Security Incident Response
In the event of a data breach that affects your personal information, we will:
- Immediately contain the breach and secure affected systems
- Investigate the scope and impact of the breach
- Notify affected users within 72 hours (or as required by law)
- Notify relevant supervisory authorities as required by GDPR
- Provide guidance on steps you can take to protect yourself
- Implement measures to prevent similar incidents in the future
24.4 Account Security
You play an important role in keeping your account secure:
- Choose a strong, unique password
- Do not share your login credentials with anyone
- Enable two-factor authentication when available
- Log out of your account on shared devices
- Report any suspicious activity immediately
24.5 Account Lockout Protection
To protect against unauthorized access, accounts are temporarily locked after 5 consecutive failed login attempts. During a lockout, login is blocked and the account requires admin intervention to unlock.
25. Your Rights & Choices
You have various rights regarding your personal information. Depending on your location, these rights may include:
25.1 Right to Access
You have the right to request a copy of the personal information we hold about you. We will provide this information within 30 days of your request.
25.2 Right to Rectification
You have the right to request that we correct any inaccurate or incomplete personal information. You can update most of your information directly through your account settings.
25.3 Right to Erasure ("Right to be Forgotten")
You have the right to request the deletion of your personal information, subject to certain exceptions. We will comply with your request within 30 days unless we have a legal basis for retaining the information.
25.4 Right to Restrict Processing
You have the right to request that we restrict the processing of your personal information in certain circumstances.
25.5 Right to Data Portability
You have the right to receive your personal information in a structured, commonly used, and machine-readable format.
25.6 Right to Object
You have the right to object to the processing of your personal information for certain purposes, including direct marketing.
25.7 Right to Withdraw Consent
Where we rely on your consent to process your information, you have the right to withdraw that consent at any time.
25.8 Right to Lodge a Complaint
If you believe your rights have been violated, you have the right to lodge a complaint with your local data protection supervisory authority.
25.9 How to Exercise Your Rights
To exercise any of these rights, please contact us at:
- Email: privacy@hivechat.online
- Through the app: Settings > Privacy > Data Requests
We may need to verify your identity before processing your request.
26. Account Deletion & Data Removal
26.1 How to Delete Your Account
You can delete your account at any time through:
- Settings > Account > Delete Account
- Email request to privacy@hivechat.online
26.2 What Happens When You Delete Your Account
- Your account is immediately deactivated
- Your profile is no longer visible to other users
- Your username is released after 30 days
- Your messages in community channels are anonymized (content preserved, author removed)
- Your direct messages are permanently deleted
- Your uploaded files are permanently deleted
- Your friend list is deleted
- Your notification history is deleted
- All your personal information is permanently deleted within 30 days
- Backup copies are purged within 90 days
26.3 Content That May Persist
After account deletion:
- Community messages you sent may remain visible but will be attributed to "Deleted User"
- Messages others quoted or replied to may retain references to your content
- AI moderation logs of your messages may be retained for security purposes
- Aggregated, anonymized analytics data may persist
27. Data Portability
You have the right to request a copy of your data in a portable format. We can provide your data in the following formats:
27.1 Available Data Export
- Profile information (username, email, bio, etc.)
- Message history (community and DM)
- Community memberships
- Friend list
- Uploaded files (links)
- Notification history
- Account activity logs
27.2 How to Request Your Data
To request a data export, contact us at privacy@hivechat.online. We will provide your data within 30 days in a structured, commonly used, machine-readable format (JSON or CSV).
28. Parental Rights & Teen Protections
Hive is committed to protecting our younger users. We provide additional protections for users under 18:
28.1 Parental Access
Parents or legal guardians of users under 18 have the right to:
- Request information about what data we collect from their child
- Request deletion of their child's account and data
- Refuse further collection of their child's information
- Review their child's activity on the Platform
28.2 Default Privacy Settings for Minors
Users under 18 may have different default privacy settings, including:
- More restrictive visibility settings
- Limited DM permissions
- Enhanced content filtering
28.3 Age-Appropriate Design
In compliance with the Children's Code (Age Appropriate Design Code) and similar regulations, we:
- Do not use data of minors for targeted advertising
- Do not sell data of minors to third parties
- Implement high default privacy settings for minors
- Provide age-appropriate privacy information
- Use data minimization for minor users
28.4 Parental Contact
Parents or guardians can contact us at any time at parents@hivechat.online to exercise their rights regarding their child's data.
29. International Data Transfers
Hive is operated from servers located in multiple countries. Your information may be transferred to and processed in countries other than your country of residence.
29.1 Where Your Data Is Processed
- Server Infrastructure: Our primary servers are located in the United States and Europe
- Cloudflare CDN: Content is served from Cloudflare's global network
- File Storage: Files are stored in Cloudflare R2 regions
29.2 Safeguards for International Transfers
When we transfer data internationally, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where applicable
- Contractual obligations on service providers to protect your data
30. Do Not Track Signals
Some browsers include a "Do Not Track" (DNT) feature that signals to websites that you do not want to be tracked. Currently, there is no industry standard for how websites should respond to DNT signals.
Hive does not currently alter our data collection and use practices in response to DNT signals. However, you can control tracking through:
- Your browser's cookie settings
- Our cookie consent mechanism (where applicable)
- Your account privacy settings
- Browser extensions that block tracking
31. Third-Party Links & Content
Hive may contain links to third-party websites, services, or content that are not operated by us. This Privacy Policy does not apply to these third-party services.
31.1 External Links
Your profile may contain links to external websites (e.g., social media profiles). When you click on these links, you leave Hive and are subject to the privacy policy of the external website.
31.2 Embedded Content
Messages may contain embedded content from third-party services (e.g., image previews, link previews). Interacting with embedded content may share data with the third-party service.
31.3 Social Media Sharing
If you share Hive content on social media, the social media platform's privacy policy applies to that data.
We encourage you to review the privacy policies of any third-party services you interact with through Hive.
32. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, and other factors.
32.1 Notification of Changes
When we make material changes to this Privacy Policy, we will:
- Update the "Last Updated" date at the top of this page
- Post the updated policy on this page
- Notify you via email or in-app notification for significant changes
- Provide a summary of key changes where appropriate
32.2 Review Period
Material changes will take effect 30 days after we post the updated policy, unless a shorter period is required by law. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.
32.3 Previous Versions
We maintain records of previous versions of this Privacy Policy. If you would like to review a previous version, please contact us at privacy@hivechat.online.
33. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Privacy Inquiries
- Email: privacy@hivechat.online
- Data Protection Officer: dpo@hivechat.online
- Parental Inquiries: parents@hivechat.online
- General Support: support@hivechat.online
Mailing Address
Hive Technologies
Privacy Team
[Address to be provided upon request]
Response Time
We aim to respond to all privacy-related inquiries within 30 days. For urgent matters, please indicate "URGENT" in your subject line.
Supervisory Authority
If you are located in the European Economic Area and believe we have not adequately addressed your privacy concern, you have the right to lodge a complaint with your local data protection supervisory authority.