Privacy policy

Effective 15 August 2026. Written to be read, not to be survived — this is the actual policy, in plain language on purpose. If anything is unclear, ask us.

Who we are

hiy.ai ("hiy", "we") operates this website and service. We are the data controller for the personal data described here. Contact: hello@hiy.ai.

What we store

If you build a twin: your account email, the material you add as sources, the profile you write, your settings, and the conversations your twin has.

If you talk to a twin: the messages in that conversation, and — only if you choose to leave them — the contact details you submit.

If you sign in with Google: we receive your name, email address, and profile picture from Google, and use them only to create and identify your account. We don't request access to anything else — no contacts, no Drive, no Gmail. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

We also keep basic technical data needed to run the service, such as rate-limiting counters, and first-party product events (for example "a question was asked", "a link in an answer was clicked") so creators can see whether their twin is working. These events are ours alone — no third-party analytics, no advertising pixels, no cross-site tracking.

In your own browser: a copy of the conversation you're currently having is kept in that tab so a refresh doesn't lose it. It's held in tab-scoped storage, not a cookie and not long-term storage, so closing the tab discards it. We chose that deliberately: a twin link often gets opened on a shared or borrowed device, and the next person to use it shouldn't be able to read what you asked.

Cookies

Every cookie we set is first-party and does a job you asked for. There are no advertising cookies, no third-party tracking cookies, and no cross-site tracking — so there's no cookie banner, because there is nothing to consent to beyond using the service. In full, that is three cookies:

  • Sign-in — keeps you signed in to your account. Lasts as long as your session does.
  • hiy_preview — set when you build a 24-hour preview without an account, so the preview opens for your browser and nobody else's. It holds only the preview's own address and a signature, expires after 24 hours with the preview itself, and is the mechanism that keeps an anonymous preview private.
  • hiy_ref — set when you arrive through someone's referral link, so the person who referred you is credited if you sign up. It holds only their public address and a signature — no identifier for you, and nothing that follows you to any other site. It expires after 30 days.

The last two are signed so they can't be forged, and they're HttpOnly, so page scripts can't read them.

What we do with it

Your material is used to answer questions as your twin, and nothing else. Your content trains your twin alone — never a shared model, and never another creator's twin. We don't sell data.

Conversations are visible to the creator whose twin was involved, so they can see what people ask and improve it. If you leave contact details, they go to that creator so they can reply.

We process this data because it's necessary to provide the service you asked for; where we rely on anything else (like sending you a product email), we ask first or make it easy to turn off.

Third parties we rely on

  • Model providers (Anthropic and/or OpenAI, depending on configuration) process your material twice: once to write the summary your twin answers from, when a source is added or changed, and again to generate the actual answer when someone asks a question.
  • OpenAI also turns every source into the search data that makes it findable, at the moment it's added — this runs on OpenAI regardless of which provider is handling the summary or the answer.
  • Supabase hosts the database and authentication, in the EU (eu-west-1).
  • Vercel hosts and serves the application.
  • Resend delivers notification emails, when notifications are enabled.
  • Stripe processes payments, if you subscribe. Card details go straight to Stripe and never touch hiy — we store their customer and subscription identifiers so we know what you're entitled to, and nothing else about your card.

Each processes data only to provide their service to us.

If you bring in an assistant's memory

If you paste in what ChatGPT, Claude or Gemini remembers about you — see ChatGPT, Claude or Gemini — a few things about that material are different from everything else you add, and worth stating on their own.

It can be special-category data. An assistant's memory of you can include health details, sex life or sexual orientation, political opinions, religious beliefs, finances, or details about your relationships. Under GDPR that's Article 9 "special category" data, and we treat it that way regardless of what your particular import contains.

The basis is your consent, not necessity. Everything else in this policy runs on necessity — it's needed to provide the service you asked for. A memory import runs on the consent you give on the import screen instead, which names those categories in words before you can add anything. Withdraw that consent by deleting the import, and we honor it in full: the source and everything indexed from it are deleted together, not hidden behind a flag.

Who sees it. The same processors listed above see this text too, nothing additional — the model provider that writes its summary and later answers from it, and OpenAI, which generates its search data.

How long we keep it. The same as any other source — for as long as it's on your twin. See below.

Deleting it here doesn't touch what the assistant itself holds. Removing the import removes hiy's copy in full. ChatGPT, Claude or Gemini keeps whatever it already remembered about you until you clear it from that assistant's own settings — we have no way to reach it, and deleting our copy doesn't ask it to.

How long we keep it

For as long as your account exists. Delete a twin, a person, or your account, and the corresponding data goes with it — deletion is real deletion, not a hidden flag. Backups age out on the infrastructure providers' standard schedules.

A preview built without an account is deleted outright once it expires — the twin, the source you gave it, everything built from that source, and any conversation it had. It stops answering anyone after 24 hours, and stays claimable by you for two days after that before it's removed; the deletion sweep runs hourly. Claim it into an account and it stops being a preview: it's then your twin, kept like everything else above.

Your controls

  • Export everything from Settings → Data & privacy, any time.
  • Delete your twin, which removes its content, its index, and its conversations.
  • Delete your account, which removes everything.
  • Delete an individual person from your People list.
  • Turn off conversation-driven features. Notifications are opt-in. Follow-up requests — where your twin offers to take a visitor's email — are on for a new twin and off in one tap; a twin that was already live is never switched on without you choosing it.

If you're in the EU/UK you also have the formal versions of these rights (access, rectification, erasure, portability, objection) — email us and we'll honour them without ceremony.

Children

hiy isn't intended for people under 16.

Changes

If this policy changes in a way that matters, we'll say so plainly on this page and update the effective date — not bury it.