Privacy policy.

A clear account of what reaches us, what stays with you, and the choices you have.

Effective May 23, 2026 12 sections about 17 min read

The short version.

Privacy starts with collecting less.

No cookies set by us.

We do not set cookies on this website.

No analytics. No ads.

No advertising, tracking pixels or visitor analytics.

Your history stays here.

Your game history stays in your browser. If you save a high score, we store only your chosen handle and score.

Your records stay with you.

Agent records in your environment stay there unless you choose otherwise.

No sale. No model training.

We do not sell personal information or use personal information or customer data to train AI models.

Ask for a demo.

Your answers are used to reply and arrange a demo.

The short version and margin notes are summaries. The full policy below controls.

1. Who we are and what this covers

Copy section link

1.1 Who is responsible

Humming Arms LLC (“Humming Arms”, “we”, “us” or “our”) is responsible as controller for personal information we handle through this website, demo requests, email correspondence, and sales and design-partner conversations. Personal information means information that identifies, relates to, or can reasonably be linked to a person.

Our privacy contact is [email protected].

1.2 Customer environments and product data

The product is not generally available. Our self-hosted-first approach is for design partners to run Humming Arms in their own infrastructure. Agent records stay in the customer’s environment unless the customer chooses otherwise. We do not read records that remain there.

Product data processed under a customer agreement is governed by that agreement and its data processing terms, rather than this website policy. Those terms determine the parties’ roles, instructions, access, retention and any authorized support access. If your information is in a customer’s records, direct requests first to that customer; we will assist as required by the applicable agreement and law.

Our product data handling principles are redaction at the sensor, data minimization, opt-in payload capture under customer policy, and customer-controlled retention and access. These principles describe the approach to customer deployments; they are not a promise that every control is available in every deployment.

1.3 Other websites and legal terms

Other websites have their own privacy policies. For website use, the designated governing law is the State of Colorado, United States and venue is the state and federal courts located in Denver, Colorado. These designations do not limit mandatory privacy rights or determine which privacy laws apply to you.

2. What we collect

Copy section link

2.1 The website itself

This website has no visitor accounts. You can request a demo through the Book a demo form on our contact page or in its overlay. We do not collect visitor analytics or set cookies, advertising identifiers or tracking pixels. The form processing described below is separate from the hosting request processing needed to deliver and protect the site.

2.2 Hosting requests and security logs

Our host, Cloudflare Pages, processes standard request data such as IP addresses, user agents, requested URLs, request times and request or security logs to deliver and protect the website. This processing is distinct from advertising or visitor analytics. We may use hosting or security information made available to us to investigate abuse, troubleshoot delivery and protect the site.

2.3 Game history on your device

The home page game saves play history, scores and game statistics in your browser’s localStorage. That history stays on your device. Only a high score you choose to save is submitted to the public leaderboard. The last handle you save to the leaderboard or for a score card is also remembered in localStorage to prefill the next prompt. It is browser storage, not a cookie. You can clear it by opening your browser’s site settings for this website and deleting its site data or local storage. This resets saved game history; browser controls and private browsing may also prevent it from being saved. Playing again may create new local history.

2.4 Demo requests

The demo form collects your name, work email, company, role, answers about your agents, and any notes you choose to provide. A submitted request also includes the request time and country. We use this information to respond to your request and arrange a demo. The form includes a consent checkbox for that use; requesting a demo does not subscribe you to promotional email.

Cloudflare Turnstile provides bot protection. It loads only when you reach the form’s review step and processes device and browser signals to distinguish people from bots. This security processing is not visitor analytics or advertising tracking. Resend delivers the internal request notification and your confirmation email; it is used server-side only.

2.5 Game leaderboard

If you choose to save a qualifying high score, we store your chosen handle, score, wave and submission time to show the public top 10. Those entries are public. Choose a handle that does not reveal personal information. Entries are deleted automatically when they fall out of the top 10.

The leaderboard uses no account or cookie. We do not store IP addresses or user agents with scores or run tokens. A signed run token and an expiring, single-use token identifier help prevent replay and implausible scores. The token identifier is separate from your entry and contains no handle or request metadata; it expires after six hours and is removed on a subsequent save. These checks raise the bar for cheating, but a determined player can still forge scores.

Cloudflare Turnstile loads only when the qualifying Save prompt opens, to perform the security check at save. It processes device and browser signals for bot protection. The hosting request processing in section 2.2 still applies. To request removal of a public entry, email [email protected] with the handle and score.

2.6 Email and business conversations

If you email us, we receive your address, name if supplied, message contents, attachments and ordinary email delivery information. Sales and design-partner conversations may include business contact details, organization, role, requirements and correspondence or meeting notes you provide. We do not record calls without telling you and obtaining consent where required.

You can choose what to share. Do not send passwords, credentials, unnecessary sensitive personal information or agent payloads containing other people’s information. Use redacted examples when discussing support or security. We do not ask for sensitive information through this website.

