> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.hyjal.cloud/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.hyjal.cloud/_mcp/server.

# Hyjal Privacy Policy

> What data Hyjal holds about you, where it lives, and what we do with it.

**Effective date:** \[DATE — set when published]
**Data controller:** \[ENTITY — legal name needed]

This policy says what data Hyjal holds about you, where it lives, and what
we do with it. It is short because we hold little. Questions:
**[support@hyjal.cloud](mailto:support@hyjal.cloud)**.

## 1. What we collect

**Account data**

* Your **email address** and a hashed password (we never store the password
  itself). That is the whole signup form.

**Billing data**

* Billing is integrated through **Stripe** and is currently **dormant** — no
  charges occur today. If and when billing activates, your card details go
  directly to Stripe; we never see or store full card numbers. See Stripe's
  privacy policy for how they handle payment data.

**Your deployed content**

* The **module bytes** (WASM files) you upload, stored in our storage
  bucket.
* **Logs from your modules** (stdout/stderr and request records), stored in
  the same bucket, so you can debug your own deployments.

**Operational data**

* Standard server logs for running and securing the platform, which include
  the **IP addresses** of requests. We use these for operations and abuse
  prevention, not profiling.

## 2. What we do NOT collect

* **No analytics or tracking.** The console and our pages currently run no
  analytics scripts, no ad pixels, no fingerprinting.
* **No data sales, ever.** We do not sell or rent your data to anyone.
* No data brokers, no advertising partners.

If we ever add analytics, it will be privacy-respecting, disclosed here
first, and announced by email.

## 3. Cookies

We use **essential cookies only**: a session cookie so you stay signed in to
the console. No third-party cookies, no advertising cookies, no consent
theater needed — the one cookie we set is required for the Service to work.
This section is our Cookie Notice.

## 4. Where your data lives

* Our infrastructure runs on **Amazon Web Services in the us-east-1 region
  (United States)**. Account data, module bytes, and logs live there,
  including backups.
* Payment data (when billing activates) lives with Stripe.

If you are outside the United States: using Hyjal means your data is
processed in the US.

## 5. Why we process it (our lawful bases)

* **To run the Service you asked for** — accounts, deployments, logs
  (contract).
* **To keep the platform safe** — abuse prevention, security logging
  (legitimate interest).
* **To bill you**, only if billing activates and you opt in (contract).
* **To answer you** when you contact support (contract/legitimate interest).

That's the list. We do not process your data for advertising or profiling.

## 6. Who we share it with

Only processors needed to run the Service:

* **AWS** — hosting and storage.
* **Stripe** — payments (dormant today).

Plus disclosure if the law genuinely compels it, in which case we limit it
to what is legally required.

## 7. How long we keep it

* **Account data:** while your account exists, then deleted.
* **Modules and their logs:** while deployed / until you delete them or your
  account.
* **Backups:** rolling; deleted data ages out of backups on the backup
  retention cycle.
* **Server logs:** kept for a limited operational window, then discarded.

## 8. Your rights

Email **[support@hyjal.cloud](mailto:support@hyjal.cloud)** and we will:

* tell you what data we hold about you (it's the list above);
* correct it;
* delete your account and its data;
* export your modules (they're your files — you can also just download
  them).

We answer as a small team: best effort, normally within a few days. If your
local law (GDPR, CCPA, etc.) grants you specific rights, we honor requests
in that spirit rather than making you cite statutes.

## 9. Security

All traffic is served over TLS. Stored state is backed up. Access to
production systems is limited to the operator. No system is perfectly
secure; if a breach ever affects your data, we will notify you by email
without undue delay.

## 10. Changes

We may update this policy. Meaningful changes will be emailed to your
account address before they take effect, and the effective date above will
change. The current version always lives at this URL.

## 11. Contact

**[support@hyjal.cloud](mailto:support@hyjal.cloud)** — privacy questions, data requests, anything else.