Privacy Policy
Version 2026-09-14
How Hiddentao Labs Pte. Ltd. collects, uses, shares and keeps personal data, across the hezo.ai website, the hosted control plane at app.hezo.ai, and the Hezo instance we run for you.
1. Who we are
Hiddentao Labs Pte. Ltd. (UEN 202443955N), a company incorporated in Singapore with its registered office at 68 Circular Road, #02-01, Singapore 049422, is the organisation responsible for the personal data described here.
Our Data Protection Officer can be reached at team@hezo.ai, for anything in this policy including a request to access or correct your data.
2. What this covers
There are three separate surfaces, and they collect different things:
- hezo.ai - the public website you are reading now.
- app.hezo.ai - the control plane, which holds your account, your subscription, and the record of the instance we run for you.
- Your instance - the Hezo application at your own subdomain of app.hezo.ai, and the agent containers it drives. Almost everything you would think of as your data lives here.
If you run Hezo yourself rather than buying the hosted service, only the website section applies to you, plus the note on product telemetry in section 10.
3. What we collect
On the website
- Analytics. Page views, referrer, approximate location, device and browser, and the pages you visit. Your IP address is sent to our analytics service so it can resolve those, and is not stored by us alongside anything that identifies you. The analytics path sets no cookies.
- Session recordings. We record a sample of browsing sessions - roughly half, for up to five minutes each - so we can see where the site confuses people. A recording captures your mouse movement, clicks, scrolling and the text the page displayed to you. Text you type into form fields is masked and not recorded. The support chat is excluded entirely.
- Support chat. If you open the chat widget, what you write goes to our chat provider along with the technical details their widget collects.
- Newsletter. If you subscribe, your email address. We send a confirmation link first and only add you when you click it.
- Fonts. The site loads its typefaces from Google's font service, so your IP address reaches Google on every page.
- Browser storage. Your theme and language preference, and a flag recording that you have seen the homepage animation. These stay in your browser.
When you create an account
- Your email address.
- The project brief you type into the signup form.
- The language you were reading in.
- Your IP address, recorded against the sign-in link we issue so we can rate-limit abuse. It expires with the link. We keep nothing about where a signed-in session was opened from.
- The version of the Terms and Privacy Policy you accepted, and when. If you asked for product news, that you did and when.
- The subdomain you choose, which is your instance's address under app.hezo.ai.
- Billing details held by Stripe. We see the subscription and its status. We never see your card number.
- Which steps of the signup you reached and when, so we can see where people get stuck.
While your instance runs
- Everything you and your agents put into Hezo - tasks, descriptions, comments, documents, chat messages, goals, uploaded files, and the repositories your agents work in.
- Agent run transcripts - the full output of every agent run, including the commands it ran and what they printed.
- Stored credentials - the secrets, API keys and tokens you add, held encrypted (section 8).
- Operational readings - how many containers are running, disk usage, the software version, and whether the box is answering. We use these to bill container-hours and to notice when something is broken.
- An audit trail of lifecycle actions and who asked for them.
4. Why we use it, and on what basis
Under the Personal Data Protection Act 2012, most of what we do with your data rests on deemed consent by contractual necessity (section 15): you asked us to run a service, and we cannot run it without doing these things.
| Purpose | Basis |
|---|---|
| Creating and securing your account, and signing you in | Necessary to provide the service |
| Provisioning and running your instance | Necessary to provide the service |
| Measuring container-hours, billing, and taking payment | Necessary to provide the service; legal obligation for tax records |
| Service email: sign-in links, instance ready, billing, security notices | Necessary to provide the service |
| Answering your support requests | Necessary to provide the service |
| Detecting and preventing abuse, fraud and attacks | Legitimate interests |
| Understanding how the website is used, and improving it | Legitimate interests |
| Sending you product news | Your express consent, which you can withdraw at any time |
We do not require marketing consent as a condition of using the service. The product-news box on the signup form is optional and starts unticked, and signing up works exactly the same whether you tick it or not. Every marketing email carries an unsubscribe link; unsubscribing withdraws that consent and stops the mail.
We do not sell your personal data, and we do not use your content to train models.