3. Why we use it

Copy section link

3.1 Purposes and lawful bases

Where the EU GDPR or UK GDPR applies, we rely on the following legal bases under Article 6. A basis applies only where its conditions are met; we do not rely on every basis for every use.

  • Legitimate interests (Article 6(1)(f)): delivering and securing the website, preventing abuse, responding to ordinary inquiries and demo requests, arranging demos, maintaining appropriate business contact records, and establishing or defending legal claims. We consider the impact on your rights and use this basis only where those interests are not overridden by your interests or fundamental rights.
  • Contract (Article 6(1)(b)): taking steps you request before entering a contract, including demo arrangements where this basis applies, or performing a contract with you. Where you represent an organization rather than contract personally, business contact processing generally rests on legitimate interests instead.
  • Consent (Article 6(1)(a)): processing where consent applies, including the permission given through the demo form’s consent checkbox, and optional communications where consent is required. You may withdraw consent at any time through our privacy contact; withdrawal does not affect the lawfulness of earlier processing. We will seek any separately required permission before sending promotional email.
  • Legal obligation (Article 6(1)(c)): complying with applicable recordkeeping, tax, regulatory, court or privacy requirements.

3.2 Choices and limits

Providing information in correspondence is voluntary, but without the details needed for a request or relationship we may be unable to respond or proceed. We do not use information collected under this policy for decisions based solely on automated processing that produce legal or similarly significant effects. We do not create advertising profiles. If we need an incompatible new purpose, we will provide the required notice and establish a lawful basis before that use.

4. What we never do

Copy section link

4.1 Our commitments

  • We do not sell personal information or share it for cross-context behavioural advertising, including “sale” or “sharing” as those terms are defined by applicable US state privacy laws.
  • We do not use personal information or customer data to train AI models, or authorize service providers to use that information for that purpose.
  • We do not read agent records that stay in the customer’s environment. Any customer-authorized transfer or support access must be covered by the customer agreement and its data processing terms.
  • We do not run website analytics, advertisements or tracking pixels, or follow visitors across websites.

5. When we share information

Copy section link

5.1 Service providers and advisers

We use our host to serve and protect the website and an email provider to deliver and store correspondence. For demo requests, Resend sends the internal notification and the confirmation email through server-side processing; the site loads no Resend browser scripts. Cloudflare Turnstile processes device and browser signals for bot protection only when the visitor reaches the form’s review step or opens a qualifying game score Save prompt. Saved game leaderboard entries are public as described in section 2.5. We will limit service provider access to what is necessary for their role and require appropriate confidentiality, security and data processing terms where required. Professional advisers, such as legal, accounting and insurance advisers, may receive information where necessary for their work and subject to appropriate confidentiality duties.

5.2 Legal requirements and protection

We may disclose information where the law requires it, in response to valid legal process, or where necessary and legally permitted to protect rights, safety or security, investigate abuse, or establish, exercise or defend legal claims. We will assess requests and limit disclosure to what is required or justified.

5.3 Business transfers and your instructions

Information may be disclosed in a proposed or completed merger, acquisition, financing, restructuring or sale of business assets, subject to appropriate safeguards and any required notice. A successor must handle information consistently with applicable law and the commitments that apply to it. We may also share information at your direction or with your consent for a stated purpose.

6. International transfers

Copy section link

6.1 Processing across borders

Hosting, email and professional services may process information outside your country, including in places whose privacy laws differ. Where applicable law restricts transfers, we will use an appropriate legal mechanism, such as an applicable adequacy decision or standard contractual clauses, with the required UK addendum or equivalent UK mechanism where relevant.

We will assess required transfer safeguards and supplementary measures where appropriate. We do not promise that all information covered by this policy stays in a particular country. Contact our privacy address to ask about relevant destinations and safeguards or to request a copy of the applicable safeguards, subject to lawful redactions.

7. How long we keep information

Copy section link

7.1 Information we control

We retain personal information only as long as reasonably necessary for the purpose described here, considering the relationship, sensitivity, legal duties and applicable limitation periods. Our policy is to retain correspondence and demo requests for up to 24 months after the last contact, unless a longer period is needed for an active relationship, a legal obligation or a dispute. We delete or anonymize information when it is no longer needed for those purposes.

For an active business relationship, we retain necessary contact and correspondence records while the relationship continues, then only for required recordkeeping or to address outstanding obligations or claims. We retain a limited record of privacy requests and our responses for as long as necessary to demonstrate compliance. If someone opts out of optional communications, we may keep the minimum suppression information needed to respect that choice.

A legal duty, dispute, security investigation or preservation requirement may justify longer retention of relevant records. When the reason ends, we will delete or anonymize information no longer needed. Where provider backups cannot be selectively edited, deletion may follow their backup lifecycle; information awaiting expiry must not be returned to ordinary use without preserving the deletion requirement.

