hilho.
FAQJoin Hilho

Privacy policy

Your conversations deserve care.

This policy explains what personal data Hilho processes, why it is needed, who may receive it and the choices available to you.

Last updated 7 August 2026

01

Who is responsible

EKOMERZE, SIA, registration number 50203659731, with its registered address at Sēļu iela 39, Mārupe, Mārupes nov., LV-2167, Latvia, is the controller responsible for Hilho.

Privacy contact: hilho@hilho.com.

02

What this policy covers

This policy applies to Hilho's website, iOS and Android mobile apps, account features, conversation-analysis services and the Hilho Telegram bot. It does not control third-party services you choose to use, such as Telegram or Google sign-in, or websites linked from Hilho.

03

Data we process

Account and identity

Name, email address, sign-in provider, selected plan, encrypted password representation and session identifiers.

Conversation content

Text, screenshots, images, PDFs or other supported files you submit, plus language, context and reply preferences.

Communication profile

If you use PERSONAL and choose to create one, the voice, humor, disagreement, response-length, language and boundary preferences you select, plus any optional wording examples you enter. The profile is encrypted before storage.

Telegram beta drafts

Only the messages you paste or forward directly to @hilho_bot. Hilho does not read your other Telegram chats. The bot retains a temporary working draft for up to 30 minutes, then removes it after analysis or expiry.

People mentioned in content

Messages and other personal data about conversation participants. You are responsible for having a lawful reason to submit it and for minimising unnecessary information.

Encrypted history

For registered users, submitted conversation text, context and generated results are encrypted before they are stored in Hilho's account history. Uploaded image and PDF files are not retained in history.

Technical and security data

IP address, device/browser information, timestamps, request and error logs, and security events processed by Hilho and its hosting providers. For the one-time public demo, Hilho stores a one-way keyed hash of a browser token and, where available, network address—not the raw values—to prevent repeat use.

Optional website analytics

If you consent, Google Analytics processes a pseudonymous browser identifier, page visits, approximate location derived from IP address, device/browser details and interaction events such as registration, checkout start and completed analysis. Conversation text, generated replies and full payment details are not sent to Google Analytics.

Support and rights requests

Messages you send to us and information needed to respond or verify your identity.

Payment data

Stripe processes card and billing details for paid subscriptions. Hilho receives limited records such as the Stripe customer and subscription identifiers, selected plan, payment status and renewal information. Hilho does not receive your full card number.

04

Why we use data

  • Provide the service and account — to authenticate you, analyze submitted content and generate a reply. Legal basis: performance of the contract or steps you request before entering it.
  • Personalize suggested replies — to apply the communication profile and per-conversation choices you actively select. Legal basis: performance of the contract. The profile describes your stated preferences; Hilho does not use it as a psychological diagnosis.
  • Protect the service — to prevent abuse, investigate incidents and keep accounts secure. Legal basis: our legitimate interests and, where applicable, legal obligations.
  • Understand and improve Hilho — to measure aggregate page and feature use through Google Analytics. Legal basis: your consent, which you may decline or withdraw without losing access to Hilho.
  • Support and communication — to answer questions, reset access and handle data-rights requests. Legal basis: contract, legitimate interests or legal obligations.
  • Improve reliability — to understand failures and aggregate usage patterns without using conversation content for unrelated advertising. Legal basis: legitimate interests, balanced against your rights.
  • Comply with law — to respond to valid legal requests, keep required records and establish or defend legal claims. Legal basis: legal obligation or legitimate interests.

Where we rely on consent for an optional feature, you may withdraw it at any time without affecting earlier lawful processing.

05

AI processing and service providers

When you request an analysis, Hilho sends the conversation text, screenshots, images or PDFs you selected, together with the context, language, per-conversation reply choices and—only when you keep it enabled—the relevant communication-profile preferences needed for that request, to OpenAI, Hilho's third-party AI processing provider. The purpose is to analyze communication signals and generate the explanation, translation and suggested reply you requested. Hilho does not send your password or full payment details to OpenAI.

