Security & data privacy

Privacy by architecture, not by policy.

Anyone can promise to protect your data. HOLLOU is built so it can't be misused — every merchant runs on their own isolated instance, and the platform never sees your conversations. Here's exactly how, in plain language, with nothing to take on faith.

The short version

What HOLLOU can't do.

The most useful thing we can show you isn't a list of promises — it's the things the system is built to make impossible.

Read your conversations

The central platform receives only aggregate counts — sessions, cost, health. Raw transcripts never leave your instance.

Mix your data with anyone else's

There is no shared database to mix it in. Each merchant runs on a separate, isolated instance.

Sell or repurpose your data

It never leaves your instance except as anonymous aggregates. There is nothing to sell, and no third party to sell it to.

Work on any site but yours

Your key is locked to your domain. A copied install snippet is inert anywhere else.

Open a dashboard with the public key

The embedded widget key runs the assistant and nothing more. Your console is a separate, real login.

How your data is protected

Six commitments, each with the mechanism that makes it true.

Isolation

Your own private instance

Every merchant runs on isolated infrastructure — your own database and compute. Your data is never sitting next to another merchant's.

Encryption

In transit and at rest

Every connection is HTTPS/TLS. Stored data is encrypted at rest on managed AWS infrastructure.

Consent

Only what a lead needs, never sold

A shopper's name, email or phone is captured only when they choose to share it. Never sold, never shared with third parties.

Control

You own your data

Export it, delete it, or rotate your key anytime. Your key is bound to your domain, so a leaked snippet is useless elsewhere.

Grounding

Answers from your catalog

The assistant answers from your own products and pages — it doesn't invent facts. When it doesn't know, it says so.

Separation

The platform can't see your chats

Central reporting receives only aggregate metrics. Your raw transcripts stay on your instance, masked by default.

Why we can make those promises

Where your data lives — and what actually crosses the line.

Your shoppers' conversations stay inside your instance. Only anonymous counts ever cross to the platform. That boundary is the whole design.

Inside your instance

Your shopper opens the assistant on your site over TLS. The conversation, your catalog, and any leads live on your own isolated instance — a separate database and compute, not a shared table.

What crosses to the platform

Only aggregate counts — sessions, cost and health — for reliability and billing. The ingestion endpoint rejects any payload that contains message content, so even by mistake a transcript can't cross the boundary.

What you see, and only you

Your own console holds the transcripts, masked by default, with reveal gated behind an audit log. No one on the platform side can read them.

Straight answers

Questions we'd rather answer before you ask.

What do you collect from my shoppers?

Only what a lead chooses to share — typically name, email or phone — and only at an explicit lead step, after they acknowledge it. We don't build hidden profiles of your visitors.

Do you sell or share my data?

Never. No third-party sharing, no ad networks, no data brokers, and no using your shoppers' data to train models for anyone else.

Can HOLLOU staff read my conversations?

From the central platform, no — it only ever receives aggregate counts. Transcripts live on your instance, masked by default, with reveal gated behind an audit log.

Is it encrypted?

Yes — HTTPS/TLS in transit and encrypted at rest. Served pages carry a strict content-security policy and standard security headers.

Is it “unhackable”?

No credible company claims that, and we won't either. What we run is defense-in-depth: per-merchant isolation, least-privilege access, encryption, input validation, security headers, and regular internal review. We'd rather tell you exactly what we do than make a promise no one can keep.

What if my install snippet leaks?

It's useless anywhere else. The key is bound to your domain and rejected on any other site. You can rotate or revoke it at any time.

Can I get my data out, or delete it?

Yes — a full export or complete erasure is available on request, and you can rotate your key whenever you like. Your data is yours.

Controls in place

The concrete measures protecting your data today.

In place

Encryption in transit & at rest

In place

Per-merchant isolation

In place

PII masking with reveal audit

In place

Domain-locked keys & least-privilege access

In place

Aggregates-only telemetry & provisioning audit log

Built on

AWS · NVIDIA · Anthropic Claude

Enterprise infrastructure and models you already trust.

Still have a question?

Bring your hardest question. We'd rather earn trust than claim it.

A straight answer from a real person beats a glossy claim. And if you'd like to verify any of the above yourself, we'll show you how.