Privacy policy
Last updated: 24 August 2026 · Effective: 21 July 2026 · What changed
Who we are
This website is operated by 8Hats Lab Inc., a Delaware corporation (United States) — the entity responsible for the personal data described on this page. Services in Singapore are provided by 8Hats Lab Pte. Ltd. (UEN 202613872E, 68 Circular Road, #02-01, Singapore 049422) — when you engage us there, your client and contract data sits with that entity. One team runs both, out of Singapore and Silicon Valley, and the same person answers for privacy across the two: see below.
8Hats Lab Inc.
131 Continental Dr, Suite 305
Newark, DE 19713-4324
United States
Privacy questions or requests: hello@8hats.ai. A real person answers.
Our Data Protection Officer is Dmitriy Istomin, who is also our chief executive — at our size the person accountable for privacy should be the person who can actually change what we build. Reach the role at hello@8hats.ai, or write to the postal address above marked for the attention of the Data Protection Officer. This designation is made for the purposes of Singapore's Personal Data Protection Act, and the same person handles privacy questions wherever you are.
This policy covers 8hats.ai, including our articles, research pages, campaign landing pages and the Agents University section of this site. Our sister product site agents.university is a separate property; don't assume this page covers it — if you have a question about that site, ask us and we'll answer directly. Zenodo, Google and our other providers have their own policies. Once you follow a link out, their terms apply, not ours.
What we collect
- Email you send us. Almost every contact point on this site is a plain email link. When you write to us — to join the self-check waitlist, request a consultation, or propose a collaboration — we get your email address and whatever you choose to write. It lands in our email provider's systems.
- What you enter in the one form we have. The exception to the above is the Agents University enrolment form at
/agent-university/, which sends what you enter — your name, email, and the answers you give about your situation, together with the campaign that brought you and basic page-use information such as how far you scrolled — to our application system atapp.8hats.ai. It also saves your partly-filled answers in your own browser so you don't lose them. - Ordinary server logs. Our web host records standard request logs — IP address, browser type, page, timestamp — as every web server does. We don't profile them, connect them to you, or use them for anything but keeping the site up.
- Cookies and measurement. One family of first-party cookies, and a set of third-party analytics and advertising scripts. The full list is below — no guessing required.
Cookies and measurement
Here is every cookie we set and every third-party script we load, as of the date at the top of this page. We keep this table current: if we add or change anything that sets a cookie or loads a third-party script, we update this table and move the date.
| What | Who sets it | Why | How long |
|---|---|---|---|
ab--, ab--landing-founders, ab--landing-executives, ab--landing-entrepreneurs |
Us (first-party) | When we run more than one version of a page to test wording, this keeps you on the same version between clicks so the site doesn't change under you. On campaign landing pages the version is picked at random per visitor. It holds a short version name, not an identifier for you — but our analytics scripts do read that name and attach it to analytics events, so we can compare versions. | 30 days |
| Google Ads tag (gtag.js, AW-18039449647) |
Google (third party) | Loads Google's advertising script on our home page and on the Agents University page, so we can see which campaigns bring people to us and which enquiries came from an ad. Google receives your IP address, the page, and its own advertising cookies, and may use them to measure and target ads. This is the only third party on the site that receives an identifier. | Set by Google — see Google's cookie notice |
| PostHog (us.i.posthog.com) |
PostHog (third party, processor for us) | Runs on our consulting and founder pages only. It assigns your browser an identifier and records which sections you view and which buttons you press, so we can see where those pages lose people. We brought it back for these pages in August 2026 after removing it site-wide in July; this table is the record of that change. | Set by PostHog — persistent until cleared |
| LinkedIn Insight Tag (snap.licdn.com) |
LinkedIn (third party) | Runs on our consulting and founder pages. It tells LinkedIn when a visit or an enquiry came from one of our LinkedIn advertisements. LinkedIn receives your IP address, the page, and its own cookies, and may use them for its own measurement and ad targeting per its policy. | Set by LinkedIn — see LinkedIn’s cookie policy |
