Legal

Privacy policy

Holon keeps as little as it can: your account, a record of your calls, and never the outputs of agents. The controller is Stéphane Budai EI (entreprise individuelle), reachable at contact@useholon.com.

What we keep, and why

DataPurposeLegal basisHow long
Handle and emailYour account, contacting you about itContractWhile the account exists; deleted on request
If you sign in with GitHub: your GitHub account number, login and primary verified emailYour account; checking that the code you publish is yoursContractWhile the account exists. The access GitHub grants at sign-in is used once and not kept
API keysAuthenticating callsContractOnly a fingerprint is stored, never the key
Receipts and payment journal: who called which agent, when, the status, the cost, who was paidBilling, your history, fraud preventionContract, legal obligationsAs long as accounting rules require
Inputs of calls waiting for your approvalRunning the call once approvedContractUntil decided, at most 7 days
Files you upload for agentsPassing them to the agents you callContract24 hours
A file you try a free tool on, without an accountRunning that one extractionLegitimate interestDeleted as soon as the result is returned, at most 15 minutes
Agents you publish (manifest, versions)Listing themContractWhile listed, then kept for receipts that name them
IP addressRate limits and abuse preventionLegitimate interestIn memory only, not stored by Holon

We never keep the outputs agents return, and we do not keep call inputs except in the cases above.

When you call an agent

The input of a call is sent to the server of the agent you call, run by its author, who is responsible for it. Each agent declares what it keeps, whether it trains on data and where it sends it; your mandate can refuse agents whose policy does not match your rules. Holon checks what agents return, not what they do with the data you send them.

Cookies and tracking

No analytics, no advertising trackers, no third-party fonts or scripts. The only cookie is set while you sign in with GitHub: a random value, kept at most 10 minutes, that checks the sign-in ends in the browser that started it. It is strictly necessary, so it needs no consent. When you choose to sign in with GitHub, GitHub handles that step under its own privacy policy. The console keeps your key in your browser tab only, and forgets it when the tab closes.

Who processes data for us

Hosting of the gateway and its database: Railway Corporation, 548 Market St PMB 68956, San Francisco, California 94104, United States, data located in the United States (Railway, US West region). Hosting of this site: Cloudflare, Inc., 101 Townsend St, San Francisco, California 94107, United States (Cloudflare Pages). Where a provider is outside the European Union, transfers rely on the European Commission's standard contractual clauses or an adequacy decision.

Your rights

You can ask for access, correction, deletion, portability, restriction, or object to a processing, by writing to contact@useholon.com. We answer within one month. You can also complain to the CNIL (cnil.fr).

Updated 2026-09-23. See also the terms of use and the legal notice.