Privacy Policy
Last updated: July 26, 2026
Introduction
This Privacy Policy explains what personal data Hylope collects, why we collect it, and what rights you have over it. It applies to the Hylope application and website.
Hylope is a French société par actions simplifiée and acts as the data controller for the personal data described here. We process personal data in accordance with Regulation (EU) 2016/679 (GDPR) and the French Loi Informatique et Libertés.
Our Terms of Service govern your use of the product. This policy covers data handling only.
The Short Version
You own what you create. Your prompts, uploads, and generations are yours.
We never train models on your content, and we never sell or rent your personal data.
Nothing you create is public by default. Your work is visible only to you and to people you deliberately share it with.
We don't track you across the web. Our marketing site uses privacy-friendly analytics that set no cookies and build no profile of you. The application itself has no analytics at all.
Your prompts go to the AI provider you choose. That is how generation works. We list every provider on our subprocessors page.
The rest of this page is the detail behind those statements.
Information We Collect
Account information. Your email address and an identifier from our authentication provider. That is all — we do not ask for your name, and we do not store your password, because sign-in is handled by Auth0.
Billing details. If you subscribe, Stripe collects the billing information it needs, which may include your name and address. That data is held by Stripe; we receive only your subscription status and the country of your payment method. Card numbers never reach our servers.
Content you create and upload. Prompts, uploaded reference files, generated images, video and audio, and the projects and workspaces you organise them into. We also store technical metadata needed to display this content — dimensions, duration, format, and generated previews, thumbnails and transcodes.
Workspace records. Which workspaces you belong to, your role in each, and a ledger of credits used per generation.
Operational records. Technical logs and counters we need to keep the service running and prevent abuse: error reports, job outcomes, request rate counters, and usage totals for features included at no extra cost. These are tied to an account identifier so we can enforce fair-use limits and investigate faults.
Support conversations. If you contact support, we keep the conversation and anything you include in it.
Website analytics. On our public marketing site (hylope.com) we use Plausible, a privacy-focused analytics tool, to count page views and see which pages and links people find useful. It sets no cookies, does not use device fingerprinting, does not follow you to other websites, and reports only aggregate figures — we cannot identify you from it. Plausible is not used inside the application.
How We Use Your Information
We use your information only for these purposes:
- To provide the service — storing your work, displaying it back to you, and sending your prompts to the AI model you selected. Legal basis: performance of our contract with you.
- To handle billing — subscriptions, credits, invoices and tax records. Legal basis: contract, and legal obligation for accounting records.
- To keep the service working and secure — diagnosing faults, preventing abuse, and enforcing usage limits. Legal basis: our legitimate interest in a reliable, non-abused service.
- To communicate with you — account notices and support replies. Marketing email is sent only if you opt in, and you can withdraw at any time. Legal basis: contract, and consent for marketing.
We do not use your content to train AI models, and we do not sell, rent, or share your personal data for advertising.
AI Providers and Your Content
Hylope does not run AI models itself. When you generate something, your prompt and any files you attach are sent to the provider behind the model you selected, which returns the result. This is necessary to deliver what you asked for.
Which providers receive your data therefore depends on which models you use. If you never use a given model, that provider never receives anything from you. Every provider we work with is listed on our subprocessors page, with a link to its own privacy policy.
Hylope never uses your prompts, uploads, or generations to train any model. Each provider's own handling of the data we send is governed by that provider's terms. We record on the subprocessors page whether each one may use submitted content for training, so you can choose accordingly.
Where Your Data Is Stored
Each workspace is assigned a region when it is created — the European Union, the United States, or Asia-Pacific. Your files, generations, and workspace records are stored in that region's database and object storage.
Some data is necessarily global: your account identity and the routing records that determine which region serves your workspace. Backups, support conversations, billing records, and processing by the providers listed on our subprocessors page may also occur outside your workspace's region.
Data is encrypted in transit using TLS, and our database and object-storage providers encrypt data at rest. Access to production systems is restricted. No system is perfectly secure, and we do not claim otherwise.
International Transfers
Some of our providers process data outside the European Economic Area. Where that happens, we rely on an appropriate transfer mechanism under Chapter V of the GDPR: the EU–US Data Privacy Framework for US providers certified under it, another adequacy decision where one applies (for example, the United Kingdom), or the European Commission's Standard Contractual Clauses.
To be clear about one thing: your workspace's region determines where your files and records are stored. It does not currently determine where a generation is processed. AI providers are reached through global endpoints, so a request may be handled outside your workspace's region — including outside the EEA — regardless of which region you chose.
Data Retention and Deletion
We keep your account data and content for as long as your account is active. You can delete individual assets at any time from within the application.
If you request account deletion, your account enters a pending state for thirty (30) days. Signing back in during that period reactivates the account and cancels the request. If the period expires, we permanently delete or irreversibly de-identify the account data — your profile, personal workspace, any team workspace you own, and stored assets under the relevant storage prefixes. Records in a shared workspace that are not solely yours may remain, with references to your account removed or anonymised.
Backups. We keep backups so we can recover from a failure. When you delete a file, that deletion is mirrored to our backup storage and the copy is purged within 30 days. Database backups are kept on a rolling 180-day cycle, so information deleted from your account can persist in them for up to 180 days before it ages out.
Backups are never used to restore deleted accounts, and if we restore from one we re-apply any deletions that happened in the meantime.
We may retain limited records after deletion where required by law — for billing, tax, fraud prevention, security, or dispute resolution. These are kept apart from active product data and only for as long as needed.
Your Rights
Under the GDPR you have the right to:
- Access the personal data we hold about you
- Correct data that is inaccurate or incomplete
- Erase your data, subject to the retention rules above
- Receive your data in a portable format
- Object to processing based on our legitimate interests
- Restrict processing in certain circumstances
- Withdraw consent where processing is based on consent
To exercise any of these, contact privacy@hylope.com. You can delete your account directly from your account settings.
You also have the right to lodge a complaint with a supervisory authority. In France this is the CNIL.
Children's Privacy
Hylope is not intended for children. As stated in our Terms of Service, you must be at least 18 years old to create an account. We do not knowingly collect data from anyone below that age; if we learn that we have, we delete it.
Changes to This Policy
We may update this policy as the product changes. The date at the top of this page reflects the most recent update, and we will notify you of material changes by email or in the application before they take effect.
Contact
For any question about this policy or your personal data, contact privacy@hylope.com.