Privacy Policy

Version v1.0 · Effective September 29, 2026

View previous versions

Polaris Privacy Policy

Effective date: 1 September 2026 · Last updated: 1 September 2026 · Version: 1.0

Operated by: Hexifyer FZ-LLC

This Privacy Policy describes the personal data Polaris handles, the purposes for which it is used, where it is stored, how long it is kept, and the rights you have in relation to it. It applies to the Polaris web application, the Polaris mobile applications and the Polaris marketing site.

Polaris holds two kinds of data in two different roles, and the role that applies determines which requests we can action directly (see Section 2). The deletion and retention periods in this policy also appear in our Terms of Service, our Data Processing Agreement and our help centre. If any of those documents states a different figure, the figure in this policy applies. Please report any such inconsistency to privacy@hexifyer.com.

1. Who we are and how to reach us

Polaris is operated by Hexifyer FZ-LLC, a free zone company registered in Ras Al Khaimah, United Arab Emirates under licence number 47017173, at FOAM1588, Compass Building, Al Shohada Road, Al Hamra Industrial Zone-FZ, Ras Al Khaimah, United Arab Emirates.

Hexifyer FZ-LLC is the sole controller of the personal data described in this policy where we act as controller. No other Hexifyer entity is a controller of that data.

RouteUse it forAddress
Privacy and data protectionRights requests, deletion and export requests, questions about this policy, Data Processing Agreement requests, sub-processor objectionsprivacy@hexifyer.com
Product supportQuestions about using Polaris. Support cannot action a rights request and will forward it to the privacy address.support@hexifyer.com

The privacy address is monitored by personnel authorised to act on requests sent to it. It is not a support queue.

2. Our two roles

We act in a different legal capacity for each of the two kinds of data Polaris holds.

Workspace content: your organization is the controller and Polaris is the processor. Workspace content comprises captures, ideas, Second Brain messages, tasks and subtasks, logs, meetings and meeting notes, comments, time logs, topics, custom fields, uploaded files and attachments, and the audit records of actions taken in the workspace. This content belongs to the organization whose workspace it is held in. We process it on that organization's instructions and for no purpose of our own.

Account, billing, usage and support data: Polaris is the controller. This comprises your account record and credentials, your profile, your plan and invoices, aggregate information about your use of the product, and your correspondence with us. We determine the purposes for which this data is processed, and this policy sets them out.

If you are a member of a workspace you do not own and you ask us to delete or correct content inside it, we cannot act on that request on our own initiative. We will acknowledge the request, inform you of this, and refer it to your workspace administrator, who is the controller of that content. Requests concerning your own account record (your profile, credentials, email address or account deletion) are handled by us directly.

Your workspace administrator is authorised under our Terms of Service to act on the workspace's behalf. Any disagreement between you and your administrator about workspace content is a matter between you and your organization, and we do not arbitrate it.

3. What we collect and how

The way data is obtained is relevant to how it is treated in the sections that follow, in particular the distinction between data you provide and data the product generates.

CategoryWhat is in itHow we obtain it
Identity and credentialsName, email address, password hash, federated sign-in identifier where you sign in with Google, Apple, Microsoft, LinkedIn or GitHub, two-factor enrolment. Held in Supabase Auth.Provided by you at sign-up, or the profile fields you approve are provided by your sign-in provider. Your account is a Hexifyer account that also signs you in to Hexifyer DevStudio (see Section 8).
ProfileDisplay name, job title, profile photo, language and timezone, notification preferences. Photos and logos are held in Supabase Storage.Provided by you. You can change all of it in the product except your email address (see below).
Workspace and membershipOrganization name and logo, workspace membership, your role and permissions, invitations you send or receive.Created by you or your administrator.
Workspace contentCaptures, ideas, Second Brain messages, tasks and subtasks, logs, meetings and meeting notes, comments, time logs, topics, custom field values. Held in the Polaris primary database.Created by you and your colleagues in the product. It may contain personal data about you or other people, entered by whoever wrote it.
Files and attachmentsProject files and anything attached to a task, message or meeting, in the format uploaded. Held in Supabase Storage.Uploaded by you.
Calendar and meeting dataEvents from the Google or Microsoft calendar you connect, with their titles, times and attendee email addresses. Where the AI notetaker is used: meeting audio, its transcript and the notes generated from it.You connect a Google or Microsoft calendar and approve read and write access on that provider's consent screen. The notetaker runs when you turn it on for a meeting.
Derived AI dataEmbeddings and vector representations of your workspace content, used for search and retrieval. Assistant chat history: your conversations with Polaris AI, held in a separate AI database. Summaries and drafts produced by the AI from your content.Generated by the product from content you have provided. Embedding takes place at ingestion, so content is sent to our embedding provider when it is created, not only when you search.
Usage and device dataPages viewed, features used, clicks and scrolling, anonymised session recordings of the web app, device and browser, IP address and the approximate location derived from it, mobile push token and device identifiers.Collected automatically as you use the product. See Section 15 for the options you have to refuse it.
Audit and security logsSign-ins, permission changes, records of who created, changed or deleted what, security events. Held in the primary database.Generated automatically by the product.
BillingBilling contact and address, plan and seat count, invoice history, a payment method token. We do not receive or store full card numbers.Provided by you to our payment processor at checkout.
Support and marketingYour correspondence with us and, if you subscribe, your marketing contact record.Provided when you write to us or subscribe.

We do not send your name or email address to our analytics provider, and text entered into input fields is masked before it leaves your browser.

Changing your email address. Polaris does not currently allow you to edit your own email address in the product. To correct it, write to privacy@hexifyer.com or ask your workspace administrator, and we will change it for you.

3.1 Data from your Google or Microsoft account

If you sign in with Google or Microsoft, or connect a Google or Microsoft calendar, we receive data from that account only with the permission you grant on the provider's consent screen.

