Privacy Policy
This Privacy Policy explains how Hexagon Startup Design LLP (“Hexagon,” “we,” “us,” or “our”) collects, uses, shares, and protects personal information when you use Hexagon AI Designer and our related websites, applications, and services (collectively, the “Services”). We are committed to handling your information transparently and in compliance with the EU/UK General Data Protection Regulation (“GDPR”), the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”), and other applicable privacy laws.
Who We Are and Scope
The Services are operated by Hexagon Startup Design LLP, a limited liability partnership registered in England and Wales under company number OC445158, with its registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. Hexagon AI Designer is an AI-powered platform that helps founders plan, build, and grow startups through AI agents (including an AI Coach and specialized assistants), document and pitch generation, a structured knowledge profile, a mentor marketplace, and an investor marketplace.
This Policy applies to all users of the Services worldwide, including users in the United States, the European Economic Area (“EEA”), the United Kingdom, and the Western Balkans. Where we act as a “controller” we determine how and why your personal data is processed. Where we process content you upload on your behalf, we may act as a “processor” for that content.
If you do not agree with this Policy, please do not use the Services.
Information We Collect
2.1 Information you provide to us
| Category | Examples |
|---|---|
| Account & profile data | Name, email address, password (hashed), company/startup name, role, country, language preference, profile photo. |
| Startup & content data | Business ideas, knowledge profile entries, brand kit, uploaded documents, generated business plans, pitch decks, financial inputs, and prompts you submit to AI agents. |
| Marketplace data | Mentor or investor applications, verification details, areas of expertise or investment interest, messages exchanged on the platform, and booking/scheduling information. |
| Payment data | Billing name, billing address, subscription tier, and transaction history. Card numbers are processed by Stripe; we do not store full card numbers. |
| Support & communications | Messages, feedback, and correspondence you send to us. |
2.2 Information we collect automatically
- Usage data: the pages you open, session start and end times, and a small number of named product events (today: whether a mentor suggestion appeared on your roadmap and whether you opened it, and changes to your cookie choice). Regardless of your analytics choice, we also compute a daily per-account summary from records we already keep in order to run the Services, such as AI credits and tokens used, coach messages, and tasks completed (Section 9.2 sets out which half depends on your consent and which does not). We do not record every feature you use or every action you take.
- Device & technical data, IP address, browser type, device type, operating system, and general (city/region-level) location inferred from IP.
- Cookies & similar technologies, authentication and session cookies, and (subject to consent where required) analytics identifiers. See Section 9.
2.3 Information from third parties
If you sign in or connect through a third-party provider (for example, an OAuth identity provider) or make a payment, we receive limited account and transaction information from that provider. Mentors and investors may receive information you choose to share with them through the platform.
How We Use Your Information
We use personal information for the following purposes:
- Provide, operate, and maintain the Services, including creating and managing your account.
- Generate AI outputs you request, we transmit your prompts, knowledge profile, and relevant content to third-party AI providers (see Section 5) so they can return generated documents, pitch decks, coaching responses, research, and other outputs to you.
- Operate the mentor and investor marketplaces, including matching, verification, scheduling, messaging, and payouts.
- Process subscriptions, payments, and (for mentors) payouts, and prevent fraud.
- Communicate with you about the Services, including service announcements, security alerts, and support.
- Personalize your experience and improve, test, and develop new features.
- Maintain security, enforce our Terms, and comply with legal obligations.
- Send marketing communications where permitted, from which you may opt out at any time.
Legal Bases for Processing (GDPR)
If you are in the EEA or UK, we rely on the following legal bases under the GDPR:
| Purpose | Legal basis |
|---|---|
| Providing the Services and your account | Performance of a contract (Art. 6(1)(b)) |
| Processing payments and managing subscriptions | Performance of a contract; legal obligation (Art. 6(1)(b),(c)) |
| Sending content to AI providers to generate your outputs | Performance of a contract (Art. 6(1)(b)) |
| Usage records kept to run, meter, and bill the Services, and the daily summary derived from them | Performance of a contract (Art. 6(1)(b)); legitimate interests for the summary (Art. 6(1)(f)) |
| Security, fraud prevention, and product improvement | Legitimate interests (Art. 6(1)(f)) |
| Product analytics (page views, session minutes, and the product events named in Section 9.2) | Consent (Art. 6(1)(a)), which you may withdraw |
| Marketing communications and non-essential cookies | Consent (Art. 6(1)(a)), which you may withdraw |
| Compliance with legal and accounting obligations | Legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interests, we have balanced those interests against your rights. You may object to such processing at any time (see Section 11).
AI Providers and How Your Content Is Processed
A core function of the Services is generating outputs using artificial intelligence. To do this, we send your prompts and relevant content (which may include your startup information and uploaded documents) to third-party AI model providers acting as our subprocessors. These providers process your content solely to return outputs to us and to you, and under our agreements with them they do not use your content to train their general models unless you have separately opted in.
AI outputs are generated by predictive models and may be inaccurate, incomplete, or out of date. We do not guarantee the accuracy of AI outputs, and you should independently verify them before relying on them. Please see the Terms & Conditions for important disclaimers regarding AI outputs and professional advice.
