Privacy
What Hilo collects, why, and what you can do about it. In plain language, because a policy you can't read isn't a policy.
Last updated 5 August 2026
What Hilo collects
Your email address, the name you choose to be called, and a password (stored hashed, never in readable form).
The questions you submit, and the briefings Hilo makes from them — the script, the show notes, and the audio.
How many briefings you've made this month, so your plan's allowance can be counted.
A fixed acquisition classification used to keep the public validation cohort separate from earlier and operator-invited accounts. When a podcast app successfully fetches a briefing's audio, Hilo also keeps one receipt for that briefing, private-feed token record, and the UTC date and time of the first successful fetch that day. The receipt does not contain your IP address, user agent, HTTP range, or other request content.
Your Stripe customer reference and billing address, if you subscribe. Card details go directly to Stripe and never touch Hilo's servers.
Limited technical records used to stop abuse: your IP address is counted against short rolling limits on signups, failed sign-ins, and free briefings; your email is counted against the free-briefing limit. Email-keyed events are included in your export and deleted with your account. IP events are not attached to an account because one address can represent several people; the live service prunes them at startup and every hour after their 24-hour protection window, so they normally remain for no more than about 25 hours.
Who else processes it
Hilo is a small product built on other companies' infrastructure. Each of them receives a specific slice of your data and no more:
Stripe handles payments and billing details. Resend delivers the emails Hilo sends you. Anthropic and Google provide the models that plan the research and write the briefing. Tavily runs the web searches. ElevenLabs turns the finished script into speech. Cloudflare provides the anti-bot check on the signup form. DigitalOcean hosts the service and holds encrypted backups. Sentry receives error reports when something breaks.
Stated plainly, because it is the first thing a careful reader will want to know: your question text leaves Hilo. It has to — researching and narrating it happens on those companies' systems. Your email address, your password, and your card details do not go to any of the research or narration providers.
Sentry is deliberately the thinnest of these. It never receives your email address, your questions, the text of your briefings, the sources they cite, or your feed token — only numeric identifiers and bounded technical detail about the failure. That limit is enforced in the code, not by policy.
Hilo does not sell your data, and does not share it for advertising.
Cookies and tracking
Hilo sets a session cookie so you stay signed in, and a token that protects forms from cross-site abuse. That's it.
There are no analytics cookies, no advertising pixels, and no third-party tracking scripts. The only third-party script anywhere in the product is the anti-bot check on the signup page.
How long things are kept
Episodes and the feed are two different things. A briefing drops out of your private podcast feed after its time window — 30 days by default, and the number is yours to change in Settings → Feed.
Dropping out of the feed is not deletion. Hilo keeps the briefing; your podcast app just stops carrying it. It stays yours until you delete it.
Cancelling a paid plan erases nothing. It changes what you can generate next; it never removes what you already made.
Encrypted backups of the database are taken every 15 minutes so your account can be restored if something fails. Every snapshot is kept for 48 hours; after that Hilo keeps one snapshot per day, and removes it after 30 days.
When you delete your account, its live database records are removed in one transaction and your private feed stops working at once. Each episode's local audio directory and exact off-host mirrored audio object are placed under one durable deletion obligation in that same transaction; Hilo tries both immediately, keeps the job through a 30-minute quiescence window, and sweeps both again at startup or hourly until they are gone. A short-lived IP abuse event may remain until the rolling window above expires because it is not reliably attributable to one account. Encrypted database backup snapshots can retain an older copy for up to 30 days; they are kept only for disaster recovery and expire under the schedule above. Hilo keeps content-free generation and provider-accounting evidence with its user link removed, plus one long-lived record that a deletion happened holding a one-way hash of the email address and counts of what was removed. Neither record contains your content or a readable address.
What you can do
Download a self-serve archive of your account identity, current plan and acquisition classification, briefings and audio, cited sources and generation runs, usage history, active and revoked access tokens, daily audio-fetch receipts with the UTC date and time of the first successful fetch that day, policy receipts, attributable email abuse events, and consumed invitation from Settings → Your data. Operational billing details, generation and provider-accounting ledgers, and security records outside that named archive are not included in the self-serve ZIP. For access to other account-specific records Hilo retains, write to support@usehilo.com.
Delete your account and its contents, from the same page. This cannot be undone.
Turn off email notifications in Settings → Profile.
Replace your private feed URL at any time in Settings → Feed, if you think it has been shared with someone it shouldn't have been.
If you are in California, a "Do Not Sell My Information" link is available to you. Hilo does not sell personal information, but the link is there.
Your private feed
Your podcast feed URL contains a long random token, and that token is the key. Anyone who has the URL can listen to your briefings, so treat it like a password. If it gets out, rotate it in Settings → Feed and the old one stops working.