Menu
PRIVACY / UPDATED SEPTEMBER 25, 2026

Privacy in plain language.

HowAICite stores only the information needed to run the workspace, preserve evidence, provide subscriptions and respond to requests.

Who is responsible

HowAICite and the HowAI Suite are operated by Nguyen Thanh Dan, an individual seller based in Vietnam and trading under the Danhoangda and HowAI product brands. For privacy questions, correction or deletion requests, use the Contact page or email howaicite@gmail.com.

What we collect

We store account usernames and protected password credentials; customer-confirmed workspace memory such as company context, audience, goals and preferences; websites and pages submitted for audits; saved prompts; AI answers, URLs and measurement context submitted to Evidence Lab; workspace-support questions and answers; workspace activity; pilot details; notification preferences and delivery history; and billing records such as Paddle customer, subscription and transaction identifiers, billing email, status, amount and consent record. Standard server logs may include IP address, user agent and request metadata.

Payment data

Paddle hosts checkout and the customer portal as merchant of record. Paddle collects payment method, billing address and tax details under its own privacy terms. HowAICite does not receive or store full card numbers or security codes. Signed Paddle events are used to activate plans and preserve transaction history.

Advertising account data

If an approved HowAIAds design partner connects an ad platform (Microsoft Advertising or ChatGPT Ads), we store an encrypted credential (a Microsoft refresh token or a ChatGPT Ads API key), the platform user and account identifiers, account names and currency, and daily campaign names, status, impressions, clicks, spend, conversions and revenue for the selected account. The connectors only read this data; it does not create, change, pause or fund campaigns. Owners and admins can disconnect at any time and choose to delete synced history, and the data is included in the organization export.

How we use it

We use this data to provide reports and paid access, personalize workspace guidance using confirmed customer context, protect accounts, diagnose problems, improve the product and contact people who request access. Selected transactional notifications may be delivered to the workspace email address; owners and admins can change the address, categories or disable email delivery from Notifications. Evidence is also transformed into a private intelligence ledger containing query fingerprints, response hashes, citation links and entity signals. We do not sell submitted workspace or contact data.

Workspace Support

When a signed-in user asks Workspace Support a question, HowAICite sends the question, recent conversation turns and a limited tenant-scoped summary of confirmed workspace memory, reports, measurements, prompts and proof work to the configured OpenAI API. Passwords, API credentials and another tenant's records are excluded. Conversations are stored for that member's support history and can be cleared from the support panel. The assistant is read-only and important decisions should be verified against its linked workspace evidence.

Automatic error diagnostics

If an application screen fails, HowAICite automatically records the affected route, error type, boundary and an opaque diagnostic reference in the workspace activity log. The diagnostic event does not include form values, passwords, AI answers or a browser stack trace.

Benchmark participation

Workspace evidence is private by default. Evidence Lab offers a separate, optional checkbox for contributing a signal to future anonymized aggregate benchmarks. Leaving it unchecked keeps that observation workspace-only. Opting in does not authorize HowAICite to publish the raw answer, brand or domain as a customer case study.

Workspace controls

Owners and admins can review, edit or clear confirmed workspace memory without deleting reports or measured evidence. Signed-in users can export their workspace data, including workspace memory, notification preferences, billing history and the intelligence ledger, from Account. Reports can be deleted from their report page. To request correction, withdrawal from benchmark processing or deletion of other data, email howaicite@gmail.com. Financial records may be retained when required for tax, fraud prevention or legal compliance.

Retention

Account, workspace, report and evidence records remain available while the workspace is active and until an authorized user deletes them or requests deletion. Support conversations and operational logs are retained only for support, security and reliability needs. Paddle transaction identifiers and related financial records may be retained for tax, accounting, fraud-prevention, dispute and legal obligations. Deleted records may remain in current backups for up to 14 days before rotation.

International processing

Hosting, AI, email and payment providers may process data in countries other than yours. We limit each provider to the information needed for its role and describe the currently used categories on the Security page. Paddle independently processes checkout, tax and payment information as merchant of record under its own privacy terms.

Security and limitations

Production uses encrypted HTTPS connections, hashed passwords, hashed session tokens, tenant-scoped queries and daily local backups. No internet service can guarantee absolute security. Backups currently remain on the same server and may retain deleted records for up to 14 days. Current controls and unavailable enterprise features are listed on the Security page.

Third-party services

Audits fetch public pages you submit. Paddle, external websites, email delivery providers and AI platforms have their own privacy practices. Provider availability varies and integrations are enabled only when server credentials are configured.

Questions

Contact howaicite@gmail.com. This notice may change as integrations and commercial service evolve.