Privacy policy
Holon keeps as little as it can: your account, a record of your calls, and never the outputs of agents. The controller is Stéphane Budai EI (entreprise individuelle), reachable at contact@useholon.com.
What we keep, and why
| Data | Purpose | Legal basis | How long |
|---|---|---|---|
| Handle and email | Your account, contacting you about it | Contract | While the account exists; deleted on request |
| If you sign in with GitHub: your GitHub account number, login and primary verified email | Your account; checking that the code you publish is yours | Contract | While the account exists. The access GitHub grants at sign-in is used once and not kept |
| API keys | Authenticating calls | Contract | Only a fingerprint is stored, never the key |
| Receipts and payment journal: who called which agent, when, the status, the cost, who was paid | Billing, your history, fraud prevention | Contract, legal obligations | As long as accounting rules require |
| Inputs of calls waiting for your approval | Running the call once approved | Contract | Until decided, at most 7 days |
| Files you upload for agents | Passing them to the agents you call | Contract | 24 hours |
| A file you try a free tool on, without an account | Running that one extraction | Legitimate interest | Deleted as soon as the result is returned, at most 15 minutes |
| Agents you publish (manifest, versions) | Listing them | Contract | While listed, then kept for receipts that name them |
| IP address | Rate limits and abuse prevention | Legitimate interest | In memory only, not stored by Holon |
We never keep the outputs agents return, and we do not keep call inputs except in the cases above.
When you call an agent
The input of a call is sent to the server of the agent you call, run by its author, who is responsible for it. Each agent declares what it keeps, whether it trains on data and where it sends it; your mandate can refuse agents whose policy does not match your rules. Holon checks what agents return, not what they do with the data you send them.
Cookies and tracking
No analytics, no advertising trackers, no third-party fonts or scripts. The only cookie is set while you sign in with GitHub: a random value, kept at most 10 minutes, that checks the sign-in ends in the browser that started it. It is strictly necessary, so it needs no consent. When you choose to sign in with GitHub, GitHub handles that step under its own privacy policy. The console keeps your key in your browser tab only, and forgets it when the tab closes.
Who processes data for us
Hosting of the gateway and its database: Railway Corporation, 548 Market St PMB 68956, San Francisco, California 94104, United States, data located in the United States (Railway, US West region). Hosting of this site: Cloudflare, Inc., 101 Townsend St, San Francisco, California 94107, United States (Cloudflare Pages). Where a provider is outside the European Union, transfers rely on the European Commission's standard contractual clauses or an adequacy decision.
Your rights
You can ask for access, correction, deletion, portability, restriction, or object to a processing, by writing to contact@useholon.com. We answer within one month. You can also complain to the CNIL (cnil.fr).
Updated 2026-09-23. See also the terms of use and the legal notice.