Privacy notice
HMN Agent Privacy Notice
Effective date: 24 September 2026
This notice explains how the HMN Local Operations Agent, also referred to as HMN Laptop Agent v2, handles information for Hunt My Nest Portal LLC, Dubai, UAE. It supplements the website Privacy Policy for this internal operations application.
Purpose and authorized account
The agent assists HMN with campaign preparation, authorized content review and revisions, management actions, analytics and public-source research. Its approved connected Google account is huntmynest@gmail.com. HMN controls the agent's mandate, and authorized HMN personnel provide required final approvals.
Information accessed and why
- Google account email/profile
- Verify that the connected account is HMN's approved account.
- Relevant Gmail messages, headers, recipients, attachments, message/thread identifiers and timestamps
- Find HMN review feedback, verify approval evidence, reconcile prior sends and avoid duplicates.
- HMN Drive assets and Sheets records
- Read branding, campaign history, actions and approvals; maintain approved assets and management records for authorized production work.
- GA4 and Search Console reports
- Assess HMN website performance using reporting access; no tracking or website configuration changes.
- Local job state, errors, evidence and diagnostic outputs
- Recover interrupted work, verify results and support management oversight.
The current Google grants include Gmail read/send, Drive read and per-file access, Sheets read/write, and Analytics/Search Console read access. Some grants are technically broader than the intended HMN records. HMN limits use to authorized records and purposes through application restrictions, access controls and operational oversight. The agent does not request Google passwords.
Use disclosure and AI processing
HMN review packages and management summaries are intended only for approved communications recipients. Access to records is limited to authorized personnel and service providers needed for the approved functionality.
OpenAI's API is used for text and image generation. HMN limits the production sharing boundary to the minimum content necessary for an authorized task: campaign briefs, approved brand assets, selected creative-revision instructions, public-source findings and aggregate website performance summaries. Google-origin content may cross this boundary only for the disclosed user-facing feature and in accordance with applicable disclosure, consent and provider-policy requirements. No bulk mailbox, whole-thread, register or Drive export is permitted.
Before an AI request, the application selects allowed fields and removes signatures, personal email addresses, phone numbers, unrelated quoted messages and unnecessary personal details. Raw email attachments are excluded by default. A specific HMN-owned or licensed creative asset may be submitted for an authorized image revision after screening; documents containing customer or tenant identity, financial, health or other sensitive information are not submitted. Credentials, tokens and passwords are never included. An uncertain classification blocks the transfer for human review.
Approval identity, email authentication and execution authority are determined from original evidence locally, not delegated to an AI model. The model may assist with wording or summarize a sanitized instruction; it cannot grant approval. Google-derived personal data is not used for advertising targeting or audience profiling. HMN does not sell these records or use them for data brokerage, general-purpose model training, fine-tuning or provider feedback/data-sharing opt-ins.
HMN's use and transfer of Google-derived information complies with the Google API Services User Data Policy, including its Limited Use requirements. Only authorized HMN personnel may access the records needed for their roles. External support does not receive unredacted Google data without a separately documented permitted purpose and necessary consent.
OpenAI states that API data is not used for model training by default unless the customer opts in. HMN does not enable provider feedback or data-sharing opt-ins and uses non-stored responses where supported. Provider abuse-monitoring retention can still apply, ordinarily up to 30 days with documented exceptions; non-stored responses do not establish zero provider retention. Persistent provider files or conversation stores are not used for this workflow. OpenAI data controls.
Storage and protection
The runtime and operational database are hosted on an HMN-controlled device. Stored OAuth credentials and the AI API key are protected with Windows user-bound encryption. HMN applies access controls, device protection and controlled backup handling to operational records.
Google-hosted mail and files, and requests sent to external APIs, remain subject to those providers' processing arrangements. Local hosting does not guarantee UAE-only processing or storage.
Retention, access and deletion
The following periods are HMN operational policy choices, not assertions of statutory retention requirements. They apply prospectively to HMN Agent production records and do not authorize deletion of existing Gmail or Drive originals or historical pilot records.
- Temporary downloads, raw fetched message copies and intermediate rendering files
- Remove within 7 days after successful processing/reconciliation. Promote only necessary evidence into the audit record before expiry.
- Raw analytics/public-source caches
- 30 days from retrieval; retain selected dated evidence and aggregate results in the relevant business record.
- Routine technical logs and non-business diagnostic files
- 90 days from creation; exclude secrets and raw message bodies. Incident evidence follows the longer incident rule.
- Campaign versions, captions, final assets, QA, scoped approval evidence, action outcomes and relevant communications evidence
- 24 months after final closure or supersession, whichever is later. Keep active or unresolved records until closure, with quarterly necessity review.
- Incidents and recovery evidence
- 24 months after closure, subject to any documented hold.
- Local rotating backups
- 30-day rolling window. Exclude unnecessary caches and plaintext credentials. HMN protects backups and reapplies deletion records after any restoration.
- Minimal deduplication ledger
- Keep hashed business keys, message identifiers and terminal state for the lifetime of the relevant integration, with annual necessity review; no bodies or attachments. Old closed work remains ineligible for automatic replay even after detailed content expires.
- OAuth tokens and API credentials
- Retain only while the integration is authorized; revoke and securely remove on decommissioning or confirmed compromise.
- Existing pilot records and historical evidence
- Preserve unchanged under HMN's governance decision. Review necessity annually; no automatic deletion or retrospective rewriting. Authorized HMN governance personnel decide any release of this preservation hold.
A documented legal, dispute or incident hold may delay expiry for specifically identified records. Sunitha coordinates the review and HMN retains final governance authority. HMN records the reason, scope, owner and next review date, and reviews holds at least quarterly. HMN does not invent a legal obligation or use a blanket indefinite hold. Conflicting privacy requests and preservation instructions are escalated to HMN's privacy and governance contacts before action.
Privacy requests go to admin@huntmynest.com. HMN's internal service target is acknowledgement within 5 working days and a substantive response within 30 calendar days, subject to any applicable shorter legal deadline. HMN verifies the requester's identity proportionately and does not automatically request identity-document copies. HMN explains the outcome or any justified delay. These targets are internal commitments, not a statement of UAE statutory deadlines.
Approved deletion covers the relevant local records and projections, with separately authorized treatment of Google originals. HMN keeps a minimal non-content deletion record to prevent restored backups from recreating removed data. Backup remnants expire within 30 days and do not return to operational use; any restoration reapplies deletion records before processing. Adopting this notice alone does not delete any record.
The account owner can revoke the app's access through Google Account connection settings. Revocation prevents future authorized access but does not itself remove existing local records, sent email, Drive files or backups. Requests for access, correction or deletion should be directed to HMN's confirmed privacy contact. HMN explains any required retention exception to the requester.
Legal operator: Hunt My Nest Portal LLC, Dubai, UAE.
Legal/privacy contact: Sunitha Varu.
Email for privacy, data-access, correction and deletion requests: admin@huntmynest.com.
Telephone: +971 55 200 0349.