International Data Transfers
We are established in the United Kingdom and use subprocessors located in the United States and elsewhere. When we transfer personal data from the EEA, UK, or Western Balkans to countries that have not received an adequacy decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum), together with supplementary measures where required. You may request a copy of the relevant safeguards by contacting us.
Data Retention
We retain personal information for as long as your account is active and as needed to provide the Services. After account closure, we delete or anonymize personal data within a reasonable period, except where we must retain it to comply with legal, tax, or accounting obligations, resolve disputes, or enforce our agreements. Backup copies are deleted on a rolling schedule. Aggregated or de-identified data that cannot reasonably identify you may be retained and used indefinitely.
Cookies and Tracking Technologies
We use strictly necessary cookies to operate the Services (for example, to keep you signed in). Subject to your consent where required by law, we may use analytics storage to understand product usage. You can control non-essential storage through our cookie banner and your browser settings, and Section 9.2 sets out exactly what that choice covers and what it does not. Blocking essential cookies may break core functionality.
9.1 Cookies and local storage we use
| Name | Purpose | Category | Duration |
|---|---|---|---|
| sb-* (cookies) | Keep you signed in — Supabase authentication and session. | Strictly necessary | Session; refreshed until you sign out. |
| hx-theme (local storage) | Remembers your light/dark theme choice. | Functional | Persists until you clear it. |
| hx-consent (cookie + local storage) | Stores your cookie choice so we don't ask again. | Strictly necessary | 12 months. |
| session_id (session storage) | Groups product-analytics events within one browser tab. Set only if you accept analytics. | Analytics — consent required | Cleared when the tab closes. |
9.2 Product analytics
With your consent, we record a deliberately small set of product events in our own first-party analytics, stored in product_events. Today that is: a page view each time you open a page (we store a normalized route pattern such as /documents/[id], plus the page you came from within the app, never the full web address), whether a mentor suggestion was shown on your roadmap and whether you clicked it, and a record when you change your cookie choice. We also record session start and end times so we can measure time on the platform. Beyond those events we do not log individual clicks, keystrokes, mouse movement, or scrolling, and we never record the content you write (your business plan, documents, chats, or pitch text). The legal basis for everything in this paragraph is your consent (Art. 6(1)(a) GDPR). If you decline, or withdraw later, we stop collecting it. These events are deleted once they are more than 180 days old, by a clean-up that runs monthly.
What the analytics choice does not cover. Running the Services produces records we keep whatever you decide about analytics: your AI calls and the credits and tokens they consume, your coach and assistant messages, which documents you edited and which tasks you completed, and your AI investor simulations. We need them to provide the Services, meter your allowance and bill you correctly, so the basis for keeping them is performance of our contract with you (Art. 6(1)(b) GDPR) and not your consent. Once a day we summarize them into daily_user_metrics: one row per account per day, holding counts such as active minutes, page views, coach messages, credits spent, tasks completed and simulations run. That row is about you by name and is not anonymous, and we read it to understand how the beta is going, which we do on the basis of our legitimate interests (Art. 6(1)(f) GDPR). Declining analytics does not remove that row. It stays in place, and every count in it that is derived from the events above sits at zero instead, including your page views and your active minutes. We keep these daily rows for as long as your account exists and delete them together with the account, and you can object to the legitimate-interests use at any time (see Section 11).
Security
We implement technical and organizational measures designed to protect personal information, including encryption in transit, access controls, row-level security on our database, hashed passwords, and least-privilege access for staff. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a personal data breach that affects you, we will notify you and the relevant authorities as required by law.
Your Privacy Rights
11.1 GDPR rights (EEA / UK / Western Balkans)
Subject to applicable law, you have the right to: access your data; rectify inaccurate data; erase your data (“right to be forgotten”); restrict or object to processing; data portability; and withdraw consent at any time. You also have the right to lodge a complaint with your local supervisory authority.
11.2 California rights (CCPA/CPRA)
California residents have the right to: know and access the categories and specific pieces of personal information we collect; delete personal information; correct inaccurate information; opt out of “sale” or “sharing” of personal information (we do not sell or share personal information as those terms are defined); and limit the use of sensitive personal information. We will not discriminate against you for exercising these rights.
Categories collected (CCPA): identifiers; customer records; commercial information; internet/network activity; geolocation (general); and professional or business information. We collect these for the business purposes described in Section 3. We do not sell or share personal information for cross-context behavioral advertising.
11.3 How to exercise your rights
To exercise any right, email us at privacy@hexagonstartup.com. We will verify your request and respond within the timeframes required by law (generally one month under GDPR and 45 days under the CCPA). You may use an authorized agent where permitted. Some account data can also be accessed or edited directly in your account settings.
Children's Privacy
The Services are intended for users who are 18 years of age or older and are not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us personal information, contact us and we will delete it.
Third-Party Links
The Services may contain links to third-party websites and tools (including mentors' and investors' resources and external courses). We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies.
Changes to This Policy
We may update this Policy from time to time. When we make material changes, we will update the “Last updated” date and, where appropriate, notify you by email or in-product notice. Your continued use of the Services after changes take effect constitutes acceptance of the updated Policy.
Contact Us
If you have questions or requests regarding this Policy or your personal information, contact us at: