What we hold about you
The list is short, and it is the whole list.
What is stored
- Your email address and name — given at sign-up. The address is how you sign in and where invitations and reset links are sent.
- Your password — hashed by the authentication service. Nobody at hm can read it, and this surface never stores it at any point in a sign-in.
- Your sessions — one per browser or device signed in as you, with the address it connected from and what it said it was, so you can recognise one that is not yours. Listed on your security page, and endable from there.
- Your organisations and role — which you belong to, as what, and since when.
- Invitations — the address one was sent to, the role, and when the link expires. The link itself is not stored: only a hash of it, so an invitation cannot be re-read out of a database and used.
- Account preferences — the short allowlist on your preferences page, and nothing outside it.
What is not stored
Your Works and everything in them. The company you run inside hm — what is being built, by whom, and what was decided — lives in folders on your own machines. This account does not sync it, mirror it, index it or back it up, and there is no route on this surface that could ask for it.
No payment details: there is nothing to buy.
No analytics on these pages. They load no script, no font and no image from anywhere — including from us — which is checked by a test rather than promised.
Who else sees it
Members of an organisation you join can see your email address and role on its roster. That is the point of a roster, and it is the only place your address is shown to anyone else.
Email is sent by a delivery provider, which necessarily sees the address a message goes to. Nothing else is shared with anyone.
Leaving
There is no self-serve delete yet, and saying otherwise would be the kind of promise this page exists not to make. Write to security@hmcortex.com and it is done by hand.