No cookies set by us.
We do not set cookies on this website.
A clear account of what reaches us, what stays with you, and the choices you have.
Privacy starts with collecting less.
We do not set cookies on this website.
No advertising, tracking pixels or visitor analytics.
Your game history stays in your browser. If you save a high score, we store only your chosen handle and score.
Agent records in your environment stay there unless you choose otherwise.
We do not sell personal information or use personal information or customer data to train AI models.
Your answers are used to reply and arrange a demo.
The short version and margin notes are summaries. The full policy below controls.
Humming Arms LLC (“Humming Arms”, “we”, “us” or “our”) is responsible as controller for personal information we handle through this website, demo requests, email correspondence, and sales and design-partner conversations. Personal information means information that identifies, relates to, or can reasonably be linked to a person.
Our privacy contact is [email protected].
The product is not generally available. Our self-hosted-first approach is for design partners to run Humming Arms in their own infrastructure. Agent records stay in the customer’s environment unless the customer chooses otherwise. We do not read records that remain there.
Product data processed under a customer agreement is governed by that agreement and its data processing terms, rather than this website policy. Those terms determine the parties’ roles, instructions, access, retention and any authorized support access. If your information is in a customer’s records, direct requests first to that customer; we will assist as required by the applicable agreement and law.
Our product data handling principles are redaction at the sensor, data minimization, opt-in payload capture under customer policy, and customer-controlled retention and access. These principles describe the approach to customer deployments; they are not a promise that every control is available in every deployment.
Other websites have their own privacy policies. For website use, the designated governing law is the State of Colorado, United States and venue is the state and federal courts located in Denver, Colorado. These designations do not limit mandatory privacy rights or determine which privacy laws apply to you.
This website has no visitor accounts. You can request a demo through the Book a demo form on our contact page or in its overlay. We do not collect visitor analytics or set cookies, advertising identifiers or tracking pixels. The form processing described below is separate from the hosting request processing needed to deliver and protect the site.
Our host, Cloudflare Pages, processes standard request data such as IP addresses, user agents, requested URLs, request times and request or security logs to deliver and protect the website. This processing is distinct from advertising or visitor analytics. We may use hosting or security information made available to us to investigate abuse, troubleshoot delivery and protect the site.
The home page game saves play history, scores and game statistics in your browser’s localStorage. That history stays on your device. Only a high score you choose to save is submitted to the public leaderboard. The last handle you save to the leaderboard or for a score card is also remembered in localStorage to prefill the next prompt. It is browser storage, not a cookie. You can clear it by opening your browser’s site settings for this website and deleting its site data or local storage. This resets saved game history; browser controls and private browsing may also prevent it from being saved. Playing again may create new local history.
The demo form collects your name, work email, company, role, answers about your agents, and any notes you choose to provide. A submitted request also includes the request time and country. We use this information to respond to your request and arrange a demo. The form includes a consent checkbox for that use; requesting a demo does not subscribe you to promotional email.
Cloudflare Turnstile provides bot protection. It loads only when you reach the form’s review step and processes device and browser signals to distinguish people from bots. This security processing is not visitor analytics or advertising tracking. Resend delivers the internal request notification and your confirmation email; it is used server-side only.
If you choose to save a qualifying high score, we store your chosen handle, score, wave and submission time to show the public top 10. Those entries are public. Choose a handle that does not reveal personal information. Entries are deleted automatically when they fall out of the top 10.
The leaderboard uses no account or cookie. We do not store IP addresses or user agents with scores or run tokens. A signed run token and an expiring, single-use token identifier help prevent replay and implausible scores. The token identifier is separate from your entry and contains no handle or request metadata; it expires after six hours and is removed on a subsequent save. These checks raise the bar for cheating, but a determined player can still forge scores.
Cloudflare Turnstile loads only when the qualifying Save prompt opens, to perform the security check at save. It processes device and browser signals for bot protection. The hosting request processing in section 2.2 still applies. To request removal of a public entry, email [email protected] with the handle and score.
