Legal
Privacy Policy
Last updated August 25, 2026
HiHi Labs (“we,” “us”) builds and operates software for a small number of clients and community projects, run from Portland, Oregon. This page describes what we collect through hihilabs.xyz and the products linked from it, why, and what we don’t do with it.
What we collect
Only what's needed to do the work:
- Contact & account information — name, email, and anything you send us through a contact form, project portal, or client login.
- Project & portal data — files, messages, and records tied to a client engagement, visible only to that client and to us.
- Payment & financial account data — processed through Stripe, our payment provider. We use Stripe to move money for invoicing, payroll, and vendor payments — we never see or store full card numbers, bank account numbers, or routing numbers ourselves. Where a financial account is linked (for example, to verify ownership of an account used for payment), that connection is made directly with Stripe under their own security controls, and the underlying account credentials never pass through our servers.
- Basic technical data — standard server logs (IP address, browser, timestamp) kept briefly for security and debugging, not for tracking.
How we use it
- To deliver, bill for, and support the work a client has engaged us for.
- To move money — invoicing clients, paying ourselves, employees, and financial backers.
- To respond to messages sent through our contact forms.
- To keep our own systems secure and working.
That's the whole list. We don't build user profiles, run ad targeting, or use this data for anything beyond running the business and the products on it.
What we don't do
- We don't sell data, to anyone, ever.
- We don't share it with third parties beyond the service providers required to operate (Stripe for payments; hosting/infrastructure we run ourselves).
- We don't run third-party ad trackers or analytics networks on our own sites.
- We don't advertise, so we're not buying or selling audiences either.
Where it lives
We self-host our own infrastructure end to end, on servers located in the United States, and we don't store this data outside the US. Financial and payment data is held by Stripe under its own security and compliance program — see stripe.com/privacy.
How long we keep it
For as long as it's relevant to an active engagement, plus whatever a given record legally requires afterward (invoices, tax records). After that, we delete it on request or on our own retention schedule.
Your rights
You can ask us what we hold about you, ask us to correct it, or ask us to delete it, at any time — see contact info below. We'll respond directly; there's no automated request portal because there's no automated system generating this data at scale.
Cookies
We use session and login cookies to keep you signed in to the client portal. No third-party ad or tracking cookies.
Changes to this policy
If this changes, we'll update the date at the top of this page. Given how few people this applies to, we're also just going to tell you directly.