GDPR-aligned
Privacy policy
Last updated: September 9, 2026
At a glance
- • We collect only what we need to run your account and your agents.
- • We never sell your data, and we never train AI on your chats or configs.
- • AI-powered features may send prompts, chat messages, voice transcripts, agent configs, and related context to Hatcher and selected model providers for inference; the iOS app asks for permission before third-party AI processing.
- • You can export or delete everything from your Settings page.
- • EU/EEA users have full GDPR rights — access, rectification, erasure, portability, objection.
- • Questions? Email [email protected].
This Privacy Policy describes how HHX Technology SRL (“Hatcher,” “we,” “us,” “our”) collects, uses, stores, and protects your personal data when you use the Hatcher platform at hatcher.host (the “Service”).
1. Data Controller
- HHX Technology SRL
- CUI: 45318471 · Trade Register: J2021004947351
- Timișoara, Timiș County, Romania
- Privacy inquiries: [email protected]
We are not required to appoint a Data Protection Officer (DPO) under GDPR Art. 37. The founder acts as the point of contact for all data subject requests.
2. Information We Collect
Account Information
- Email address and username (required for registration)
- Password — stored as a bcrypt hash; we never see or store the plaintext
- Solana wallet address (optional; filled automatically on your first on-chain payment)
- Stripe customer ID (optional; created on your first card payment)
Agent Data
- Agent configurations — name, description, avatar, prompts, personality, plugin list
- Agent creation descriptions, voice transcripts, session context, and tool-call content you provide
- Chat history with your agents (PostgreSQL, scoped to your account)
- Voice input transcripts and speech-related request metadata when you use voice features
- Files you upload to or create within agent workspaces
- Agent activity logs and performance metrics
- Integration tokens (Telegram bot token, Discord, Twitter, etc.) — encrypted at rest with AES-256-GCM
Usage Data
- IP address (truncated after 24h), browser type, device information
- Pages visited, features used, session duration
- API usage patterns, interaction counts, search counts
Payment Information
- Transaction signatures for on-chain payments (SOL, USDC, $HATCHER)
- Stripe handles all card data — we never see or store card numbers, CVC, or expiry
- Apple App Store transaction identifiers and subscription product IDs for in-app purchases
- Invoice line items (tier, addon, amount, currency, timestamp)
Beta Program Applications
- Name, email address, and optional company or project name
- Requested cohort, operating systems, hardware class, availability, and intended test case
- Contact consent and a separately recorded optional product-update preference
3. Lawful Bases for Processing (GDPR Art. 6)
For EU/EEA users, we rely on the following legal bases:
- Contract (Art. 6(1)(b)) — running your account, deploying your agents, processing payments. Without this data the Service cannot be delivered.
- Legitimate interest (Art. 6(1)(f)) — fraud prevention, abuse detection, infrastructure security, anonymized usage analytics.
- Consent (Art. 6(1)(a)) — optional analytics (PostHog), beta-program contact, marketing emails, and cookie banner choices. You can withdraw consent at any time.
- Legal obligation (Art. 6(1)(c)) — tax and accounting records (Romanian Fiscal Code requires 7-year retention).
4. How We Use Your Information
- Provide, maintain, and improve the Service
- Authenticate your identity and manage your account
- Process payments and manage subscriptions / addons
- Process AI requests, generate agent replies, create agent configurations, and perform requested agent tasks
- Enforce tier limits (AI Credits, agent count, resource quotas)
- Send transactional emails (signup, password reset, billing, expiry reminders)
- Monitor platform health, detect abuse, prevent fraud
- Analyze aggregate usage to improve features
- Respond to support requests
- Review beta applications, select test cohorts, and contact applicants about available test slots
We do not sell your personal data to third parties, use your agent configs or chat history to train AI models, or target advertising.
When you use AI-powered features, we may send your chat messages, voice transcripts, agent creation descriptions, prompts, agent configuration, relevant session context, files or tool-call content you provide, and generated agent outputs to Hatcher's backend and selected AI model providers for inference. These providers may include OpenRouter, UsePod, Xiaomi MiMo, AceData, or the underlying model provider selected for your agent. If you use Bring Your Own Key, requests route through Hatcher to the provider you configure, and that provider's privacy policy applies.
5. Data Storage & Security
Your data is stored on our infrastructure in Falkenstein, Germany (Hetzner EU). Security measures:
- Passwords hashed with bcrypt before storage
- Integration secrets, API keys, and sensitive credentials encrypted with AES-256-GCM
- Beta applicant contact details and free-text test cases encrypted at rest
- All traffic encrypted in transit via TLS 1.3 (HTTPS)
- Cloudflare provides DDoS protection and edge security
- Agent containers run as non-root, with CPU/memory limits and network isolation
- Database access restricted to the application server over localhost
- Firewall (iptables) limits Docker egress to our LLM proxy + API only
No method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security, but we commit to following industry best practices and notifying affected users without undue delay if a data breach occurs (GDPR Art. 33 & 34 — within 72 hours where required).
