Skip to main content

Privacy Policy

Last updated: April 2, 2026

Note: This policy is pending legal review before the marketplace goes live.

hellotilda.com ("we," "us," or "our") operates the Platform at hellotilda.com. Full legal entity registration details will be added before marketplace launch. This Privacy Policy explains what data we collect, how we use it, who we share it with, and what rights you have over it.

The short version: we collect what we need to run the platform, nothing more. We do not sell your data. We do not use it for advertising. Your data is yours.


1. What We Collect

What you give us

  • Email address — to create and secure your account
  • Hashed password — we hash passwords with an industry-standard, memory-hard algorithm before storing them; we never see or store your plaintext password
  • Payment method metadata — processed by Stripe (fiat) or Strike (Bitcoin). We never receive or store card numbers, bank account details, or Bitcoin private keys
  • Project data you create — sites, listings, and associated content you upload or create on the Platform
  • Business profile information — if you publish a business profile to the Nostr network, this includes your display name, description, website, and contact details. See Section 4 (Nostr Identity and Relay Data) for how this data is treated once published.
  • Guardian contact information — if you use the key recovery feature, you designate one or more guardians by providing their contact details (typically email address). This data is used solely to notify guardians of their role and to facilitate key recovery. See Section 4 (Nostr Identity and Relay Data).

What we collect automatically

  • Session tokens — stored as cryptographic hashes; used to authenticate your requests
  • Usage data — API call timestamps, endpoints accessed, response codes, and rate limit counters
  • Logs — IP address, request path, and response metadata, retained for 90 days
  • EFS workspace data — when you use agent or AI-powered features, your session history and agent memory files are stored on encrypted AWS Elastic File System (EFS) volumes attached to your workspace. This includes conversation history, agent context, and any files you create or upload during a session. EFS workspace data is isolated per user and is not shared between accounts.

What we collect only for custody-option users

If you choose our managed custody option for your Nostr identity, we additionally store:

  • Nostr private key — your Nostr keypair (public + encrypted private key) is stored on encrypted EFS storage. The private key is encrypted at rest using a key stored in AWS Secrets Manager. You may export your key or switch to self-custody at any time.
  • Secret shares — to support key recovery, your private key may be split into cryptographic shares using a threshold secret-sharing scheme. A subset of shares is distributed to the guardians you designate. We retain one or more shares on our infrastructure; we never hold a complete set sufficient to reconstruct your key without guardian cooperation.

If you choose self-custody, your private key is generated and stored only on your device. We never receive or store it.

What we do not collect

  • Raw payment card numbers or bank account numbers (PCI DSS — Stripe handles this entirely)
  • Your Bitcoin private keys or seed phrases
  • Your Nostr private key if you choose the self-custody option
  • Biometric data of any kind
  • Behavioral profiling data
  • Third-party tracking data (we have no tracking pixels, no third-party analytics)

2. How We Use It

We use your data to:

  • Provide and maintain the Platform
  • Process payments and settlements
  • Authenticate your identity and authorize access
  • Send account and security notifications (transactional email only)
  • Enforce rate limits and prevent abuse
  • Comply with legal obligations
  • For custody-option users: safeguard your Nostr private key and support key recovery through your designated guardians

We do not use your data for targeted advertising. We do not sell it. We do not share it beyond what is listed in Section 5.


3. Bitcoin and Lightning Network

When you pay via Bitcoin Lightning:

  • Lightning payment hashes are public by protocol design — this is inherent to how Lightning works, not a Platform choice
  • Strike handles all Lightning routing and invoice management
  • We do not store your wallet addresses, private keys, or seed phrases
  • Strike's privacy policy applies to data Strike processes on our behalf

4. Nostr Identity and Relay Data

The Platform supports Nostr, a decentralized, censorship-resistant protocol. The following applies to all users who interact with Nostr features:

Published data is public and permanent

When you publish data to the Nostr network — including business profiles, listings, and public content — that data is broadcast to Nostr relays operated by third parties. Once published to a relay, data is outside our control. Relays may retain, redistribute, or index that data indefinitely. You should not publish any information to Nostr that you expect to remain private or that you may need to retract.

Nostr key pairs (custody option)

For users who choose managed custody:

  • Your Nostr public key is public by protocol design and will appear in any content you publish.
  • Your Nostr private key is stored encrypted on AWS EFS. We do not use it for any purpose other than signing actions on your behalf at your direction.
  • Key material is never logged, transmitted in cleartext, or included in backups that are accessible to Platform staff.