7.2 Hosting logs, device storage and customer records

Hosting logs follow the host’s retention settings and applicable terms; this policy does not promise a log deletion period we do not control. Public game entries are deleted automatically when they fall out of the top 10, or following an applicable removal request. Game history and your remembered handle remain in your browser until you clear them, your browser removes that data or the game replaces older history. Customer product records follow customer-controlled retention and the applicable customer agreement.

8. How we protect information

Copy section link

8.1 Proportionate safeguards

We will apply technical and organizational safeguards appropriate to the nature of the information and the risks, including limiting access to people and providers who need it, minimizing information we request, and addressing security issues. No method of transmission or storage is completely secure; we cannot guarantee absolute security.

If a personal data breach triggers legal notification duties, we will notify the relevant authorities and affected people as required. To report a suspected security issue, contact [email protected]. Avoid including secrets or unnecessary personal information in your report.

9. Your privacy rights

Copy section link

9.1 EU, EEA and United Kingdom

Where the GDPR or UK GDPR applies, you may have rights to access your personal information and obtain a copy; rectify inaccurate or incomplete information; request erasure; restrict processing; and receive or transfer information in a portable format where processing is automated and based on consent or contract.

You may object to processing based on legitimate interests on grounds relating to your situation. We will stop that processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or processing is needed for legal claims. You may object to direct marketing at any time, without that balancing test. You may withdraw consent at any time.

You may complain to a competent supervisory authority, including in the place of your habitual residence, work or an alleged infringement. In the UK, this includes the Information Commissioner’s Office. Contacting us first is optional and does not limit your right to complain.

9.2 California and other US states

Where the CCPA/CPRA or another applicable state privacy law covers our processing, eligible residents may request to know or access the categories and specific pieces of personal information collected, its sources, purposes and recipients; delete personal information; correct inaccuracies; and obtain a portable copy where required.

You may opt out of sale, sharing for cross-context behavioural advertising, targeted advertising or certain profiling where applicable. We do none of those activities. We do not collect sensitive personal information for purposes that require a right to limit its use under California law. The categories, sources, purposes and disclosures described in this policy also explain our practices during the preceding 12 months, or since operations began if shorter.

We will not discriminate or retaliate against you for exercising a privacy right. Where permitted, you may designate an authorized agent to submit a request. We may request proof of authorization and verify your identity directly, except where applicable law requires a different process, including for a valid power of attorney.

If we deny a request, we will explain the reason and any available appeal process. Where your state provides an appeal right, reply to our privacy address asking for an appeal; we will provide a reasoned response within the applicable deadline and explain how to contact the relevant regulator if the appeal is denied.

9.3 How to make a request

Email [email protected] with the right you wish to exercise and enough context to locate the information. You do not need an account. We will verify identity and authority proportionately to the request and the risk, normally using information already available to us. We will request additional information only when reasonably necessary, use it to verify and respond, and avoid asking for identity documents unless necessary. Opt-out signals do not require identity verification where the law says otherwise.

Rights are subject to lawful exceptions, including protection of others’ rights and required retention. If we cannot fulfill all or part of a request, we will explain the legal reason and available remedies. Requests are generally free; a fee or refusal applies only when allowed by law, with an explanation.

9.4 Response deadlines

For GDPR and UK GDPR requests, we will respond without undue delay and within one month of receipt. Where legally permitted because of complexity or the number of requests, this may extend by two further months; we will explain the extension within the initial month. Any lawful adjustment to the deadline for necessary clarification or identity checks will follow the applicable rules.

For California requests to know or delete, we will acknowledge receipt within 10 business days. We will respond to California requests to know, delete or correct within 45 calendar days, with an additional 45 calendar days only where reasonably necessary and legally permitted, and notice within the initial period. Other states’ deadlines and appeal rules may differ; we will follow the applicable deadline, including any shorter one. Any applicable opt-out request will be handled as soon as feasible within the legally required period.

10. Children’s privacy

Copy section link

10.1 Age and deletion

The website and our services are not directed to children under 16. We do not knowingly collect their personal information. If you believe a child has provided personal information to us, contact our privacy address. We will take appropriate steps to investigate and delete information collected contrary to applicable law.

11. Browser privacy signals

Copy section link

11.1 Do Not Track and Global Privacy Control

We honor Do Not Track and Global Privacy Control by default because we do not track visitors across websites, sell personal information or share it for cross-context behavioural advertising. You receive those protections whether or not your browser sends a signal. Necessary hosting request processing and local game storage do not become advertising tracking because of these signals.

If our practices change, we will preserve required opt-out rights and implement any required signal handling before the new processing starts.

12. Changes and contact

Copy section link

12.1 Policy changes

We may update this policy to reflect our practices or legal requirements. We will publish the revised policy here and update its effective date. For material changes, we will provide additional notice and obtain consent where required before applying the change. A new policy does not override mandatory rights or a separate customer agreement.

12.2 Contact

For privacy questions or requests, contact [email protected]. For legal correspondence, contact [email protected]. For security reports, use the security contact in section 8.