5. Who we share it with
We use the following providers to run the service. Each receives only what its job needs.
| Provider | What it does | Where |
|---|---|---|
| DigitalOcean | Your instance's server, its database and the private network around it; the control plane itself; and the server our analytics runs on | London, United Kingdom for your instance. We do not pin a region for the control plane or the analytics server |
| Daytona | The agent containers, which hold your prompts and copies of the repositories your agents work in | United States or European Union |
| Cloudflare | DNS, the website, the object storage that holds your uploaded files, and the database holding product telemetry | Global. Object storage is not pinned to a country - see section 6 |
| Telegram | Operational alerts to our engineers. Receives an instance's internal identifier and what is wrong with it, plus a daily fleet summary. Never your content, your address or anything naming you | Outside the European Economic Area |
| Stripe | Payments and subscriptions | United States and European Union |
| Resend | Service email and the newsletter list | Sent from a regional relay; account data, delivery logs and metadata are stored in the United States |
| Crisp | Support chat. Receives your email address so we know who is asking | European Union |
| Umami | Website analytics and session recordings, on a server we run | Software we self-host, on DigitalOcean |
| Web fonts. Receives your IP address when a page loads | Global | |
| Your model provider (Anthropic, OpenAI, Google, and others, as you choose) | Runs your agents. Receives your prompts, task text and repository contents | Depends on the provider, most commonly the United States |
- DigitalOcean
- Your instance's server, its database and the private network around it; the control plane itself; and the server our analytics runs on
- Where: London, United Kingdom for your instance. We do not pin a region for the control plane or the analytics server
- Daytona
- The agent containers, which hold your prompts and copies of the repositories your agents work in
- Where: United States or European Union
- Cloudflare
- DNS, the website, the object storage that holds your uploaded files, and the database holding product telemetry
- Where: Global. Object storage is not pinned to a country - see section 6
- Telegram
- Operational alerts to our engineers. Receives an instance's internal identifier and what is wrong with it, plus a daily fleet summary. Never your content, your address or anything naming you
- Where: Outside the European Economic Area
- Stripe
- Payments and subscriptions
- Where: United States and European Union
- Resend
- Service email and the newsletter list
- Where: Sent from a regional relay; account data, delivery logs and metadata are stored in the United States
- Crisp
- Support chat. Receives your email address so we know who is asking
- Where: European Union
- Umami
- Website analytics and session recordings, on a server we run
- Where: Software we self-host, on DigitalOcean
- Web fonts. Receives your IP address when a page loads
- Where: Global
- Your model provider(Anthropic, OpenAI, Google, and others, as you choose)
- Runs your agents. Receives your prompts, task text and repository contents
- Where: Depends on the provider, most commonly the United States
The model provider is your own arrangement. You supply the key, the account is yours, and what the provider does with what it receives is governed by their terms rather than ours.
We also share data where the law requires it, and we would share it with an acquirer if the business were sold, in which case we would tell you first.
6. Sending data outside Singapore
We are a Singapore company, but the service does not run in Singapore. The table above says where each provider holds data. In summary:
- Your instance and its database are in London. That is where the bulk of your content lives.
- Agent containers run in the United States or the European Union, because our container provider offers no other region. They hold your prompts and copies of your repositories while a run is in progress.
- Files you upload are stored on Cloudflare R2, which we cannot pin to a country. R2 offers jurisdictional guarantees only for the European Union and the United States, and the regional hint we could otherwise use is documented as a performance optimisation rather than a residency guarantee. We say this plainly rather than implying your files stay with your server.
- Payments, email and support chat are handled in the United States and the European Union.
As required by section 26 of the Personal Data Protection Act, we take reasonable steps to satisfy ourselves that each provider gives your data a standard of protection comparable to the Act, through the contractual terms we have with them.
7. How long we keep it
| What | How long |
|---|---|
| Your tasks, comments, documents, chat and files | Until you delete them, or your account is deleted |
| Agent run transcripts | Indefinitely, unless you compact them. Nothing deletes them automatically. Your instance has a control that trims logs older than a window you choose |
| Sign-in links | 15 minutes, then swept |
| Sessions | 30 days, then swept |
| Signup funnel records | 180 days |
| Health readings about your instance | 30 days |
| A project brief from a signup that never chose an address | 7 days |
| Our audit trail of lifecycle actions | Kept. It is the record of what was done to your account |
| Billing and tax records | As long as the law requires |
What deleting your account actually does
Be clear-eyed about this. Deleting your account:
- cancels your subscription;
- destroys your instance's server, its database, and the bucket holding your files;
- deletes your project brief, your signup funnel records, your subscription record and every session.
