Privacy Policy
Last updated August 8, 2026
What we collect
Account data (email, display name, hashed password), billing state (handled by Stripe — we never see card numbers), runtime telemetry (health heartbeats, public connection status), and metering records (model, token counts, cost). Your desk's content — files, conversations, event history — lives on your Habitat's own volume, not in our control plane.
How AI processing works
When you talk to your Envoy or run workers, the relevant text or audio is sent to the model provider serving that lane (xAI, OpenRouter and its upstream hosts, OpenAI for transcription) to produce the response. If you connect your own Codex or Claude subscription, those requests go to your provider under your own agreement, and your credentials stay on your Habitat's volume — we never receive them.
Processors
Cloudflare (edge, control plane, storage), ascii.dev (cloud servers), Stripe (payments), Resend (transactional email), and the model providers above. Each receives only what its role requires.
Retention and deletion
Deleting your device disconnects it and revokes its credential; cloud volumes follow the stated retention policy before removal. Deleting your account removes account records; email us to exercise deletion or export rights and we will complete them within 30 days.
Security
Passwords are slow-hashed; sessions are opaque tokens stored hashed; runtime credentials are revocable and stored hashed; secrets never enter event logs. Report issues to hello@habitatagents.com.