Privacy Policy

Last updated: July 17, 2026

Plain English Summary

FieldHash provides authority and evidence infrastructure for enterprise AI workflows. We use data to govern candidate memory, actions, and reviewed precedents; produce evidence artifacts where configured; secure the platform; and support customer deployments. We do not sell personal data. Model routing, hosting region, retention, subprocessors, and audit-log ownership may vary by deployment agreement and configuration.

1. Scope

This policy applies to the FieldHash website, request-access flow, hosted product surfaces, APIs, authority and evidence services, ledger/evidence tooling, and related enterprise pilots or deployments unless a separate written agreement says otherwise.

For enterprise customers, a data processing addendum, pilot agreement, statement of work, or deployment-specific security terms may control in the event of conflict with this public policy.

2. Our Role

FieldHash acts as the controller for public-site inquiries, pilot requests, and direct account or support relationships. When an enterprise customer supplies workflow data under a deployment agreement, FieldHash acts as a processor or service provider to the extent stated in that agreement and follows the customer's documented instructions.

The customer remains responsible for deciding what data may enter the workflow, which systems and reviewers define authority, and which retention or regional requirements apply.

3. Information We Collect

Depending on how FieldHash is used, we may collect or process:

  • Account and contact information, such as name, email address, organization, role, and authentication identifiers.
  • Request-access and support communications, including pilot requirements, deployment preferences, and security-review materials you provide.
  • Candidate memory, context, actions, and reviewed-precedent inputs submitted to FieldHash, such as records, documents, notes, decisions, corrections, rollback events, scopes, review status, supersession metadata, action packets, and model-input packets.
  • Governed-inference outputs, such as selected-record references, blocked-record or action references, precedent reuse or suspension status, governance reasons, audit packets, evidence trails, and ledger references. Full source content is included in evidence artifacts only where configured or needed to provide the requested workflow.
  • Technical and operational data, such as device/browser metadata, API logs, timestamps, request identifiers, usage metrics, error logs, security events, and deployment diagnostics.
  • Configuration data, such as model-route settings, region preferences, VPC/on-prem requirements, access controls, retention settings, and customer-approved integrations.

4. Website Analytics and Cookies

The public FieldHash website sets no cookies. We do not use advertising trackers, cross-site identifiers, or session recording.

To understand aggregate site usage, we use a cookieless analytics service provided by our hosting platform. It stores nothing on your device. Visits are counted using an anonymous identifier derived from the incoming request that rotates daily, so visitors cannot be tracked across days or across sites. We see aggregate page counts, referrers, and coarse device and geography categories, not individual browsing profiles.

This is why the site shows no cookie banner: there is nothing stored on your device to consent to. If that ever changes, this section and the site will change visibly with it.

5. How We Use Information

We use information to:

  • Provide FieldHash Governed Memory: evaluating candidate context, enforcing approved/current state, suppressing stale/rejected/rolled-back influence, and constructing governed model packets.
  • Provide FieldHash Governed Actions where configured: evaluating tool or action candidates, enforcing authorization signals, suppressing revoked/out-of-scope action candidates, and constructing governed action packets.
  • Provide FieldHash Governed Precedent where configured: recording reviewed authority decisions, checking scope, expiry, evidence, and tracked dependency state, and routing invalid reuse away from clean allow.
  • Provide FieldHash Ledger where configured: recording evidence packets, packet hashes, checkpoint references, certificates, transparency anchors, customer-owned exports, and audit packets.
  • Operate model routing through customer-approved hosted, private, VPC, EU-region, local, or on-prem paths where configured.
  • Secure the service, detect abuse, investigate incidents, enforce access controls, and maintain auditability.
  • Support pilots, demos, customer success, billing administration, and technical diligence.
  • Improve reliability, product quality, deployment tooling, and documentation.

6. AI Model Routing

FieldHash may route prompts, candidate memories, governed context packets, tool or action candidates, governed action packets, reviewed-precedent context, and related inputs to AI model providers when needed to provide requested functionality. The specific model path depends on the customer configuration.

Enterprise deployments may be configured for customer-approved providers, private endpoints, customer VPC, EU-region cloud infrastructure, local models, or on-prem processing. If a deployment uses a third-party model provider, that provider may process the submitted information according to the applicable agreement and configuration.

FieldHash is designed to govern what context is sent to a model and which action candidates are allowed forward; it is not a guarantee that all deployments are local, zero-egress, or provider-free unless those controls are explicitly configured and contractually agreed.

7. Ledger and Audit Artifacts

FieldHash Ledger artifacts may include governance events, selected/blocked record references, selected/blocked action references, reasons, hashes, signatures, checkpoint metadata, certificate references, transparency anchors, and verification reports. These artifacts are designed to make the answer path or action path reviewable while minimizing the sensitive source content retained in the evidence layer.

