Hivepod Privacy Policy

Effective date: May 18, 2026
Last updated: September 29, 2026

1. Who is responsible

Shenzhen Resopod Technology Limited Company (深圳市念舱科技有限公司) operates Hivepod and controls personal information processed for its accounts, membership, official Relay and managed speech services. Contact [email protected] or +86 186 2801 2255. Our registered address is 深圳市龙岗区布吉街道龙珠社区京南路24号金百信B栋408, China.

Hivepod iOS is a companion remote client for Hivepod Desktop on a computer you operate. Your desktop runs your chosen AI agents and tools. Hive does not operate a general-purpose conversational model. The optional Hive-managed speech service sends audio through our regional cloud service to a speech provider.

2. Data on your devices

Conversation history, project files, settings, skills and personas are stored on your devices. Selected messages, files, images and audio leave the phone when you use the sharing features described below. Your computer and third-party agents may retain their own copies. Deleting a Hive Cloud account does not delete files or conversations on your computer. Removing mobile pairing data or uninstalling the mobile app does not delete those desktop copies.

3. Tasks, files and your choices

Task messages, selected images/files and relevant conversation context go to your computer. Its AI agents and tools may forward them to configured providers, such as Anthropic, OpenAI, Moonshot, Alibaba, Tencent, xAI, Cursor or a custom service. Hive can describe configuration it manages, but cannot inspect all settings, extensions or endpoints managed directly by third-party agents. Review those services on your computer and their notices before sending content. They process information under their own terms; operating a remote client does not make Hive the operator of every service on your computer.

File transfers copy selected files to your computer. Files attached to an AI task may be processed by your configured agents and services. AI output may be inaccurate; verify it before relying on it.

4. Voice input

Mobile audio is sent over the encrypted connection to your desktop. The desktop uses the speech option you configured:

Transcription may include configured vocabulary and, when enabled on the desktop, limited draft/session context. These options are managed in desktop speech settings. In direct-send mode, the resulting text is subsequently sent to your desktop AI agent.

Hive-managed speech forwards audio and partial/final transcripts in memory for the request; Hive does not persist that content. We retain account/device references, request status, duration, usage/quota, timestamps and provider cost/request references to operate and reconcile the service. This is account-linked usage, even though no advertising analytics SDK is present.

Provider terms govern their own processing. See Soniox's privacy policy, Volcengine's privacy policy and ElevenLabs' privacy policy. Do not assume a promise about Hive's storage applies to a user-configured provider's asynchronous API or files.

5. Remote access and accounts

Phone-to-desktop application payloads are end-to-end encrypted. Our Relay cannot decrypt those payloads. You can use our regional official Relay, LAN, Tailscale or your own tunnel. Third-party tunnel providers have their own terms. The official CN Relay is hosted in Hangzhou; the international Relay is hosted in the United States. Servers and network providers necessarily handle IP addresses and connection metadata.

For authorization, our official Relay stores device public keys, activation/binding status, authorization timestamps and relevant labels or account associations. Membership-based device bindings are linked to your account. Legacy invitation-code authorizations may be independent of an account. Contact support to revoke an independent authorization. LAN and user-operated connection paths do not require a Hive membership or Relay invitation code.

An optional cloud account uses an email address and password. We store the email, a password hash, region, login sessions, device bindings, membership/entitlement records, usage and policy acknowledgment records. We do not request government ID or a phone number for this account. Registration and account management occur on the desktop or its browser flow; iOS does not have a separate registration screen. Managed features invoked from the phone still use the paired desktop's account.

6. Recipients and processing locations

We use infrastructure providers to operate requested services: Hetzner for international website and service hosting, with account and Relay services in the United States; Cloudflare for international web/API delivery and protection; Resend for international account emails; and Alibaba Cloud services for mainland hosting and account email delivery. Email providers receive the destination email and the message needed for verification. Regional speech recipients are described in section 4. These providers can process necessary service and security metadata under their applicable terms.

International services and mainland services maintain separate regional accounts. Data does not become EU-resident merely because you use the international region. Users in the EEA may have data processed outside the EEA, including in the United States or China depending on the chosen route. Where applicable, transfers and entrusted processing require appropriate contractual or other lawful safeguards. Contact us for information about the safeguards applicable to your service. User consent to a feature does not waive your statutory rights.

