Legal
Last updated: 2026-07-17 — Version 1.1
This Privacy Policy describes how Handgemacht AI FlexCo ("HAVI", "we", "us") collects, uses, and protects personal data in connection with the HAVI annotation platform and related services. It applies to all users of the HAVI web application, browser extension, embeddable widget, and API (including the MCP endpoint).
HAVI is a hosted service offered on free and paid plans. Our core application data and screenshots are hosted in the European Union (Frankfurt). Certain processors are based in the United States, including payment processing (Stripe), error monitoring (Sentry), content delivery (Cloudflare), screenshot storage (Tigris), and, only if you use it, Google sign-in. Sections 5 and 6 describe those transfers and the safeguards that apply. We do not sell personal data, use advertising trackers, or profile users for marketing.
The data controller responsible for processing your personal data is:
A direct electronic point of contact, as required under §5(1)(3) ECG, is available at [email protected]. To exercise data-subject rights or raise a privacy concern, contact us at this address. We will respond within one month of receipt (GDPR Art. 12(3)).
No Data Protection Officer (DPO) has been appointed. HAVI does not engage in large-scale systematic monitoring or process special-category data as a core activity (GDPR Art. 37(1)), so appointment is not currently mandatory. If a DPO is voluntarily appointed in future, their contact details will be published here.
For your account data, billing data, server logs, and error-monitoring data, HAVI acts as the data controller. For the annotation content you capture — screenshots and technical context from applications you are testing, which may contain other people's personal data — a business customer that uses HAVI to store that content typically acts as the controller and HAVI as the processor acting on that customer's instructions. Business (controller) customers may request a data processing agreement under GDPR Art. 28 (Auftragsverarbeitungsvertrag / AVV) covering that content; contact us at the address above. Consistent with this allocation, HAVI's position is that the customer who captures such content bears controller responsibility for it and HAVI acts solely as processor on that customer's documented instructions; where HAVI acts as a processor, data-subject requests relating to that content are directed to and handled by the controlling customer.
When you capture an annotation via the HAVI browser extension or the embeddable widget, the following data is sent to and stored by HAVI:
The extension and widget capture content from whichever page is active at the time you trigger a capture. HAVI does not knowingly process special-category data (GDPR Art. 9), and you must not capture screens containing such data (for example health, financial, or other sensitive information visible in an application you are testing). If your screen incidentally contains personal data, that data will appear in the screenshot; please take care to capture no more than you need. This notice does not relieve HAVI of its own responsibilities as a controller (or, where applicable, processor) for the data captured, but it does ask you to meet any obligations you have to the people whose data may appear on your screen.
Full payment card numbers are never processed or stored by HAVI. Card data passes directly to Stripe and is subject to Stripe's own privacy policy. Your billing email, card details (brand, last four digits), and invoices are held by Stripe under its own privacy policy, not by HAVI.
When you connect a coding agent, MCP client, or the browser extension to HAVI using a credential issued to you, we record the last successful call made with that credential, together with the client display name and the repository, worktree, and branch names your client reports. This lets you see which of your clients are connected and helps us secure the service.
If you try HAVI without an account via /try, we create an anonymous guest workspace and issue a short 6-character connect code (single-use, valid for 8 minutes, and rate-limited by IP address) so you can link a coding-agent session. Annotations you create as a guest belong to that anonymous workspace and can later be claimed into a registered account.
If the in-app feedback feature is enabled (off by default) and you submit feedback, we store the free-text comment plus optional context your client sends — the page URL, the extension version, your browser's user-agent string, and your workspace name. Feedback is submitted through an unauthenticated endpoint and is not linked to your user account.
We keep a permanent list of email addresses that must not receive email (for example, after an unsubscribe request or a hard bounce), so that we can honour those requests. This record is limited to the email address and the suppression reason.
If you arrive at HAVI via a link that carries campaign parameters (utm_source, utm_medium,
utm_campaign
— for example from a launch announcement) and then request a magic sign-in link, we record those parameters together with the email address you submit, so we can measure which channel brought a signup. This happens entirely server-side: the parameters travel only in the page URL, no cookie or browser storage is used for it, and no third-party service is involved. The information is not used to profile you and is not shared with anyone. Attribution records are automatically deleted after 12 months at the latest.
