Politică de confidențialitate pentru Hilo
https://hilo-policy.lucas-4ee.workers.dev/
Privacy Policy — Hilo
Last updated: April 29, 2026
Hilo ("we", "our", "the extension") is a browser extension that provides instant AI-powered explanations for text you select on any web page. This policy explains what data we collect, why, and how we protect it.
1. What We Collect
Data you provide
- Email address — collected when you create an account via magic link / OTP. Used solely for authentication and to associate your usage quota with your account.
Data collected automatically
- Daily request count — we track the number of explanation requests you make each day to enforce the free-tier quota (10 requests/day). This counter resets daily.
- Account plan — "free" or "pro", stored in our database.
Data we explicitly do NOT collect
- The text you select on any web page.
- The context extracted from pages (surrounding paragraph, page title, URL).
- Your browsing history.
- Any content of the AI responses returned to you.
None of the text sent to the AI model is logged or stored by us, at any point in the pipeline.
2. How We Use Your Data
| Data | Purpose |
| ------------------- | ----------------------------------------- |
| Email address | Authentication (magic link / OTP login) |
| Daily request count | Enforce per-tier usage limits |
| Account plan | Determine which features and limits apply |
We do not sell, rent, or share your data with third parties for advertising or marketing purposes.
3. Third-Party Services
To deliver the service, we use the following sub-processors:
| Provider | Role | Privacy Policy |
| -------------- | -------------------------------------------------------------- | ----------------------------------------- |
| Anthropic | AI model inference (text is sent to their API for explanation) | https://www.anthropic.com/privacy |
| Supabase | Authentication and database | https://supabase.com/privacy |
| Cloudflare | Edge infrastructure hosting our API | https://www.cloudflare.com/privacypolicy/ |
| Polar | Payment processing and subscription management | https://polar.sh/legal/privacy |
Your selected text and page context are transmitted to Anthropic's API to generate explanations. This transmission happens server-side through our backend — your Anthropic API key is never exposed to the browser. Anthropic's API usage policies apply to this data; please consult their privacy policy for details.
When you upgrade to the Pro plan, your email address is shared with Polar to create a customer record and process your payment. Polar handles all payment card data; we never receive or store your payment details. Polar's privacy policy applies to data processed during checkout and subscription management.
4. Data Storage & Retention
- Your email and account data are stored in our Supabase (PostgreSQL) database, hosted in the EU region.
- JWT authentication tokens are stored locally in your browser via
chrome.storage.local(or equivalent). These tokens are encrypted by the browser and inaccessible to other extensions or web pages. Tokens expire after 7 days. - Daily usage counters reset automatically each day. No historical request logs are kept.
- You may request deletion of your account and all associated data at any time by contacting us (see Section 8).
5. Permissions Used
The extension requests the following browser permissions:
| Permission | Reason |
| ------------------------------ | ----------------------------------------------------------------------------------------------- |
|
storage | Store your authentication token and preferences locally ||
activeTab | Read selected text and surrounding context on the active page to generate an explanation ||
host_permissions: <all_urls> | Required to inject the selection listener and popover on any web page you choose to use Hilo on |We do not use these permissions to read or transmit your browsing history.
6. Children's Privacy
Hilo is not directed at children under the age of 13 (or 16 in the EU). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
7. Your Rights (GDPR / CCPA)
If you are located in the EU or California, you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate data.
- Erase your data ("right to be forgotten").
- Restrict or object to processing.
- Portability — receive your data in a machine-readable format.
To exercise any of these rights, contact us at the address in Section 8.
8. Contact
For privacy questions, data deletion requests, or any concerns:
Email: lucasmartinez.it@gmail.com
We will respond within 30 days.
9. Changes to This Policy
We may update this policy from time to time. When we do, we will update the "Last updated" date at the top. Continued use of the extension after changes constitutes acceptance of the revised policy.