Privacy Policy
Last updated: March 2026. Applies to all users of haiv.dev.
1. Who We Are
haiv (haiv.dev) is an AI-powered software development platform operated within the European Union. We act as the data controller for all personal data collected through the platform.
Contact: [email protected]
2. Data We Collect
Account registration:
- Email address, username, password (hashed — never stored in plain text)
- Optional: GitHub account if you connect it via OAuth
Platform usage:
- Project names and descriptions
- Chat history with AI agents
- Files created inside your project containers
- Terminal session activity (command history is not stored server-side)
Billing:
- We do not store card details — payment processing is handled by our payment processor
- We store transaction records (amount, date, status) and your account credit balance
Automatically collected:
- IP address — used for security and fraud prevention only, not shared for advertising
- Browser user agent
- Pages visited — aggregated analytics to improve the platform
- Session token — stored in an HTTP-only Secure cookie
3. How We Use Your Data
- To create and manage your account and deliver the platform services
- To process billing and prevent fraud
- To send transactional emails: account verification, password reset, billing receipts, service notices
- To enforce platform security (rate limiting, brute-force protection, audit logs)
- To improve the platform through aggregated, anonymised usage analytics — we do not profile individuals for advertising
4. Legal Basis (GDPR Art. 6)
- Contract (Art. 6(1)(b)): Processing necessary to provide the service you have requested.
- Legitimate interests (Art. 6(1)(f)): Security monitoring, fraud prevention, and aggregated platform analytics.
- Legal obligation (Art. 6(1)(c)): Retaining billing records as required by applicable EU tax and accounting law.
5. Data Sharing
We do not sell or rent your personal data. We share data only with the following categories of processor, under data processing agreements:
- AI providers (Anthropic, OpenAI, Google) — to process the content of your chat messages and agent responses. Only message content is sent; your email, name, and billing information are never transmitted to AI providers.
- Cloud infrastructure (Google Cloud Platform) — for hosting isolated project containers. Data is processed within the EU or in jurisdictions providing adequate protection under GDPR.
- Payment processors — for credit top-ups and billing.
We may disclose data if required by law, court order, or to protect the rights and safety of users.
6. Data Retention
- Account data: retained for the lifetime of your account plus 90 days after deletion.
- Project data (files, chat history, containers): deleted within 30 days of project deletion or account termination.
- Billing records: retained for 7 years as required by EU tax law.
- Security and audit logs: retained for 12 months.
7. Your GDPR Rights
As a data subject under GDPR, you have the following rights:
- Access: request a copy of the personal data we hold about you.
- Rectification: correct inaccurate or incomplete data.
- Erasure ("right to be forgotten"): request deletion of your account and personal data, subject to legal retention obligations.
- Restriction: request that we limit how we process your data.
- Portability: receive your data in a structured, commonly used, machine-readable format.
- Objection: object to processing based on legitimate interests.
- Complaint: lodge a complaint with your national supervisory authority (e.g. CNIL, ICO, BfDI).
To exercise any right, email [email protected]. We will respond within 30 days. Account deletion is also available directly from your account settings.
8. Cookies
We use strictly necessary cookies only:
We do not use tracking, advertising, analytics, or any third-party cookies. No third-party scripts that set cookies are included on this platform.
Because we use only strictly necessary cookies, we do not require your consent under GDPR — but we inform you here in the interest of transparency.
9. Security
Passwords are hashed with PBKDF2-SHA256 (600,000 iterations) and a random per-user salt. Sensitive configuration (API keys, SMTP credentials) is encrypted at rest. All connections use TLS. Sessions are cryptographically hashed before storage and are invalidated immediately on logout. Each project runs in an isolated container with separate networking.
10. Children
haiv is not directed at persons under 16 years of age. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected data from a minor, please contact us and we will delete it promptly.
11. Changes to This Policy
We will notify registered users by email of any material changes to this policy at least 14 days before they take effect. The "last updated" date at the top of this page reflects the most recent revision. Continued use of the platform after changes take effect constitutes acceptance of the revised policy.
12. Contact
Data controller contact: [email protected]
General support: [email protected]