| Reddit Pixel (redditstatic.com) |
Reddit (third party) | Runs on one page (our US founder page). It tells Reddit when a visit came from a Reddit advertisement. Reddit receives your IP address, the page, and its own cookies. | Set by Reddit — see Reddit’s cookie notice |
| Plausible | Plausible (third party, processor for us) | Aggregate page counts. Plausible sets no cookies and does not track you across sites. | No cookie set |
| Script and font hosts (fonts.googleapis.com, fonts.gstatic.com, cdnjs.cloudflare.com) |
Google, Cloudflare (third parties) | Deliver the typeface this site is set in, and animation code on the Agents University page. The fonts load on every page, including this one, because our stylesheet asks for them — so Google receives your IP address on any page you read here. Cloudflare receives it only on the pages using that animation library. Neither sets a cookie for us. | No cookie set by us |
Where each runs. The Google Ads tag runs on our home page and on the Agents University page. Plausible runs on our articles, Agents University and campaign landing pages. The ab- cookies are set across the site, including on this page. The LinkedIn tag runs on the consulting and founder pages, PostHog on the same set, and the Reddit pixel on the US founder page only. That is the whole list. We removed PostHog and Google Analytics site-wide on 21 July 2026; in August we brought PostHog back for the consulting and founder pages and added the two advertising tags above, because we started paying for traffic to those pages and needed to see whether the money buys anything. The rest of the site stays as it was.
Your choice
We set the ab- cookies without asking, on the view that remembering which version of a page you saw is a functional use rather than tracking. We should be honest that a regulator could take a narrower view: it serves our testing, not something you asked for. Deleting it, or blocking cookies for this site, costs you nothing and breaks nothing.
What you can do today. There is no cookie banner on this site — the advertising and analytics scripts above load for everyone. That is a defect we are fixing, not a design, and we are not going to describe it as a choice we offered you. What does work right now: any standard content blocker, or blocking third-party scripts in your browser, stops every third-party row above. Our analytics loader is served from our own domain, but the trackers it loads come from theirs, so a blocker stops them. The site's content and every contact link keep working; some animations on the Agents University page use a third-party script library and may not run. A blocker is genuinely the reliable route: because we don't know who you are as you browse, there is no name or address for us to exclude at our end. If you have written to us, or applied through the enrolment form, then we do hold data tied to you — email hello@8hats.ai and we will delete it and stop processing it.
We do not run session recording, heatmaps, keystroke capture, or data brokerage, and we never exchange your personal information for money. We should be precise about one thing rather than make a blanket denial: our home page loads a Google Ads tag, and through it Google receives your IP address, the page you are on, and its own advertising cookies, which it may use for its own advertising purposes. Under California and several other US state privacy laws that can count as "sharing" personal information for cross-context behavioural advertising, even though no money changes hands. To opt out, email hello@8hats.ai or use a content blocker.
Do Not Track and Global Privacy Control
Browser Do Not Track was never agreed as a standard and this site does not act on it. Global Privacy Control (GPC) is different — it is a recognised opt-out signal under California and several other US state laws — and this site does not currently detect or act on it either. We would rather tell you that than claim a control we haven't built. We are implementing GPC handling; when it is live, this page will say so, and not before. In the meantime any standard content blocker stops the third-party rows above completely, and that is the control we would actually point you to.
How we use it
- To reply to you, and to tell you when the self-check ships.
- To understand who's interested and what they need — which shapes what we build.
- To see which pages and which campaigns actually work, in aggregate.
- We don't send you anything you didn't ask for. Any email we send about the launch has a one-click unsubscribe.
You don't have to give us anything
There is no account to create, and nothing on this site is gated behind personal data. Giving us your email is voluntary — no law and no contract requires it. The only consequence of not giving it is that we cannot reply to you or tell you when the self-check ships.
