Effective 30 August 2026
From our Privacy Statement, verbatim: we do not sell your data, share it between customers, use it to train AI models, or use it for advertising. Running a review does send your prompt text to third-party AI providers, under their own API terms and solely to generate your review.
The AI providers currently include Anthropic and Google, and models reached through OpenRouter (an aggregator that routes to further providers, such as Z.ai). We change providers and models over time as we tune quality, cost, and availability. The Service runs on Supabase (database and sign-in), Vercel (hosting and cookieless site analytics), Render (hosting), and Google (sign-in). Your data is stored and processed primarily in the United States.
Access is decided by workspace membership, not by who managed to sign in. Anyone with a Google account can authenticate; what they can then see is governed by an explicit membership record mapping an email address, or a whole company domain, to one workspace. A signed-in person with no membership sees nothing at all - not an empty version of someone else's workspace, but no customer data whatsoever. Every data route and every page re-checks this server-side and fails closed, so a missing or unreadable membership denies access rather than granting it. Whole-domain grants reject public email providers, so no one can claim a workspace by signing up with a consumer address.
Keys for the MCP server and the Git Action are minted per person and shown once. We store them to validate requests; our own operator tools display only a one-way fingerprint, never the key, so a key cannot be recovered from a screen or a screenshot. Disabling a key takes effect on its next request, with no cache to wait out. If a key is exposed, tell us or disable it yourself and mint a new one - we never re-enable an exposed key.
The Git Action reports counts about each run - how many files it reviewed, skipped, or suppressed - so we can measure the service. Those reports carry no prompt content, no diffs, and no file bodies. The prompt text itself is sent only when you ask for a review of it.
From Settings you can delete a workspace, all of your organisation's data, or your whole account, at any time, without asking us. Deleting a workspace or your organisation's data removes that content from our live systems. Deleting your account removes your personal data and access, and anonymises your email address on work your team keeps. Backups age out on their normal cycle. Deleting an organisation also disables its API keys.
Hosho is an early-stage product and we would rather you hear this from us than discover it in a questionnaire: we do not hold a SOC 2 or ISO 27001 certification, we do not publish a third-party penetration test, and we do not offer a contractual uptime SLA. If your procurement needs any of these, email otto@hoshoai.com and we will tell you honestly where we are and what we can commit to.
Email otto@hoshoai.com with what you found and how to reproduce it. We will confirm receipt, keep you updated while we fix it, and credit you if you would like us to. Please do not run automated scans against production or access data that is not yours.