Security & Privacy
Your privacy and security are our top priorities. Here's how HAINT protects your data.
Core Security Principles
- Private Audio Routing: AI audio hints play strictly through safe private headphones or headsets. Output to laptop speakers is disabled by design.
- Real-Time Processing: Audio streams in real time via encrypted WebSocket TLS connection directly to our secure proxy service.
- 100% Local Storage: Optional per-turn session history and continuous Full Call Recordings are stored strictly on your local computer (in
%LOCALAPPDATA%/HAINT/History/) and never uploaded to cloud storage. - Secure Browser Authentication: Sign in securely via browser OAuth (Supabase Auth). Credentials and session tokens are managed securely via Windows Credential Manager.
How Data Flows
1. Audio Capture
When you press Shift or auto-start a session, HAINT captures system audio (WASAPI Loopback) and microphone input locally through an isolated subprocess.
2. Real-Time AI Processing
Audio is streamed over an encrypted WebSocket TLS proxy to AI models. Requests are processed in real-time without permanent cloud server retention.
3. Private Hint Delivery
AI responses are converted to speech on your device using Windows WinRT SpeechSynthesis and played privately into your headphones. Subtitles display on an optional floating overlay.
What We Store
- Account & Auth Data: Email address, subscription status, and Account Balance (stored securely via Supabase Auth)
- Payment Records: Balance top-ups and subscription transactions (processed securely via Telegram Stars)
- AI Secretary Context: Your personal context document edited in desktop Settings → Secretary (stored server-side to ground your async Telegram bot)
What We Don't Store on Cloud Servers
- Audio recordings of your calls or meetings
- Transcriptions or speech-to-text outputs of your sessions
- AI hints or suggestions generated during calls
- Full call audio archives (saved locally on your machine only)
Third-Party Services
HAINT integrates with the following third-party infrastructure:
Supabase Auth
- Used for secure OAuth browser login, JWT token verification, and account management
- See Supabase Privacy Policy
AI Model Providers
- Audio real-time processing and hint generation via secure proxy connections
- Included with your HAINT subscription / minute balance — no personal API keys required
Telegram Stars
- Purchases and balance top-ups are completed securely via Telegram Stars in Telegram
- We do not collect or store raw credit card numbers on our servers
- See Telegram Privacy Policy
Your Rights
You have the right to:
- Access & Manage: View your account balance and subscription details under Settings → Account
- Delete Account: Request full account and data deletion at any time
- Local Data Control: Delete or move your local history folder at any time under Settings → Saved Sessions
To exercise any account rights, please contact support.
Compliance
- GDPR & CCPA: We adhere to principles of data minimization and user data ownership
- SOC 2: Our core cloud infrastructure partners are SOC 2 certified
Security Contact
If you have security concerns or wish to report a vulnerability, please contact our support team.
We take all security reports seriously and respond promptly.