Guardian data and secret shares

If you use the key recovery feature:

  • Guardian contact details (email address) are used only to communicate recovery instructions and to notify guardians of their role. We do not use guardian contact details for marketing or any other purpose.
  • Secret shares are cryptographic fragments — a share alone does not reveal your private key or any meaningful portion of it. Shares held on our infrastructure are encrypted at rest.
  • If you remove a guardian or delete your account, we will destroy any shares we hold and instruct you to notify your guardians to destroy theirs.

Relay selection

The Platform submits your published content to a default set of public Nostr relays. Each relay operates under its own terms of service and privacy policy. We do not control relay operators and are not responsible for their data handling practices.


5. Who We Share It With

We share your data only with:

  • Stripe — payment processing (fiat). Stripe's privacy policy governs data they process.
  • Strike — Bitcoin Lightning payments. Strike's privacy policy governs data they process.
  • AWS — infrastructure (compute, storage, database hosting, EFS workspace volumes). AWS processes data on our behalf under a data processing agreement.
  • Neon — database hosting (PostgreSQL). Neon processes data on our behalf.
  • Anthropic — AI processing (idea workshops, AI-assisted features, and AI-assisted abuse and fraud detection). Anthropic processes data on our behalf under their Data Processing Addendum. Anthropic's privacy policy governs data they process.
  • Nostr relay operators — when you publish content to the Nostr network, that content is transmitted to relay operators as part of the protocol. Relay operators are not data processors acting on our behalf; they are independent third parties. Published Nostr data is public.
  • Partner integrations — if you connect a third-party partner integration (e.g., a payment processor, analytics tool, or marketplace connector), we share only the data necessary for that integration to function. Each partner integration discloses what data it receives at the time of connection. You may revoke partner access at any time from your account settings.
  • Your designated guardians — contact information and recovery instructions are shared with guardians you designate as part of the key recovery feature. Guardians receive secret shares and recovery guidance only.

All subprocessors listed above are bound by data processing agreements providing sufficient guarantees for technical and organizational measures as required by GDPR Art. 28. Where required, subprocessors rely on Standard Contractual Clauses or equivalent mechanisms for international data transfers from the EEA/UK.

We do not sell your personal information to any third party. We share only what is necessary for service provision.

We may disclose data if required by law, court order, or legal process — and where legally permitted, we will notify you.


6. Your Rights

You have the following rights, regardless of where you live:

  • Access — request a copy of the data we hold about you
  • Export / portability (Art. 20 GDPR) — download your data in a structured, machine-readable format (JSON or CSV) at any time
  • Correction — request correction of inaccurate data
  • Deletion — request account deletion; your primary account data is purged within 72 hours of a confirmed request. Session history and analytics data have separate retention windows — see Section 7.1 for the full timeline. Note: EFS workspace data, Nostr key material, and secret shares we hold are destroyed as part of account deletion. We cannot retract data already published to Nostr relays.
  • Opt out — opt out of any non-essential communications at any time
  • Key export — custody-option users may export their Nostr private key or switch to self-custody at any time from account settings
  • Guardian removal — you may add, update, or remove guardians at any time. Removal triggers destruction of shares we hold.
  • Object to processing (Art. 21 GDPR) — where we process your data on the basis of legitimate interests (Art. 6(1)(f) GDPR — see Section 11), you have the right to object. We will cease that processing unless we can demonstrate compelling legitimate grounds that override your interests. Contact privacy@hellotilda.com to exercise this right.
  • Lodge a complaint — EEA and UK users have the right to lodge a complaint with their national data protection authority (GDPR Art. 13(2)(d)). A list of EEA supervisory authorities is available at edpb.europa.eu.

The right to opt out of the sale or sharing of personal information (Cal. Civ. Code § 1798.120) does not apply to the Platform because we do not sell or share personal information for advertising or commercial purposes.

GDPR and CCPA rights apply to all Platform users regardless of location. To exercise any of these rights, email privacy@hellotilda.com with the subject line "Privacy Request." We will respond within 30 days.


7. Data Retention

DataRetention
Account dataActive account + 30 days post-deletion
Payment records7 years (legal requirement)
Session tokens24 hours (automatic expiry)
API usage logs90 days
Server logs90 days
Password reset tokens1 hour (automatic expiry)
AI-processed idea contentUp to 30 days (Anthropic API); up to 90 days (Platform analytics) — see Section 7.1
EFS workspace data (session history, agent memory)Active account + 30 days post-deletion; purged on confirmed deletion request
Nostr private key (custody option)Active account; purged immediately on key export, switch to self-custody, or account deletion
Secret shares (key recovery)Active account; purged immediately on guardian removal or account deletion
Guardian contact informationUntil guardian is removed or account is deleted
Partner integration tokens and credentialsUntil integration is revoked or account is deleted
Business profile data (local copy)Active account + 30 days post-deletion; note that published relay copies are outside our control

After deletion, we retain payment records for the legally required period but they are severed from any data that identifies you wherever legally permissible.