If you email us, we receive your address, name if supplied, message contents, attachments and ordinary email delivery information. Sales and design-partner conversations may include business contact details, organization, role, requirements and correspondence or meeting notes you provide. We do not record calls without telling you and obtaining consent where required.
You can choose what to share. Do not send passwords, credentials, unnecessary sensitive personal information or agent payloads containing other people’s information. Use redacted examples when discussing support or security. We do not ask for sensitive information through this website.
Where the EU GDPR or UK GDPR applies, we rely on the following legal bases under Article 6. A basis applies only where its conditions are met; we do not rely on every basis for every use.
Providing information in correspondence is voluntary, but without the details needed for a request or relationship we may be unable to respond or proceed. We do not use information collected under this policy for decisions based solely on automated processing that produce legal or similarly significant effects. We do not create advertising profiles. If we need an incompatible new purpose, we will provide the required notice and establish a lawful basis before that use.
We use our host to serve and protect the website and an email provider to deliver and store correspondence. For demo requests, Resend sends the internal notification and the confirmation email through server-side processing; the site loads no Resend browser scripts. Cloudflare Turnstile processes device and browser signals for bot protection only when the visitor reaches the form’s review step or opens a qualifying game score Save prompt. Saved game leaderboard entries are public as described in section 2.5. We will limit service provider access to what is necessary for their role and require appropriate confidentiality, security and data processing terms where required. Professional advisers, such as legal, accounting and insurance advisers, may receive information where necessary for their work and subject to appropriate confidentiality duties.
We may disclose information where the law requires it, in response to valid legal process, or where necessary and legally permitted to protect rights, safety or security, investigate abuse, or establish, exercise or defend legal claims. We will assess requests and limit disclosure to what is required or justified.
Information may be disclosed in a proposed or completed merger, acquisition, financing, restructuring or sale of business assets, subject to appropriate safeguards and any required notice. A successor must handle information consistently with applicable law and the commitments that apply to it. We may also share information at your direction or with your consent for a stated purpose.
Hosting, email and professional services may process information outside your country, including in places whose privacy laws differ. Where applicable law restricts transfers, we will use an appropriate legal mechanism, such as an applicable adequacy decision or standard contractual clauses, with the required UK addendum or equivalent UK mechanism where relevant.
We will assess required transfer safeguards and supplementary measures where appropriate. We do not promise that all information covered by this policy stays in a particular country. Contact our privacy address to ask about relevant destinations and safeguards or to request a copy of the applicable safeguards, subject to lawful redactions.
We retain personal information only as long as reasonably necessary for the purpose described here, considering the relationship, sensitivity, legal duties and applicable limitation periods. Our policy is to retain correspondence and demo requests for up to 24 months after the last contact, unless a longer period is needed for an active relationship, a legal obligation or a dispute. We delete or anonymize information when it is no longer needed for those purposes.
For an active business relationship, we retain necessary contact and correspondence records while the relationship continues, then only for required recordkeeping or to address outstanding obligations or claims. We retain a limited record of privacy requests and our responses for as long as necessary to demonstrate compliance. If someone opts out of optional communications, we may keep the minimum suppression information needed to respect that choice.
A legal duty, dispute, security investigation or preservation requirement may justify longer retention of relevant records. When the reason ends, we will delete or anonymize information no longer needed. Where provider backups cannot be selectively edited, deletion may follow their backup lifecycle; information awaiting expiry must not be returned to ordinary use without preserving the deletion requirement.
Hosting logs follow the host’s retention settings and applicable terms; this policy does not promise a log deletion period we do not control. Public game entries are deleted automatically when they fall out of the top 10, or following an applicable removal request. Game history and your remembered handle remain in your browser until you clear them, your browser removes that data or the game replaces older history. Customer product records follow customer-controlled retention and the applicable customer agreement.
We will apply technical and organizational safeguards appropriate to the nature of the information and the risks, including limiting access to people and providers who need it, minimizing information we request, and addressing security issues. No method of transmission or storage is completely secure; we cannot guarantee absolute security.
