1. Who we are
Hilo is operated by Finis Ventures LLC ("Finis", "we", "us"), a Wyoming (USA) limited liability company. For the account data described in this policy, Finis is the data controller. Contact: contact@hilo.team.
For everything that lives on your own machine — conversations, documents, tasks, agent memory, API keys — you are the controller. We do not durably store that data. When you use the hosted app, requests and responses pass through our gateway as described in Section 3; your own machine and your own model-provider agreements govern the source data.
2. What we store (the complete list)
Our cloud durably stores only the following service records:
- Account: name, email address, password hash, language preference.
- Organization: org name, membership list, roles.
- Connection and routing: your node's address, so the hosted interface can reach it, together with the records that provision and route to that connection — the hostname we issue for it, the tunnel and DNS identifiers behind that hostname, the secret your node and our gateway use to authenticate each other, and the activation history that lets a connection be replaced or rolled back. This is connection metadata; none of it is fleet content.
- Sessions: login sessions and the device push tokens for notifications you enable.
- Billing and plan state: trial dates, entitlement, bare human and agent seat counts, and Stripe customer, subscription, schedule, Checkout and event identifiers. Stripe holds payment-card, billing-address and tax details; Hilo does not receive full card numbers.
- Agent-runtime waitlist: if you ask to be told when a runtime other than Claude Code is supported, we keep the email address you give us, the runtime you named, and when you asked. You do not need a Hilo account to join that list, and it is used only to contact you about that runtime.
- Legal acceptance: when you create an account you tick a box to accept these Terms and this Privacy Policy. We keep a record of that: which revision of each document you accepted, when you accepted it, in which organization, and where in the product the acceptance happened. It holds no password, no payment detail and no fleet content, and it is deleted with your account.
- Operational metadata: limited request metadata such as IP address, timestamp and path may be processed by our infrastructure providers for security and debugging. Our own store additionally keeps the requesting IP address for rate limiting, a short-lived abuse-prevention record that is discarded once it is more than a minute old. Hilo does not intentionally log proxied fleet request or response bodies.
Hilo does not durably store fleet content: no messages, documents, tasks, files, agent memory or LLM API keys.
3. What passes through us without being stored
When you use the hosted web app, your requests travel through our gateway to your node over an encrypted tunnel. TLS terminates at the gateway, so for that instant the request is readable there. We do not store or log this content. Hilo does not offer a local interface: using the workspace requires this hosted transit path.
4. Push notifications
When a message lands for you and you have notifications enabled, a push — including the sender, the conversation, and a preview of the message text — is relayed in transit through our push infrastructure and either Apple Push Notification service (APNs) or your browser's Web Push endpoint. We do not persist or content-log notification payloads. Push providers may retain an undelivered notification under their delivery policies. You can turn push notifications (or previews) off at any time; the workspace works fully without them.
5. What we never store
- Your fleet's conversations, documents, tasks, and files.
- Your agents' memory, configuration, and track records.
- Your LLM API keys. Your node talks to your model providers directly, under your own keys and your own agreements — those providers are your vendors, not our subprocessors.
- Training data: Hilo does not retain fleet content or operate a training pipeline over it. Your separate model provider relationship is governed by that provider's terms.
Because Hilo does not durably store your fleet's content, the records available to us in response to a legal demand are the service records in Section 2 rather than the source data on your node.
6. Why we process account data (legal bases)
Under the GDPR, our legal bases are:
- Contract (Art. 6(1)(b)): creating your account, routing you to your node, operating sessions and billing.
- Legitimate interests (Art. 6(1)(f)): security logging, abuse prevention, service communications about your account.
- Consent (Art. 6(1)(a)): marketing emails, if you ever opt in — never pre-ticked, always revocable.
We do not sell personal data, and we do not use it for advertising.
7. Service providers
We use a small number of infrastructure providers to run the service:
- Cloudflare — gateway/edge infrastructure and the encrypted tunnel between our gateway and your node.
- Stripe — subscription billing, invoices, payment methods, tax calculation and the customer billing portal.
- Brevo — transactional account, security and billing email.
- Apple (APNs) and browser push services — delivery of notifications to devices and browsers.
- Vercel — hosting of this marketing website.
- jsDelivr — delivery of the website and app's font files.
Each receives only what its function requires. We never receive full card numbers.
8. International transfers
Finis Ventures LLC is a US company. Where account data of EU/UK users is transferred outside the EEA/UK, we rely on Standard Contractual Clauses and equivalent safeguards with our providers. Hilo does not durably move fleet content into those systems. Hosted workspace requests and notification previews can cross borders while in transit as described in Sections 3 and 4; model calls go directly to the provider you choose under your agreement with it.
9. Retention and deletion
Account data is kept while your account is active. If you delete your account, we delete your account, organization (if you are its last owner), connection and routing, and session records within 30 days, except billing records we must keep for tax and accounting law and narrowly retained security or trial-consumption records where lawful. Provider metadata follows the applicable provider retention policy. Your fleet's data is untouched by any of this — it is on your disk, in open formats, and leaves with you.
The agent-runtime waitlist is deliberately not tied to an account — you can join it without having one — so deleting an account does not remove a waitlist entry. We keep that entry until you ask us to delete it. To have it removed at any time, write to contact@hilo.team from the address you signed up with, or naming it.
10. Your rights
If you are in the EU/UK: access, rectification, erasure, restriction, portability, objection (GDPR Arts. 15–22), and the right to complain to your supervisory authority. California residents have equivalent rights under the CCPA/CPRA. Write to contact@hilo.team — we respond within 30 days. For the data on your own machine, no request is needed: it is already yours.
11. Cookies
This marketing site (hilo.team) sets no first-party cookies and runs no analytics. It loads font files from jsDelivr, which receives ordinary network metadata for that request. The hosted app uses strictly necessary session cookies to keep you signed in — nothing for tracking or advertising, so there is no cookie banner to click.
12. Age
Hilo is a business tool, not directed at children. You must be at least 16 to create an account.
13. Changes
If we change this policy, we will post the new version here with a new effective date and, for material changes, notify account holders by email before they take effect.
14. Contact
Finis Ventures LLC
contact@hilo.team