Privacy Policy
Effective date: September 25, 2026
This Privacy Policy explains how Tachara LLC collects, uses, discloses, and retains information when you use the HiddenPro AI website, account and billing portal, and Windows desktop application (collectively, the “Service”). Tachara LLC operates the Service from the United States.
Our separate Terms and Conditions govern your use of the Service.
1. Scope and our role
This Policy applies to information Tachara LLC processes for the Service. It does not apply to a third-party website or service you visit independently. When we send content to a provider to perform a requested function, that provider may also process the content under its own terms and privacy notice.
If you use HiddenPro through an employer or another organization, that organization may have separate rules for its devices, accounts, meetings, and information. Ask that organization about its practices.
2. Information we collect
Information you provide
- Account data: email address, a password stored on our server as a one-way hash, password-reset data, and sign-in status.
- Payment and plan data: Stripe customer, checkout, payment or subscription identifiers; plan status; access dates; and query usage. Stripe processes full payment-card details, and we do not store full card numbers.
- Content: prompts, screenshots, audio, transcripts, meeting text, work-context or professional-profile text, and AI responses processed when you use the relevant feature.
- Communications: feedback, support emails, attachments you choose to send, and marketing-email preferences.
Information collected automatically
- Usage data: query and AI-call counts, plan limits, billing-period resets, feature activity, and application version.
- Device and trial data: a random install identifier and a one-way machine hash derived from device characteristics for lifetime trial enforcement. We also store hashed IP information associated with anonymous trials.
- Network and security data: IP address, approximate city/country derived from IP, timestamps, request metadata, browser or desktop user agent, authentication events, and abuse or block-list signals.
- Website analytics: page views and related browser, device, referral, and cookie or similar identifier data collected through Google Analytics.
- Email engagement: for marketing campaigns, whether an email was opened, a tracked link was used, and whether the recipient unsubscribed.
Information from other sources
We receive payment and subscription status from Stripe, email-delivery events from Resend, and approximate location information from IP-location services. We may also receive information from a person who contacts support about an account or use of the Service.
3. How desktop content is handled
The desktop app uses both local storage and online processing:
- AI processing: text prompts, relevant conversation context, professional-profile text, screenshots, and transcripts are sent through our authenticated server proxy to OpenAI to produce the requested output.
- Speech transcription: recorded microphone or system-audio segments are sent through our server proxy to OpenAI for speech-to-text processing.
- Local meeting records: meeting transcripts, summaries, session history, settings, and work-context text are stored on the PC. Meeting records remain until you remove them; clearing Meeting History clears the session-history view.
- Local media: staged screenshots are stored temporarily beside the portable app and are removed after successful analysis or when you clear them. They may remain after an error so you can retry. The app can also save a local
voice_recording.wavfile. - Local logs:
api.logand a bounded session-history file are stored beside the Windows executable. Secret-like values are automatically redacted, but logs may still contain account, prompt, transcript, or response details. - Saved sign-in: if credentials are saved on Windows, the password is protected locally with Windows Data Protection API (DPAPI) where available.
HiddenPro does not automatically upload local meeting-history files or support logs to our support team. They leave your PC only when required for an online feature or when you choose to send them. Avoid entering Social Security numbers, financial credentials, health records, trade secrets, or other sensitive content unless you have authority and a genuine need to process it.
4. How we use information
We use information to:
- provide authentication, transcription, AI responses, meeting summaries, downloads, updates, and support;
- administer trials, query allowances, purchases, subscriptions, and account deletion;
- secure the Service, detect fraud and abuse, enforce our Terms, and troubleshoot failures;
- measure website performance and understand how public pages are used;
- send account, security, payment, product, and marketing communications and honor unsubscribe requests;
- comply with law, preserve legal claims, and protect users, Tachara LLC, and others; and
- create aggregated or deidentified statistics that are not reasonably linkable to an individual.
We do not use the contents of your meetings to make decisions about employment, credit, housing, insurance, education admission, or another legally significant decision about you.
5. How we disclose information
We disclose information only as reasonably necessary for the purposes described above, including to:
- OpenAI for AI generation and speech transcription;
- Stripe for checkout, payments, subscription management, fraud prevention, and billing support;
- MongoDB and our hosting provider for account, entitlement, trial, release, and operational data storage;
- Resend for transactional and marketing email delivery and related delivery events;
- Google Analytics for public-website analytics;
- IP-location services for coarse city/country information used for security and administrative reporting;
- professional advisers, authorities, or other parties when reasonably necessary to comply with law, enforce agreements, investigate misuse, or protect rights and safety; and
- a successor or transaction participant in a merger, financing, reorganization, acquisition, bankruptcy, or sale of all or part of our business, subject to appropriate safeguards.
We do not sell personal information for money. We do not use personal information for cross-context behavioral advertising. We do not knowingly sell or share the personal information of anyone under 16. If these practices change, we will update this Policy and provide any choice required by law.