What we receiveWhy we use itWhere it is held
Sign-in: your name, email address, profile photo and account identifierTo create your Hexifyer account and sign you inSupabase Auth, in Frankfurt (Section 8)
Calendar, only if you connect one: read and write access to your calendar events, with their titles, times and attendee email addressesTo keep your meetings in sync in both directions: events in your calendar appear in Polaris, and meetings you create or change in Polaris are created or updated in your calendar. Where you turn it on, to send the AI notetaker to a meetingThe Polaris primary database, in Frankfurt (Section 8)
  • We use this data only to provide the Polaris features you use. We do not sell it, use it for advertising, or use it to train any AI or machine learning model, including generalised models.
  • We share it only with the sub-processors listed in Section 21, only to provide those features, or where the law requires it. Where a feature uses AI, Section 5 applies.
  • Hexifyer personnel do not read it unless you ask us to (for example, in a support request), or unless it is necessary for security or required by law.
  • You can disconnect a calendar in Polaris at any time, or remove Hexifyer's access in your Google or Microsoft account settings. We then stop reading and updating it. Events already written to your calendar remain there until you delete them. Calendar data already synced is retained in accordance with Section 9, and you can ask us to delete it sooner at privacy@hexifyer.com.

Polaris's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Data we receive from Microsoft is handled on the same terms.

Your sign-in is a Hexifyer account shared with Hexifyer's other product. A summary covering both products is available at hexifyer.com/privacy.

4. Why, and on what legal basis

The table below sets out each purpose for which we process personal data and the legal basis we rely on. Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing carried out before it.

PurposeData usedLegal basis
Providing Polaris to youIdentity and credentials, profile, workspace and membership, workspace content, filesPerformance of a contract. For workspace content we act as processor on your organization's instructions.
AI features: the assistant, the writers, searchWorkspace content relevant to the request, assistant chat history, embeddingsPerformance of a contract, on your organization's instructions. An administrator can switch the AI features off for the whole workspace (see Section 5).
Calendar sync and AI meeting notesCalendar and meeting dataConsent. No calendar data is read or written until you connect a calendar, and the notetaker runs only when it is turned on for a meeting.
Billing, invoicing and taxBilling, identityPerformance of a contract, and compliance with a legal obligation to retain tax records.
Security, abuse prevention and audit loggingAudit and security logs, usage and device dataLegitimate interests in keeping the service and its customers' data secure, and compliance with a legal obligation to be able to investigate and report a breach. We maintain a recorded balancing test for this processing.
Product analytics and improving PolarisUsage and device dataConsent. Analytics run only if you allow them, and you can refuse or change your choice at any time in the Cookie Notice (Section 20). No Polaris functionality depends on them. Session recordings are anonymised. We do not use your workspace content to improve Polaris.
SupportSupport correspondence, identityPerformance of a contract, and legitimate interests in responding to you.
Marketing emailsMarketing contact recordConsent. Separate from the service emails described in Section 16.

5. AI features

Polaris uses AI in two places. The assistant answers questions about your workspace and carries out actions you request. The writers draft content on request: idea drafts, log entries, task descriptions and idea classification. A scheduled agent, described in Section 5.7, also reads your captures without being initiated by a user.

5.1 Which features send content outside Polaris infrastructure

Every AI feature sends the workspace content relevant to the request to a model provider outside Polaris infrastructure. In addition, your content is sent for embedding when it is created, not only when you search. Embedding is what enables workspace search.

5.2 Which providers receive it

Every AI request leaves Polaris through a single gateway, OpenRouter, which routes it to the provider serving that request. The current list of providers, with the function of each and its processing location, is in the sub-processor list in Section 21, which is the authoritative version and is updated more often than this policy. As at the effective date of this policy the providers are: OpenRouter (gateway), OpenAI (text generation and embeddings), Google (text generation, request classification, and the safety checks that run on every inbound and outbound message), Anthropic (answering questions over retrieved content), and Google for the conversation analysis, routing and classification that run before your message reaches a model.

All of them process in the United States. Polaris does not route any AI request to a provider processing outside the United States or the European Union.

5.3 Model training

Your workspace content is not used to train any model, whether ours or a provider's. Every request is pinned to a named provider from the list above, and the gateway is not permitted to fall back to a provider that is not listed.

5.4 Provider retention

The providers we route to retain the inputs and outputs of a request for up to 30 days, solely for trust, safety and abuse monitoring of their own services, and then delete them permanently. This retained data is not used to train a model or to improve a product, and is not read by a person unless an automated system flags an incident. We do not route to any endpoint for which the provider's data policy cannot be established.

5.5 Where AI processing takes place

AI processing does not necessarily take place where your data is stored. Your workspace content is stored in Frankfurt (Section 8), but AI processing takes place in the provider's own region, which is the United States for OpenRouter, OpenAI, Google and Anthropic. The processing location for each provider is stated in the sub-processor list in Section 21.

5.6 Switching the AI features off

An administrator can switch off the AI features for the whole workspace. When they do so, the features stop immediately for everyone in that workspace, and that workspace's embeddings and assistant chat history are deleted. Captures, tasks, comments, meetings and files are not affected.

This deletion follows the same timings as any other deletion in Polaris: the data is removed from our live systems within 72 hours, and copies in encrypted backups age out within 14 days after that and are not restored to serve a request. Section 9 sets out both figures.

While the features are switched off, no workspace content is sent to any AI provider, including for embedding. While the features are on, content is sent to our embedding provider when it is created, whether or not anyone in the workspace uses the assistant. Switching the features off stops this and removes the data already generated.

5.7 The scheduled agent

One AI feature runs without being initiated by a user: a scheduled agent that reads your captures at set intervals in order to organize and classify them. It sends the same content to the same providers, under the same retention and training terms set out in Sections 5.3 and 5.4.

The contractual terms for AI processing are set out in the AI Services Addendum (Schedule 2 to the Terms).

6. Automated decisions

Polaris makes no automated decision that has a legal effect on you, or any other similarly significant effect.

AI output in Polaris is subject to human confirmation: a draft remains a draft until someone accepts it, and a classification remains a suggestion until someone keeps it. No Polaris feature makes decisions about a person's employment, pay, access or standing, and the product does not profile you to reach conclusions about you.

Any change to this would be a material change to this policy, notified as set out in Section 19.

7. Who we share it with

We do not sell personal data, and we do not share it for anyone else's advertising.

