Privacy Policy
Last updated: 25 June 2026
This policy explains what information Hatchik collects, how we use it, and the choices you have — including what happens when you connect Hatchik to an AI tool such as Claude or Cursor so it can create and deploy projects on your behalf.
1. Who we are
"Hatchik" ("we", "us", "our") provides a hosting platform that lets you create and deploy applications and websites — including directly from AI coding tools via our connector. You can reach us about privacy at hello@hatchik.com.
Operating entity and registered address are listed at the end of this policy.
2. Information we collect
Account information
When you sign in (via Google), we receive your email address and basic profile (name, profile picture) from Google. We use this to identify your account and to determine your access level. We do not receive your Google password.
Authorisation tokens
When you connect Hatchik to an AI tool, we issue access (and refresh) tokens so that tool can act on your behalf. These tokens are stored only as irreversible hashes and can be revoked at any time. We never expose tokens back to the AI tool's chat.
Project & content data
To run your projects we store: project names and configuration, environment details, any custom domains you add, and the code, files and content you (or your AI tool) deploy. For application projects this also includes the data your app writes to its own database. This content is yours; we host it so your sites and apps can run.
Operational data
We keep technical logs needed to operate the service securely and reliably — for example timestamps, IP addresses, request and deployment events, and error logs. We use these to provision projects, detect abuse, and troubleshoot.
3. How we use your information
- To create, host, deploy and update your projects, and to keep them running.
- To authenticate you and authorise actions taken on your behalf by a connected AI tool.
- To issue TLS certificates for your custom domains and route traffic to your sites.
- To operate, secure, monitor and improve the service, and to prevent abuse.
- To contact you about your account, security, or important service changes.
- Where applicable, to process payments for paid plans.
We do not use your code, content, or project data to train AI models, and we do not sell your personal data to anyone.
4. The AI-tool connector
Connecting an AI tool (such as Claude or Cursor) uses the open Model Context Protocol with an OAuth 2.1 sign-in. In plain terms:
- You start the connection in your AI tool and approve it in your browser by signing in with Google.
- From then on, the AI tool can call Hatchik actions on your behalf — only the actions the connector exposes, and only for your own account and projects.
- You can revoke access at any time (see Your choices), which immediately stops the AI tool from acting on your behalf.
5. Service providers (sub-processors)
We share data only with the providers we rely on to deliver the service, and only as needed:
| Provider | Purpose |
|---|---|
| Sign-in / authentication (OAuth) | |
| Hetzner | Hosting infrastructure where your projects run |
| Cloudflare | DNS for Hatchik subdomains |
| Let's Encrypt | Automatic TLS certificates for your domains |
| Resend | Transactional and service emails |
| Paddle | Payment processing for paid plans (when applicable) |
We do not sell or rent your personal data, and we do not share it for advertising.
6. Data retention
We keep your account and project data for as long as your account is active. If a project is deleted, its hosting, database and files are decommissioned. If you close your account or ask us to delete your data, we remove your personal data and project content, except where we must retain limited records for legal, security, or accounting reasons. Operational logs are kept only as long as needed to run the service.
7. Your choices and rights
- Revoke AI-tool access — disconnect the connector in your AI tool, or contact us to revoke tokens, at any time.
- Access, correct, or delete — request a copy of your personal data, ask us to correct it, or request deletion.
- Delete projects — remove any project, which decommissions its hosting and data.
- Object or restrict — where applicable under your local law (e.g. GDPR), you may object to or restrict certain processing.
To exercise any of these, email hello@hatchik.com.
8. Security
We protect your data with measures including: encryption in transit (HTTPS/TLS) for the dashboard, the connector and your sites; hashing of authorisation tokens and credentials; per-project isolation of hosting and databases; and access controls on our infrastructure. No system is perfectly secure, but we work to protect your information and to respond quickly to any issue.
9. Cookies
The Hatchik dashboard uses a single, essential, signed session cookie to keep you logged in. We do not use third-party advertising or tracking cookies.
10. International transfers
Your data may be processed in the locations where our infrastructure and service providers operate. Where data is transferred across borders, we rely on appropriate safeguards as required by applicable law.
11. Children
Hatchik is not directed to children under 16, and we do not knowingly collect their personal data.
12. Changes to this policy
We may update this policy from time to time. We will revise the "last updated" date above and, for material changes, take reasonable steps to notify you.
13. Contact
Questions, requests, or concerns about this policy or your data: hello@hatchik.com.
Hatchik is operated by Namaa Solutions SPC, registered at Al Ghushbah, Sohar, North Al Batinah Governorate, Sultanate of Oman.