1. Who we are
Hilo is operated by Finis Ventures LLC ("Finis", "we", "us"), a Wyoming (USA) limited liability company. For the account data described in this policy, Finis is the data controller. Contact: contact@hilo.team.
For everything that lives on your own machine — conversations, documents, tasks, agent memory, API keys — you are the controller. We never receive that data and this policy does not govern it; your own machine and your own model-provider agreements do.
2. What we store (the complete list)
Our cloud durably stores only account and routing data:
- Account: name, email address, password hash, language preference.
- Organization: org name, membership list, roles.
- Routing: your node's address, so the hosted interface can reach it.
- Sessions: login sessions and the device push tokens for notifications you enable.
- Billing and plan state: your plan tier and, once paid plans exist, billing records processed through our payment provider (we never see full card numbers).
- Operational logs: standard server logs (IP address, timestamp, request path) kept for security and debugging, retained for 30 days, then deleted.
Nothing else is stored. No messages, no documents, no tasks, no files, no agent memory, no LLM API keys.
3. What passes through us without being stored
When you use the hosted web app, your requests travel through our gateway to your node over an encrypted tunnel. TLS terminates at the gateway, so for that instant the request is readable there. We do not store or log this content. If you want to remove even this transit exposure, you can connect to your node directly and bypass our gateway entirely — sovereignty means the option is always yours.
4. Push notifications
When a message lands for you and you have notifications enabled, a push — including the sender, the conversation, and a preview of the message text — is relayed in transit through our push infrastructure and Apple Push Notification service (APNs) to your device. We do not store or log notification content. One honest caveat: Apple's push service holds the most recent undelivered notification per device, on Apple's infrastructure, until it is delivered. You can turn push notifications (or previews) off at any time in your device settings; the workspace works fully without them.
5. What we never have
- Your fleet's conversations, documents, tasks, and files.
- Your agents' memory, configuration, and track records.
- Your LLM API keys. Your node talks to your model providers (e.g. Anthropic) directly, under your own keys and your own agreements — those providers are your vendors, not our subprocessors.
- Training data: we do not train models on your data — structurally, since we do not have it.
Because we never store your fleet's content, a legal demand for it reaches a cloud that never had it. The only records we can produce are the account and routing records in Section 2, and we tell you that plainly.
6. Why we process account data (legal bases)
Under the GDPR, our legal bases are:
- Contract (Art. 6(1)(b)): creating your account, routing you to your node, operating sessions and billing.
- Legitimate interests (Art. 6(1)(f)): security logging, abuse prevention, service communications about your account.
- Consent (Art. 6(1)(a)): marketing emails, if you ever opt in — never pre-ticked, always revocable.
We do not sell personal data, and we do not use it for advertising.
7. Service providers
We use a small number of infrastructure providers to run the service:
- Cloudflare — gateway/edge infrastructure and the encrypted tunnel between our gateway and your node.
- Apple (APNs) — delivery of push notifications to Apple devices.
- Vercel — hosting of this marketing website.
Each receives only what its function requires. When paid plans launch, a payment processor will be added here (with an updated version of this policy) — we never see full card numbers.
8. International transfers
Finis Ventures LLC is a US company. Where account data of EU/UK users is transferred outside the EEA/UK, we rely on Standard Contractual Clauses and equivalent safeguards with our providers. Your fleet's content does not make this journey — it stays on your machine.
9. Retention and deletion
Account data is kept while your account is active. If you delete your account, we delete your account, organization (if you are its last owner), routing, and session records within 30 days, except billing records we must keep for tax and accounting law. Operational logs expire on the schedule in Section 2. Your fleet's data is untouched by any of this — it is on your disk, in open formats, and leaves with you.
10. Your rights
If you are in the EU/UK: access, rectification, erasure, restriction, portability, objection (GDPR Arts. 15–22), and the right to complain to your supervisory authority. California residents have equivalent rights under the CCPA/CPRA. Write to contact@hilo.team — we respond within 30 days. For the data on your own machine, no request is needed: it is already yours.
11. Cookies
This marketing site (hilo.team) sets no cookies and runs no analytics. The hosted app uses strictly necessary session cookies to keep you signed in — nothing for tracking or advertising, so there is no cookie banner to click.
12. Age
Hilo is a business tool, not directed at children. You must be at least 16 to create an account.
13. Changes
If we change this policy, we will post the new version here with a new effective date and, for material changes, notify account holders by email before they take effect.
14. Contact
Finis Ventures LLC
30 N Gould St, Ste R, Sheridan, WY 82801, USA
contact@hilo.team