We share personal data with the following recipients:

  • Other members of your workspace. Content you create in a workspace is visible to its members in accordance with the role model described in Section 13.
  • Sub-processors. Providers we engage to operate the service, each limited by written agreement to the purpose we specify. Categories: cloud infrastructure and databases, authentication and file storage, payment processing, transactional email, mobile push notifications, meeting transcription, product analytics, and the AI providers in Section 5.
  • Independent controllers. If you sign in with Google, Apple, Microsoft, LinkedIn or GitHub, that provider authenticates you under its own terms. It is not our sub-processor, because we do not instruct it to process anything on our behalf. If you connect a Google or Microsoft calendar, we read and update it directly through that provider under the permission you grant, and the provider is not our sub-processor for that data either.
  • Where the law requires it. In response to a binding legal request, or for the defence of a legal claim. We notify the affected customer unless we are prohibited from doing so.

Every sub-processor is named in the sub-processor list in Section 21, with its purpose, the data it receives and the country in which it processes. The list carries its own date and is updated separately from the rest of this policy.

7.1 Changes to the sub-processor list

  • A new sub-processor is added to the list and notified by email to everyone subscribed to changes at least 30 calendar days before it begins processing customer data.
  • You have 30 calendar days from that notice to object in writing, on reasonable grounds relating to data protection, to privacy@hexifyer.com.
  • We will work with you to resolve the objection, normally by explaining the safeguards in place or by making a change to the service available where possible. If we cannot resolve the objection within a reasonable period, you may terminate the affected subscription without penalty.
  • Where you exercise a right that must be passed on (for example, an erasure or correction affecting data held by a sub-processor), we propagate it to every affected sub-processor within 30 days, and we maintain a written record of how each sub-processor is contacted and how it responds.

These notice and objection periods are the same as those in clause 7 of the Data Processing Agreement (Schedule 3 to the Terms).

Each sub-processor is engaged under terms requiring confidentiality, security measures appropriate to the data, and processing limited to the purpose we specify. Where a sub-processor's contract commits it to a standard of protection equivalent to ours, our agreement with it records this. We do not claim protections beyond those the contracts provide.

8. Where your data is stored

All Polaris workspace content, files and account records are stored in Frankfurt, Germany, in the AWS eu-central-1 region. This applies to every customer, regardless of location.

ProviderWhat it holdsWhere
Supabase (Supabase, Inc.)Authentication: user records, credentials, federated sign-in identifiers. Stored files: profile photos, organization logos, project files, task and message attachments.Germany, AWS eu-central-1
Render (Render Services, Inc.)The primary database: ideas, Second Brain messages, tasks, logs, meetings, comments, audit logs. The AI database: your chat history with Polaris AI. The Polaris backend, frontend and AI services.Germany, AWS eu-central-1
Amazon Web Services (Amazon Web Services, Inc.)The underlying cloud infrastructure for both providers above. AWS does not access the data in the ordinary course.Germany, eu-central-1

Backups. Backups of both stores are held by Supabase and Render in the same region, AWS eu-central-1. If a backup is ever held outside that region, this policy will state it.

Shared infrastructure with Hexifyer DevStudio. Hexifyer operates a second product, Hexifyer DevStudio, on the same infrastructure. Your sign-in is a Hexifyer account held in Supabase Auth, and the same account signs you in to both products. Both products run on the same database and schema, with separation between them enforced by the application. Content created in Polaris does not appear in DevStudio, and content created in DevStudio does not appear in Polaris. Signing in to one product gives no access to anything in the other: access to a workspace or project is granted only by invitation. We do not move content between the two products or use one product's data to operate the other.

The narrower categories of data that reach our platform and AI sub-processors are processed in those providers' own regions (the United States and Ireland), as stated for each entry in the sub-processor list in Section 21. Section 5 covers the AI providers.

9. How long we keep it

Where the table below states "until you delete it", no other retention limit applies: Polaris does not delete workspace content on its own initiative.

CategoryRetention periodWhat happens next
Active workspace contentUntil you delete it. No time limit and no automatic expiry.Your organization determines the retention purpose for its own content. We hold it until instructed otherwise.
Deleted content, in trash30 days, fixed. Not configurable per workspace.Purged from the live systems. You can restore it at any time within the 30 days.
Content after a workspace is deleted14-day grace period, during which deletion can be cancelled.Erased from the live systems within 72 hours of the end of the grace period. See Section 11 for what is retained.
A verified erasure requestErased from the live systems within 72 hours of verification of the request.The data is deleted, not hidden or flagged. Backups follow the row below.
BackupsThe last backup copy is removed within 14 days of erasure from the live systems.See the note on backups below this table.
Meeting recordings, transcripts and notesUntil you delete them, or the workspace is deleted. No time limit and no automatic expiry.Treated as workspace content: the 30-day trash period applies, then erasure from the live systems within 72 hours.
Embeddings, summaries and other AI-derived dataDeleted in the same transaction as the content from which they were derived, and when an administrator switches the AI features off for the workspace.Deleting a comment deletes the embedding of that comment. Switching the AI features off deletes all of the workspace's embeddings (see Section 5.6).
Assistant chat historyUntil you delete the conversation, the workspace is deleted, or an administrator switches the AI features off.Held in a separate AI database and deleted on any of those events, subject to the same 30-day trash and 72-hour erasure periods.
Data held by an AI providerUp to 30 days.Retained solely for automated security and abuse monitoring, then permanently deleted. Not used to train a model. See Section 5.4.
Audit and security logs12 months from the event.Deleted.
Locked projects after a plan downgradeUntil you delete them. No limit.A downgrade locks projects that exceed your plan's limit; it does not delete them. Upgrading unlocks them with their content intact.
Inactive accounts and workspacesWe do not delete data for inactivity.No action.
Marketing contact recordsUntil you unsubscribe, then deleted within 30 days.We keep a minimal suppression record so that we do not email you again.
Support correspondence24 months from the last message in the thread.Deleted.
Billing, invoices and tax records7 years under UAE corporate tax law, 5 years under Egyptian VAT law.Statutory retention. See below.

Backups. Backups exist to restore the service after a failure, and they rotate on a schedule rather than being edited. Within the 14-day period, your data exists only in backup, is not accessible in the product, and is used only for disaster recovery. If we restore a backup taken before your deletion, we re-apply the deletion to the restored data. Where a stricter rule applies in your jurisdiction, Section 18 states it.

Meeting recordings. Audio captured by the AI notetaker, the transcript made from it and the notes generated from it are workspace content and are kept and deleted on the same terms as all other workspace content. We do not apply a separate expiry period to them. The retention period for a recording is determined by the organization that made it.

