Join WaitlistSign In

Privacy Policy

Last updated: July 26, 2026

Introduction

This Privacy Policy explains what personal data Hylope collects, why we collect it, and what rights you have over it. It applies to the Hylope application and website.

Hylope is a French société par actions simplifiée and acts as the data controller for the personal data described here. We process personal data in accordance with Regulation (EU) 2016/679 (GDPR) and the French Loi Informatique et Libertés.

Our Terms of Service govern your use of the product. This policy covers data handling only.

The Short Version

You own what you create. Your prompts, uploads, and generations are yours.

We never train models on your content, and we never sell or rent your personal data.

Nothing you create is public by default. Your work is visible only to you and to people you deliberately share it with.

We don't track you across the web. Our marketing site uses privacy-friendly analytics that set no cookies and build no profile of you. The application itself has no analytics at all.

Your prompts go to the AI provider you choose. That is how generation works. We list every provider on our subprocessors page.

The rest of this page is the detail behind those statements.

Information We Collect

Account information. Your email address and an identifier from our authentication provider. That is all — we do not ask for your name, and we do not store your password, because sign-in is handled by Auth0.

Billing details. If you subscribe, Stripe collects the billing information it needs, which may include your name and address. That data is held by Stripe; we receive only your subscription status and the country of your payment method. Card numbers never reach our servers.

Content you create and upload. Prompts, uploaded reference files, generated images, video and audio, and the projects and workspaces you organise them into. We also store technical metadata needed to display this content — dimensions, duration, format, and generated previews, thumbnails and transcodes.

Workspace records. Which workspaces you belong to, your role in each, and a ledger of credits used per generation.

Operational records. Technical logs and counters we need to keep the service running and prevent abuse: error reports, job outcomes, request rate counters, and usage totals for features included at no extra cost. These are tied to an account identifier so we can enforce fair-use limits and investigate faults.

Support conversations. If you contact support, we keep the conversation and anything you include in it.

Website analytics. On our public marketing site (hylope.com) we use Plausible, a privacy-focused analytics tool, to count page views and see which pages and links people find useful. It sets no cookies, does not use device fingerprinting, does not follow you to other websites, and reports only aggregate figures — we cannot identify you from it. Plausible is not used inside the application.

What we do not collect. We use no advertising networks and no cross-site tracking, and we do not build a behavioural profile of you. Inside the application there is no product analytics at all. Your generation history is your own library — we store it so you can find your work, not to analyse your behaviour.

How We Use Your Information

We use your information only for these purposes:

  • To provide the service — storing your work, displaying it back to you, and sending your prompts to the AI model you selected. Legal basis: performance of our contract with you.
  • To handle billing — subscriptions, credits, invoices and tax records. Legal basis: contract, and legal obligation for accounting records.
  • To keep the service working and secure — diagnosing faults, preventing abuse, and enforcing usage limits. Legal basis: our legitimate interest in a reliable, non-abused service.
  • To communicate with you — account notices and support replies. Marketing email is sent only if you opt in, and you can withdraw at any time. Legal basis: contract, and consent for marketing.

We do not use your content to train AI models, and we do not sell, rent, or share your personal data for advertising.

AI Providers and Your Content

Hylope does not run AI models itself. When you generate something, your prompt and any files you attach are sent to the provider behind the model you selected, which returns the result. This is necessary to deliver what you asked for.

Which providers receive your data therefore depends on which models you use. If you never use a given model, that provider never receives anything from you. Every provider we work with is listed on our subprocessors page, with a link to its own privacy policy.

Hylope never uses your prompts, uploads, or generations to train any model. Each provider's own handling of the data we send is governed by that provider's terms. We record on the subprocessors page whether each one may use submitted content for training, so you can choose accordingly.

Some AI providers are located outside the European Union, including in the United States and Singapore. See International Transfers below.

Sharing and Visibility

Nothing you create is public by default. Your content is visible to you, and to other members of a workspace you belong to, according to their role.

If you create a share link, it is an unguessable web address. Anyone who has that link can view what you shared, so treat it like a password. You can set an expiry date, limit the number of views, protect it with a password, and revoke it at any time — revoking takes effect immediately.

We do not publish your work, use it to promote Hylope, or make it available to other users outside your workspace unless you choose to share it.

Where Your Data Is Stored

Each workspace is assigned a region when it is created — the European Union, the United States, or Asia-Pacific. Your files, generations, and workspace records are stored in that region's database and object storage.

Some data is necessarily global: your account identity and the routing records that determine which region serves your workspace. Backups, support conversations, billing records, and processing by the providers listed on our subprocessors page may also occur outside your workspace's region.

Data is encrypted in transit using TLS, and our database and object-storage providers encrypt data at rest. Access to production systems is restricted. No system is perfectly secure, and we do not claim otherwise.

International Transfers

Some of our providers process data outside the European Economic Area. Where that happens, we rely on an appropriate transfer mechanism under Chapter V of the GDPR: the EU–US Data Privacy Framework for US providers certified under it, another adequacy decision where one applies (for example, the United Kingdom), or the European Commission's Standard Contractual Clauses.

To be clear about one thing: your workspace's region determines where your files and records are stored. It does not currently determine where a generation is processed. AI providers are reached through global endpoints, so a request may be handled outside your workspace's region — including outside the EEA — regardless of which region you chose.

Cookies

We use cookies only where they are necessary for the service to work: keeping you signed in, and keeping access to a share link you have unlocked.

We set no advertising cookies and no cross-site tracking cookies. The analytics on our marketing site are cookieless — see Website analytics above.

Because we set only strictly necessary cookies and our analytics are cookieless, we do not show a cookie consent banner.

Data Retention and Deletion

We keep your account data and content for as long as your account is active. You can delete individual assets at any time from within the application.

If you request account deletion, your account enters a pending state for thirty (30) days. Signing back in during that period reactivates the account and cancels the request. If the period expires, we permanently delete or irreversibly de-identify the account data — your profile, personal workspace, any team workspace you own, and stored assets under the relevant storage prefixes. Records in a shared workspace that are not solely yours may remain, with references to your account removed or anonymised.

Backups. We keep backups so we can recover from a failure. When you delete a file, that deletion is mirrored to our backup storage and the copy is purged within 30 days. Database backups are kept on a rolling 180-day cycle, so information deleted from your account can persist in them for up to 180 days before it ages out.

Backups are never used to restore deleted accounts, and if we restore from one we re-apply any deletions that happened in the meantime.

We may retain limited records after deletion where required by law — for billing, tax, fraud prevention, security, or dispute resolution. These are kept apart from active product data and only for as long as needed.

Your Rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you
  • Correct data that is inaccurate or incomplete
  • Erase your data, subject to the retention rules above
  • Receive your data in a portable format
  • Object to processing based on our legitimate interests
  • Restrict processing in certain circumstances
  • Withdraw consent where processing is based on consent

To exercise any of these, contact privacy@hylope.com. You can delete your account directly from your account settings.

You also have the right to lodge a complaint with a supervisory authority. In France this is the CNIL.

Children's Privacy

Hylope is not intended for children. As stated in our Terms of Service, you must be at least 18 years old to create an account. We do not knowingly collect data from anyone below that age; if we learn that we have, we delete it.

Changes to This Policy

We may update this policy as the product changes. The date at the top of this page reflects the most recent update, and we will notify you of material changes by email or in the application before they take effect.

Contact

For any question about this policy or your personal data, contact privacy@hylope.com.