It does not delete your account row, which includes your email address. That row is marked deleted and kept, because our audit trail names it and removing it would take the record of what happened with it. The record of the instance itself - its address, its plan and its usage totals - is kept alongside it and marked destroyed, for the same reason and because the address is never reissued. Stripe also keeps its own record of your payments, which is theirs to erase on request to them.
If you want the retained email address erased as well, write to our Data Protection Officer and we will deal with it individually.
8. How we protect it
Your credentials are encrypted with a key we do not hold. Your instance is unlocked with a passphrase only you know. From it, your browser derives the key that encrypts your stored secrets, API keys, OAuth tokens and signing keys. That key is held in your instance's memory and is never written to its disk. We never receive it, so nothing we hold lets us decrypt what it protects. Never store that passphrase on the machine running your instance.
Agents reference your secrets by placeholder. An agent never holds the real value: it is substituted at your instance's outbound proxy, at the moment of the request, and only for the hosts that secret is allowed to reach. One credential is the exception. The key for the model provider an agent is running against is placed in its container in readable form, because the agent's own tool authenticates to that provider directly rather than through the proxy. Every other secret stays out.
What we can read, stated plainly. Not holding your passphrase is narrower than not being able to read your data. We administer the database your instance uses, so we can technically read your application rows - your tasks, comments, documents, chat messages and agent run transcripts. We access them only where we need to for support you have asked for, to investigate abuse, or where the law requires. What is genuinely beyond us is what your passphrase encrypts.
Beyond that: traffic is encrypted in transit, tokens and session secrets are stored hashed rather than in the clear, each customer gets their own database and their own credentials for it, and access to production is limited to the people who need it.
No system is perfectly secure. Agent containers are strong isolation but not a guarantee against determined, hostile code, so treat what you let an agent execute with the same care you would treat running it yourself.
9. Your rights
Under the Personal Data Protection Act you may:
- Ask what we hold about you and how we have used or disclosed it in the past year;
- Ask us to correct anything wrong or incomplete;
- Withdraw consent for anything that rests on it. For product news, the unsubscribe link does it. For anything necessary to run the service, withdrawing means closing your account, because we cannot run it without doing those things.
Write to team@hezo.ai. We will respond within 30 days, or tell you when we can if we need longer. There may be a reasonable fee for an access request, and we will tell you before we charge it.
Singapore's data portability provisions have not been brought into force, and we do not currently offer a data export feature. If that changes, this page changes with it.
If you are unhappy with how we have handled your data, please tell us first so we can put it right. You may also complain to the Personal Data Protection Commission.
10. Cookies, tracking and telemetry
The website sets no advertising cookies and runs no advertising trackers. What it does run is described in section 3: analytics served from our own domain, sampled session recordings, and the support chat widget, which sets its own storage. Your theme and language preferences are kept in your browser. The dashboard at app.hezo.ai sets one cookie, which keeps you signed in.
You can block all of it with your browser's tracking protection or an extension, and the site will still work.
Hezo the product sends usage telemetry. Every installation, self-hosted and hosted alike, reports a daily aggregate: counts of teams, projects, agents and tasks, token totals, the mix of AI providers used, the version, and the operating system. It contains no names, no prompts, no repository details and no user identities. It carries a random identifier for the installation so the same install is not counted twice. The aggregate is published at hezo.ai/stats. If you run Hezo yourself you can turn it off with --disable-telemetry.
For hosted customers this telemetry is not fully anonymous. Hosted instances report with it enabled, and the same installation identifier is visible to our control plane alongside your account. We do not link the two, but we could, so we will not describe it as anonymous to you. Tell us if you would rather your instance did not send it and we will turn it off.
11. Children
The service is not intended for anyone under 13, and we do not knowingly collect their personal data. Between 13 and 17 the service may be used only with a parent or guardian's agreement, as the Terms of Service set out. If you believe a child has given us personal data, write to our Data Protection Officer and we will delete it.
12. If something goes wrong
If a data breach happens, we assess it without delay. Where it is likely to cause you significant harm, or affects a significant number of people, we notify the Personal Data Protection Commission no later than three calendar days after determining it is notifiable, and we tell affected people as soon as practicable. We will say what happened, what data was involved, and what you should do.
13. Changes to this policy
We may update this policy. The version identifier at the top of the page changes when we do. For a change that materially affects how we handle your data, we will tell you by email before it takes effect.
14. Contact
Data Protection Officer: Hezo DPO, team@hezo.ai.
Hiddentao Labs Pte. Ltd. (UEN 202443955N), 68 Circular Road, #02-01, Singapore 049422.