Providing your account and billing data is necessary to create an account and to use paid features; without it we cannot provide the service. Captured annotation data is provided entirely at your discretion. Where a workspace member invites you, we receive your email address from the inviting user; the invitation email itself serves as the notice required under GDPR Art. 14 and links you to this policy.
| Processing activity | Purpose | Legal basis (GDPR Art. 6(1)) |
|---|---|---|
| Account creation and management | Provide access to the HAVI service | Art. 6(1)(b) — performance of contract |
| Magic-link sign-in email delivery | Authenticate the user without a password | Art. 6(1)(b) — performance of contract |
| Google sign-in (OAuth), where you choose it | Authenticate you via your Google account as an alternative to magic-link | Art. 6(1)(b) — performance of contract |
| Storing and serving annotations (text, screenshots, selectors, URLs, console errors, network failures, web vitals, viewport) | Core product functionality: capturing and retrieving development observations | Art. 6(1)(b) — performance of contract |
| Serving annotations via MCP to connected agent sessions on request | Core product functionality: making annotations available to the developer's agent session when it requests them via MCP | Art. 6(1)(b) — performance of contract |
| Subscription billing via Stripe | Processing payment for the paid SaaS subscription | Art. 6(1)(b) — performance of contract |
| Guest / demo workspaces and connect codes | Providing the no-account trial you requested via /try | Art. 6(1)(b) — performance of contract (including pre-contractual steps) |
| Recording connected-client / agent activity (last call, repo / worktree / branch names) | Showing you your connected clients; service security and abuse prevention | Art. 6(1)(f) — legitimate interest. You have the right to object: see Section 8. |
| Recording the campaign link (UTM parameters) a signup request arrived with (Section 2j) | Measuring which of our own marketing channels bring signups | Art. 6(1)(f) — legitimate interest. You have the right to object: see Section 8. |
| Error tracking and performance monitoring via Sentry / OpenTelemetry | Detecting and fixing bugs; ensuring service reliability and security | Art. 6(1)(f) — legitimate interest (HAVI's interest in maintaining a stable, secure service). You have the right to object: see Section 8. |
| Server access logs (IP address, request metadata) | Security, abuse prevention, and infrastructure operation | Art. 6(1)(f) — legitimate interest. You have the right to object: see Section 8. |
| Processing feedback you submit (where the feature is enabled) | Understanding user needs and improving the product | Art. 6(1)(a) — consent. You may withdraw consent at any time: see Section 8. |
| Maintaining the email-suppression list | Honouring unsubscribe requests and not emailing addresses that must be suppressed | Art. 6(1)(c) — legal obligation, and Art. 6(1)(f) — legitimate interest |
| Retention of billing records | Tax and accounting obligations under Austrian UGB §212 and §132 BAO | Art. 6(1)(c) — legal obligation |
_havi_key
session cookie is cleared when you close your browser. The authentication token it references remains valid for up to 14 days from sign-in or until you sign out.
We share data only with the processors listed below. We do not sell personal data or share it with advertising networks, analytics platforms, or marketing services.
No analytics, advertising, or marketing processors are used. HAVI uses no third-party tracking scripts on any page.
Several processors listed in Section 5 are incorporated in the United States. Under GDPR Art. 44, transfers to third countries require an adequate safeguard. The mechanisms in place for each US processor are as follows.
Primary mechanism: EU-US Data Privacy Framework (DPF) — Fly.io holds a current DPF certification. The DPF is based on the European Commission adequacy decision of 10 July 2023 (Implementing Decision (EU) 2023/1795). The DPF survived its first judicial challenge before the EU General Court (Latombe v. Commission, Case T-553/23, 3 September 2025, action dismissed); the adequacy of the DPF remains subject to ongoing legal review. Fallback: Standard Contractual Clauses adopted by European Commission Decision (EU) 2021/914 of 4 June 2021, incorporated into the executed Fly.io DPA. Although Fly.io stores and processes HAVI data in its Frankfurt (fra) EU region, Fly.io Inc. as a US entity may be subject to US law (including the CLOUD Act). We have conducted a Transfer Impact Assessment (TIA) documenting our assessment of the adequacy of these safeguards.