7.1 AI Data Processing

When you use Workshop or AI-assisted features, your input and the AI's response are processed by Anthropic. The table below shows retention by data store:

Data storeRetentionNotes
Neon PostgreSQL (account, ideas, content)72 hours after confirmed deletion requestPrimary data store
DynamoDB chat sessions30-day TTLUp to 48-hour async lag; on-request deletion available at marketplace launch
DynamoDB analytics90-day TTLUp to 48-hour async lag; on-request deletion available at marketplace launch
DynamoDB workshop sessions7-day TTLUp to 48-hour async lag
EFS workspace (session history, agent memory)Active account + 30 days; purged on deletion requestPer-user isolated volumes; encrypted at rest
CloudWatch logs (Lambda)14 daysAutomatic expiry; request metadata only, not idea content
Anthropic API (inputs/outputs)Up to 30 days from processing dateStandard commercial API terms; see exception below

Anthropic retention exception: Anthropic may retain content flagged for policy violations for up to 2 years, and trust-and-safety classifier metadata for up to 7 years, to protect the integrity of their systems. This exception applies only to flagged content, not standard idea content.

Model training: By default, Anthropic does not use your inputs or outputs to train their models. This is Anthropic's standard commercial API policy, backed by their Data Processing Addendum.

EEA: If you have concerns about Anthropic's data handling, you may contact Anthropic at privacy@anthropic.com or lodge a complaint with your national data protection authority.

Scope and re-verification: This section covers the current production pathway. Anthropic retention figures reflect standard commercial API terms as of April 2, 2026 — re-verify at Anthropic's Privacy Center for the current schedule.


8. Security

We take security seriously. This is not a slogan — it is the platform's first law.

  • Passwords: Hashed using an industry-standard, memory-hard algorithm. Never stored in plaintext.
  • Sessions: httpOnly, Secure, SameSite=Strict cookies. Session tokens are stored as one-way hashes, not raw values.
  • Transit: Data is encrypted in transit (TLS 1.2+) — no plaintext connections accepted.
  • At rest: Data encrypted at rest on AWS infrastructure, including EFS workspace volumes.
  • Access controls: Least-privilege policies. Access to production data is restricted to authorized services through layered access controls.
  • PCI DSS: Raw card data is never present on our servers. Stripe's hosted and tokenized flows handle card input end-to-end.
  • API keys: Stored as one-way cryptographic hashes. We cannot recover a lost key — generate a new one.
  • Nostr private keys (custody option): Encrypted at rest using AWS Secrets Manager-managed keys. Key material is never logged or transmitted in cleartext. Access is restricted to the signing service only.
  • Secret shares: Encrypted at rest. Threshold scheme ensures no single party — including hellotilda.com — can reconstruct your key without the required number of guardian shares.
  • EFS workspace data: Per-user volume isolation. Workspace data is not accessible across accounts.

In the event of a data breach affecting your personal information, we will notify you within 72 hours of discovery. We will describe what happened, what was affected, and what we are doing about it.


9. Cookies

We use one cookie: your session cookie.

  • Session cookie: httpOnly, Secure, SameSite=Strict. Set on login, cleared on logout.
  • No tracking cookies.
  • No third-party analytics.
  • No advertising pixels.

If you block cookies, you will not be able to log in to the Platform.


10. Children's Privacy

The Platform is not directed to individuals under 18. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected data from a minor, we will delete it promptly.


11. International Users

The Platform is hosted in the United States (AWS cloud infrastructure). If you access the Platform from outside the US, your data is transferred to and processed in the US. By using the Platform, you acknowledge this transfer.

For users in the European Economic Area or United Kingdom: we process your data under the following legal bases:

  • Contract performance (Art. 6(1)(b) GDPR) — account creation, payment processing, service delivery, and AI-powered Workshop features
  • Legitimate interests (Art. 6(1)(f) GDPR) — security monitoring, fraud prevention, abuse detection
  • Legal obligation (Art. 6(1)(c) GDPR) — payment record retention, tax compliance

You may contact us to exercise your GDPR rights.


12. Changes to This Policy

We will notify you of material changes by email and by posting the updated policy on this page, with a new "Last updated" date. Transparency is a core value — we will not bury changes.


13. Contact

For privacy questions or to exercise your rights: