HIVEBack to Hive →

Privacy policy

How Hive handles your data

Hive is a private messenger. We do not sell data, show no ads, use no trackers and do not train AI models with your content ourselves. We earn money with plans and credits, not with your data. This page explains what Hive processes, why, with whom and for how long.

1. Controller

Typhora Group LLC
Limited Liability Company (LLC), incorporated in Wyoming, USA
33 N Gould St, Sheridan, WY 82801, USA
Email: hey@typhora.group

You can reach us at this address for all questions about data protection. We have not appointed a data protection officer.

The representative in the Union within the meaning of Art. 27 GDPR, to the extent one is required by law, is Heinrich Songmin Berger, Barbarossaplatz 2, 50674 Cologne, Germany, hey@typhora.group.

2. Where your data is stored

Hive runs on Cloudflare, Inc. (USA). The database (Cloudflare D1) and the file storage (Cloudflare R2) are located in data centres in Western Europe. This is a location setting at Cloudflare, not a legal commitment to the EU. Individual requests to Hive are handled by the Cloudflare data centre closest to you, which may be outside the EU, for example when you travel. Typhora Group LLC itself is based in the USA.

As the provider of a messenger, we observe the secrecy of telecommunications (Section 3 TDDDG). We only process the content and circumstances of your communication to the extent necessary for the service or permitted by law.

3. Account and sign-in

All you need for an account is an email address. We store it together with your account number, language, plan and the times the account was created and last signed in. When you sign in, you confirm that you are at least 16; if you confirm that you are at least 18 before using a Google model for the first time, and when you agree to content being passed to AI providers (section 8), we store the time of each. Optionally, you add a display name, a username (handle) and a profile picture. Other members can see these three items, but they only find you through the people search if you leave discoverability switched on. We do not show your full email address to others. If you have set neither a display name nor a handle, Hive shows others the part of your email address before the @ sign as your name.

To sign in, we send you a six-digit code by email. For this we store your email address, language, the code only as a hash, the IP address of the request and the number of attempts. The code is valid for 15 minutes; we delete the record one day after it expires. When a code is redeemed, we log the IP address, browser identifier (user agent) and referring page without any link to your account and delete this log after 30 days. After that, a cookie keeps you signed in in the browser (section 12), and in the iPhone and Android apps a sign-in key in the app’s storage. For each session we store the identifier of the device (browser identifier). A session in the browser is valid for 30 days; in the apps it is valid for 90 days from the last use and at most one year from signing in. We delete it once it has expired, when you sign out on that device, when you choose “Sign out on all other devices” in Settings or when you delete your account.

The administrator account can also sign in with a password; we store failed attempts together with the email address entered for one day to slow down password guessing.

Legal basis: Art. 6(1)(b) GDPR (contract) for account, profile and sign-in; Art. 6(1)(f) GDPR for logs and limits against abuse, because we have a legitimate interest in a secure service.

4. Chats, media and location

Hive stores your chats, meaning one-to-one chats, frequencies (several separate chats with the same person), groups and your notes chat: messages, replies, reactions, images, videos, voice messages and files including the original file name and caption, plus delivery and read status. You share read receipts by default; you can switch them off in general or per chat. Our server can read messages outside Secret Chats so that it can deliver them and offer features such as translation. In transit they are encrypted with TLS. Media can only be retrieved by the members of the respective chat.

If you add someone by email address or handle, we only use what you enter to look the person up; what we store is the contact connection. The person receives a request they can accept or decline.

Hive only transmits a location if you explicitly share it: once, as a single point accurate to about one metre, without live tracking and never in Secret Chats. If you open the point in Google Maps, Apple Maps or OpenStreetMap, that map service receives the coordinates.

Deleting: You can delete your own messages for everyone; we delete the related media along with them. Disappearing messages (30 days at most) and the self-destruct of a one-to-one chat delete messages and media at the set time. “Delete chat for me” only hides the history for you; it remains stored for the other members. We store deletion requests to the other person together with their outcome.

Legal basis: Art. 6(1)(b) GDPR. Retention: until the message is deleted or expires, otherwise until you delete your account with “Delete everything” (section 15).

5. Secret Chats (end-to-end encryption)

You can turn a one-to-one chat into a Secret Chat if both sides have set this up. Messages are then encrypted and decrypted on your devices; our server only stores ciphertext and cannot read it. This applies only to Secret Chats, only to one-to-one chats and only to text: images, files, voice messages, locations and AI features are blocked there. What remains unencrypted and visible to us are the circumstances: who sends a message of what length in which chat and when, which message it replies to and who has read it. Reactions (emojis) and call entries are not end-to-end encrypted either.