What we send you, and leaving the list
If you join the waitlist, we email you when the self-check ships — and occasionally before that if something we're building is directly relevant to why you signed up. That is the whole of it: no newsletter cadence, no drip sequence, no selling your address to anyone. Every email has a one-click unsubscribe, and leaving the list changes nothing else — we'll still answer if you write to us.
Where your data comes from
Everything on this page comes from you directly, or from your browser when you visit. We don't buy contact lists, and we don't append data about you from brokers. If we are preparing for a conversation you asked for, we may read what you or your company have published publicly — a website, a public profile, a paper — the same way any person would before a meeting. We don't build a profile on you from that, and we don't merge it into an advertising audience.
Who else sees it
Our providers are: our web host (site hosting and server logs), our email provider (the mail you send us), Plausible (aggregate page counts, cookieless), Google (advertising measurement), and app.8hats.ai, our own application system, for Agents University enrolments. Some pages also load code and fonts from Cloudflare and Google Fonts, which receive your IP address as part of the request.
For the Google tags, we and Google LLC are joint controllers for the collection and transmission the tags perform on this site (Article 26 GDPR) — we chose to put them here and we benefit from the measurement. Once Google has the data it acts as an independent controller for its own advertising purposes under its own controller terms. You can exercise your rights against either of us; email us and we will help either way.
Beyond those providers, nobody else receives your data — with two honest exceptions. If we are legally required to hand something over under a valid court order or lawful demand, we will, and we will tell you unless we are barred from doing so. And if 8Hats Lab is ever acquired or merged, your data moves with the business, along with the promises on this page, which bind whoever ends up holding it. We do not sell it to anyone.
How we protect it
The site is served over HTTPS. The mail you send us sits in our email provider's systems, reachable only by the handful of people at 8Hats who need it, on accounts with two-factor authentication. We deliberately keep the number of systems holding your data small — that is the main control, and it is a real one.
No system is perfectly secure and we will not pretend otherwise. If a breach ever puts your data at risk, we will notify the relevant regulator within 72 hours where the law requires it, and we will email you directly rather than post a notice and hope you see it.
How long we keep it
- Email you send us: while the conversation is live, and up to 24 months after the last message, then deleted — sooner if you ask, longer only if we need it for a live engagement or a legal claim.
- Waitlist addresses: until the self-check ships and we have told you, or until you unsubscribe, whichever comes first, and no more than 24 months.
- Agents University enrolment submissions: for as long as your application is live and up to 24 months afterwards.
- Server logs: our host's standard rotation window, which we are confirming and will state here.
- Cookies and analytics: the periods in the table above.
Your rights
Email hello@8hats.ai to see, correct, export, delete or restrict anything we hold about you, to object to how we use it, or to withdraw consent you've given. No process theatre — we will do it, or tell you plainly why we cannot. We answer within one month, as Article 12(3) GDPR requires, and within 45 days where US state law sets that clock. If a request is complex, or you have made several, we may extend — we will tell you inside the first period, and why. Two honest caveats: we may ask a question or two to check the request really comes from you, and we may have to keep a narrow slice of data where the law or a signed agreement requires it, in which case we will say exactly what and why. If someone is asking on your behalf, say so and we will handle it. We don't make decisions about you by automated means. We won't treat you differently for asking.
If you are unhappy with how we handled it
Write to hello@8hats.ai and say so. We will look again and answer in writing within 45 days, with our reasons if we still say no. Several US state laws give you that right of appeal; we extend it to everyone.
If you're in the EU or the UK
8Hats Lab Inc. is the data controller. Our legal bases are:
- Consent (Art. 6(1)(a) GDPR) when you email us to join the waitlist — you give it by writing to us, and you can withdraw it at any time by replying or emailing hello@8hats.ai. Withdrawing doesn't affect anything we did before you withdrew.
- Legitimate interest (Art. 6(1)(f)) in answering you when you write to us, and in keeping the site secure and available.