6. Third-Party Services (Sub-Processors)
We use the following sub-processors. Each has their own privacy policy — by using Hatcher you consent to the data flows listed:
For AI features, the content sent for processing can include your prompts, chat messages, agent instructions, selected model/provider, uploaded or generated context files, voice transcripts, tool inputs/outputs, and routing or usage metadata needed to return the response and meter AI Credits. Hatcher routes this data through Hatcher's backend and may share it with UsePod, OpenRouter, Xiaomi MiMo, AceData, OpenServ, or the model provider you select. When you use BYOK, requests are routed to the provider attached to your own key. The iOS app asks for permission before sending personal data for third-party AI processing.
We require our AI sub-processors and other service providers to protect personal data with security, confidentiality, and transfer safeguards that are the same or equivalent to the protections described in this Policy, including Data Processing Agreements, standard contractual terms, or provider terms where applicable.
| Service | Purpose | Data Shared | Region |
|---|---|---|---|
| Hetzner | Hosting + compute | All account + agent data | Germany |
| Cloudflare | CDN, DDoS, DNS | Request metadata | Global |
| UsePod | LLM inference (hosted key) | AI prompts, chat messages, voice transcripts, agent configs, session context, and generated outputs when routed to hosted models | USA / Global |
| OpenRouter | LLM inference (hosted key) | AI prompts, chat messages, voice transcripts, agent configs, session context, and generated outputs when routed to hosted models | USA |
| Xiaomi MiMo | LLM inference via UsePod/OpenRouter route | AI prompts, chat messages, voice transcripts, agent configs, session context, and generated outputs when selected | UsePod/OpenRouter infrastructure |
| AceData | LLM inference and data/media tools (direct partner route) | AI prompts, chat messages, voice transcripts, agent configs, session context, files/tool-call content, and generated outputs when selected | Partner infrastructure |
| OpenServ | Partner-hosted AI inference and agent services | AI prompts, chat messages, voice transcripts, agent configs, session context, and generated outputs when selected | Partner infrastructure |
| Apple | In-app purchase processing | App Store transaction identifiers and subscription status | Global |
| Stripe | Card payments | Email, billing address, card token | Ireland / USA |
| Resend | Transactional email | Email address, email content | EU / USA |
| PostHog | Product analytics (opt-in) | Anonymized events, session IDs | EU |
| Sentry | Error tracking | Error stacks, user ID | EU |
| Helius / Jupiter | Solana RPC / price feeds | Wallet address, tx signature | USA |
International transfers to US-based sub-processors rely on the EU-US Data Privacy Framework and Standard Contractual Clauses (SCCs) where applicable. When you use BYOK (Bring Your Own Key), your LLM requests go directly to your chosen provider through our proxy; their privacy policies apply to those requests.
7. Cookies & Local Storage
We use essential cookies for authentication and optional cookies for analytics. Full details are in our Cookie Policy.
We do not use advertising cookies or participate in cross-site tracking networks.
8. Data Retention
- Account data — for the lifetime of your account; deleted within 30 days of account deletion.
- Chat history & agent configs — until you delete them or the agent is removed.
- Payment records & invoices — 7 years minimum (Romanian Fiscal Code & EU accounting directive).
- Server & access logs — 90 days then purged.
- Beta applications — up to 12 months after the beta closes, unless you ask us to delete them sooner.
- Anonymized analytics — retained indefinitely for aggregate trend analysis.
9. Your Rights (GDPR)
If you are in the EU/EEA, UK, or Switzerland you have the right to:
- Access — request a copy of the data we hold about you (Art. 15).
- Rectification — correct inaccurate data (Art. 16). Most fields are self-service in Settings.
- Erasure — “right to be forgotten” (Art. 17); delete your account from Settings.
- Restriction — ask us to limit processing while a complaint is reviewed (Art. 18).
- Portability — machine-readable export of configs + chat history (Art. 20). Available from Settings → Export data.
- Objection — opt out of non-essential analytics or marketing (Art. 21).
- Withdraw consent — for anything we process with your consent (Art. 7(3)).
- Not be subject to automated decision-making — we do not make automated decisions with legal effect about you (Art. 22).
Exercise any of these rights by emailing [email protected]. We respond within 30 days (extendable by 60 days for complex requests, per GDPR).
You also have the right to lodge a complaint with your local data protection authority. In Romania that is the ANSPDCP.
10. Children's Privacy
The Service is not intended for individuals under 18. We do not knowingly collect data from children. If you believe a minor has provided us with personal data, contact [email protected] and we will delete the account and associated data promptly.
11. International Transfers
Primary data storage is in Germany (EU/EEA). Certain sub-processors (UsePod, OpenRouter, AceData, Stripe, Helius) are US-based or operate on partner infrastructure. Transfers outside the EU/EEA rely on the EU-US Data Privacy Framework and/or Standard Contractual Clauses as approved by the European Commission.
12. Changes to This Policy
We may update this Policy. Material changes (scope of processing, new sub-processors affecting EU users, retention changes) will be announced by email at least 14 days before taking effect. The “Last updated” date above always reflects the current version.
13. Contact
- All inquiries (privacy, support, general): [email protected]
- Legal notice: Impressum