§Legal
Privacy Policy
What we collect, why, where it is stored, who processes it, and how to ask us about it. Written to describe how Horme actually works today.
Draft. This page is waiting for founder and legal review and is not yet in effect. Items marked TODO or Legal review are unresolved.
Summary
- Horme is in private beta. On the public website, the only personal information we ask for is your email address, if you join the waitlist.
- If you use the Horme app during the private beta, we store your account email, the projects and tasks you create, and records of agent runs. Run records can include excerpts of your source code, file paths, commands, and command output.
- Coding agents such as Claude Code and Codex run on your computer under your own accounts with Anthropic and OpenAI. What those agents send to their providers is governed by your agreements with those providers.
- A small number of service providers host Horme for us. They are listed on Subprocessors.
- The website sets no cookies and uses no analytics or advertising tools. We do not sell personal information.
Who operates Horme
Horme is operated by TODO: launch blocking, legal name of the operator and its business address. To be added once the business is formally established., based in Ontario, Canada. In this policy, "Horme", "we", and "us" mean that operator.
Our Privacy Officer is accountable for how Horme handles personal information. You can reach the Privacy Officer at hello@usehorme.com.
What this policy covers
This policy covers the Horme website at www.usehorme.com, the waitlist, the Horme web app offered in private beta, and the Horme runner, which is the program you install on your own computer to connect it to Horme.
It does not cover services you use alongside Horme, such as Claude Code, Codex, GitHub, or your own computers and repositories.
Information we collect through the website
The waitlist
When you join the waitlist, we store:
- your email address
- that the signup came from the website
- the time of the signup, as reported by your browser and as recorded by our database
We do not ask for your name, company, or any other details. We use your email address only to contact you about access to the Horme early beta. Founder to confirm
Visiting the website
The website is a set of static pages. It does not set cookies, does not use local storage, and does not use analytics, advertising, or tracking tools. Its fonts are served from our own site.
Our hosting provider, Vercel, processes the technical information needed to deliver pages, such as your IP address, browser details, and the page you request, and may keep it in its logs for operations and security.
Email you send us
If you email us, we receive your email address and whatever you include in the message. Our email is hosted by Hostinger.
Information we collect in the Horme app
The Horme app is available only to private beta users. If you use it, we collect the following.
| Category | What we store | Where it comes from |
|---|---|---|
| Account | Your email address. Sign in is handled by Supabase Auth, our authentication provider, which stores a password hash. Horme does not receive or store your plaintext password. | You, when you sign up |
| Connected computers | Each computer's hostname, operating system type, runner version, how many runs it may run at once, and which coding agents are installed and signed in, with their versions | The runner, when you pair a computer and regularly while it runs |
| Runner access | One time pairing codes, and a one way hash of each runner's access token. The token itself stays on your computer. | The app and the runner |
| Projects | Project names, the path of each repository on your computer, and repository check results, which can include file paths | You, and the runner |
| Tasks | Task titles, prompts, acceptance notes, standing instructions, and references such as file paths, links, and snippets you paste | You |
| Runs | Status and timing; the agent's summary and completion report; failure reasons, which can include short excerpts of error output; counts of files and lines changed; token counts and cost where the agent reports them; branch names and commit identifiers; and technical details such as agent version, model, permission mode, session identifier, and working folder paths on your computer | The runner |
| Run activity | Messages from the agent, commands it ran, summaries of tool use, excerpts of tool and command output, the paths of files it changed, and short excerpts of the agent's raw events. These excerpts can contain your source code, the contents of files, and any secrets that appear in them. | The runner, while a run is active |
The runner does not upload your whole repository, and it does not upload full diffs. It does upload the excerpts described above. They are limited in size, but they can still contain sensitive content. Keep secrets out of task prompts and references, and remember that agents may read files that contain secrets.
We do not collect or store your Claude Code or Codex sign in credentials. To check whether an agent is signed in, the runner runs the agent's own status command and keeps only whether you are signed in.
Coding agents and AI providers
Horme starts Claude Code and Codex on your computer. They run under your own accounts with Anthropic and OpenAI. When a task runs, the agent receives the instructions Horme assembles from your prompt, acceptance notes, references, and standing instructions, and it can read files in the repository you connected. The agent sends that content to its provider to do the work.
