Privacy policy
Effective 4 September 2026. Written to be read, not to be survived — this is the actual policy, in plain language on purpose. If anything is unclear, ask us.
Who we are
hiy.ai ("hiy", "we") operates this website and service. We are the data controller for the personal data described here. Contact: [email protected].
What we store
If you build a twin: your account email, the material you add as sources, the profile you write, your settings, the answers you give when you set your twin up (what you're building, its main job, where your knowledge lives, roughly who talks to it and in what language, and whether there's a team — a question you skip is simply not stored), and the conversations your twin has.
If you talk to a twin: the messages in that conversation, and — only if you choose to leave them — the contact details you submit. If the creator has set up an action that asks for a few specific things — an order number, a plan, which environment you're on — the values you give it are stored on the same record as those contact details: a short list the creator chose to ask for, never more than six things in one action, and only the ones you actually gave.
If you store a credential for an action: a token or password you paste in so one of your actions can reach the system it calls is encrypted before it is stored, and the encrypted value is all we hold — there is no screen anywhere that shows it back to you. Beside it we keep the name you gave it, its last few characters so you can tell two apart, who added it and when, and a log of every time it was stored, replaced, revoked, read by an action, or refused — which action asked, and when. Removing it destroys the encrypted value and keeps that log.
If you sign in with Google: we receive your name, email address, and profile picture from Google, and use them only to create and identify your account. We don't request access to anything else — no contacts, no Drive, no Gmail. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
We also keep basic technical data needed to run the service, such as rate-limiting counters, and first-party product events (for example "a question was asked", "a link in an answer was clicked") so creators can see whether their twin is working. If you build a twin, that also includes which section of your own dashboard you opened — so the app can put the parts you use first. It records the section name and nothing else. The same goes for which of the five setup questions you answered: the question's name and the kind of twin, never the answer itself. These events are ours alone — no third-party analytics, no advertising pixels, no cross-site tracking.
In your own browser: a copy of the conversation you're currently having is kept in that tab so a refresh doesn't lose it. It's held in tab-scoped storage, not a cookie and not long-term storage, so closing the tab discards it. We chose that deliberately: a twin link often gets opened on a shared or borrowed device, and the next person to use it shouldn't be able to read what you asked.
Cookies
Every cookie we set is first-party and does a job you asked for. There are no advertising cookies, no third-party tracking cookies, and no cross-site tracking — so there's no cookie banner, because there is nothing to consent to beyond using the service. In full, that is two cookies:
- Sign-in — keeps you signed in to your account. Lasts as long as your session does.
hiy_ref— set when you arrive through someone's referral link, so the person who referred you is credited if you sign up. It holds only their public address and a signature — no identifier for you, and nothing that follows you to any other site. It expires after 30 days.
hiy_ref is signed so it can't be forged, and it's HttpOnly, so page
scripts can't read it.
What we do with it
Your material is used to answer questions as your twin, and nothing else. Your content trains your twin alone — never a shared model, and never another creator's twin. We don't sell data.
Conversations are visible to the creator whose twin was involved, so they can see what people ask and improve it. If you leave contact details, they go to that creator so they can reply.
A creator can invite colleagues into their organisation, and an invited colleague can read the same conversations, contact details and collected values for that organisation's twins — the people replying to you are often a team, not one person. They cannot change the twin, publish it, or manage the account. One thing they can change: material in the organisation's Knowledge Hub that was added there rather than on a particular agent — an invited colleague can add to that pool and take things out of it, because it belongs to the organisation and not to one person. They cannot mark material confidential, and material added on a specific agent stays that agent owner's to change. Team Agents are the exception in the other direction: nobody, including invited colleagues, gets a per-person record of what a colleague asked one.
We process this data because it's necessary to provide the service you asked for; where we rely on anything else (like sending you a product email), we ask first or make it easy to turn off.
Third parties we rely on
- Model providers (Anthropic and/or OpenAI, depending on configuration) process your material twice: once to write the summary your twin answers from, when a source is added or changed, and again to generate the actual answer when someone asks a question.
- OpenAI also turns every source into the search data that makes it findable, at the moment it's added — this runs on OpenAI regardless of which provider is handling the summary or the answer.
- Supabase hosts the database and authentication, in the EU (eu-west-1).
- Vercel hosts and serves the application.
- Resend delivers notification emails, when notifications are enabled.