If a personal data breach triggers legal notification duties, we will notify the relevant authorities and affected people as required. To report a suspected security issue, contact [email protected]. Avoid including secrets or unnecessary personal information in your report.
Where the GDPR or UK GDPR applies, you may have rights to access your personal information and obtain a copy; rectify inaccurate or incomplete information; request erasure; restrict processing; and receive or transfer information in a portable format where processing is automated and based on consent or contract.
You may object to processing based on legitimate interests on grounds relating to your situation. We will stop that processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or processing is needed for legal claims. You may object to direct marketing at any time, without that balancing test. You may withdraw consent at any time.
You may complain to a competent supervisory authority, including in the place of your habitual residence, work or an alleged infringement. In the UK, this includes the Information Commissioner’s Office. Contacting us first is optional and does not limit your right to complain.
Where the CCPA/CPRA or another applicable state privacy law covers our processing, eligible residents may request to know or access the categories and specific pieces of personal information collected, its sources, purposes and recipients; delete personal information; correct inaccuracies; and obtain a portable copy where required.
You may opt out of sale, sharing for cross-context behavioural advertising, targeted advertising or certain profiling where applicable. We do none of those activities. We do not collect sensitive personal information for purposes that require a right to limit its use under California law. The categories, sources, purposes and disclosures described in this policy also explain our practices during the preceding 12 months, or since operations began if shorter.
We will not discriminate or retaliate against you for exercising a privacy right. Where permitted, you may designate an authorized agent to submit a request. We may request proof of authorization and verify your identity directly, except where applicable law requires a different process, including for a valid power of attorney.
If we deny a request, we will explain the reason and any available appeal process. Where your state provides an appeal right, reply to our privacy address asking for an appeal; we will provide a reasoned response within the applicable deadline and explain how to contact the relevant regulator if the appeal is denied.
Email [email protected] with the right you wish to exercise and enough context to locate the information. You do not need an account. We will verify identity and authority proportionately to the request and the risk, normally using information already available to us. We will request additional information only when reasonably necessary, use it to verify and respond, and avoid asking for identity documents unless necessary. Opt-out signals do not require identity verification where the law says otherwise.
Rights are subject to lawful exceptions, including protection of others’ rights and required retention. If we cannot fulfill all or part of a request, we will explain the legal reason and available remedies. Requests are generally free; a fee or refusal applies only when allowed by law, with an explanation.
For GDPR and UK GDPR requests, we will respond without undue delay and within one month of receipt. Where legally permitted because of complexity or the number of requests, this may extend by two further months; we will explain the extension within the initial month. Any lawful adjustment to the deadline for necessary clarification or identity checks will follow the applicable rules.
For California requests to know or delete, we will acknowledge receipt within 10 business days. We will respond to California requests to know, delete or correct within 45 calendar days, with an additional 45 calendar days only where reasonably necessary and legally permitted, and notice within the initial period. Other states’ deadlines and appeal rules may differ; we will follow the applicable deadline, including any shorter one. Any applicable opt-out request will be handled as soon as feasible within the legally required period.
The website and our services are not directed to children under 16. We do not knowingly collect their personal information. If you believe a child has provided personal information to us, contact our privacy address. We will take appropriate steps to investigate and delete information collected contrary to applicable law.
We honor Do Not Track and Global Privacy Control by default because we do not track visitors across websites, sell personal information or share it for cross-context behavioural advertising. You receive those protections whether or not your browser sends a signal. Necessary hosting request processing and local game storage do not become advertising tracking because of these signals.
If our practices change, we will preserve required opt-out rights and implement any required signal handling before the new processing starts.
We may update this policy to reflect our practices or legal requirements. We will publish the revised policy here and update its effective date. For material changes, we will provide additional notice and obtain consent where required before applying the change. A new policy does not override mandatory rights or a separate customer agreement.
For privacy questions or requests, contact [email protected]. For legal correspondence, contact [email protected]. For security reports, use the security contact in section 8.