Privacy Policy
Last updated: July 5, 2026
1. Controller
The controller of your data is Hito Labs. You can contact us at [email protected] for anything related to your privacy.
2. What data we collect
We collect only what is needed to provide the service:
- Account: your email and an encrypted (hashed) version of your password.
- Your activity in Hito: milestones and goals you create, and your focus sessions (duration, timestamps, associated milestone).
- Devices: technical identifiers needed to sync and for cross-device blocking.
- Technical data: basic usage and diagnostic information to keep the service running.
3. How we use it
We process your data to:
- create and manage your account;
- sync your milestones and sessions across your devices;
- run distraction blocking, including cross-device blocking;
- keep the service secure, prevent abuse and improve the product.
4. Legal basis
We process your data to perform our service contract with you (providing Hito), on the basis of your consent where we expressly ask for it, and on our legitimate interest in keeping the service secure and functional, in accordance with the GDPR.
5. Who we share it with
We do not sell your data. We rely on infrastructure providers that process it on our behalf, solely to operate the service:
- Render — hosting for the backend (application server).
- Neon — database (PostgreSQL) where your data is stored.
- Cloudflare — web delivery and network protection.
6. Retention
We keep your data while your account is active. If you delete your account, we delete or anonymize your personal data within a reasonable period, except what we must retain for legal obligations.
7. Your rights
You may exercise your rights of access, rectification, erasure, portability, objection and restriction of processing at any time. To do so, write to us at [email protected]. You also have the right to lodge a complaint with the competent supervisory authority (in Spain, the AEPD).
8. Security
Passwords are stored encrypted and communications travel over secure connections. We apply reasonable technical and organizational measures to protect your data, although no system is infallible.
9. Minors
Hito is not directed to anyone below the minimum legal age to consent to data processing in their country. We do not knowingly collect data from minors.
10. International transfers
If any of our providers processes data outside the European Economic Area, we ensure appropriate safeguards are in place under the GDPR (for example, standard contractual clauses).
11. Changes
We may update this policy. We will publish the current version on this page and, if the change is significant, we will notify you.
12. Contact
For any questions about your data, write to us at [email protected].