Privacy Policy
Last updated 2026-05-31. This describes how HodLLM handles your data. It is written to be accurate but is not a substitute for independent legal review before relying on it commercially.
What we collect
- Account: your email address (for magic-link sign-in) and your 18+ confirmation.
- Chat: the messages you send and the AI replies, grouped into sessions, kept so you can return to your conversations.
- Wallet & activity: token balance, the transaction ledger, and game history.
- Preferences: chat and display settings.
- Security: audit and rate-limit logs, including IP address and browser user-agent, to prevent fraud and abuse.
Why we use it (legal bases)
- To provide the service (performance of a contract): authentication, chat, wallet, games.
- Legal obligations: age assurance and keeping financial/transaction records.
- Legitimate interests: security, fraud prevention, and keeping the service reliable.
Who we share it with
We do not sell your data. We use a small number of processors to run the service:
- OpenRouter (and, through it, the AI model providers you choose): the contents of your chat messages are sent to generate replies. These providers may process the text outside the EU. Do not paste anything into chat you wouldn't want a third-party model provider to process.
- Resend: sends your magic-link sign-in emails.
- Payment providers (only if/when deposits are enabled): to process top-ups.
- Our hosting/database infrastructure.
How long we keep it
- Chats & preferences: until you delete them or your account. Chats you delete are purged for good within ~30 days.
- Security/audit logs: up to ~12 months, then deleted automatically.
- Financial records: retained as long as the law requires (e.g. accounting / anti-fraud), in anonymised form after account deletion.
Your rights
- Access & portability: download everything we hold about you from Account → Export my data.
- Erasure: delete your account from Account → Delete my account. This erases your chats, preferences and profile and anonymises retained financial records.
- Rectification / objection / restriction: contact us (below).
- Self-exclusion: available at any time from your account.
- Complaint: you may lodge one with your local data-protection supervisory authority.
Other
- We use only the cookies needed to keep you signed in — no advertising or third-party tracking cookies.
- Tokens have no cash value and never convert back to money.
Contact
Questions or requests: privacy@hodllm.com.