Privacy Policy

Last updated: July 7, 2026

Table of Contents

  1. Overview
  2. Data Controller
  3. Information We Collect
  4. How We Use Information
  5. Legal Basis for Processing (GDPR)
  6. Information Sharing and Disclosure
  7. Data Retention
  8. Data Security
  9. Your Rights
  10. Cookies and Tracking
  11. Children's Privacy
  12. International Data Transfers
  13. Changes to This Policy
  14. Contact Information

1. Overview

Hi Holo ("we", "us", or "our") respects Your privacy. This Privacy Policy explains what information we collect when You use our website (hiholo.ai), our API reference tool (engine.hiholo.ai), and our software products including Holo Engine MCP Server and Holo Engine Workspace Server (collectively, the "Services").

We design our Services to process Your data locally on Your machine. We collect the minimum information necessary to operate, license, and improve our Services.

2. Data Controller

The data controller responsible for Your personal information is:

Kirill Kazakov (operating as "Hi Holo")
Email: kirill@hiholo.ai
Website: hiholo.ai

Upon formation of a legal entity, the data controller shall transfer to said entity. We will notify You of any such change via the email address associated with Your account.

3. Information We Collect

3.1 Information You Provide Directly

DataWhen CollectedPurpose
Email addressTrial registration, MCP trial form, demo API key requestLicense delivery, account communication
Name, company, and message contentContact form on hiholo.aiResponding to your inquiry and follow-up communication
NameTrial registration, MCP trial formLicense personalization, customer support
OrganizationTrial registration (optional)Customer records
Payment informationPurchase of paid licenseProcessed by third-party payment processor; we do not store card numbers

3.2 Information Collected Automatically

DataHow CollectedPurpose
Device fingerprintComputed locally (SHA-256 of hardware UUID + salt) during license activationLicense binding to device, fraud prevention
License IDTransmitted during license activation and heartbeat verificationLicense validation, revocation checking
IP addressServer logs when contacting our VPS for license verificationRate limiting, abuse prevention
Anonymous usage metricsEndpoint call counts, error rates (no data content)Service improvement, debugging

3.3 What We Do NOT Collect

4. How We Use Information

We use the information we collect for the following purposes:

  1. Service delivery — issuing, validating, and refreshing Your license;
  2. Communication — sending You license files, setup instructions, expiration notices, and critical security alerts;
  3. Account management — managing Your trial and paid licenses, processing upgrades and renewals;
  4. Security and fraud prevention — detecting unauthorized use, rate limiting, device binding;
  5. Service improvement — analyzing anonymous usage patterns to identify bugs and prioritize features;
  6. Legal compliance — maintaining records as required by applicable tax and business laws.

We do not use Your information for targeted advertising, selling to third parties, or training machine learning models on Your personal data.

If You are located in the European Economic Area, United Kingdom, or Switzerland, we process Your personal data under the following legal bases:

Processing ActivityLegal Basis
Issuing and validating licensesContract performance (Art. 6(1)(b))
Sending license-related emailsContract performance (Art. 6(1)(b))
Device fingerprinting for license bindingLegitimate interests: fraud prevention (Art. 6(1)(f))
Anonymous usage metricsLegitimate interests: service improvement (Art. 6(1)(f))
IP address logging for securityLegitimate interests: security and abuse prevention (Art. 6(1)(f))
Processing paymentContract performance (Art. 6(1)(b))

6. Information Sharing and Disclosure

We do not sell, rent, or trade Your personal information. We share information only in the following circumstances:

  1. Service providers — We use Resend (email delivery) and our payment processor. These providers receive only the information necessary to perform their functions and are bound by confidentiality obligations;
  2. Legal requirements — If required by law, court order, or government regulation, we may disclose information to the extent necessary;
  3. Business transfer — In the event of a merger, acquisition, or asset sale, information may be transferred to the successor entity. You will be notified via email before such transfer;
  4. Security — We may disclose information to protect the rights, property, or safety of Hi Holo, our users, or others.

7. Data Retention

We retain Your personal information for as long as Your license is active, plus the following periods after termination:

Data TypeRetention Period After Termination
Email and name3 years (for legal/tax record-keeping)
License records3 years
Device fingerprintsDeleted immediately upon license termination
IP addresses (server logs)30 days
Anonymous usage metricsAggregated and anonymized after 90 days; retained indefinitely in aggregate form

8. Data Security

We implement reasonable technical and organizational measures to protect Your personal information:

  1. All license files are signed using Ed25519 digital signatures to prevent tampering;
  2. API communications use HTTPS/TLS encryption;
  3. Administrative access requires two-factor authentication (TOTP);
  4. API keys are stored as SHA-256 hashes, not plaintext;
  5. Server infrastructure is access-controlled and regularly updated.

No method of transmission or storage is 100% secure. We cannot guarantee absolute security but commit to notifying You of any data breach within 72 hours of discovery, as required by GDPR Art. 34.

9. Your Rights

Depending on Your jurisdiction, You may have the following rights regarding Your personal data:

  1. Access — request a copy of the personal data we hold about You;
  2. Rectification — request correction of inaccurate or incomplete data;
  3. Erasure — request deletion of Your personal data ("right to be forgotten");
  4. Restriction — request that we limit processing of Your data;
  5. Portability — receive Your data in a structured, machine-readable format;
  6. Objection — object to processing based on legitimate interests;
  7. Withdrawal of consent — withdraw consent at any time where processing is based on consent;
  8. Complaint — lodge a complaint with Your local data protection authority.

To exercise any of these rights, contact us at kirill@hiholo.ai. We will respond within 30 days. We may request additional information to verify Your identity before processing Your request.

10. Cookies and Tracking

Our website uses minimal cookies and does not use third-party tracking pixels, advertising cookies, or social media plugins. We use only:

  1. Session cookies — for admin panel authentication (deleted when You close Your browser);
  2. Essential cookies — required for the website to function properly.

We do not use Google Analytics, Facebook Pixel, or similar tracking services.

11. Children's Privacy

Our Services are intended for professionals and businesses. We do not knowingly collect personal information from children under 16 years of age. If You believe we have collected information from a child, please contact us, and we will promptly delete it.

12. International Data Transfers

Your information may be processed on servers located outside Your country of residence. By using our Services, You consent to such transfers. We take appropriate measures to ensure adequate protection of Your data, including:

  1. Using service providers that comply with GDPR, CCPA, or equivalent data protection standards;
  2. Minimizing the data transferred to what is strictly necessary;
  3. Implementing Standard Contractual Clauses where applicable.

13. Changes to This Policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top indicates the most recent revision. We will notify You of material changes via email to the address associated with Your license. Your continued use of the Services after any such change constitutes acceptance of the updated policy.

14. Contact Information

For questions, requests, or complaints regarding this Privacy Policy or Your personal data, please contact:

Kirill Kazakov (Hi Holo)
Email: kirill@hiholo.ai
Website: hiholo.ai

If You are in the EU/UK, You may also contact Your local data protection authority. The supervisory authority in Your jurisdiction can be found at edpb.europa.eu.