CoLab
Privacy
Effective September 14, 2026
Honrly Inc. (“we”) runs CoLab at ainativememory.com. We collect what a bulletin board needs to run, and we do not sell personal information. This notice covers the marketing site, researcher workspaces, and respondent boards.
Who is responsible
For the product itself - accounts, hosting, security, and this website - Honrly Inc. is the controller (GDPR) and business (CCPA). For answers, recordings, and uploads on a live study, the research workspace that invited you is the controller. We process that study data on their instructions as a processor.
Controller contact: hello@honrly.com. San Francisco, CA.
What we collect
- Researchers: name, work email, password hash, workspace role, and how the product is used.
- Respondents: name, email, password hash, answers, ratings, photos, video, audio, transcripts, and support-chat messages you send in the board.
- Session quality: IP address, approximate city/region/country from the host, browser, device, and OS. Researchers see this so they know who is on the board and whether a complete is real.
- Cookies: first-party, httpOnly session cookies only. No advertising or social pixels.
Why we use it (GDPR legal bases)
- Contract: to create your account, run the board you joined, and show researchers the study they paid to field.
- Consent: joining a board (you tick the box), optional cookies if we ever add them, and camera or microphone access in the browser for a task.
- Legitimate interests: keeping sessions signed in, spotting duplicate or impossible logins, securing the product, and sending transactional email.
- Legal obligation: tax, accounting, and responding to a valid authority request.
Cookies
These cookies are strictly necessary. The site does not run without them. Optional analytics and marketing cookies are off and unused today.
| Cookie | Life | Why |
|---|---|---|
| user-session | 7 days | Keep workspace users signed in. |
| board-session | 21 days | Keep a respondent on the board they joined. |
| participant-session | 21 days | Keep a participant signed in across boards in one workspace. |
Change optional cookies any time from Cookie settings. We honor Global Privacy Control (GPC) as an opt-out of sale/share.
California (CCPA / CPRA)
We do not sell personal information and we do not share it for cross-context behavioral advertising. We do not use sensitive personal information to infer characteristics beyond running the board. California residents can:
- Know the categories and specific pieces we hold
- Delete personal information, with the exceptions the law allows
- Correct inaccurate personal information
- Opt out of sale or sharing (we already do not sell or share)
- Limit use of sensitive personal information
- Not be discriminated against for exercising these rights
Categories we collect: identifiers (name, email, IP), customer records, internet / device activity, geolocation at city level, audio/visual content you submit, and inferences researchers draw from answers (themes, codes). We disclose these to the research workspace on your board and to the processors listed below. We retain study data until that workspace deletes the project or we complete a verified deletion request. Use Do Not Sell or Share or Your privacy requests. Authorized agents may email hello@honrly.com with proof of authority.
Your GDPR rights
If EU/UK GDPR applies, you can access, rectify, erase, restrict, or port your data, and object to processing based on legitimate interests. You can withdraw consent without affecting processing already done. You may complain to your local supervisory authority. We respond within one month (GDPR) or 45 days (CCPA), and may extend once if the request is complex.
Who we share with
Researchers in your workspace see respondent profiles and answers. We do not sell this data. We use these subprocessors:
| Name of subprocessor | Service provided | Location | Cybersecurity Compliances |
|---|---|---|---|
| Vercel | Cloud hosting | USA | ISO 27001, SOC 2, GDPR |
| Supabase | Database as a service | USA | SOC 2, GDPR |
| Google Gemini | AI and machine learning | USA | ISO 27001, SOC 2, GDPR |
| Amazon SES | Email delivery | USA | ISO 27001, SOC 2, GDPR |
| Email delivery | USA | ISO 27001, SOC 2, GDPR | |
| Microsoft | Document services | USA | ISO 27001, SOC 2, GDPR |
Servers are in the United States. If we transfer EU/UK data here, we rely on the processor’s Standard Contractual Clauses (or equivalent) plus the security measures in this product.
Retention and security
Session cookies expire in 7 or 21 days. Project data stays until the workspace deletes the study or we fulfill a deletion request. Passwords are hashed. Session cookies are httpOnly and Secure in production. No method of transmission is perfectly secure; tell us at hello@honrly.com if you think something went wrong.
Children
CoLab is not directed at children under 16. Workspaces must not invite minors unless they have a lawful basis and any required guardian consent. Contact us if you believe a child used the product so we can delete the account.
How to reach us
Email hello@honrly.com. If you are signed in as a respondent, you can download a copy from Your privacy requests, or ask the research team on the board to delete your answers. We may need to verify the email on the account before we act.