Your private key is stored only in your browser. We store your public key so that others can write to you in encrypted form. If you wish, we store a key backup that is encrypted with your recovery code or passphrase; we cannot decrypt it. Without a backup and without your device, nobody, including us, can recover Secret Chat messages.

6. Calls, recordings and podcasts

Voice and video calls between two people run via WebRTC. Sound and picture travel encrypted between the devices; we do not hear or see them and do not store them unless you agree on a recording (see below). To set up the connection, your devices exchange their network addresses via our server, including their public and local IP addresses. The other person on the call receives these addresses on every call, even if the call then runs through a relay. The app uses Cloudflare (Cloudflare Realtime STUN and TURN) to discover addresses and as a relay; the relay sees your IP address and only forwards encrypted packets. If Cloudflare cannot be reached, the app also asks a public Google STUN server, which sees your IP address in the process.

Group calls do not run directly between the devices but via Cloudflare Realtime SFU, a relay service from Cloudflare: every device sends sound and picture encrypted to Cloudflare, where they are decrypted and forwarded encrypted to the other participants. Group calls are therefore not end-to-end encrypted. Cloudflare does not store sound or picture, and we do not hear or see them. Cloudflare sees the IP addresses of all participants; the other participants do not see your IP address. During the call we process who is in the call (name and profile picture), whether microphone and camera are on, who is speaking (your device detects this from the volume and only reports “speaking”, no sound) and which cameras you are viewing. If you treat everyone, everyone in the call sees your name with it; only you see your limit. So that nobody stays in a call after signing out or being removed from the group, the call checks every minute whether your sign-in and your membership still exist. The chat shows an entry when the call starts (“Group call started”) and one after the call with duration, number of people and who treated everyone, if anyone. If anyone paid with credits in the call, we also store for billing: who started the call, start and end, how many people took part, an estimate of the data traffic, for each paying person the amount charged and the share for others, and your consent before any costs arise with time and price or limit (section 9). For free calls we delete this information when the call ends; only the chat entries remain.

In the chat we store an entry about the call (answered or missed, duration, with or without video). So that we can fix connection problems, the app sends a technical report for every call between two people: browser identifier, type of connection (direct or via relay, without IP addresses), connection states, duration, amounts of data, audio and video quality and error messages. We delete these reports after 14 days.

Recordings and podcasts only happen if the caller chooses this when calling; the person being called sees it while the phone is still ringing. Each device only records its own microphone and, for video, its own camera, and uploads the recording as a message to your chat; section 4 applies there. If you merge a podcast on our server, a container at Cloudflare renders the recordings into one video; we cannot determine where this container runs. Its working files are deleted after the job, at the latest when the container shuts down after a few minutes without a job. The finished video is posted as a message in the chat. If you merge the podcast in your browser instead, the result stays on your device.

Legal basis: Art. 6(1)(b) GDPR; for the technical reports Art. 6(1)(f) GDPR (our legitimate interest in working calls); for the records of consent in group calls Art. 6(1)(f) GDPR (proof in case of queries and disputes).

7. Push notifications

If you switch on notifications, we store your browser’s push subscription (the address at the push service and the related keys), at most ten per account. For new messages and calls we send an encrypted notification with the sender’s name and a short note such as “sent you a message”, without message content. It is delivered via the push service of your browser vendor, for example Google, Apple or Mozilla. The service cannot read the notification, but it sees when something is sent to which device. We delete the subscription when you switch off notifications, sign out, the push service declares it invalid or you delete your account.

Legal basis: Art. 6(1)(b) GDPR.

8. AI features

AI features only run when you trigger them, and only after you have agreed once to content being passed to the providers listed below. You can withdraw this consent in Settings at any time; Hive will then ask again before the next AI feature. We then send the content required for this to the respective provider and receive the result. All requests pass through a Cloudflare node that is normally located in Western Europe; the providers therefore do not see your IP address. Content from Secret Chats and the coordinates of shared locations are never sent to AI providers. Members of a chat can also apply AI features to other members’ messages in that chat, for example to translate or summarise them or to turn a voice message into text.

We store generated images and videos, except the AI profile picture, with their description, model and format in your gallery until you delete them there or delete your account. If you send them to a chat, section 4 applies there. Your browser remembers your latest descriptions and models. For every request we record the feature, model and usage (section 9).

The providers process the data on our behalf and keep it for a period under their own terms, for example to detect abuse; according to their own statements this is usually up to 30 days for Anthropic and up to 30 days for images at OpenAI. For fal: for images, including the AI profile picture made from your photo, fal does not store the request and response and deletes generated and uploaded files after one day. For videos, fal deletes the generated files after 7 days; under its standard rules, fal may keep the request and response for up to 30 days there. Until they are deleted, the files are stored at fal under addresses that are hard to guess but publicly accessible. Some of the makers behind fal are based in China (ByteDance, Alibaba, Kuaishou).

