Privacy Policy
Effective: May 30, 2026 · Last updated: May 30, 2026
1. Who We Are
Hyphan is operated by Miles Huffman, Chico, California, USA ("Hyphan," "we," "us," or "our"). This Privacy Policy describes how we collect, use, disclose, and protect information obtained through the Hyphan website, dashboard, daemon software, and inference API (collectively, the "Service").
For questions, data access requests, or legal notices related to this Policy, contact us at hello@hyphan.io.
2. Information We Collect
Account information: Your email address, collected when you create a Hyphan account. No name, address, or phone number is required to create an account or operate as a Compute Provider.
Hardware telemetry (Compute Providers only): The Hyphan daemon transmits the following to our servers on a continuous basis while active: GPU model, VRAM size, current GPU temperature, power draw percentage, current load status (active/idle), daemon version, and assigned node identifier. This data is used exclusively for: earnings calculation, network health monitoring, and safety limit enforcement. We do not collect keystrokes, clipboard content, browser history, file system contents, or any other data from your machine beyond the telemetry listed above.
Inference request metadata (API Customers): We log the following for each inference API request: API key identifier (hashed), model requested, token counts (input and output), request latency, and timestamp. We do not log or persistently store the content of inference requests or responses. Prompts and completions are routed through the network in memory and returned to the caller without being written to disk or a database.
Financial information: When you initiate a payout as a Compute Provider, Stripe collects and processes your bank account details, tax identification information (W-9 for US persons, W-8BEN for non-US persons), and identity verification documents. Hyphan does not receive or store your bank account numbers, Social Security Number, Employer Identification Number, or other sensitive financial identifiers — this data is held exclusively by Stripe under their own privacy policy and is subject to their PCI DSS compliance program.
Usage and log data: Standard web server logs including IP address, browser user-agent, referring URL, and pages visited, retained for up to 90 days for security monitoring and debugging. We do not use this data for advertising or behavioral profiling.
Communications: If you contact us by email, we retain that correspondence to resolve your inquiry and to improve the Service.
3. How We Use Your Information
We use the information we collect for the following purposes:
- To provide, operate, and maintain the Service, including calculating and disbursing earnings to Compute Providers.
- To authenticate users and authorize API access.
- To monitor the health, safety, and performance of the compute network.
- To detect, investigate, and prevent fraud, abuse, and violations of our Terms of Service.
- To send transactional communications, including sign-in magic links, payout notifications, and important service announcements. We do not send marketing emails without your explicit opt-in.
- To comply with applicable legal obligations, including tax reporting requirements and responding to lawful government requests.
- To improve and develop the Service based on aggregated, anonymized usage patterns.
We process your personal data on the following lawful bases under the GDPR: contract performance (providing the Service you signed up for); legitimate interests (security, fraud prevention, network integrity); and legal obligation (tax compliance, responding to lawful requests).
4. Information We Share
We do not sell your personal data to any third party, ever. We do not operate advertising networks or share data for behavioral advertising purposes.
We share information only in the following limited circumstances:
- Stripe: Payment processing, identity verification, and tax compliance for provider payouts. Privacy policy ↗
- Supabase: Database and authentication infrastructure, hosted on AWS us-east-1. Privacy policy ↗
- Vercel: Web hosting, edge delivery, and serverless function execution. Privacy policy ↗
- Google Cloud Platform: Gateway compute (Cloud Run) and model file storage (Cloud Storage, us-central1). Privacy policy ↗
We may also disclose information if required by law, regulation, legal process, or governmental request; to enforce our Terms of Service; to protect the safety of any person; or in connection with a merger, acquisition, or sale of substantially all of Hyphan's assets (in which case we will notify you before your data is transferred and becomes subject to a different privacy policy).
API marketplace confidentiality: Compute Providers are never identified to API marketplaces, enterprise customers, or any demand-side party. Inference traffic appears as originating solely from Hyphan. Provider identities are not shared with any party outside Hyphan.
5. Cookies and Local Storage
We use browser cookies strictly for session management (Supabase authentication tokens, set as HTTP-only, Secure, SameSite=Lax). We use localStorage to persist your dashboard state between page loads. We do not use tracking cookies, third-party analytics cookies, or advertising cookies. Our site does not load any third-party tracking scripts.
6. Data Retention
We retain your personal data for as long as your account is active and for a reasonable period thereafter to comply with our legal obligations, resolve disputes, and enforce our agreements.
Specifically: account and earnings data are retained for the life of your account plus 7 years (to satisfy tax record retention requirements); hardware telemetry data older than 13 months is automatically purged; server log data is retained for 90 days; inference request metadata (token counts, latency) is retained for 24 months for billing and auditing purposes.
If you delete your account, we will delete or anonymize your personal data within 30 days, except for records we are required to retain by law (such as Stripe transaction records for tax compliance, which Stripe retains under their own retention policies).
7. Your Rights
Depending on your jurisdiction, you may have the following rights with respect to your personal data:
- Right of access: to receive a copy of the personal data we hold about you.
- Right to rectification: to correct inaccurate or incomplete data.
- Right to erasure ("right to be forgotten"): to request deletion of your data, subject to legal retention requirements.
- Right to data portability: to receive your data in a structured, machine-readable format.
- Right to object or restrict processing: to object to or request restriction of certain processing activities.
- Right to withdraw consent: where processing is based on consent, to withdraw that consent at any time.
To exercise any of these rights, email hello@hyphan.io. We will respond within 30 days. We may require identity verification before processing your request.
California residents (CCPA/CPRA): Hyphan does not sell or share personal information as those terms are defined under the California Consumer Privacy Act. You have the right to know what personal information we collect, the right to delete, and the right to opt out of sale (not applicable — we do not sell data). To exercise these rights, contact us at the address above.
EU/UK/EEA residents (GDPR): If you are located in the European Union, United Kingdom, or European Economic Area, you have the right to lodge a complaint with your local data protection authority if you believe we have processed your personal data in violation of applicable law.
8. International Data Transfers
Hyphan is operated from the United States. If you access the Service from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States and other countries where our service providers maintain facilities.
For transfers of personal data from the EEA, UK, or Switzerland to the United States, we rely on Standard Contractual Clauses (SCCs) incorporated into our agreements with sub-processors where required. Our primary sub-processors (Stripe, Supabase, Vercel, Google Cloud) each maintain their own cross-border transfer compliance mechanisms.
9. Security
We implement commercially reasonable administrative, technical, and physical safeguards to protect your personal data, including: TLS 1.3 encryption for all data in transit between the Hyphan Node and our servers; encryption at rest for database storage; HTTP-only and Secure flags on all session cookies; hashed storage of API keys (plaintext is never stored); and access controls limiting employee access to personal data on a need-to-know basis.
Authentication is passwordless — we use magic links delivered to your registered email address. We do not store passwords in any form.
In the event of a data breach that is likely to result in a high risk to your rights and freedoms, we will notify you and applicable regulatory authorities within the timeframes required by applicable law (72 hours under GDPR where we are the data controller).
No security system is impenetrable. We cannot guarantee that unauthorized third parties will never be able to defeat our security measures or improperly access your data.
10. Children's Privacy
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected personal information from a child, please contact us immediately at hello@hyphan.io and we will take prompt steps to delete such information.
11. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last updated" date at the top of this page and notify active users by email at least 14 days before the change takes effect. Your continued use of the Service after the effective date of the revised Policy constitutes your acceptance of the changes.