- Stripe processes payments, if you subscribe. Card details go straight to Stripe and never touch hiy — we store their customer and subscription identifiers so we know what you're entitled to, and nothing else about your card.
Each processes data only to provide their service to us. A creator can also point one of their twin's actions at a system of their own choosing, which is not on this list and is covered next.
Endpoints a creator chooses
A creator can give their twin an action that makes one request to a URL they name. When it runs, that request carries the name the creator gave the action, a short factual summary — written by the model — of what the person asking needs, and, where the action carries them, the facts the creator's own site attested about that person.
The system it writes into is the creator's processor, chosen by them under their own agreement with it. hiy does not select it, does not contract with it, and does not process what it holds on its own behalf: hiy makes the call the action describes and records that it happened, and it does not become a party to what happens at the other end. It is not added to hiy's own list above.
A fact a creator's site attested about the person asking is that creator's data about their own user, and the same answer follows: they are its controller, hiy never asks for it and never keeps it, and it exists here only for as long as the answer it was sent for.
If you bring in an assistant's memory
If you paste in what ChatGPT, Claude or Gemini remembers about you — see ChatGPT, Claude or Gemini — a few things about that material are different from everything else you add, and worth stating on their own.
It can be special-category data. An assistant's memory of you can include health details, sex life or sexual orientation, political opinions, religious beliefs, finances, or details about your relationships. Under GDPR that's Article 9 "special category" data, and we treat it that way regardless of what your particular import contains.
The basis is your consent, not necessity. Everything else in this policy runs on necessity — it's needed to provide the service you asked for. A memory import runs on the consent you give on the import screen instead, which names those categories in words before you can add anything. Withdraw that consent by deleting the import, and we honor it in full: the source and everything indexed from it are deleted together, not hidden behind a flag.
Who sees it. The same processors listed above see this text too, nothing additional — the model provider that writes its summary and later answers from it, and OpenAI, which generates its search data.
How long we keep it. The same as any other source — for as long as it's on your twin. See below.
Deleting it here doesn't touch what the assistant itself holds. Removing the import removes hiy's copy in full. ChatGPT, Claude or Gemini keeps whatever it already remembered about you until you clear it from that assistant's own settings — we have no way to reach it, and deleting our copy doesn't ask it to.
How long we keep it
For as long as your account exists. Delete a twin, a person, or your account, and the corresponding data goes with it — deletion is real deletion, not a hidden flag. Backups age out on the infrastructure providers' standard schedules.
The credential log is the one thing that outlives what it describes. Removing a credential destroys the encrypted value and keeps its log, because a record of use that vanished along with the credential would not be a record. Each entry says what happened — stored, replaced, revoked, read by an action, or refused — which action asked, when, and, for something you did yourself, who did it. It never contains the credential value, and never anything from a conversation. Nothing expires it on a schedule of its own: it is kept for as long as the organisation it belongs to exists, and is deleted together with that organisation — for a personal account, that is the moment you delete your account.
Your controls
- Export everything from Settings → Data & privacy, any time.
- Delete any agent, which removes its content, its index, its conversations, and anyone who left contact details with it. Material it shared with your other agents stays in your Knowledge Hub.
- Release an address you are holding from a deleted agent, or let it lapse on its own after 90 days.
- Delete your account, which removes everything — the credential log described above included.
- Delete an individual person from your People list.
- Turn off conversation-driven features. Follow-up requests — where your twin offers to take a visitor's email — are on for a new twin and off in one tap; a twin that was already live is never switched on without you choosing it.
- Change what your twin emails you. A new twin starts with the new-people alert and the weekly summary switched on, and the unanswered-questions alert switched off. All three live in that twin's settings, and each can be turned off entirely.
- Account mail is not switchable, because it is about your account rather than your twin's activity: a decision on your twin's identity review, a warning before a trial ends, the receipt when you delete your account, and a password reset you asked for.
If you're in the EU/UK you also have the formal versions of these rights (access, rectification, erasure, portability, objection) — email us and we'll honour them without ceremony.
Children
hiy isn't intended for people under 16.
Changes
If this policy changes in a way that matters, we'll say so plainly on this page and update the effective date — not bury it.
4 September 2026. This update adds description, not new practice. Since August the product gained actions that collect a few values alongside contact details, a credential store with its log, and actions that call an endpoint a creator names — each is now described above. How long the credential log is kept is stated in "How long we keep it". And "Your controls" now says which of your twin's emails start switched on, and that account mail is sent whether or not those are.