Audit and security logs. Logs are retained for 12 months because a security incident cannot be scoped within 72 hours without records predating it.

Inactivity. There is no dormancy deletion in Polaris 1.x, and we do not reserve a right to delete an inactive account's content. Any change to this would be a material change under Section 19.

Billing and tax records. These records are retained for longer than any other category because the law requires it. The statutory retention continues after account deletion, workspace deletion and an erasure request. It covers invoice and tax data only, not your content.

Email already sent. Polaris notification emails include the content of the item they concern (for example, a task title, a comment or a project name). Deleting an item in Polaris does not remove it from email already delivered to a recipient's mailbox. Those copies are held in recipients' mail systems, outside our control, and cannot be recalled.

10. Your rights and how to exercise them

To exercise any of these rights, write to privacy@hexifyer.com. Exercising any of these rights is free of charge.

RightWhat you can ask for
AccessA copy of the personal data we hold about you, and confirmation of whether we hold any.
RectificationCorrection of inaccurate data and completion of incomplete data. This is also the route for changing your email address (see Section 3).
ErasureDeletion of your personal data. Section 11 sets out what erasure covers and what it does not.
RestrictionSuspension of processing while a dispute about the accuracy of your data or our legal basis is resolved.
ObjectionThat we stop processing where we rely on legitimate interests, including product analytics.
PortabilityYour data in a structured, commonly used, machine-readable format. Section 12 sets out the specification.
Withdrawal of consentWithdrawal at any time of any consent you have given (calendar sync, the notetaker, marketing, analytics).
Not being subject to automated decisionsHuman involvement in a decision with legal or similarly significant effect. Polaris makes no such decisions (see Section 6).

10.1 Response time

We respond within 6 working days.

We apply this deadline to every customer in every market. For example, a request logged on a Monday has a decision recorded by the following Tuesday.

10.2 Verification

We verify a request against the account it concerns, usually by requiring it to be sent from, or confirmed at, the account's registered email address and, for a workspace-level request, by confirming the requester's role. If we cannot verify your identity, we will tell you what further information we need. We do not ask for identity documents.

10.3 Requests about content in a workspace you do not own

We refer the request to your workspace administrator, as described in Section 2, and inform you that we have done so within the same six working days.

10.4 Complaints

You may contact us first so that we can try to resolve your concern. You also have the right to lodge a complaint with a supervisory authority. Section 18 names the authority and the route for each region.

11. Deleting your account and your workspace

Account deletion and workspace deletion can both be requested in the product. Both are subject to a 14-day grace period, during which you can cancel the deletion without loss of data. After the grace period, erasure from the live systems is completed within 72 hours, and the backup period in Section 9 applies.

Your account is a Hexifyer account. The same account signs you in to Hexifyer DevStudio, so deleting it from Polaris deletes it for both products and removes your access to DevStudio. The treatment of your DevStudio data is set out in Section 14 of DevStudio's Privacy Policy. If anything in either product prevents the deletion, the product informs you before you confirm.

11.1 Deleting your profile

Which of the following cases applies depends on your workspaces. The product tells you which case applies before you confirm.

(i) You are a member of another person's workspace. Your account and your personal data are deleted. Content you created in that workspace is retained, because it belongs to the organization, and your authorship of it is anonymised. Other members can see that the content exists and that a former member created it, but not your name, email address or profile.

(ii) You are the sole member of your own workspace. The workspace and all of its content are deleted with your account. As the only member, you are the organization, so your instruction to delete your account is an instruction to delete the content.

(iii) You own a workspace that has other members. Deletion is blocked until you either transfer ownership to another member or delete the workspace yourself. This prevents a workspace being left with content that no one can administer.

11.2 Scope of account deletion

Deletion of your account removes your account record and your personal data. It does not remove personal data about you that another person entered into workspace content, such as your email address in a task description, your name in a meeting note or a mention of you in a comment. That text is the organization's content, which we hold as processor on its instructions. To have it erased, ask the workspace administrator, or ask us and we will refer the request to the administrator within six working days.

11.3 What is retained after a workspace deletion

Only the following are retained: invoice and tax records, for the statutory periods in Section 9, and audit records, for 12 months. They are retained to evidence what we billed and to enable investigation of security incidents. Neither includes your workspace content.

Before you delete anything, see Section 12 for how to obtain a copy of your data. The in-app deletion flow states the export route and its turnaround time before you confirm.

12. Exporting your data

Request an export at privacy@hexifyer.com. We deliver your export within 5 working days, which is within the six-working-day deadline for rights requests in Section 10.

ItemDetail
ArchiveOne ZIP archive named polaris-export-[workspace]-[YYYY-MM-DD].zip
READMEThe export date, the workspace, the requester, every entity type included, and any data excluded, named explicitly
Data filesUTF-8 CSV, one file per entity type: captures, tasks, subtasks, comments, meetings, time logs, topics, custom field values, members with their roles, assistant chats, and an audit extract. Archived content is included.
KeysEach row carries its own identifier and its parent's identifier, so the structure of your workspace is preserved
FilesAttachments in their original formats, with a manifest mapping stored filename to original filename, parent item, uploader and upload date

A self-serve export in the product is planned. Until it is available, the email route above applies, and the same commitment appears in our Terms of Service and in the deletion flow.

13. How we protect it

  • Encryption. In transit over TLS, and at rest in every store described in Section 8.
  • Authentication. Password hashing, optional two-factor authentication, and federated sign-in with Google, Apple, Microsoft, LinkedIn and GitHub.
  • Access control within your workspace. A role model that determines what each member can see and do, and topics that can be marked confidential so that their content is restricted within the workspace.
  • Audit logging. Sign-ins, permission changes and content changes are recorded and kept for the 12 months stated in Section 9.
  • Staff access. Polaris staff access to customer data is limited to personnel who need it to operate or support the service, requires a business reason, and is logged. Staff access to data stored in Frankfurt is remote access and does not move your data.
  • Sub-processor diligence. Written agreements, purpose limitation, and a recorded route for instructing each sub-processor to delete data when required.

We do not currently hold SOC 2 or ISO 27001 certification. Our security commitments are those set out above, in the sub-processor list in Section 21 and in the Data Processing Agreement. If certification is relevant to your procurement process, contact us for information on our current position.