Tigris Data, Inc. stores HAVI's screenshot image bytes in its Frankfurt (fra) EU region, but as a US entity it may be subject to US law. We could not confirm a current EU-US Data Privacy Framework certification for Tigris, so we rely on the Standard Contractual Clauses adopted by European Commission Decision (EU) 2021/914, incorporated into the Tigris Data Processing Addendum (Module 2, controller → processor, and, where applicable, Module 3, processor → processor).
Primary mechanism: DPF certification confirmed. Fallback: SCCs Modules 1 and 2 per the Stripe Data Transfers Addendum (stripe.com/legal/dta).
Primary mechanism: DPF certification confirmed. Fallback: SCCs Module 2 (controller → processor) or Module 3 (processor → processor) as set out in the Sentry DPA.
Primary mechanism: EU-US Data Privacy Framework — Cloudflare holds a current DPF certification. Fallback: Standard Contractual Clauses adopted by European Commission Decision (EU) 2021/914, incorporated into the Cloudflare Data Processing Addendum.
Google acts as a separate controller for the authentication it performs; where you choose to sign in with Google, your verified email address and name are disclosed to Google in the United States. Primary mechanism: EU-US Data Privacy Framework — Google LLC holds a current DPF certification. Fallback: Standard Contractual Clauses adopted by European Commission Decision (EU) 2021/914.
Copies of the applicable Standard Contractual Clauses (the appropriate safeguards) are available on request (GDPR Art. 46(1), and Art. 13(1)(f)). Contact us using the details in Section 1.
HAVI uses only technically necessary cookies and equivalent browser storage. No advertising cookies, cross-site tracking cookies, or third-party analytics trackers are used on any HAVI page or in the extension.
Under §165(3) of the Austrian Telekommunikationsgesetz 2021 (TKG 2021), which implements the ePrivacy Directive (2002/58/EC), prior consent is not required for cookies that are strictly technically necessary to provide a service explicitly requested by the user. All cookies HAVI uses fall into this category. No cookie consent banner is legally required.
| Cookie / storage item | Purpose | Type | Duration |
|---|---|---|---|
| _havi_key (SameSite=Lax) | Carries your sign-in session and CSRF token | Session cookie | Cleared when you close your browser. The authentication token it references remains valid for up to 14 days from sign-in or until you sign out. |
You can clear cookies at any time via your browser settings. Clearing the _havi_key cookie will sign you out of HAVI.
Under GDPR Arts. 15–22 and the Austrian Datenschutzgesetz (DSG), you have the following rights regarding your personal data. To exercise any of these rights, contact us at the address in Section 1. We will respond within one month of receipt. For complex or numerous requests we may extend the response period by up to two further months, and will inform you of any extension within the first month (GDPR Art. 12(3)). Exercising your rights is free of charge. We may charge a reasonable fee, or refuse, only where a request is manifestly unfounded or excessive (Art. 12(5)).
You can export all your annotations at any time through HAVI's authenticated REST API, at no charge. The API returns your data in an open standard, so you are never locked in.
You can delete individual annotations yourself at any time in the HAVI app, which also removes the associated screenshot. Full account deletion and other erasure requests are handled on request at [email protected] within the GDPR deadlines (see Section 8). Providing your annotation data via the API, together with the account and profile data we supply on request, satisfies your right to data portability under GDPR Art. 20; if you need help exporting your data, contact us at the same address.
You have the right to lodge a complaint with the competent data protection supervisory authority at any time (GDPR Art. 77). The lead supervisory authority responsible for Austria is:
As HAVI is an Austrian company, the DSB is the lead supervisory authority. If you are habitually resident or employed in another EU member state, you may also lodge a complaint with the supervisory authority of that member state (Art. 77(1)).
We implement appropriate technical and organisational measures (TOMs) to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, in accordance with GDPR Art. 32. Our measures include:
We may update this Privacy Policy from time to time. The current version is always available at havi.handgemacht.ai/privacy.
Version history:
Questions about this policy? Contact us at the address in Section 1.