We do not sell personal information, use it for advertising or combine it with third-party data for cross-app tracking. We may disclose information where legally required. Distribution platforms process their own information under their own notices.

7. Retention and account deletion

Account and membership records are retained while needed to operate your active account. You can export account data or delete the account in desktop Account settings, or contact support for access, correction or deletion assistance.

On account deletion, we remove login identities (including email), password credentials and associated verification/desktop-login codes; revoke sessions, membership access and bound-device access; and clear consent IP addresses and device labels. Email can be registered again as a new account without restoring the deleted account's membership.

Limited pseudonymous account, membership and usage/security records are normally purged 90 days after deletion. If device access revocation or a metered operation remains unresolved, purging of the affected account records is postponed until that work is completed; these records are not reused to provide service or for marketing. Device keys needed for incomplete revocation are retained until it is resolved, and completed revocation payloads are scrubbed. Necessary financial/legal records, if separately required by law, are handled under their applicable obligations and are not represented as deleted by this account operation.

Expired email verification and one-time desktop-login codes are removed after one day; registration acknowledgment IP addresses are cleared after 30 days. These cleanups run through the service's periodic maintenance. Restricted database backups expire under the 14-day backup policy. Restoring a backup requires replaying deletion receipts before service resumes. An opaque account-ID deletion receipt is retained through purging and for 30 further days to prevent resurrection from supported backups. It contains no email, device key, IP or conversation content.

Your local files and independent third-party provider records remain under your control and the relevant provider's retention policy.

8. Legal bases and your rights

Where GDPR applies, necessary account, authentication, Relay and requested service processing is based on performing our service contract; proportionate security and abuse prevention relies on our legitimate interests; required recordkeeping relies on applicable legal obligations. Optional desktop diagnostics require a separate affirmative choice. Accepting terms or acknowledging this policy is not blanket consent to every purpose.

You may request access, correction, erasure, restriction, portability, objection and withdrawal of consent where applicable. Contact [email protected]. We respond within the applicable statutory period, normally one month for GDPR requests; permitted extensions and their reasons will be explained. You may complain to the competent data-protection authority. We do not use cloud account data for automated decisions producing legal or similarly significant effects.

9. Permissions, diagnostics and security

Camera access is used for pairing QR codes and images you choose to capture; photo access for chosen attachments; microphone access for voice input; and local-network access for your paired computer. The mobile app has no advertising, behavioral analytics or crash-reporting SDK.

Desktop crash/error reporting is separate and off by default. If enabled, it sends scrubbed stack traces, device/app context, an installation identifier and technical breadcrumbs to our self-hosted error service in mainland China, with the existing 30–90 day retention policy. Manual desktop feedback includes your description and a scrubbed log excerpt you can preview. Do not put secrets or private content into feedback. Disable automatic reporting in desktop Settings → Privacy or contact support regarding retained reports.

We use encrypted transport, access controls and password hashing. End-to-end encryption protects the phone-to-desktop channel, not a later transcription or AI-provider request. Device security and permissions of installed agents/tools remain important.

10. Children and websites

Hivepod is not directed at children. Follow the applicable App Store age rating and local consent-age requirements; we do not knowingly collect account information from children under 13. A guardian can contact us regarding a child's information. Website cookies and browser storage are subject to the relevant website notices; this mobile app does not use advertising cookies.

11. Changes

We publish revisions here and notify users of material changes as required. New purposes or recipient changes requiring permission are presented before further sharing. Continued use alone does not supply a new consent where law requires one.

12. Contact and filings

Controller: Shenzhen Resopod Technology Limited Company (深圳市念舱科技有限公司). Email: [email protected]. Phone: +86 186 2801 2255. Address: 深圳市龙岗区布吉街道龙珠社区京南路24号金百信B栋408, China.

Website ICP: 粤ICP备2026040915号-1. APP filing: 粤ICP备2026040915号-2A. Product/support: https://resopod.ai/products/hivepod/support and https://resopod.cn/products/hivepod/support.