Back to Studio Overview
LEGAL SPECIFICATION // DATA PRIVACY & GOVERNANCE

Privacy Policy

EFFECTIVE DATE: SEPTEMBER 20, 2026REVISION: V1.2SCOPE: HOPFIELDLABS.COM

At Hopfield Labs, privacy and data integrity are fundamental to how we engineer systems. We design our client intake pipelines, storage buckets, and web applications with strict confidentiality and minimal telemetry.

This Privacy Policy details how we handle information submitted through hopfieldlabs.com, our multi-step intake estimator, and our live GenAI demonstration terminal. It explains where your technical data is persisted, how long it is retained, and how you can exercise your statutory privacy rights.

Zero Data Monetization

We do not sell, rent, or commercialize client inquiries, briefs, or contact records under any circumstance.

Isolated Private Storage

Form data and briefs are secured by Supabase Row-Level Security (RLS) and authenticated private buckets.

Automated Draft Pruning

Uncompleted intake drafts and temporary resume tokens are automatically purged after 14 calendar days.

Cookieless Analytics

We use privacy-friendly edge telemetry with zero third-party marketing trackers and zero cross-site cookies.

Contractual Scope: This policy strictly applies to our public website, the interactive GenAI concierge demo, and our multi-step project intake pipeline. Commercial engagements and engineering deliverables are independently governed by dedicated Master Services Agreements (MSA) and IP assignment contracts.

01 //Information We Collect

A. Information You Provide Directly

  • Contact and Intake Form Data: Full name, email address, company name, service area of interest, project stage (solo founder, funded startup, enterprise, or university student), budget tier, target delivery timeline, and scoping specifications.
  • Academic / FYP Details: Academic institution, degree program, submission deadlines, and specific assistance requirements (prototype build, LaTeX documentation, or 1-on-1 viva defense mentoring).
  • Files and Technical References: Architectural specifications, project briefs, proposal drafts (PDF, DOCX), Figma design links, and GitHub repository URLs attached during intake.
  • Direct Communications: Any inquiries transmitted via email, verified messaging channels, or scheduled discovery video conferences.

B. Information Collected Automatically

  • Telemetry and Network Diagnostics: Client IP address (temporarily hashed for in-memory rate limiting and spam defense), device category, operating system version, browser user-agent, and anonymized page transition timestamps.

C. Information from the GenAI Concierge Demo

Our homepage features an interactive streaming terminal demonstrating GenAI integration capabilities. Prompts and assistant responses are logged in memory to monitor retrieval quality and enforce anti-abuse rate limits (15 queries per 10 minutes per IP).

Notice: Do not input proprietary source code, patient healthcare identifiers, API keys, or confidential financial credentials into the demonstration terminal. It is an illustrative technical showcase.

D. Incomplete & Saved Intake Drafts

When you initiate the "Start a Project" pipeline and supply an email address for a resume link, we generate a cryptographically random token to preserve your in-progress selections. Unsubmitted drafts are automatically pruned after 14 days.

02 //How We Use Your Information

We process personal and technical information strictly to deliver our core studio operations:

  • Evaluate project technical feasibility, engineer architecture proposals, and generate binding cost estimates.
  • Execute development sprints, code reviews, and academic capstone mentoring engagements.
  • Issue authenticated resume links for saved multi-step intake drafts.
  • Benchmark, optimize, and calibrate our serverless infrastructure and GenAI models.
  • Enforce automated IP rate limits, honeypot defenses, and bot protection protocols.
  • Satisfy statutory legal, tax, and accounting reporting requirements.
HOPFIELD LABS DOES NOT SELL, RENT, OR MONETIZE CLIENT PERSONAL DATA UNDER ANY CIRCUMSTANCE.

03 //Infrastructure & Storage Architecture

DATABASE LAYER (SUPABASE)

Contact submissions and intake records are persisted in a managed PostgreSQL cluster hosted by Supabase. Access is restricted to authenticated server-side service roles; anonymous client queries are rejected by Row-Level Security (RLS).

ISOLATED STORAGE BUCKETS

Files attached during intake are uploaded directly to private storage buckets using single-use signed URLs. Buckets are not public; assets can only be retrieved by authorized Hopfield Labs staff.