14. Personal data breaches

If personal data we hold is breached, we notify the relevant supervisory authority within 72 hours of becoming aware of the breach, or sooner where a regime requires it. Under UAE law, notification is required immediately on discovery, and we comply with that requirement. The 72-hour period applies under Saudi, Egyptian and EU law.

Where we act as your processor, we notify your organization without undue delay so that it can meet its own obligations as controller, and we provide the information it needs to do so.

Where a breach is likely to result in a high risk to you, we also notify you.

We document every breach, including breaches that do not meet the notification threshold, together with the reasons for that conclusion.

15. Cookies and analytics

We use cookies and similar technologies to keep you signed in, remember your preferences, and understand how the product is used, including through session recording of the web app. Session recordings run only if you allow analytics, and they are anonymised: we do not send your name or email address to our analytics provider, and text entered into input fields is masked before it leaves your browser.

Essential cookies are required for Polaris to function. You can refuse all other technologies (analytics, session recording, and the attribution and advertising technologies on our marketing site) without losing any product functionality.

The Cookie Notice in Section 20 lists each technology used, who sets it, its purpose and its duration, and explains how to change your choices.

16. Marketing communications

Polaris sends two kinds of email.

Service email. Workspace invitations, email verification, password resets, billing notices, security alerts, and the notifications you have configured. These are part of the service and you cannot opt out of them while your account is active, although you can control which notifications you receive in your profile.

Marketing email. Product news, feature announcements and other promotional communications. Marketing email is sent only with your consent, and you can stop it with one click. Every marketing email contains an unsubscribe link. Unsubscribing takes effect immediately and does not affect service email. Users on a free plan are not added to a marketing list by default, and use of Polaris does not constitute consent.

Notification content. A notification about a task includes the task's title and the relevant text. Notification emails are delivered to recipients' mail systems, which we do not control, and deleting the item in Polaris does not remove it from mail already delivered (see also Section 9). Where content is sensitive, an administrator should configure notification preferences accordingly before the content is created.

17. Age and children

Polaris is a workplace tool for organizations. You must be at least 16 to have a Polaris account.

We do not knowingly collect personal data from anyone under 16, and Polaris is not directed at children. Where the law of a country requires guardian consent for a person below an age higher than 16, the organization is responsible for obtaining that consent before inviting that person into a workspace.

If we learn that we hold personal data belonging to a person under 16, we promptly delete the account and its personal data and inform the workspace administrator. If you believe a child has an account, write to privacy@hexifyer.com and we will act on it.

18. Regional terms

The preceding sections apply to all users. Hexifyer FZ-LLC is established in the United Arab Emirates, and the law set out in Section 18.1 applies to us as a company. The following appendices set out additional terms for users in other regions. Where an appendix conflicts with any preceding section, the appendix prevails for people in that region.

18.1 United Arab Emirates

ItemDetail
Applicable lawFederal Decree-Law No. 45 of 2021 on the Protection of Personal Data. Hexifyer FZ-LLC is registered in a Ras Al Khaimah free zone, which has no data protection legislation of its own, so the federal law applies and the DIFC and ADGM regimes do not.
AuthorityThe UAE Data Office. Its Executive Regulations have not yet been issued.
Response deadlineThe federal law requires a response without undue delay and sets no fixed period. We apply 6 working days.
BreachNotified immediately upon discovery. This is stricter than the 72-hour period, and we comply with it.
LanguageThis policy is published in Arabic and English with the same effective date. Where the two versions conflict, the English version governs, except where UAE consumer protection rules require otherwise.

18.2 Saudi Arabia

ItemDetail
Applicable lawThe Personal Data Protection Law and its Implementing Regulations.
AuthoritySDAIA, the Saudi Data and AI Authority.
Response deadline6 working days, which is shorter than the Law requires.
BackupsWhere Saudi law requires that all backup copies of erased data be destroyed rather than allowed to rotate out, we destroy them, and the 14-day period in Section 9 is a maximum rather than a fixed schedule.
RecordsWe keep our record of processing activities for the processing period plus five years, as required.
TransfersYour data is stored in the EU. See below.

Transfers. The transfers described in Section 5 to providers processing in the United States are covered by the safeguards in our Data Processing Agreement. Polaris applies one standard to every customer in every market rather than country-specific transfer clauses. Where the Law requires a particular instrument for a transfer out of the Kingdom, the organization holding the workspace, as the exporter of that data, is responsible for putting it in place.

18.3 Egypt

ItemDetail
Applicable lawPersonal Data Protection Law No. 151 of 2020 and its 2025 Executive Regulations.
AuthorityThe Egyptian Personal Data Protection Centre. You may complain to the Centre directly without first contacting us.
Response deadline6 working days, per Article 32.
Legal basisConsent is the primary basis. Where Section 4 names legitimate interests, we collect and record your consent instead, and maintain a register of consent records with the withdrawal route attached.
LicensingThe Law provides for licences issued by the Centre to controllers and processors. Hexifyer FZ-LLC does not currently hold one.
Transfer out of EgyptArticles 14 to 16. See below.
BreachNotified to the Centre within 72 hours of awareness. The Centre notifies affected individuals within three days of our notification.

Licensing. The protections described in this policy (where your data is held, who can access it, how long we keep it and the rights you can exercise) do not depend on a licence and apply to you in full.

Transfer out of Egypt. Your personal data is written to Frankfurt, Germany when you create it, so it is transferred out of Egypt at the point of collection and continuously thereafter. Articles 14 to 16 govern the transfer, and the arrangement differs for the two kinds of data described in Section 2.

  • Workspace content (Polaris is the processor). The transfer is governed by the Data Processing Agreement between Hexifyer FZ-LLC and your organization, which your organization accepts when it accepts our Terms of Service and which is incorporated into them by reference. The Data Processing Agreement sets out the safeguards that apply to the transfer, names the sub-processors involved, and states our obligations to your organization as the controller of that content.
  • Account data (Hexifyer FZ-LLC is the controller). We rely on the level of protection available at the destination: Germany is a member state of the European Union, and the data is protected there by the EU General Data Protection Regulation and by German federal data protection law.

We do not ask individual users to consent to this transfer, and no individual consent is required for either arrangement.