Before the Hilho mobile app sends this content to OpenAI for the first time, it displays a contextual notice naming the data, recipient and purpose and asks for explicit permission. If you choose “Not now,” nothing is sent and the analysis does not start. You can withdraw permission at any time in Account → AI data sharing. After withdrawal, the server blocks new mobile AI requests until you give permission again.

OpenAI states that business/API data is not used to train its models by default. The current implementation requests that responses are not stored as reusable application state, but OpenAI may retain limited API data for up to 30 days for abuse monitoring and service operation under its standard controls.

We may also use:

  • Sites and Cloudflare for application delivery, security and hosting infrastructure;
  • Google Identity if you choose Google sign-in;
  • Google Analytics for optional, consent-based website measurement;
  • our configured email provider for transactional and support email; and
  • Stripe for secure checkout, subscription billing and the customer billing portal.

Providers process data under their own terms and, where required, data-processing agreements.

06

How long data is kept

  • Analysis history: encrypted text, context and completed results are kept while your account is active so you can reopen them, or until you delete the individual item or account. Uploaded image and PDF files are processed during the request but are not retained in history. OpenAI's standard API retention described above may still apply.
  • Communication profile: kept while your account is active until you remove it from the profile page or delete the account. Optional wording examples are limited to 400 characters each. Do not place secrets or another person's private messages in these fields.
  • Telegram beta drafts: retained only while you assemble a conversation, for up to 30 minutes, and deleted after analysis or expiry. A minimal webhook receipt identifier may be retained to prevent duplicate replies and duplicate analysis requests.
  • Account records: while your account is active and for up to 30 days after deletion, unless a longer period is needed for security, legal claims or law.
  • Session cookie: up to 7 days, or until you sign out or clear it.
  • One-time demo anti-abuse token: the browser token and its one-way hashed anti-abuse record are kept for up to 180 days. They are not used for advertising or cross-site tracking.
  • Password reset token: up to 15 minutes.
  • Support and rights requests: as long as needed to resolve the request and demonstrate compliance, normally no longer than 3 years unless law requires more.
  • Security and hosting logs: according to the provider's operational schedule and only as long as reasonably necessary.
  • Optional analytics: Google Analytics identifiers may remain for up to 2 years after consent unless you withdraw consent or clear them sooner. Aggregate reports may no longer identify a specific browser.

07

International transfers

Some providers may process data outside the European Economic Area. Where GDPR transfer rules apply, we use an adequacy decision, Standard Contractual Clauses or another lawful safeguard, together with additional protections where appropriate. You may ask for information about the relevant safeguard.

08

Your choices and rights

Depending on applicable law, you may ask to access, correct, delete, restrict or receive your personal data, object to certain processing, or withdraw consent. You may also object to a decision based solely on automated processing that produces legal or similarly significant effects. Hilho is not intended to make such decisions.

You can edit or remove your saved communication profile from My communication profile and turn it off for an individual conversation without deleting it. You can change your analytics choice at any time using the Cookie settings button on Hilho. In the mobile app, you can withdraw third-party AI data-sharing permission under Account → AI data sharing. Withdrawal does not remove earlier processing, but it prevents new mobile analyses until you allow the transfer again.

Submit a request through Your Data Rights. We normally respond within one month under the GDPR, although a complex request may lawfully take longer. You may complain to your local supervisory authority. In Latvia, this is the Data State Inspectorate.

09

Age requirement

Hilho is intended for people aged 18 or older. Do not submit a child's personal data unless you have a clear lawful basis and the processing is genuinely necessary.

10

Security and data minimisation

We use reasonable technical and organisational measures, including encrypted connections, restricted secrets and protected session cookies. No online service is risk-free. Redact details that are not needed for the analysis, especially passwords, payment information, identity documents, health details and intimate material.

11

Changes and contact

We may update this policy as the service or law changes. Material changes will be highlighted on the service or sent to the account email where appropriate. Questions can be sent to hilho@hilho.com.

hilho.

© 2026 Hilho. Powered by HIL™.

PricingHow Hilho thinksFAQPrivacyTermsCookiesAI transparencyYour data rights
hilho@hilho.com