HHC Logo Remote Control Panel ← Back

Privacy Policy

Last Updated: September 6, 2026 • Effective Date: September 6, 2026
Privacy First & Zero Cross-Tenant Leakage: HHC operates a hosted, multi-tenant Model Context Protocol (MCP) gateway designed to connect user-authorized AI agents to their own explicit host machines. We never sell your personal data, inspect private command payloads for training, or share machine inventories across tenants.

1. Overview & Scope

This Privacy Policy describes how HHC ("we", "our", or "us"), accessible via https://hhc.zone and https://mcp.hhc.zone, collects, uses, and safeguards information when you register an account, enroll physical or virtual host machines, and integrate external AI clients (such as OpenAI ChatGPT, Anthropic Claude, OpenCode, or Cursor).

2. Information We Collect

  • Account & Identity Data: When you register or sign in via our federated identity providers (Google, GitHub, GitLab, or Discord), we receive your primary email address, public profile name, and unique provider subject identifier. We do not access your third-party repositories, cloud drives, or private messaging channels. If you register via email, your password is encrypted using salted scrypt hashes and is never stored in plaintext.
  • Host Machine Telemetry: When you enroll a device running the HHC Agent (Windows, Linux, or macOS), we collect canonical hardware metadata including OS platform, architecture, hostname, agent daemon version, and liveness status (heartbeat timestamps).
  • Cryptographic Device Keys: During enrollment, devices bind an asymmetric Ed25519 public key thumbprint. Private keys remain exclusively on your local host machines and never leave your environment.
  • Operations & Audit Logs: We log command execution timestamps, tool invocation identifiers, durations, and exit statuses to provide real-time dashboard telemetry and security audits. On-demand log content (log_read) is transiently streamed and is not retained in our database.

3. How We Use Your Information

  • To authenticate your identity and isolate your enrolled machines within your dedicated Workspace (Tenant).
  • To verify OAuth 2.0 authorization codes and issue cryptographically signed Bearer tokens for your selected AI MCP clients.
  • To route authorized JSON-RPC operations strictly to your own enrolled hosts with fail-closed security policies.
  • To deliver automatic over-the-air (OTA) agent security updates when enabled by your host policy.
  • To detect and prevent unauthorized cross-tenant probing, credential reuse, and system misuse.

4. Multi-Tenant Isolation & Zero AI Training

HHC enforces strict multi-tenant boundary isolation at the database, gateway, and transport layers:

  • External AI callers can only discover or execute tools on machines belonging to the authenticated tenant. Probing other machine IDs returns an opaque CLIENT_NOT_FOUND response.
  • We do not use your command outputs, filesystem content, or prompts to train machine learning or AI models. All tool execution payloads belong exclusively to you.

5. Third-Party Integrations & Sharing

We do not sell, rent, or trade your personal information. Data is shared exclusively under the following strict conditions:

  • Authorized AI Clients: When you grant OAuth consent to an AI assistant (such as ChatGPT or Claude), tool invocation payloads are communicated over TLS to execute commands on your authorized machines.
  • Federated OAuth Providers: Identity verification tokens are exchanged strictly to validate your login credentials with Google, GitHub, GitLab, or Discord.
  • Legal Requirements: We may disclose information only if required by valid law enforcement requests or applicable court orders.

6. Data Retention & Erasure

You maintain full control over your infrastructure data:

  • You can revoke connected AI clients (OAuth grants) at any time from your dashboard.
  • You can forget (uninstall) host machines from your tenant, which purges their device credentials and retained central telemetry.
  • Account closure requests permanently delete your user profile, memberships, and associated tenant records.

7. Data Retention Matrix

We keep each data category only as long as its purpose requires:

  • Account & identity: account lifetime.
  • OAuth identities: while linked; removed on disconnect.
  • Hosts & enrollment: while the host belongs to your workspace.
  • Audit trail: plan retention (Free 7 days, Dev 30 days, Cluster 90 days).
  • Usage ledger: billing retention while subscribed.
  • Support tickets: support policy duration.
  • Billing records: as required by financial law.
  • Security logs: security retention for abuse prevention.
  • Diagnostics bundles: short retention, only when you attach them.

8. Subprocessors

We use a minimal set of service providers, each only for its purpose:

  • Hosting provider: runs the HHC control plane and dashboard.
  • Payment provider: processes subscriptions (see Terms).
  • OAuth identity providers (Google, GitHub, GitLab, Discord): login only.

9. Security Safeguards

All communication between browsers, AI connectors, the HHC Control Plane, and edge host daemons is encrypted using TLS 1.3. Device authorizations utilize 60-second bounded Ed25519 digital signatures, preventing replay attacks and clock skew manipulations.

10. Contact Us

If you have any questions, privacy inquiries, or data deletion requests regarding this Privacy Policy, please contact our team:

Contact: GitHub Issues (privacy requests: in-dashboard support)
Official Domain: https://hhc.zone • https://mcp.hhc.zone

© 2026 HHC MCP Platform • • Privacy Policy • Terms of Service • Sign In