- The Google Ads tag has no consent basis today. Under Article 5(3) of the ePrivacy Directive it needs your prior consent, and there is no consent banner on this site, so we are not going to claim a legal basis we don't have. We have started fixing this at source rather than by writing around it: PostHog and Google Analytics were removed on 21 July 2026, leaving cookieless Plausible, which needs no consent. The advertising tag is the remaining piece. Until it is resolved, a content blocker stops it at your end — which, while we have no consent mechanism, is the only reliable control available to you.
You have the rights of access, rectification, erasure, restriction, portability and objection.
8Hats Lab Inc. is a US company with no establishment in the EU or the UK. When you email us or visit this site, we collect your data directly in the United States — under Article 3(2) GDPR that is a direct collection, not a transfer out of the EEA. Where we pass data to providers, Google LLC is a US company; Plausible processes in the EU. We rely on the EU-US Data Privacy Framework and its UK Extension where a provider is certified under it, and on the European Commission's Standard Contractual Clauses where it is not. Ask us at hello@8hats.ai for a copy of the safeguards that apply. You may complain to your supervisory authority — in the EU your national authority, in the UK the ICO (ico.org.uk). You do not have to come to us first. We would just rather you did, so we can fix it.
If you're in California or another US state
We never exchange your personal information for money. Disclosures to Google through the advertising tag on our home page may count as "sharing" for cross-context behavioural advertising under California law, and we say so above rather than deny it. You have the right to know, delete, correct, take your data with you, and opt out. For anything we hold that is tied to you — mail you have sent us, an enrolment application — email hello@8hats.ai and we will act on it. For the advertising tag itself, we have to be straight with you: we do not yet detect Global Privacy Control, and while browsing you are anonymous to us, so there is no request we could apply at our end. A content blocker stops the tag outright, and that is the working opt-out until GPC handling ships. When it does, this page will say so.
In the categories California law uses, we collect identifiers (the email address you write from, your name if you give it, and your IP address in ordinary server logs), commercial information (that you joined the waitlist, applied, or asked about a diagnostic), and internet activity (which pages you read on this site). We collect them from you directly and from your browser, for the purposes and periods set out above. We do not collect sensitive personal information as California law defines it, and we do not knowingly sell or share the personal information of anyone under 16.
Children
This site is for professional audiences. We don't knowingly collect data from anyone under 16. If you think a child has written to us, tell us and we'll delete it.
Research data and diagnostic engagements
Published datasets. We publish research datasets on Zenodo. Each is de-identified before release, and the method used is documented in that dataset's own Zenodo record — read the record, not this page, for what a given dataset contains. Our published datasets come from our own products and our own operations — not from client engagements. Where a future dataset ever does derive from client work, we would publish it only under the terms of our agreement with that client, and we would say so in the record. If you believe a published dataset contains something that identifies you, write to hello@8hats.ai: we will act on it, including pulling the record while we check.
Diagnostic engagements. A paid diagnostic runs on a separate written agreement between 8Hats Lab and the client organisation, and that agreement governs the evidence collected during it. Those terms sit alongside this page — they add detail about a specific engagement, they don't replace the rights described here. If you took part in a diagnostic at your employer and want to know what we hold about you, write to us: we will tell you what we have and route you to the right place, rather than leave you guessing.
When the self-check ships, we may publish aggregate statistics from it — for example the distribution of results. Never anything that identifies you or your organisation. If that changes, this page changes first.
When this changes
We keep the table above current. If we add or change anything that sets a cookie or loads a third-party script, updating that table and the date at the top is part of shipping the change, not an afterthought.
21 July 2026. An earlier version of this page said the site set no cookies and loaded no third-party scripts. That was inaccurate, and it was live from 18 July to 21 July 2026. This page now lists what the site actually sets and loads. Earlier versions are archived and available on request. We would rather correct this plainly than quietly.