Legal basis: Art. 6(1)(b) GDPR, because you trigger the feature. Where names and messages of other chat members are processed, Art. 6(1)(f) GDPR: you and we have a legitimate interest in the feature you trigger in a shared chat working.

9. Plans, credits and payment

For your credits we store the balance (monthly credits and bought credits), a transaction log (charges, credits returned after failures, purchases, refunds and chargebacks of packs, the monthly top-up and upgrades to a higher plan, each with feature and time) and, for every AI request, the feature, model and usage. For group calls with more than four cameras, the billing per call and the records of your consent are added (section 6); we keep both for three years, even if you delete your account. We use this to charge credits, return them after failures and manage our costs.

You buy plans and credit packs through the Stripe checkout. The sale is handled by Sold through Link, LLC (“Link”), a Stripe company, for us but in its own name and under its own responsibility as so-called merchant of record: Link collects the payment, remits the tax, sends receipts and invoices and handles questions about payment, subscriptions and refunds. You enter your payment details (such as card number or bank details), your name and your billing address only at the checkout with Stripe or Link. We never see your full card number or your Link login details. Our Stripe account does, however, store for each purchase your name, email address, billing address and country, your tax number if you provide one, the payment method and, for cards, card brand, last four digits and expiry date; we only use them for refunds, queries and proof. Stripe and Link are responsible for the payment processing itself, independently of us; their privacy policy applies: https://link.com/privacy.

We send Stripe your email address, your Hive account number and what you are buying. From Stripe we receive a customer number, the subscription ID, plan, billing period, status and any pending cancellation, the payment ID and notifications about refunds and chargebacks.

After every purchase we send you an email with the terms, the withdrawal notice and the model withdrawal form; we record that it has been sent together with your email address. If you cancel or withdraw via our pages that work without signing in (Terms, sections 7 and 8), we store the details you enter there (email address, name, contract and, for a cancellation, its type, requested date and reason, or, for a withdrawal, whether it concerns a subscription or a credit pack), the language, your account number if the address belongs to an account, the time of receipt, what happened automatically as a result, and your IP address to curb abuse. The confirmation of receipt goes to you by email, with a copy to us. We keep these records and the records of purchase confirmations for three years, even if you delete your account.

Legal basis: Art. 6(1)(b) GDPR; for cost control, for keeping proof of purchases (towards tax authorities and in disputes) and for the records of cancellations, withdrawals and purchase confirmations Art. 6(1)(f) GDPR. Retention: three years for the records, otherwise until you delete your account with “Delete everything”. With “Delete only my account”, this data remains attached to your account number without your email address for as long as we need it for refunds, chargebacks and proof. With “Delete everything”, we delete it, except for the records; Stripe and Link keep their records under their own obligations (section 15).

10. Reporting, blocking and security

If you block someone, we store this until you lift the block. If you report a person, a message, a group or an AI result, we store who reports, whom or what the report concerns (account, chat, message, file), the category, your description and the IP address of the report. So that the report can still be reviewed if the content is later deleted, we secure the reported message text, the group name, the description (prompt) of the AI image or the text of the reported AI result (such as a summary or translation, which may reproduce what others said). We cannot read the content of Secret Chats; there you only include the text if you tick the box for it. Reports are sent by email to our inbox (via Resend, section 13; if there are unusually many form reports, only as a summary), and a person reviews each one. If you report without an account via the report form on our help page, we store your description, where the content is located, your statement that the information is accurate to the best of your knowledge, your name if you provide it, and your email address for the confirmation of receipt (at most three per address and day), follow-up questions and our decision if you provide it, and the network of your IP address (for IPv6 shortened to the first 64 bits) to limit mass reports. The person reported does not learn who reported them. We delete reports after one year. If you delete your account, your own reports remain as proof without any link to you and without the IP address, and reports about you remain until their year has passed.

Suspensions: If we suspend an account, we store the time and the reason, end all sessions and send the person concerned the reason by email. The person who reported also receives our decision by email. The suspension remains stored until we lift it or the account is deleted.

Your feedback: If you send us a message via “Send feedback”, we store it with your account number, the type (bug, idea, praise, other) and technical details (app version, language, browser identifier, screen size, plan) and send it by email to our inbox so that we can read it and reply to you. No chat content is included. We delete it after one year or together with your account. The legal basis is Art. 6(1)(f) GDPR (improving Hive and replying to you).

