Privacy

Privacy Policy

This policy explains how Henson handles account, publication, billing, analytics, and generated research data.

Last updated July 24, 2026

Henson helps publishers and creators analyze public website content and discover affiliate programs that may fit their audience. The service is operated as a business tool and is not intended for children.

Information we collect

Account information: when authentication is enabled, Henson uses Clerk to create and manage sign-in. We store the account identifiers, email address, name, user role, workspace, and workspace membership needed to operate the product.

Publication information: when you submit a website or publication for analysis, we store the submitted URL, normalized host, property relationship, verification state, scan settings, and scan status. Henson crawls public HTTP or HTTPS pages only, respects robots directives, avoids private network addresses, and stores public page titles, descriptions, extracted text, canonical URLs, content hashes, crawl errors, and selected crawl metadata.

Generated research and recommendations: Henson stores generated audience profiles, field confidence, supporting public page references, profile corrections or confirmations you make, affiliate program candidates, program sources, recommendation scores, evidence excerpts, suggested placements, status changes, tags, action items, and feedback events.

Billing information: if paid reports are enabled and you buy a report, Henson uses Polar for checkout, payment, customer, order, refund, and receipt handling. Henson stores purchase and fulfillment records such as checkout IDs, order IDs, product IDs, customer IDs, amount, currency, refund state, grant state, webhook IDs, and related timestamps. Henson does not store full payment card numbers.

Analytics and device information: when PostHog analytics is configured, Henson records product usage events such as page views and page leave events, along with the browser and device information normally associated with those events. Analytics is used for product operations and improvement.

How we use information

We use this information to provide the service, authenticate users, provision workspaces, run scans, generate publication profiles, discover affiliate programs, rank recommendations, preserve source evidence, process purchases, prevent duplicate fulfillment, respond to support needs, protect against abuse, debug failures, improve the product, and comply with legal or operational obligations.

Henson's AI-assisted features may send public page excerpts, generated profile fields, program search sources, and related prompts to configured model providers through AI Gateway. Henson uses Tavily to search the public web for affiliate program sources when program discovery is enabled.

How we share information

We share information with service providers that help us operate Henson: Clerk for authentication, Neon or PostgreSQL infrastructure for application storage, Vercel or similar hosting infrastructure for deployment, Polar for checkout and billing, PostHog for analytics when configured, AI Gateway and model providers for generated analysis, and Tavily for public web search.

We may also disclose information if required by law, to protect the rights and safety of Henson or others, to investigate abuse, or in connection with a business transaction such as a merger, acquisition, financing, or sale of assets.

We do not sell personal information. We do not use submitted publication data to show third-party advertising.

Public website scans

Henson is designed to analyze publicly available website content. A scan may capture public text from the submitted site and public affiliate program pages discovered through search. Because the same public publication may be submitted by more than one workspace, some public crawl evidence can be reusable infrastructure data rather than private workspace data.

Workspace-specific data, including your account, workspace relationship, scan requests, private report access, profile overlays, recommendation batches, status changes, and feedback, remains tied to your workspace access controls.

Retention and deletion

We keep information for as long as needed to provide Henson, maintain billing and security records, debug workflows, preserve report history, and meet legal or operational requirements.

Authenticated users can request account deletion from the application. Account deletion removes workspace-owned records such as workspace membership, report grants and purchases, submitted properties, scan requests, profile overlays, recommendations, tracker data, action items, and feedback events. When applicable, deletion also attempts to remove linked Clerk identity and Polar customer records.

Some records may remain when they are not workspace-owned, are required for security, fraud prevention, legal compliance, billing reconciliation, or are public crawl evidence that Henson must preserve separately from an individual workspace.

Security

Henson uses access controls, same-origin mutation checks for sensitive account actions, provider-managed authentication, limited public crawling safeguards, and database constraints to protect product data. No online service can guarantee absolute security, but we work to collect only what the product needs and to restrict access according to role and workspace permissions.

Your choices

You can choose not to create an account, not to submit a publication URL, or not to buy a paid report. You can update profile corrections and recommendation workflow state inside the product. You can request account deletion from settings when authentication is configured.

To ask about privacy, account data, or deletion, contact privacy@henson.app.

Changes to this policy

We may update this policy as Henson changes. When we make material changes, we will update the date on this page and, when appropriate, provide additional notice in the product.