Last updated: July 17, 2026
FieldHash provides authority and evidence infrastructure for enterprise AI workflows. We use data to govern candidate memory, actions, and reviewed precedents; produce evidence artifacts where configured; secure the platform; and support customer deployments. We do not sell personal data. Model routing, hosting region, retention, subprocessors, and audit-log ownership may vary by deployment agreement and configuration.
This policy applies to the FieldHash website, request-access flow, hosted product surfaces, APIs, authority and evidence services, ledger/evidence tooling, and related enterprise pilots or deployments unless a separate written agreement says otherwise.
For enterprise customers, a data processing addendum, pilot agreement, statement of work, or deployment-specific security terms may control in the event of conflict with this public policy.
FieldHash acts as the controller for public-site inquiries, pilot requests, and direct account or support relationships. When an enterprise customer supplies workflow data under a deployment agreement, FieldHash acts as a processor or service provider to the extent stated in that agreement and follows the customer's documented instructions.
The customer remains responsible for deciding what data may enter the workflow, which systems and reviewers define authority, and which retention or regional requirements apply.
Depending on how FieldHash is used, we may collect or process:
The public FieldHash website sets no cookies. We do not use advertising trackers, cross-site identifiers, or session recording.
To understand aggregate site usage, we use a cookieless analytics service provided by our hosting platform. It stores nothing on your device. Visits are counted using an anonymous identifier derived from the incoming request that rotates daily, so visitors cannot be tracked across days or across sites. We see aggregate page counts, referrers, and coarse device and geography categories, not individual browsing profiles.
This is why the site shows no cookie banner: there is nothing stored on your device to consent to. If that ever changes, this section and the site will change visibly with it.
We use information to:
FieldHash may route prompts, candidate memories, governed context packets, tool or action candidates, governed action packets, reviewed-precedent context, and related inputs to AI model providers when needed to provide requested functionality. The specific model path depends on the customer configuration.
Enterprise deployments may be configured for customer-approved providers, private endpoints, customer VPC, EU-region cloud infrastructure, local models, or on-prem processing. If a deployment uses a third-party model provider, that provider may process the submitted information according to the applicable agreement and configuration.
FieldHash is designed to govern what context is sent to a model and which action candidates are allowed forward; it is not a guarantee that all deployments are local, zero-egress, or provider-free unless those controls are explicitly configured and contractually agreed.
FieldHash Ledger artifacts may include governance events, selected/blocked record references, selected/blocked action references, reasons, hashes, signatures, checkpoint metadata, certificate references, transparency anchors, and verification reports. These artifacts are designed to make the answer path or action path reviewable while minimizing the sensitive source content retained in the evidence layer.
By default, evidence artifacts should retain the least source content needed for review: record identifiers, hashes, reason codes, authority-source references, timestamps, and reviewer-visible status. Deployments may be configured to store redacted snippets, customer-owned packet exports, or fuller evidence copies when the customer requests them for legal, security, compliance, or dispute-resolution workflows.
If source content is deleted or redacted, FieldHash will apply the deletion or redaction to eligible copies under the applicable agreement and product configuration. Some minimized audit references may remain when retention is required or permitted for security, legal, dispute-resolution, contractual, or compliance-review purposes. Enterprise agreements can define retention periods, redaction behavior, export ownership, deletion workflows, and whether audit records are held by FieldHash, the customer, or both.
We may use third-party services to operate FieldHash, including:
These providers process information as needed to deliver the requested service. Enterprise customers may receive deployment-specific subprocessors, region, retention, and security documentation during procurement or pilot setup.
FieldHash does not assume one fixed production model or hosting route for every customer. The subprocessors required for a deployment are disclosed before that deployment processes customer workflow data. Material subprocessor changes are handled under the notice method and timing in the applicable agreement.
We do not sell personal data. We may share information only when necessary to:
We retain information for as long as reasonably needed for the purpose collected, unless a longer period is required or permitted by law, contract, security, audit, or dispute-resolution needs.
| Data class | Default public posture |
|---|---|
| Website and inquiry data | Kept only as needed to respond, operate the site, and meet limited security or legal needs. |
| Pilot workflow data | Defined by product settings, customer instructions, and the deployment agreement. |
| Evidence and security records | Minimized to references, hashes, reason codes, and operational metadata where fuller content is unnecessary. |
We use reasonable technical and organizational safeguards, including access controls, secure transport, least-privilege practices, logging, and deployment-specific controls where configured. FieldHash Ledger can add reviewer-verifiable evidence packets for selected artifacts, with stronger tamper-evidence profiles available where anchoring, signing, key custody, and retention controls are configured. No system can be guaranteed perfectly secure or tamper-proof.
If FieldHash confirms a security incident affecting customer data, we will investigate, contain, and notify affected customers as required by applicable law and the relevant agreement. Suspected vulnerabilities should be reported to security@fieldhash.ai.
Subject to legal and contractual limits, you may request to:
Some requests may be handled through your organization if FieldHash is provided under an enterprise agreement. To submit a privacy request, email privacy@fieldhash.ai from the relevant account or organization email.
FieldHash is not directed to children under 13 or the minimum age required by local law. If you believe a child has provided personal data, contact us so we can take appropriate action.
If you are in the EEA or UK, legal bases may include contract performance, legitimate interests in operating and securing FieldHash, consent where required, and compliance with legal obligations. Where international transfers occur, appropriate safeguards may be used as required.
If you are in California, this policy is intended to serve as a notice at collection. We collect the categories above for the purposes above, do not sell personal information, and share information with service providers/processors as needed to operate requested features. You may request access, correction, deletion, and information about applicable sharing practices by contacting privacy@fieldhash.ai.
We may update this policy from time to time. If we make material changes, we will update the date above and provide additional notice where required.
Privacy requests: privacy@fieldhash.ai
General support: support@fieldhash.ai
Security reports: security@fieldhash.ai
Deployment and security posture: Security and Deployment