To prevent abuse, we limit how often sign-in codes can be requested, people looked up, chats created and reports sent. For this we count these actions per account or IP address; we delete the counters for lookups after 24 hours. We check uploaded files by their content to determine the file type; the app only displays images, PDF, audio and video directly, everything else only as a download. We automatically check display names, handles, group and chat names and descriptions for AI images and videos against a list of prohibited terms. We do not scan messages or files automatically.

Technical error logs at Cloudflare may contain identifiers such as your account number and are kept for 7 days at most. Our database can be rolled back for up to 30 days to recover from errors (Cloudflare D1 Time Travel); deleted data may therefore remain in this history for up to 30 days.

If content indicates a criminal offence that threatens the life or safety of people, we inform the competent authorities (Art. 18 DSA). We only provide information to authorities where a law obliges us to do so.

Legal basis: Art. 6(1)(f) GDPR (a secure service free of abuse); Art. 6(1)(c) GDPR where the Digital Services Act or another law obliges us.

11. Our newsletter

If you sign up for our newsletter, we store your email address, language, source, time and IP address of the sign-up as proof and send you a confirmation email via Resend. You are only subscribed once you click the link in it (double opt-in); if you do not confirm, we send you nothing further and delete the sign-up after 30 days. The legal basis is your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time via the unsubscribe link in every email or by writing to us. After you unsubscribe, we keep the address marked as “unsubscribed” for three years so that we send you nothing more and can prove your earlier consent (Art. 6(1)(f) GDPR).

12. Cookies and browser storage

All of this is technically necessary for Hive to work the way you use and set it up (Section 25(2) no. 2 TDDDG); no consent is required for it. There are no advertising or analytics cookies. The data in browser storage stays on your device until you delete it in your browser; signing out does not delete it. On devices that are not yours, you should delete it after use. When you buy something, the Stripe checkout opens; Stripe’s cookies and rules apply there.

13. Recipients and transfers to third countries

We only pass on data where this is necessary for the feature in question. The following service providers process it on our behalf (Art. 28 GDPR):

The following receive data not on our behalf but under their own responsibility:

You can get a copy of the standard contractual clauses by writing to hey@typhora.group. You can find certifications under the Data Privacy Framework at https://www.dataprivacyframework.gov/list.

14. Retention at a glance

15. Deleting your account

You delete your account yourself in the app (Settings, “Delete account”), which takes effect immediately, or by email to hey@typhora.group. With both deletion options, we end running subscriptions at Stripe immediately, without refunding the remaining period; if this fails, the account remains and the app shows an error. Your monthly credits expire; unused bought credits are refunded on request (Terms, section 5). Ideally, write to us before you delete: after “Delete everything” we no longer have any data with which we can match your credits to you. We delete sessions, sign-in codes, push subscriptions, contacts, your profile picture, your feedback and your AI gallery with all images and videos.

In both cases, records of cancellations, withdrawals and purchase confirmations as well as the billing of paid group calls with the consents for it are kept for three years (section 9). What remains outside Hive: Stripe and Link keep their purchase data under their own rules and obligations; you can request deletion there from Link. The providers in sections 8 and 13 delete according to their own time limits. Deleted data remains in the database recovery history for up to 30 days. If you later sign in with the same email address, a new, empty account is created.

16. Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). You can withdraw consent at any time with effect for the future (Art. 7(3)). To exercise these rights, write to hey@typhora.group. You change your display name, handle, language, discoverability and profile picture yourself in the app; we change your email address on request. With “Export chat” you download up to 50,000 messages of a chat that you can still see in the app as a text file, the newest ones for longer chats (without images, videos and files); we send you a complete copy of your data on request.

Right to object

Where we process data on the basis of Art. 6(1)(f) GDPR (legitimate interests), you can object at any time on grounds relating to your particular situation (Art. 21 GDPR). We will then no longer process the data unless we demonstrate compelling legitimate grounds that override your interests, or the processing serves to establish, exercise or defend legal claims.

17. Right to lodge a complaint

You can lodge a complaint with any data protection supervisory authority, in particular in the EU country where you live or work or where the alleged infringement took place. In Germany, the Federal Commissioner for Data Protection and Freedom of Information (BfDI) is responsible for telecommunications services such as Hive: https://www.bfdi.bund.de.

18. Obligation to provide data, no automated decisions

We cannot create an account without an email address; all other information is voluntary. For purchases, Stripe and Link need your payment details. Automated decisions within the meaning of Art. 22 GDPR, including profiling, do not take place. Technical limits, for example on sign-in attempts, are not such decisions.

19. Changes

If Hive changes, we update this privacy policy. We inform you about material changes in the app or by email.

Last updated: 1 October 2026.

Legal noticePrivacyTermsCancel contracts hereWithdraw from a contract← Back to Hive