← Back to home

Privacy Policy

Last updated: March 25, 2026

1. Responsible Entity

Responsible for data processing on this website and within the browser extension:
Jasper Schmidt
Email: hello@hyphos.app

2. What Data We Collect and Why

2.1 Account Data

A user account is required to use hyphOS. We collect:

Legal basis: Art. 6 (1) (b) GDPR (Performance of a contract).
Retention period: Until account deletion upon request.

2.2 Memos and Content

When you create memos or save AI analyses, the following data is processed:

Legal basis: Art. 6 (1) (b) GDPR (Performance of a contract).
Retention period: Until deleted by you or upon account deletion request.

2.3 AI Processing of Web Content

When you explicitly trigger an AI function (e.g., "Summarize"), the text content of the current page is transmitted to our servers and forwarded to the Google Gemini API (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland).

Legal basis: Art. 6 (1) (b) GDPR (Performance of a contract).

2.4 Research Path (Browsing History)

The optional "Research Path" feature, when enabled, collects:

Legal basis: Art. 6 (1) (b) GDPR (Performance of a contract).
Retention period: Until manually deleted by you or upon account deletion.

2.5 Cloud Synchronization (Optional)

When you enable Cloud Sync, your memos are encrypted locally with AES-256-GCM before transmission and stored at Supabase (Supabase Inc., 970 Toa Payoh North, Singapore). We do not read your memos.

Legal basis: Art. 6 (1) (a) GDPR (Consent via enabling Cloud Sync).
Retention period: Until Cloud Sync is disabled or the account is deleted.

2.6 Usage Metrics (Server-Side)

To ensure service quality and operate the credit system, we collect server-side:

This data is stored exclusively in our Supabase database and never shared with third parties.
Legal basis: Art. 6 (1) (b) GDPR (Performance of a contract).
Retention period: Until account deletion.

3. Browser Extension Permissions

The extension requires the following permissions:

Permission Purpose Data Transmission
storage / unlimitedStorage Local storage of memos, settings, and Research Path data No (local)
tabs Session Manager: view, group, and close open tabs No
activeTab Extract text from active page for AI analysis (only on user action) Only during AI analysis
contextMenus Right-click menu: "Save as Memo" and "Explain with AI" No
webNavigation Research Path: track page visits for research trail Local, optional cloud
host_permissions Display sidebar on all websites (universal research tool) No

Privacy Blacklist

The extension does not collect data from the following categories of sites:

4. No Third-Party Analytics

We do not use tracking tools such as Google Analytics, Facebook Pixel, or similar services.

5. Payment Processing (Lemon Squeezy)

Subscriptions are processed via Lemon Squeezy (Lemon Squeezy, LLC). Payment data is processed exclusively by Lemon Squeezy. We only receive a purchase confirmation and your email address to activate your subscription.

Legal basis: Art. 6 (1) (b) GDPR (Performance of a contract).

6. Data Transfers to Third Countries

Processing by Google (AI API), Supabase (database), and Lemon Squeezy (payments) may involve transfer to the United States. All providers are either certified under the EU-U.S. Data Privacy Framework or use EU Standard Contractual Clauses (Art. 46 GDPR) to ensure an adequate level of data protection.

7. Your Rights

Under the GDPR, you have the following rights:

To exercise your rights, contact us at: hello@hyphos.app

For complete account deletion including all stored data, please contact us at the same address.

8. Right to Lodge a Complaint

You have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data (Art. 77 GDPR). If you are located in the EU, you may contact the supervisory authority of your country of residence.