Privacy isn't a promise here. It's the architecture.
This policy describes what Hachiflow collects, why, and what happens to it. It is written to be read, not skimmed past. If anything is unclear, email hello@hachiflow.com and a human will answer.
Effective date: July 29, 2026
This policy is pending review by legal counsel. The facts in it are accurate today; the phrasing may be refined after review, and any substantive change will be announced as described below.
Plain-English summary
- Join the waitlist and we store your email, a timestamp, your country, and the referring page. Nothing else, and only to contact you about access.
- Our analytics are cookieless. No ad trackers, no fingerprinting, no cross-site anything.
- Your workspace content lives on your own dedicated server in the EU. We do not read it, sell it, or train models on it.
- Sign-in and payments are handled by WorkOS and Stripe. We never see your password or your card number.
- Ask and we hand you everything we hold for you, keys included, and delete it within 30 days of cancellation.
Exactly this. Nothing more.
Hachiflow collects the minimum needed to run a waitlist today and a managed hosting service tomorrow. Each category below states what is collected, where it is stored, and why.
Waitlist signups
When you join the waitlist we store your email address, a timestamp, your country (derived at the Cloudflare edge, not from your precise location), and the referring page.
This lives in Cloudflare KV and is used solely to contact you about access. A welcome email is sent via Cloudflare Email Service. No marketing list, no third-party sharing.
Site analytics
hachiflow.com uses DataFast, a privacy-focused, cookieless analytics service, for page analytics and a single conversion goal on the waitlist form.
There are no advertising trackers and no cross-site profiles. Visits are counted, visitors are not identified.
Sign-in (when the service is live)
Sign-in is processed by WorkOS AuthKit using Google, Microsoft, or email. We receive your verified email address and use it for one thing: determining which workspace you belong to.
Anyone with a verified email address can create a workspace. The domain only determines how teammates join: a company domain lets colleagues join automatically, while a consumer domain such as gmail.com gets a private workspace that grows by invite link. We never see or store passwords.
Billing (when the service is live)
Payments are processed by Stripe. Card numbers go to Stripe directly and never touch our systems.
What we store: your subscription id and tier. That is the whole billing record on our side.
Workspace content
Your workspace content lives on your own dedicated server, hosted with Hetzner in Germany or Finland, with encrypted-at-rest backups in Cloudflare R2. Every message is signed with per-user keys.
Hachiflow operators access tenant infrastructure only for operations, support, and legal compliance. The content is yours: handed over in full whenever you ask, deleted within 30 days of cancellation.
Operational logs
We keep operational logs and metrics via Cloudflare observability tooling: request logs, error traces, and service health metrics.
These exist to keep the service up and debuggable, not to profile anyone, and they age out on short retention windows.
The list that matters most.
Some things are off the table by design, not by policy alone.
We do not sell your data
Not your email, not your usage patterns, not aggregate "insights". No data broker has ever heard of you through us, and none will.
We do not run ad tracking
No advertising pixels, no retargeting, no cookies for tracking. The analytics we run are cookieless and cannot follow you anywhere else.
We do not train models on your content
Your workspace content is never used to train, fine-tune, or evaluate any machine learning model, ours or anyone else's.
We do not read your workspace content
Operator access to tenant infrastructure is limited to operations, support you request, and legal compliance. Browsing customer conversations is not an access category, full stop.
Why we are allowed to process what we process.
Where European data protection law (GDPR and equivalents) applies, we rely on the following bases:
- Consent: joining the waitlist. You gave us your email for one purpose and can withdraw at any time by asking us to delete it.
- Performance of a contract: authentication, billing, and hosting your workspace once you are a customer. We cannot provide the service without processing these.
- Legitimate interests: cookieless site analytics and operational logs, processed minimally to run and improve a service you asked for, in ways that do not override your rights.
- Legal obligation: the rare case where law requires us to retain or disclose specific records.
Data has a shelf life.
- Waitlist entries are kept until you become a customer or ask to be removed, whichever comes first.
- Workspace content is kept for as long as your subscription is active, and deleted within 30 days of cancellation. Backups rotate while it is active: the newest 14 are kept in object storage and older ones are pruned automatically.
- Billing records (subscription id and tier) are kept for the life of the subscription plus what tax and accounting law requires.
- Operational logs and metrics age out automatically on short retention windows measured in days to weeks, not years.
Access. Export. Delete. One email away.
You can ask us at any time to tell you what we hold about you, hand you a full export, or delete it. Email hello@hachiflow.com from the address in question and we will act on it promptly, and confirm when it is done.
For workspace customers, that means everything: your database with its signed messages, your files, your git repos, your keys, and your membership records, in full and in usable form. An operator packages it for you; there is no self-serve download yet. Deletion means your dedicated server and its R2 backups, completed within 30 days of cancellation. If you are in a jurisdiction that grants additional rights, such as rectification, restriction, or portability under the GDPR, those apply too, through the same email address.
EU servers, US company.
Workspace content is hosted on dedicated servers in Germany or Finland and backed up within Cloudflare's infrastructure. Hachiflow itself is a US company, and some subprocessors (Cloudflare, Stripe, WorkOS, DataFast) are US companies operating global infrastructure, so limited personal data such as your email address may be processed in the United States under those providers' safeguards.
The exact transfer mechanisms (standard contractual clauses and related safeguards) for each subprocessor are being documented as part of the pending counsel review noted above.
Who touches your data, and why.
The complete list. If it ever changes, this page changes first.
| Subprocessor | Purpose | Location |
|---|---|---|
| Cloudflare | Website hosting, waitlist storage (KV), welcome email delivery, backup storage (R2), operational observability | Global edge, US company |
| Hetzner | Dedicated workspace servers | Germany and Finland (EU) |
| Stripe | Payment processing | US, global infrastructure |
| WorkOS | Authentication (sign-in via Google, Microsoft, or email) | US |
| DataFast | Cookieless site analytics | Privacy-focused analytics provider |
When this page changes, you'll know.
We will update this policy as the service evolves, and the effective date at the top will change with it. If a change is substantive, meaning it affects what we collect or what we do with it, we will notify waitlist members and customers by email before it takes effect. We will not quietly weaken this policy.
Questions? A human answers.
Privacy questions, rights requests, or anything this page did not cover: email hello@hachiflow.com. During early access, the people answering are the people running your relay.