By default, evidence artifacts should retain the least source content needed for review: record identifiers, hashes, reason codes, authority-source references, timestamps, and reviewer-visible status. Deployments may be configured to store redacted snippets, customer-owned packet exports, or fuller evidence copies when the customer requests them for legal, security, compliance, or dispute-resolution workflows.

If source content is deleted or redacted, FieldHash will apply the deletion or redaction to eligible copies under the applicable agreement and product configuration. Some minimized audit references may remain when retention is required or permitted for security, legal, dispute-resolution, contractual, or compliance-review purposes. Enterprise agreements can define retention periods, redaction behavior, export ownership, deletion workflows, and whether audit records are held by FieldHash, the customer, or both.

8. Third-Party Services and Subprocessors

We may use third-party services to operate FieldHash, including:

  • Cloud hosting, storage, database, observability, and security providers.
  • Authentication, email, support, and customer-operations providers.
  • AI model providers, unless a private/local/customer-controlled model route is configured.
  • Customer-approved integrations, such as databases, vector stores, graph stores, cloud storage, SIEM/GRC systems, or internal knowledge systems.

These providers process information as needed to deliver the requested service. Enterprise customers may receive deployment-specific subprocessors, region, retention, and security documentation during procurement or pilot setup.

FieldHash does not assume one fixed production model or hosting route for every customer. The subprocessors required for a deployment are disclosed before that deployment processes customer workflow data. Material subprocessor changes are handled under the notice method and timing in the applicable agreement.

9. Data Sharing

We do not sell personal data. We may share information only when necessary to:

  • Provide FieldHash through processors, subprocessors, model routes, deployment infrastructure, and customer-approved integrations.
  • Comply with legal obligations or lawful requests.
  • Protect users, customers, FieldHash, and the security of the service.
  • Support a business transaction, such as financing, acquisition, merger, or corporate restructuring, subject to appropriate safeguards.

10. Retention

We retain information for as long as reasonably needed for the purpose collected, unless a longer period is required or permitted by law, contract, security, audit, or dispute-resolution needs.

  • Account and customer records are retained while the relationship is active and for a limited period afterward for support, tax, security, and legal purposes.
  • Candidate memory, governed packets, source records, and packet exports are retained according to product settings, customer instructions, and deployment agreements.
  • Ledger, security, and audit artifacts may be retained for longer periods when needed to preserve evidence integrity, investigate incidents, or satisfy contractual obligations, but should be minimized to references, hashes, reason codes, and other audit metadata where fuller source content is not required.
  • Technical logs are retained for limited operational, reliability, and abuse-prevention windows unless needed longer for security or legal reasons.
Data classDefault public posture
Website and inquiry dataKept only as needed to respond, operate the site, and meet limited security or legal needs.
Pilot workflow dataDefined by product settings, customer instructions, and the deployment agreement.
Evidence and security recordsMinimized to references, hashes, reason codes, and operational metadata where fuller content is unnecessary.

11. Security and Incident Notice

We use reasonable technical and organizational safeguards, including access controls, secure transport, least-privilege practices, logging, and deployment-specific controls where configured. FieldHash Ledger can add reviewer-verifiable evidence packets for selected artifacts, with stronger tamper-evidence profiles available where anchoring, signing, key custody, and retention controls are configured. No system can be guaranteed perfectly secure or tamper-proof.

If FieldHash confirms a security incident affecting customer data, we will investigate, contain, and notify affected customers as required by applicable law and the relevant agreement. Suspected vulnerabilities should be reported to security@fieldhash.ai.

12. Your Rights and Choices

Subject to legal and contractual limits, you may request to:

  • Access personal data associated with your account.
  • Correct inaccurate account information.
  • Export eligible data.
  • Delete eligible account or content data.
  • Object to or restrict certain processing where legally applicable.

Some requests may be handled through your organization if FieldHash is provided under an enterprise agreement. To submit a privacy request, email privacy@fieldhash.ai from the relevant account or organization email.

13. Children's Privacy

FieldHash is not directed to children under 13 or the minimum age required by local law. If you believe a child has provided personal data, contact us so we can take appropriate action.

14. Regional Notices

If you are in the EEA or UK, legal bases may include contract performance, legitimate interests in operating and securing FieldHash, consent where required, and compliance with legal obligations. Where international transfers occur, appropriate safeguards may be used as required.

If you are in California, this policy is intended to serve as a notice at collection. We collect the categories above for the purposes above, do not sell personal information, and share information with service providers/processors as needed to operate requested features. You may request access, correction, deletion, and information about applicable sharing practices by contacting privacy@fieldhash.ai.

15. Changes

We may update this policy from time to time. If we make material changes, we will update the date above and provide additional notice where required.

16. Contact

Privacy requests: privacy@fieldhash.ai

General support: support@fieldhash.ai

Security reports: security@fieldhash.ai

Deployment and security posture: Security and Deployment