🍯 Honeybase

Privacy Policy

Last updated: 15 July 2026

This Privacy Policy explains how Honeybase ("we", "us") collects, uses, and safeguards personal data when you visit honeybase.ai, request early access, or use the Honeybase application at app.honeybase.ai. It also describes the rights available to individuals in the European Union (EU), European Economic Area (EEA), and United Kingdom (UK) under the General Data Protection Regulation (GDPR) and UK GDPR.

1. Who is responsible for your data

Honeybase is the data controller for the personal data described in this policy. For any privacy question or to exercise your rights, contact us at privacy@honeybase.ai.

2. What we collect

  • Early-access form: your work email, and optionally your company name and team size.
  • Account data: your first and last name, email address, and the organization and team you belong to.
  • Authentication data: a securely hashed password (we never store it in plain text) or, if you sign in with Google, your verified Google account email.
  • Content you create: the workflows, tasks, and data you and your team enter into the product, which may include content sent to AI providers when you run AI-powered steps, when you use the Barry AI assistant in the workflow editor, or when you ask it to debug a workflow run (the run's step outputs are then shared with your chosen AI provider, with credential-like fields redacted).
  • Connected AI apps (MCP): you can connect an AI assistant of your choice (for example Claude) to your Honeybase account through our MCP connector. After you sign in and explicitly approve the connection for one of your organizations, that assistant can read (and, with the scopes you approve, create and edit) your processes, workflows, run results, tasks, schedules, AI agents and Agent tools on your behalf — so that content flows to the AI app you chose to connect, under that provider's own terms. Credential-like fields are redacted and access is limited to what your own account can see. You can revoke a connection at any time, and revocation takes effect within seconds.
  • In-app notifications: messages we generate for you in the product (for example, when a workflow run fails), stored against your account so you can see them in the notification centre. These stay within our own systems and are not shared with any third party.
  • Availability status & history: whether you are currently available to work, which processes you accept tasks for, and a change history of those settings (who changed them and when), used to route work within your team. Other members of your organization can see this status; changing it for someone else requires a permission granted by your administrator. This data stays within our own systems and is not shared with any third party.
  • Technical logs: limited operational logs (e.g. request method, path, and timing) used to keep the service reliable and secure. We do not run third-party analytics or advertising trackers.

3. Why we use it and our legal bases

  • To provide the service (managing your account, running your workflows) — performance of a contract.
  • To respond to early-access interest and contact you about the product — legitimate interest.
  • To keep the service secure and reliable (authentication, rate limiting, fraud and abuse prevention) — legitimate interest.
  • To comply with legal obligations where applicable — legal obligation.

4. Service providers (sub-processors)

We share personal data only with the service providers needed to operate Honeybase, each under a data processing agreement:

  • Google Cloud Platform — application and database hosting (United States).
  • Resend — transactional and notification email delivery.
  • Google (Sign in with Google) — optional authentication; used only to verify your identity at sign-in.
  • Google reCAPTCHA — protects our forms from automated abuse; collects device and usage signals to distinguish humans from bots.
  • Infisical — secure storage of secrets and integration credentials.
  • Meta (WhatsApp Business Cloud API) — if you connect a WhatsApp Business number, sends and receives WhatsApp messages on your behalf; processes sender/recipient phone numbers, message content and contact profile names, including data of the people who message your business.
  • AI providers (via our model gateway) — process the content of AI-powered workflow steps you choose to run, of your Barry AI assistant conversations (including workflow definitions), and of workflow run outputs when you ask Barry AI to debug a run.
  • Neon (a Databricks company) — if your organization activates its dedicated database, hosts that PostgreSQL database on AWS (us-east-1, N. Virginia); processes whatever operational data your organization chooses to store in it, which may include personal data of your own users or contacts.
  • Exa — web-search API behind the built-in web search tool available to AI agents; processes the search queries those agents compose (which may include details from the conversation or task that prompted the search).

AI apps you connect yourself — whether by bringing your own AI provider key or by connecting an assistant through our MCP connector — are your chosen providers, not our sub-processors: they receive data only because you connected them, and under your agreement with that provider.

We do not sell your personal data.

5. International data transfers

Honeybase is currently hosted in the United States. If you access the service from the EU, EEA, or UK, your personal data is transferred to and processed in the United States. We rely on appropriate safeguards for these transfers, including the EU–U.S. Data Privacy Framework where available and the European Commission's Standard Contractual Clauses with our providers.

6. How long we keep it

  • Account data is kept for as long as your account is active, and deleted on request.
  • Internal change logs are automatically deleted after 30 days.
  • Authentication tokens are short-lived and expire automatically.
  • Early-access enquiries are kept only as long as needed to follow up with you.

7. Your rights

Subject to applicable law, you have the right to access, correct, delete, or export your personal data, to object to or restrict certain processing, and to withdraw consent where processing is based on it. To exercise any of these rights, email privacy@honeybase.ai and we will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.

8. Cookies and local storage

The Honeybase landing page sets no tracking or advertising cookies. The application uses strictly necessary storage to keep you signed in and to remember preferences such as your language and theme. We do not use third-party analytics or advertising trackers. Where the early-access form is protected by Google reCAPTCHA, Google may set cookies and process device signals for the sole purpose of fraud and abuse prevention on our sign-up and sign-in forms; this use is governed by Google's privacy policy.

9. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above and, where appropriate, by notifying you directly.

← Back to home