Responsibilities. For workspace content, the Data Processing Agreement makes your organization the exporter of the data and Polaris the importer, because the rights and approvals required for a transfer attach to your organization's relationship with the individuals concerned. Polaris does not obtain Egyptian licences or permits on an organization's behalf. This does not affect your rights: requests are made as set out in Section 10, the response deadline is six working days, and you may contact the Centre directly.

18.4 European Economic Area and United Kingdom

ItemDetail
Applicable lawThe EU General Data Protection Regulation, and the UK GDPR with the Data Protection Act 2018.
AuthorityYour national data protection authority or, in the UK, the Information Commissioner's Office.
StorageYour data is stored in Frankfurt, Germany. Hosting it does not involve a transfer out of the EEA.
TransfersThe platform and AI sub-processors in Section 5 and in the sub-processor list in Section 21 process in the United States. Those transfers rely on Standard Contractual Clauses with the supplementary measures set out in our Data Processing Agreement.
BackupsThe 14-day period in Section 9 is our advance disclosure of the backup deletion delay, as guidance requires. If regulatory guidance on backup erasure changes and this period is updated, we will notify you.
Data Processing AgreementIncorporated into our Terms of Service by reference, and therefore in force for every customer without separate signature. It includes Standard Contractual Clauses and the security annex carrying every period in Section 9. A copy is available from privacy@hexifyer.com, and we will sign a countersigned version on request.

18.5 California

We do not sell personal information and we do not share it for cross-context behavioural advertising. Section 9 states our retention period for each category, as required. California's rules permit a delay in erasing data held in backup until that backup is restored or next used. Our practice is the 14-day period in Section 9, which is shorter, and we apply the shorter period.

19. Changes to this policy

The effective date of this version is stated at the top of the page.

  • Material changes (a new purpose, a new category of recipient, a longer retention period, a weaker commitment, or a change to how deletion works) are announced at least 30 days before they take effect, by email to workspace administrators and by a notice in the product. The introduction of deletion for inactivity, for example, would be a material change.
  • Other changes (clarifications, corrections and drafting changes that do not alter our practices) take effect on publication, and the last-updated date at the top of the page is changed.
  • Previous versions are kept in a public archive, showing what this policy stated on any date and what changed.
  • The sub-processor list in Section 21 is not part of this policy. It is updated separately, with its own 30-day notice and objection period as described in Section 7.1.

20. Cookie Notice

This Cookie Notice describes the information Polaris stores on your device, the purposes for which it is stored, and the choices available to you. It applies to the Polaris web application, the Polaris mobile applications and our marketing site.

In this notice, "cookies" refers to cookies, browser storage that functions in a similar way, and data that our mobile applications store locally on your device. Where any of this information is personal data, your rights in relation to it are set out in this Privacy Policy.

20.1 Summary

CategoryPurposeCan you refuse it?
Strictly necessaryKeeping you signed in and keeping your account secure. Polaris cannot operate without them.No. They are used for no other purpose.
Functional and preferencesRemembering your theme, language, sidebar state, last view and unsubmitted drafts.Yes, by clearing site data. This removes your preferences, not your work.
AnalyticsUnderstanding how Polaris is used in order to improve it. Set by Microsoft Clarity, a third party, and anonymised.Yes. They are not loaded without your consent. See Section 20.7.

We do not use cookies for advertising, and we do not sell the information we collect.

20.2 Strictly necessary cookies

The following are the only cookies set by Polaris itself. They are required to sign in and to maintain a secure session.

CookiePurposeDuration
sb-{project-ref}-auth-tokenHolds your authentication session so that you remain signed in while using Polaris. Set by Supabase, our authentication provider. First-party.The duration of your sign-in session
password_reset_pendingA temporary marker used during password reset and multi-factor verification. First-party, and removed when the process ends.Minutes (the duration of the process)

These cookies cannot be disabled. If you block them, you will not be able to sign in.

20.3 Browser storage

Most of the information Polaris retains on your device is held in browser storage rather than in cookies. Browser storage remains on your device and is not sent to us with each request. It falls into three groups.

Sign-in and navigation

ItemPurpose
authTokenMaintains your session in the application.
app_sourceRecords whether you arrived at Polaris or at Hexifyer DevStudio, so that you are directed to the correct product.
hexifyer_pending_invite_urlRecords the workspace invitation you were opening, so that you are taken to it after signing in.
Sign-up cooldown timersPrevent repeated sign-up and verification attempts in quick succession, as an abuse control.

Preferences

ItemPurpose
Language (i18nextLng) and themeRetain your language and appearance settings between visits.
Sidebar and widget layoutRetain whether your sidebar is collapsed and the arrangement of your dashboard widgets.
View modesRetain whether you last used Kanban or list view on a project.
Dismissed hints and toursPrevent a tip from being shown again after you have dismissed it.

Caches and unfinished work

ItemPurpose
Attachment display URLsA short-lived cache so that files you are viewing do not need to be fetched repeatedly.
Meeting recording timersKeep a recording's elapsed time accurate if the page reloads during a meeting.
Unsubmitted draftsHold work in progress, such as an incomplete estimator wizard, so that it is not lost on refresh.
Session-only itemsProject and task filters, and temporary redirects during sign-up. These are held in session storage and are removed when you close the tab.

This information remains on your device. Clearing your browser's site data removes it and does not affect anything you have saved in Polaris, which is stored on our servers.

20.4 Mobile applications

The Polaris mobile applications do not use cookies. They store the following in the application's own storage on your device:

  • Push notification subscription ID (onesignal_subscription_id), so that notifications are delivered to your device.
  • The chat thread you currently have open, so that the application can return you to it.
  • Grouped notification contents (onesignal_group_thread:{id}), so that multiple notifications about the same item are displayed as a single entry.

Deleting the application removes this information. You can disable notifications in your device settings at any time.

20.5 Analytics

If you consent to analytics, we use Microsoft Clarity to understand how Polaris is used, including which features are used, where users encounter difficulty and where errors occur. Clarity records interactions such as mouse movement, clicks, scrolling and page rendering, and replays them as a session.

Clarity is a Microsoft product and sets its own cookies, only after you have consented to analytics. Two are first-party; the others are Microsoft's own and are set across Microsoft services.

