HONCHO — PRIVACY POLICY

SOC 2 Type II Verified by Delve

Effective Date: April 24 2025 | Last Updated: April 24 2025

This Privacy Policy explains how Plastic Labs, Inc. ("Plastic Labs," "we," "us," "our") collects, uses, discloses, and protects personal data when you or your end-users interact with Honcho—the cloud API, dashboard, and related services we operate (together, the "Services").

It is part of, and governed by, the Honcho Terms of Service. Capitalized terms not defined here have the meanings given in the Terms.

1. Information We Collect

CategoryExamplesSource
Account DataName, email, company, billing addressYou
Authentication DataAPI keys, OAuth tokens, hashed passwordsYou / automated
Usage DataRequest logs, IP address, user-agent, timestamps, error tracesAutomated
Customer ContentMessages, file uploads, embeddings, prompts and other data you or your end-users send to the API (may include personal or sensitive info)You / your end-users
Payment DataLast 4 digits of card, billing country, transaction IDsFlowglad (using Stripe as payment processor)
Marketing & AnalyticsNewsletter preferences, product-update clicks, PostHog event dataAutomated

We do not knowingly collect data about children under 13. You must not allow children under 13 to use the Services.

2. How We Use Information

PurposeLegal Basis (GDPR, if applicable)
Provide, secure and maintain the ServicesContract
Improve, debug and develop features (including non-public fine-tuning on de-identified data)Legitimate interests
Process payments and invoicesContract
Detect, prevent and investigate fraud or abuseLegitimate interests
Send product or marketing communications (you may opt out)Consent / Legitimate interests
Comply with legal obligations (tax, export control, court orders)Legal obligation

We never train public large-language models on Customer Content without your explicit opt-in.

3. Sharing & Sub-Processors

We use a small number of trusted vendors ("sub-processors") solely to operate the Services:

VendorFunctionPrimary Region*
SupabasePostgres DB & file storageUnited States (default)
Fly.ioAPI hostingGlobal anycast (primary US & EU)
FlowgladBilling & payments (using Stripe as payment processor)United States
GroqModel inference (optional)United States
AnthropicModel inference (optional)United States / EU
Google Cloud PlatformModel inference (optional)United States
VercelDashboard & docs hostingUnited States / EU
SentryError trackingUnited States
LangfuseObservability / monitoringUnited States
AWS (S3 / Glacier)Log-archive storageUnited States
PostHogProduct analyticsUnited States / EU

* "Primary Region" shows where each vendor initially stores or processes data. Some vendors operate globally-redundant systems; contact privacy@honcho.dev if you need region-specific guarantees.

Changes to sub-processors. We may add or replace a sub-processor. If the change materially affects how we handle personal data, we will notify account owners (e-mail or in-dashboard) before the new vendor goes live.

4. International Transfers

Our primary infrastructure is in the United States, so your information will be processed there regardless of your location. By using the Services, you acknowledge and consent to the transfer of your personal data to the United States and any other country where we or our sub-processors operate, as detailed in Section 7.5 of our Terms of Service.

If specific legal mechanisms are required for cross-border data transfers (such as the EU's Standard Contractual Clauses or the U.K.'s International Data Transfer Addendum), we will implement appropriate safeguards before accepting such data.

Plastic Labs has not yet self-certified to the EU-U.S. Data Privacy Framework. We will update this Policy if that changes.

5. Security

(Honcho is not yet SOC 2 or ISO 27001 certified; those audits are on our 2025 roadmap.)

6. Data Retention

DataDefault RetentionDeletion
Account & BillingWhile account active + 90 daysPurged after 90 days of inactivity
API Logs90 daysDeleted from AWS archive on day 91
Customer ContentConfigurable; default 90 daysImmediate hard-delete when you issue a "purge" call or delete a workspace
BackupsEncrypted snapshots for 90 daysOverwritten on rolling basis

You may request shorter retention via the dashboard or API where supported.

7. Your Privacy Rights

Depending on your location, you may have the following rights regarding your personal data:

RightDescriptionHow to exercise
Access / PortabilityObtain a copy of your personal data in a structured, machine-readable formatEmail privacy@honcho.dev
CorrectionUpdate inaccurate or incomplete informationUpdate profile or email support
DeletionRequest erasure of your personal data (subject to certain exceptions)Email privacy@honcho.dev → identity verified → completed within 30 days
Restrict / ObjectLimit how we use your data or object to certain processingEmail privacy@honcho.dev
Opt-out of marketingStop receiving marketing communicationsClick "unsubscribe" in any message
Opt-out of sales/sharingFor California residents: opt out of personal information sales or sharingVisit privacy settings in dashboard or email privacy@honcho.dev

We will not discriminate against you for exercising your rights.

8. California Privacy Rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) provides you with specific rights regarding your personal information:

To exercise these rights, please contact us at privacy@honcho.dev. We will verify your identity before responding to your request.

9. Cookies & Tracking

Our website and dashboard use the following cookies:

Visitors in the EU/UK will see a consent banner and can refuse non-essential cookies. We respect Global Privacy Control (GPC) signals from your browser.

We do not serve third-party behavioral advertisements or sell your data to advertising networks.

10. Children's Privacy

The Services are not directed to children under 13, and we do not knowingly collect their data. If we discover that we have inadvertently received such data, we will delete it.

11. Changes to This Policy

We post any changes here and, for material changes, notify account owners at least 30 days in advance. Continued use of the Services after the effective date constitutes acceptance of the revised Policy.

12. Contact Us

Plastic Labs, Inc.
169 Madison Avenue, STE 2703
New York, NY 10016 USA
privacy@honcho.dev | +1 (917) 773-8115

For European users: While we do not specifically target EU users, we welcome them to use our Services. Although we have not appointed a formal EU representative under GDPR Article 27, we remain committed to respecting EU privacy rights. Please contact us directly at privacy@honcho.dev with any EU-specific privacy inquiries.