Horme's cloud service does not directly send your task content to Anthropic or OpenAI in the current local execution model. The local Horme runner passes the assembled task to Claude Code or Codex on your computer, and those applications may send prompts, repository content, and other information to their provider under your own account and agreement with that provider. Anthropic and OpenAI are not service providers to Horme, and their handling of information they receive is governed by your own agreements with them, not by Horme. Horme is independent and is not affiliated with or endorsed by Anthropic or OpenAI.
Concurrent runs may use separate Git worktrees, which keep each run's git state separate. Git worktrees are not a filesystem security sandbox. Depending on the coding agent and the operating system permissions of your account, an agent process may technically be able to read files outside its assigned worktree that your operating system user can access. Horme does not currently provide filesystem isolation.
How we use information
- To provide the Horme app: show your projects, tasks, and runs, send work to your runner, and record what happened.
- To keep accounts and runners secure, investigate problems, and prevent abuse.
- To contact you about early beta access if you joined the waitlist.
- To answer messages you send us.
- To meet legal obligations.
We do not sell personal information, use it for advertising, or use your task content, source code, or run records to train AI models.
Consent
We collect, use, and disclose personal information with your consent, which you give by joining the waitlist, creating an account, or using the app as described in this policy, or as otherwise permitted or required by law. You can withdraw your consent at any time by contacting us, subject to legal or contractual limits. If you withdraw consent for the app, we may not be able to keep providing it to you. Legal review
How we share information
We share personal information only with:
- service providers that host and run Horme for us, listed on Subprocessors, which process it on our behalf
- authorities or others when the law requires it, or when needed to protect the rights, safety, or security of Horme, our users, or the public
- a successor organization if Horme is merged, acquired, or restructured, under the protections of this policy Legal review
Where information is stored
The Horme database, which holds waitlist entries and all app information described above, is hosted by Supabase in the United States, in the Amazon Web Services US East region. Vercel delivers the website through a global network, so page requests may be processed outside Canada. Email you send us is handled by Hostinger. TODO: confirm where Hostinger stores email for this account
Information stored or processed outside Canada is subject to the laws of those countries, which may allow authorities there to access it. Legal review
How long we keep information
- Waitlist entries. We keep them until you ask us to remove you, or until we no longer need them to offer early beta access.
- App information. We keep it until you delete it in the app or ask us to delete your account. Deleting a project deletes its tasks, runs, and run activity. Deleting a task deletes its runs and run activity. Removing a computer removes its agent records but keeps the records of past runs. There is no automatic deletion schedule yet.
- Backups and logs. Our providers may keep backups and logs for a period after deletion under their own practices. TODO: record the Supabase backup retention for the current plan
- Email. We keep messages as long as needed to respond and to keep a record of the conversation.
How we protect information
We use safeguards suited to the sensitivity of the information. They include row level security so that each account can read only its own data, runner access tokens stored only as one way hashes, and privileged database credentials kept on our servers. The Security page describes them. No method of storing or transmitting information is completely secure, and we cannot guarantee that information will never be accessed without authorization.
Your choices and requests
You can ask us to:
- tell you what personal information we hold about you and how we use it
- correct information that is inaccurate
- delete your account or remove you from the waitlist
- withdraw your consent
Email the Privacy Officer at hello@usehorme.com. During the private beta we handle these requests by hand, and we may need to confirm your identity first. The app does not have self serve account deletion yet. We will respond within the time required by applicable law. Legal review
Marketing email
We do not send newsletters or promotional email. If we start, we will ask for your consent where the law requires it, identify Horme in every message, and include a working way to unsubscribe. Messages needed to run your account, such as security notices, are not marketing.
Cookies
The website does not use cookies. The Horme app uses one essential cookie to keep you signed in. See Cookies for details.
Children
Horme is intended for adults. You must be at least 18 years old to join the waitlist or use Horme, and we do not knowingly collect personal information from anyone under 18. If you believe a minor has given us personal information, contact us and we will delete it. Legal review
Questions and complaints
Please contact the Privacy Officer first at hello@usehorme.com. If you are not satisfied with our response, you can contact the Office of the Privacy Commissioner of Canada. Legal review
Changes to this policy
We will update this page when our practices change and change the last updated date above. If a change materially affects how we use information you already gave us, we will tell you before it takes effect and ask for your consent where the law requires it.
Contact
Privacy Officer, Horme
hello@usehorme.com
Horme