6. Retention and deletion
We keep personal information for the period reasonably necessary to provide the Service, administer an account or purchase, meet tax and accounting requirements, prevent abuse, resolve disputes, enforce agreements, and comply with law. Retention varies by record and context.
- Marketing-email tracking tokens are configured to expire after approximately 90 days.
- Password-reset links expire after approximately one hour; short-lived desktop session credentials expire or are refreshed on a limited schedule.
- When you delete an account from the dashboard, the active account is removed and any recurring Stripe subscription associated with it is canceled. A restricted deleted-account record and transaction records may remain where reasonably necessary for fraud prevention, accounting, legal compliance, or legal claims.
- Local desktop files remain on your PC until you clear or delete them, remove the portable app data, or uninstall the app. Uninstalling may not remove files kept outside the installer-managed directory.
- Service-provider copies and backups may persist for their normal backup, security, and legal-retention periods.
7. Your privacy rights and choices
Depending on your state of residence and whether a particular law applies, you may have the right to:
- confirm whether we process your personal information and access or obtain a copy of it;
- correct inaccurate personal information;
- request deletion, subject to legal exceptions;
- receive certain information in a portable format;
- opt out of sale, targeted advertising, or certain profiling where applicable;
- limit certain uses of sensitive personal information where applicable;
- appeal a denied request where state law provides that right; and
- not receive discriminatory treatment for exercising a privacy right.
Submit a request to info@hiddenproai.online using the email associated with your account. We may verify your identity and authority before responding. An authorized agent may submit a request where permitted by law, but we may require proof of authorization and direct verification with the account holder. If we deny a request, reply to our decision with “Privacy Appeal” in the subject line.
You may delete your account from the web dashboard, clear local history in desktop Settings, remove staged screenshots with Clear All, manage cookies through your browser, and unsubscribe from marketing email using the link in the message. Transactional or security messages may continue after a marketing opt-out.
8. California notice at collection
This section supplements the rest of this Policy for California residents. In the preceding 12 months, we have collected the categories below. Whether the California Consumer Privacy Act (CCPA) applies to Tachara LLC or a particular request depends on the law’s scope and exemptions.
- Identifiers: email, account and payment-provider IDs, IP address, install ID, machine hash, cookie identifiers, and similar identifiers.
- Customer and commercial information: plan, purchase, subscription, entitlement, query allowance, and support history.
- Internet or electronic activity: website activity, application and feature usage, interactions with marketing email, logs, and security events.
- Approximate geolocation: city and country inferred from IP address. We do not request GPS location.
- Audio, visual, and communications content: audio segments, transcripts, screenshots, prompts, feedback, and AI responses you choose to process.
- Professional information: resume or work-context information you choose to enter for personalized responses.
- Sensitive personal information: account sign-in credentials and content of communications, plus any sensitive information you voluntarily include in submitted content. We use this information to provide and secure the Service, not to infer characteristics about you.
We collect these categories from you, your device or browser, and the providers described in Section 2. We use them for the purposes in Section 4 and disclose them to the categories of recipients in Section 5. We do not sell these categories for money or use them for cross-context behavioral advertising. California residents may request to know, access, correct, or delete covered information and may exercise the other rights listed in Section 7, subject to exceptions.
Because we do not sell or share personal information for cross-context behavioral advertising, the site does not currently provide a “Do Not Sell or Share My Personal Information” link. We do not currently respond differently to browser Do Not Track signals. Where legally required, we will treat a qualifying opt-out preference signal such as Global Privacy Control as a request for the activity to which it applies.
9. Security
We use administrative, technical, and organizational safeguards designed for the nature of the information, including hashed server passwords, authenticated desktop sessions, encrypted network transport, local Windows credential protection where available, access controls, and secret redaction in logs. No security measure can guarantee absolute security. Keep your device, account, and local HiddenPro files secure, and do not send support logs until you have reviewed them for information you do not want to share.
10. Children
The Service is intended for adults and is not directed to children under 13. Our Terms require an account holder to be at least 18 or the age of legal majority where they live. We do not knowingly collect personal information online from a child under 13. If you believe a child provided information, contact us so we can investigate and take appropriate action under the Children’s Online Privacy Protection Act (COPPA).
11. Recording privacy and consent
HiddenPro can capture microphone and computer audio. Federal and state recording and interception laws vary, and some states or circumstances require consent from every participant. You are responsible for giving notice, obtaining all legally required permissions, and following employer, school, platform, and contractual rules before capturing or submitting anyone else’s voice, image, screen, or confidential information.
12. Processing in the United States
We operate from the United States. If you use the Service from another country, information may be processed in the United States and other locations where our providers operate. Those locations may have privacy laws different from the laws where you live. You are responsible for determining whether the Service is suitable for your use under local law.
13. Changes to this Policy
We may update this Policy as the Service or law changes. We will post the revised Policy and update the effective date. We will provide additional notice when required by applicable law.
14. Contact us
HiddenPro AI is operated by Tachara LLC in the United States. For privacy questions, requests, or complaints, email info@hiddenproai.online.