CookieSet byPurpose for which Microsoft uses it
_clckFirst-partyHolds a Clarity identifier for your browser, so that repeat visits are recognised as the same user.
_clskFirst-partyCombines the pages you view into a single recorded session.
CLIDMicrosoftIdentifies the Clarity project to which the recording belongs.
ANONCHKMicrosoftIndicates whether a user identifier is used for analytics only, and supports fraud checks.
MRMicrosoftControls whether the MUID identifier is refreshed.
MUIDMicrosoftIdentifies a browser across Microsoft sites. Microsoft's documentation describes it as used for advertising, site analytics and other operational purposes.
SMMicrosoftSynchronises the MUID identifier across Microsoft domains.

We do not use Clarity for advertising and do not run advertising campaigns using this data. The Microsoft cookies listed above operate as described by Microsoft.

Consent. Clarity is not loaded until you accept analytics in the cookie settings. If you decline, or do not respond, Clarity is not loaded and none of the cookies above are set. No Polaris functionality depends on Clarity.

Data not sent to Clarity. We do not send Clarity your name or email address. Recordings are not linked to a named account, and we are unable to retrieve the activity of a specific individual. Text entered into input fields is masked before it leaves your browser.

Page addresses. Masking applies to text you enter and does not apply to page addresses. A page URL may be sent to Clarity as part of a recording, and a Polaris URL may contain a project or workspace name.

Microsoft retains Clarity recordings for up to 30 days, and for up to nine months where a recording has been marked as a sample or favourite. Microsoft's privacy statement governs its use of the data it holds.

You may withdraw your consent at any time, as described in Section 20.7.

20.6 Technologies we do not use

  • No Google Analytics, and no advertising or attribution pixels in the Polaris application.
  • No advertising profiles. We do not build, buy or sell advertising profiles, and we do not sell the information we hold.
  • No IndexedDB and no persistent offline database. Our API caches are held in memory only and are cleared when you refresh the page.
  • No cross-site tracking. The only third party that sets any item through Polaris is Microsoft Clarity, as described in Section 20.5.

20.7 Managing your preferences

Analytics. We request your consent before loading analytics. You can change your choice at any time using the cookie settings link in the footer of any Polaris page. Declining prevents Clarity from loading and has no other effect.

Other cookies and storage. These are controlled through your browser. Major browsers allow you to view and delete cookies and site data for an individual site, block third-party cookies, or clear all data on exit. Clearing Polaris site data signs you out and resets your preferences. It does not affect your work.

Mobile. Notification permissions are managed in your device settings. Removing the application removes the information it stored.

Do Not Track and global privacy signals. Polaris does not respond to these signals. Use the cookie settings link described above to manage analytics.

Information on how to request access to or deletion of the data we hold about you, and our response times, is set out in this Privacy Policy.

20.8 Changes to this notice

We update this notice if we add a cookie, add a provider, or begin using an existing one for a new purpose. A material change (a new third party, or an existing one used for a new purpose) is announced at least 30 days before it takes effect, which is the same notice period as applies to this Privacy Policy and our Terms of Service. Corrections and clarifications take effect on publication, and the last-updated date is revised. Previous versions are kept in a public archive.

21. Sub-processors

Polaris is operated by Hexifyer FZ-LLC, a free zone company registered in Ras Al Khaimah, United Arab Emirates under licence number 47017173, at FOAM1588, Compass Building, Al Shohada Road, Al Hamra Industrial Zone-FZ, Ras Al Khaimah, United Arab Emirates. To provide the service, we use a limited number of third-party providers that store or process personal data on our behalf. Each of these is a sub-processor.

This section lists every sub-processor we use, its function, the data it receives and the location of processing. We keep this list current. You can subscribe to be notified in advance of changes, as described in Section 21.5.

21.1 What a sub-processor is

Your team's content in Polaris belongs to you. Polaris processes it on your instructions, which makes Polaris a processor and your organization the controller. A sub-processor is a company we engage to help deliver the service and which may access that content in doing so.

Each sub-processor listed below is engaged under a written agreement that restricts it to processing data for the specified purpose, requires confidentiality, and requires security measures appropriate to the data involved. We remain responsible to you for their performance.

21.2 Infrastructure sub-processors

These providers host the Polaris service and the data held in it.

Sub-processorPurposeProcessing locationMore information
Supabase (Supabase, Inc., United States)Authentication and file storageGermany (AWS eu-central-1)supabase.com/privacy
Render (Render Services, Inc., United States)Application hosting and databasesGermany (AWS eu-central-1)render.com/privacy
Amazon Web Services (Amazon Web Services, Inc.)Underlying cloud infrastructureGermany (eu-central-1)aws.amazon.com

Data processed:

  • Supabase: account records and credentials, including email addresses, password hashes and federated sign-in identifiers; files uploaded to a workspace, including profile photos, organization logos, project files, and task and message attachments.
  • Render: the main Polaris database (ideas, Second Brain messages, tasks, logs, meetings, comments and audit logs) and the AI database (chat history between a user and Polaris AI). Render also hosts the Polaris backend, frontend and AI services.
  • Amazon Web Services: all data held by Supabase and Render is stored on AWS. AWS does not access it in the ordinary course.

All Polaris workspace content, files and account records are stored in Frankfurt, Germany, in the AWS eu-central-1 region. The platform sub-processors listed in Section 21.3 receive narrower categories of data and process them in the regions stated for each.

21.3 Platform sub-processors

These providers deliver specific features. Each receives only the data required for that feature.

Sub-processorPurposeProcessing locationMore information
Stripe (Stripe, Inc., United States)Payments and subscription billingUnited States, Irelandstripe.com/privacy-center/legal
Twilio SendGrid (Twilio Inc., United States)Transactional email deliveryUnited Statestwilio.com/legal/privacy
OneSignal (OneSignal, Inc., United States)Mobile push notificationsUnited Statesonesignal.com data handling
Nylas (Nylas, Inc., United States)AI meeting notesUnited Statesnylas.com/platform/security
Microsoft Clarity (Microsoft Corporation, United States)Product analytics and session recording, loaded only where a user has accepted analyticsUnited Statesprivacy.microsoft.com

Data processed:

  • Stripe: billing contact name and email, billing address, plan and seat count, invoice history, and a payment method token. Polaris does not receive or store full card numbers.
  • Twilio SendGrid: recipient name and email address, and message content. This includes workspace invitations, email verification, password resets and notification emails, which may contain task and project names.
  • OneSignal: device push token, device and app identifiers, and notification content, which may contain task, project and workspace names. Delivery to the device is completed by Apple Push Notification service on iOS and Firebase Cloud Messaging on Android.
  • Nylas: where the AI notetaker is used, the details of the meeting it joins, the meeting audio, the transcript and the notes generated from it.
  • Microsoft Clarity: anonymised session recordings of use of the Polaris web app, including pages viewed, clicks, scrolling, form interaction, device and browser, and approximate location derived from IP address. Microsoft Clarity is not loaded unless a user has accepted analytics. Polaris does not send Microsoft a user's name or email address, and text entered into input fields is masked before it leaves the browser. Page addresses are not masked and may form part of a recording.

