Privacy Policy
Last updated: September 25, 2026
1. What we collect
- Account data — name, email, and a salted password hash. We never store plaintext passwords.
- Organization data — org names, memberships, roles, and invitations.
- Service data — the projects, functions, buckets, databases, and domains you create, plus configuration you provide.
- Usage and audit data — API calls, resource events, and audit logs (actor, action, timestamp) kept for security and billing. AI Gateway request logs record the model, token counts, cost and timing, never the prompt or the answer.
- Support data — messages you send through our contact form.
2. What we don't do
- We do not sell your personal data.
- We do not use your deployed code or stored content to train AI models.
- We do not read the contents of your storage buckets or databases except as needed to operate the Service or as required by law.
3. Cookies
We use a single essential session cookie (hk_session) to keep you signed in, and a preference cookie for your active organization. We do not use third-party advertising or tracking cookies.
4. How data is used
Data is used to operate and secure the Service, meter usage for billing, prevent abuse, and communicate with you about your account. Aggregated, de-identified statistics may be used to improve the platform.
5. Sharing
Your workloads run on infrastructure providers (edge hosting, file storage, databases and email delivery), payments are handled by our payment processor, domains are registered through our registrar, and prompts you send through the AI Gateway go to the model provider you choose. These processors act under data-processing terms. We share data with them only as needed to provide the Service, and with authorities only when legally required.
6. Security
Passwords are hashed with salted PBKDF2-SHA256, API keys and session tokens are stored as SHA-256 digests and API keys are shown only once, sessions are httpOnly cookies, two-factor sign-in is available, and every privileged action is recorded in an audit log. Access to production systems is restricted and logged.
7. Retention and deletion
Account data is kept while your account is active. When you delete a resource or your account, associated data is removed from production systems within 30 days, except minimal records we must retain for legal or billing purposes.
8. Your rights
You can access, correct, export, or delete your personal data from the dashboard or by contacting us. Depending on your jurisdiction (including the EU/EEA under GDPR and California under CCPA), you may have additional rights, which we honor regardless of where you live.
9. Contact
Privacy questions or requests? Contact usand mention "privacy" in the subject line.