This Privacy Policy describes how Bit Haus (“Bit Haus”, “we”, “us”) processes personal data in connection with the hal software application (the “Software”) and the hal.bit.haus website (the “Site”). It forms part of, and should be read with, the Terms of Service.
Using hal requires a Bit Haus account and a monthly subscription, so we process your email address, account identifier and subscription status. That is the extent of it: the Software itself runs on your device, sends no usage telemetry, and Bit Haus does not receive your source code, prompts, transcripts, specifications or model credentials. Your work leaves your machine only when the Software sends it to the model providers and services you configure, under their own terms.
Bit Haus is the controller for the account, subscription and Site data described below. For the material the Software processes inside your repositories, you are the controller: it stays on your device except where you configure the Software to transmit it to a provider. Privacy enquiries and data-subject requests: privacy@bit.haus.
To create an account and maintain a subscription we process your email address, an account identifier, authentication tokens issued to your devices, subscription status and renewal dates, and a record of your sign-ins for security purposes. Payment card details are collected and held by our payment processor, not by Bit Haus; we receive only the billing metadata needed to operate the subscription, such as plan, status, country and the last four digits of the instrument. The legal basis for this processing is performance of our contract with you (Art. 6(1)(b) GDPR, where applicable). Account and billing records are retained for the life of the account and for as long afterwards as tax and accounting law requires.
Beyond authenticating your subscription, the Software transmits no analytics, product telemetry, feature-usage events, session metadata, transcript content, cost data or crash reports to Bit Haus. The Software’s only other contact with the Site is a periodic request for the update feed (appcast.xml), which carries no account or device identifier beyond the standard server log described in section 6.
The Software stores the following on your device only, under your user account and your control: session transcripts and conversation history; repository paths, configuration and per-repository settings; specification documents, versions, stories and work items, which live in your own repositories; the agent's memory files, which also live in your repositories; cost and token estimates; and application preferences such as appearance. This data is never transmitted to Bit Haus. You may delete it by removing the Software's configuration directory and the relevant files in your repositories.
Model-provider API keys, credential-router tokens and any code-hosting login you authorise are held in the macOS Keychain or in a configuration file on your device, and are used only to authenticate the requests you cause the Software to make. Bit Haus never receives, transmits or stores your credentials. A repository you open cannot redirect your credentials to a different endpoint. Where a credential router is used, revoking the Software's access is performed at that router.
To produce a response, the Software transmits to the model provider you have configured the material necessary for the request, which may include: your prompts and replies; source code, file contents and diffs from the repository in question; specification text; command output; project instruction files; and the agent's memory index. Where the reviewer role is enabled, the corresponding material is also transmitted to the second provider you have configured for that role. Where you enable web research, pull-request tooling, or a Model Context Protocol server, requests are made to those endpoints.
Each such transmission is governed by the receiving party's privacy policy and terms, including any provision regarding retention, human review or training on submitted content. Bit Haus has no access to, and no control over, that processing. You should review those policies before enabling a provider, and should not direct the Software at material you are not permitted to disclose to it.
The Site is a static site. It sets no cookies, embeds no advertising or analytics trackers, and requires no account. Our hosting provider records standard server access logs for security and abuse prevention — IP address, timestamp, requested path, referrer and user-agent string — retained for no more than thirty (30) days and not used to build profiles. Downloading a release produces such a log entry. The Site loads web fonts from a third-party font service, which receives your IP address as a technical necessity of serving the request.
If you contact us by email, or voluntarily send a bug report, log excerpt or crash file, we process the content you send and your email address for the purpose of responding, on the basis of our legitimate interest in supporting the Software. Such correspondence is retained for up to twenty-four (24) months. Please redact anything confidential before sending a log or transcript: what you send is what we receive.
Where the EU or UK General Data Protection Regulation applies, our legal basis for processing server logs and correspondence is our legitimate interest in operating the Site securely and in responding to enquiries (Art. 6(1)(f)). Subject to the conditions in applicable law, you have the right to request access to, rectification of, or erasure of your personal data; to restrict or object to processing; to data portability; and to lodge a complaint with your supervisory authority. Residents of California and other US states with comparable law have rights of access, deletion and correction, and the right not to be discriminated against for exercising them. Bit Haus does not sell or share personal data for cross-context behavioural advertising, and does not process it for automated decision-making or profiling. Deleting your account cancels the subscription and erases the account record, subject to the retention required by tax and accounting law. Requests: privacy@bit.haus.
Our hosting and font providers may process server-log data in the United States and other jurisdictions, under the transfer mechanisms available to them, including the European Commission's standard contractual clauses where applicable. We apply appropriate technical and organisational measures to the limited data we hold, but no method of transmission or storage is completely secure. The Software and the Site are not directed to children under the age of 16, and we do not knowingly process their personal data.
We may update this Privacy Policy to reflect changes in the Software or in applicable law. The version and effective date at the head of this page identify the current text, and material changes will be noted here. If a future release introduces any transmission of data to Bit Haus beyond the authentication described above — for example an opt-in crash reporter — this policy will be amended before that release ships, and the feature will be off by default.