We relay your data.
We don't store it.
Last updated: March 9, 2026
HuginnCloud is a WebSocket relay service. Your agent conversations, code, and session data travel through our infrastructure — but they are never stored, logged, or inspected by us. This policy explains exactly what we do and don't collect.
1. What we collect
When you create an account, we collect:
- Email address — used to identify your account and send essential service communications
- Password — stored as a one-way bcrypt hash; we cannot recover or read your password
- First and last name — optional, used only for display purposes
When you connect a satellite and use the service, we collect:
- Satellite metadata — the name and identifier you assign to each connected machine, its online/offline status, and the timestamp it was last seen
- Account metadata — your subscription plan, trial expiry date, and Stripe customer identifier
- Connection metadata — IP address and timestamps of WebSocket connections, used for security and service operation
2. What we do not collect
HuginnCloud operates a transparent relay architecture. The following data passes through our infrastructure but is never stored, logged, cached, or inspected:
- Agent conversations, prompts, and responses
- Code, files, or repository content
- Routine results, session transcripts, or inbox notifications
- Any content transmitted between your browser and your local Huginn instance
Traffic between your browser and your satellite is relayed in-memory and discarded immediately. We have no ability to read, replay, or recover it.
3. How we use your data
We use the data we collect to:
- Operate and maintain your account
- Enforce satellite connection limits per your subscription plan
- Process payments through Stripe
- Send transactional emails (account verification, billing receipts)
- Detect and prevent abuse or unauthorized access
We do not sell your data. We do not use your data for advertising.
4. Payment processing
Payments are processed by Stripe. HuginnCloud never receives, stores, or processes your payment card details. Stripe handles all card data under their own Privacy Policy and PCI DSS compliance program.
We store only your Stripe Customer ID (a reference token) and your current subscription plan name.
5. Data storage and security
Account data is stored in Amazon DynamoDB in the United States. We use TLS encryption for all data in transit. Passwords are hashed with bcrypt and are never stored in recoverable form.
We implement reasonable technical and organizational measures to protect your data. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
6. Data retention
We retain your account data for as long as your account exists. If you delete your account, we will delete your personal data within 30 days, except where retention is required by law.
Satellite metadata (machine names, last-seen timestamps) is deleted when you remove the satellite or close your account.
7. Third-party services
We use the following third-party services to operate HuginnCloud:
- Amazon Web Services (AWS) — infrastructure, database, and hosting
- Stripe — payment processing and subscription management
Each of these providers handles data under their own privacy policies and security standards.
8. Your rights
You may at any time:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your account and associated data
- Export your account information
To exercise any of these rights, contact us at privacy@huginncloud.com.
9. Google user data
HuginnCloud supports connecting Google services — including Gmail, Google Calendar, Google Drive, and other Google APIs — via OAuth. This connection is established by your local Huginn instance (not by HuginnCloud directly), but HuginnCloud relays commands that may invoke these integrations. The following applies to all Google user data:
- Gmail and other Google services: If you authorize Huginn to access your Gmail or other Google services, data from those services may pass through the HuginnCloud relay in response to requests you initiate. This data is relayed in real time and is never stored, logged, or retained on HuginnCloud servers.
- Limited use: HuginnCloud's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used solely to fulfill the specific action you request — it is not used for advertising, analytics, training, or any secondary purpose.
- Scope minimization: Only the OAuth scopes required for the features you explicitly enable are requested. We do not request broader access than necessary.
- Token storage: OAuth tokens for Google services are stored in your local machine's OS keychain by Huginn — not on HuginnCloud servers. HuginnCloud does not store or have access to your Google OAuth tokens.
- Revoking access: You may revoke Google access at any time from your Google Account permissions page or by disconnecting the integration within your local Huginn configuration.
10. Cookies
The HuginnCloud marketing site (huginncloud.com) does not use tracking cookies or analytics. The application (app.huginncloud.com) uses session cookies strictly necessary for authentication. We do not use advertising, behavioral, or third-party analytics cookies.
10. Children
HuginnCloud is not directed to children under 13. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a notice on the site. Your continued use of the service after changes are posted constitutes your acceptance of the updated policy.
12. Contact
Questions about this policy? Contact us at privacy@huginncloud.com.