EDGE HOSTING (VERCEL)

Next.js App Router applications, static assets, and Server Actions run across Vercel's global edge network, protected by TLS 1.3 encryption and DDoS mitigation.

EMAIL DISPATCH (RESEND)

Transactional alerts and intake confirmations are delivered through Resend over encrypted SMTP/API protocols.

04 //Data Retention Windows

Data CategoryRetention SchedulePurpose & Mechanism
Qualified Inquiries & LeadsDuration of Project + 5 YearsRetained for project lifecycle continuity, accounting, and tax compliance.
Abandoned Intake Drafts14 Calendar DaysAutomatically deleted from PostgreSQL database if not completed.
GenAI Concierge Logs30 Calendar DaysMaintained in transient logs for quality review and abuse prevention, then purged.

You may request expedited erasure of your records at any time by contacting our data protection officer (see Section 07).

05 //Cookies & Tracking Technologies

Hopfield Labs prioritizes minimalist, privacy-first web architecture:

  • Local Storage: We use browser localStorage solely to preserve client-side stepper progress during the intake flow so your selections are not lost on accidental refresh.
  • Cookieless Analytics: We utilize Vercel Web Analytics to measure aggregated traffic, geographical region, and core web vitals. This system does not place tracking cookies, collect personal identifiers, or perform cross-site tracking.

06 //Disclosure & Sub-Processors

We disclose client information solely under the following limited conditions:

  • Operational Infrastructure Partners: Cloud hosting, database, and email delivery providers listed in Section 09, strictly bound by data processing agreements.
  • Statutory & Legal Compulsion: When required by binding legal process, judicial warrant, or regulatory order.
  • Studio Restructuring: In the event of a merger, acquisition, or asset transfer, subject to identical confidentiality commitments.

07 //Your Rights & Data Subject Requests

Under GDPR, CCPA, and international data protection standards, you maintain enforceable rights regarding your records:

Right of Access
Request an explicit copy of all personal and project data associated with your profile.
Right of Rectification
Correct outdated, inaccurate, or incomplete contact and scoping information.
Right of Erasure
Demand total deletion of your database records, uploaded briefs, and draft tokens.
Right to Restrict Processing
Limit how we utilize your contact profile during active negotiations.
Right to Data Portability
Receive your technical specifications and inquiry data in a structured JSON format.
Right to Withdraw Consent
Opt out of non-essential communications at any moment with zero penalty.

To submit an inquiry, email our privacy desk at privacy@hopfieldlabs.com. We process and confirm verification within 30 business days.

08 //GenAI Demonstration Terminal Disclosures

The GenAI Concierge embedded on our homepage is an illustrative demonstration of low-latency token streaming and domain-specific knowledge augmentation. It does not constitute a confidential client portal or binding consultation channel.

Sessions are rate-limited via client IP hashing. Queries may be reviewed by engineering staff to calibrate our RAG retrieval algorithms, prevent prompt injection, and audit system performance.

09 //Third-Party Sub-Processors & External Policies

SupabaseVERIFIED
PostgreSQL Database & Storage

Stores intake leads and uploaded files protected by Row-Level Security (RLS).

Review Supabase Privacy Policy
VercelVERIFIED
Hosting & Serverless Compute

Hosts web platform and provides cookieless privacy-preserving edge telemetry.

Review Vercel Privacy Policy
ResendVERIFIED
Transactional Email Infrastructure

Dispatches lead notification alerts and draft resume tokens.

Review Resend Privacy Policy
Cal.comVERIFIED
Discovery Call Scheduling

Handles direct calendar discovery session booking when initiated by client.

Review Cal.com Privacy Policy

10 //Children's Privacy

Hopfield Labs platforms and engineering services are structured exclusively for enterprise founders, commercial SMEs, and university students engaging in technical research. We do not knowingly harvest or solicit data from individuals under 13 years of age (or the relevant age threshold in your jurisdiction).

11 //Amendments to This Policy

We periodically revise this specification to mirror adjustments in technical architecture, legal standards, or operational workflows. The effective revision timestamp at the top of this document will always denote the latest release.

12 //Data Protection Officer & Contact

HOPFIELD LABS ENGINEERING STUDIO

Direct all privacy inquiries, data subject access requests, or security disclosures to:

Privacy Officer:privacy@hopfieldlabs.com
General Inquiries:contact@hopfieldlabs.com