Public policy

Highsfield Privacy Notice

How the current browser-only website handles information and what must change before new data features launch. Effective 2026-08-26.

This notice explains what information the current Highsfield website handles, why the data footprint is intentionally small, and what must change before any future account, upload, analytics, payment, or AI service is introduced.

Scope of this notice

This notice applies to the public website at highsfield.com and the deterministic campaign-planning prototype available through its published pages. The site is designed to demonstrate a workflow, not to operate a hosted creative service. It currently has no user accounts, authentication, subscriptions, payment processing, project database, cloud asset library, or live model connection.

External websites and email providers operate under their own notices. Following an external link or sending an email leaves the browser-only website environment described here. Visitors should review the destination provider’s terms before sharing personal information, confidential campaign material, credentials, or protected creative assets.

Information entered into the prototype

A visitor may type a short campaign brief and choose a planning priority. JavaScript running in the current page uses those values to assemble deterministic planning text. The website does not send the brief to Highsfield, an AI provider, an analytics system, or persistent storage. Refreshing or closing the page clears the current interaction state.

Because the prototype is intentionally limited, visitors should still avoid entering secrets, passwords, financial data, health information, unreleased customer records, private identifiers, or material they are not authorized to use. Browser-only processing reduces collection, but it does not make a shared or unmanaged device an appropriate place for sensitive work.

Server and technical records

A hosting provider may ordinarily process basic network requests needed to deliver a website, including an IP address, requested path, timestamp, user agent, and security-related diagnostics. No hosting platform has been selected for this local validation build, so provider-specific logging, location, access, and retention details are not yet claimed on this page.

Before deployment, the operator must document the selected host, actual server-log behavior, security purpose, access controls, retention period, and deletion process. If those facts differ from this notice, publication must pause until the policy and configuration match the deployed system.

Analytics, events, and tracking

The current website does not load a remote analytics provider, advertising pixel, session recorder, or cross-site tracking service. Prototype events are dispatched as browser CustomEvents so developers can test names and sanitized properties locally. They are not transmitted by the website and intentionally exclude the entered brief, email addresses, and other sensitive values.

Any future measurement plan must define a limited purpose, collect only necessary fields, prevent prompt or asset content from entering telemetry, and document the provider and retention period. Consent requirements must be evaluated before non-essential tracking is enabled. The policy, cookie controls, tests, and public configuration must all be updated together.

Sharing, selling, and service providers

The current website does not sell personal information, build advertising profiles, or share prototype briefs with model providers. There are no enabled vendors for generation, storage, payments, remote analytics, or marketing automation. The support mailbox is the only published communication channel, and messages sent there are handled by the relevant email infrastructure.

If a service provider is added later, the operator must evaluate its role, security, contractual terms, processing location, subprocessors, deletion options, and use of submitted content. A provider must not be described as active until the integration exists and the public notice accurately explains the resulting data flow.

Retention, security, and individual choices

The website itself has no account record or saved prototype project to retain, export, correct, or delete. In-page values disappear when the browser context is reset. Email correspondence may remain in the support system according to that provider’s operational settings and legitimate support or legal needs; visitors can request help using the published address.

No website can promise absolute security. The current design reduces exposure by avoiding collection and persistence, but visitors remain responsible for device security and for the information they choose to email. Requests concerning access, correction, or deletion should identify the communication involved without resending sensitive material.

Children, changes, and contact

The minimum age for this website is 16. The service is not directed to children below that age, and the current prototype does not knowingly create child accounts or profiles. If the operator learns that information was submitted contrary to this restriction, the matter should be reported through the support address for appropriate review.

This notice is effective 2026-08-26. It must be reviewed before enabling accounts, forms, uploads, AI generation, analytics, payments, cookies, or persistent storage. Questions may be sent to support@highsfield.com. Material changes should be reflected through a new effective date and a clear description of the current behavior.

Review and change controls

  • Highsfield privacy must describe the deployed website rather than a planned product roadmap.
  • Review Highsfield privacy whenever a provider, data flow, browser technology, or public feature changes.
  • Keep Highsfield privacy consistent with the public configuration, automated tests, and actual network behavior.
  • Do not publish Highsfield privacy claims that depend on a vendor or retention period that has not been confirmed.
  • Record the effective date when a material Highsfield privacy revision is approved for publication.
  • Route questions about Highsfield privacy to the published support address without requesting unnecessary personal data.
  • Check Highsfield privacy against the production build before every public release.
  • Archive each approved Highsfield privacy version so material changes remain traceable.

Frequently asked questions

Is my campaign brief saved?

No. The current website processes the brief only in the open browser page and does not persist it.

Does the site send prompts to an AI provider?

No live AI provider is connected, so the current site does not transmit prompts for generation.

How can I ask a privacy question?

Email support@highsfield.com and avoid including unnecessary sensitive information.