Privacy & data handling
Operational description of how Hido handles unpublished research code. Not a law firm letter; if your institution needs a signed DPA, contact the operators.
What we store
- GitHub account id / login for the console session
- Which App installations you granted, and which repositories you anonymized
- The term list you typed, commit SHA of the snapshot (console only — never on the reader origin)
- Anonymized artifacts on Cloudflare R2 under opaque repo ids
What we do not do
- No cookies or analytics on
hido.science
- No sale of repository contents
- No training ML models on your code
Retention
Published artifacts expire after the review window (default 120 days) unless you Update. Delete removes R2 objects and scrubs the source binding; the opaque id remains as a tombstone so it is never reused.
Security reports
See SECURITY.md in the project repository: private vulnerability reporting for de-anonymization channels and serving-origin regressions.