Sign-in providers. Google, Apple, Microsoft, LinkedIn and GitHub are not sub-processors when used to sign in to Polaris. The provider authenticates you under its own terms and provides Polaris with the profile fields you approve. Polaris does not instruct it to process data on our behalf, and it acts as an independent controller. Your account record, including the identifier linking it to that provider, is held by Supabase. If you connect a Google or Microsoft calendar, Polaris reads and updates it directly through that provider under the permission you grant, on the same basis. Google is listed in Section 21.4 in respect of the AI models Polaris uses, not sign-in.

21.4 AI sub-processors

Polaris uses AI in two features. The assistant answers questions about your workspace and performs actions you request. The writers draft content on request, including idea drafts, log entries, task descriptions and idea classification.

Both features send the workspace content relevant to the request to a model provider outside Polaris infrastructure. Every AI request is sent through a single gateway, OpenRouter, which forwards it to the provider serving that request.

Sub-processorPurposeProcessing locationMore information
OpenRouter (OpenRouter, Inc., United States)AI gatewayUnited Statesopenrouter.ai/privacy
OpenAI (OpenAI, L.L.C., United States)Text generation and embeddingsUnited Statesopenai.com/policies
Google (Google LLC, United States)Text generation, and processing before a request reaches a modelUnited Statespolicies.google.com/privacy
Anthropic (Anthropic, PBC, United States)Text generation over retrieved contentUnited Statesanthropic.com/legal/privacy

Purpose and data processed:

  • OpenRouter: routes every AI request to the model provider that serves it. It processes the full request sent to the model: your message, recent conversation history, and any workspace content the request requires, such as retrieved tasks, logs, meeting notes, Second Brain messages and activity records.
  • OpenAI: converting a request into a task or log, drafting ideas and log entries, writing the final reply, summarising retrieved documents, and generating the embeddings used for workspace search. It processes the request content described above and the text of workspace content embedded for search.
  • Google: drafting task descriptions, generating ideas, conversation analysis, routing and classifying requests, tool selection, rewriting search queries, answering questions about Polaris itself, and safety checks on incoming and outgoing messages. It processes the request content described above. The conversation analysis and safety checks process every message sent to and from the assistant.
  • Anthropic: answering questions about your workspace activity and documents from the records retrieved for that question. It processes the retrieved records and documents, your question and recent conversation history.

Retention and training. The providers listed above retain the inputs and outputs of a request for a maximum of 30 days, solely to detect and investigate misuse of their own services, and then delete them permanently. This retention is limited to trust, safety and abuse monitoring. It is not used to train any model and is not used to improve any product. Polaris does not route requests to an endpoint whose data policy cannot be established. Each request is pinned to a named provider listed above, and the gateway is not permitted to fall back to a provider not listed in this section. Sections 5 and 9 of this Privacy Policy state the same 30-day period.

Processing location. All AI providers process data in the United States. Polaris does not route any AI request to a provider processing outside the United States or the European Union. The safeguards applying to these transfers are set out in the Data Processing Agreement (Schedule 3 to the Terms).

Disabling AI features. A workspace administrator can disable the AI features for a workspace. This stops them immediately for all members and deletes that workspace's embeddings and assistant chat history, on the same timescales as any other deletion in Polaris. While the features are enabled, workspace content is sent for embedding when it is created, not only when a search is performed, and therefore reaches OpenAI whether or not the assistant is used. Disabling the features stops this. Section 5 of this Privacy Policy states the same.

21.5 Change notifications

We update this list when we add, replace or remove a sub-processor.

  • New sub-processors are posted in this section, and all subscribers are notified by email, at least 30 calendar days before they begin processing customer data.
  • You may object in writing within 30 calendar days of that notice, on reasonable grounds relating to data protection, by writing to privacy@hexifyer.com. This applies to all customers, not only those on a paid plan.
  • We will work with you to resolve the objection. If it cannot be resolved within a reasonable period, you may terminate the affected subscription without penalty.
  • Removal of a sub-processor requires no notice and no objection period. This list and our configuration are updated in the same release.

Subscribing to updates

The address you provide is used only to send sub-processor and data processing notices.

Subscribe

21.6 Questions

Questions may be sent to privacy@hexifyer.com. Our Data Processing Agreement is Schedule 3 to our Terms of Service and is already in force. If your procurement process requires a countersigned copy, you may request one at the same address.

22. Deleting your account

This section describes how to delete your Polaris account, what is deleted and what is retained. Full details are set out in Section 11.

Hexifyer account. Your account is a Hexifyer account. The same account is used to sign in to Hexifyer DevStudio, and deleting it removes your access to both products. The treatment of your Hexifyer DevStudio data is set out in Section 14 of the Hexifyer DevStudio Privacy Policy.

In the app. On the web, or in the Polaris app for iOS or Android, open your account settings and select Delete account. Before you confirm, the app indicates which of the cases below applies to you and whether anything prevents the deletion.

By email. Write to privacy@hexifyer.com from the email address associated with your account and request deletion. We verify the request against the account and respond within 6 working days.

What is deleted. Your account record, your credentials and your profile.

  • If you are a member of another organization's workspace, the content you created there remains with that organization, and your authorship of it is anonymised.
  • If you are the sole member of your own workspace, the workspace and all of its content are deleted with your account.
  • If you own a workspace that has other members, deletion is blocked until you transfer ownership to another member or delete the workspace.

What is retained. Invoice and tax records, for the statutory periods set out in Section 9, and audit records, for 12 months. No other data is retained.

Timing. A 14-day grace period applies, during which you can cancel the deletion without loss of data. After the grace period, your data is erased from live systems within 72 hours, and the last backup copy is removed within 14 days after that.