Privacy Policy
Last updated: October 2026
HippoKit.ai, operated by Bong Realty CA LLC, respects your privacy. This policy explains how we collect, use, and protect your personal information.
Information We Collect
- Account information (email, name) via Firebase Authentication
- Content you provide for generation — including topics, documents you upload as a source, and images you add while editing a kit — which we process and store to create your study content
- Usage data (generation counts, feature usage) for service improvement
- Payment information (processed by Stripe; we do not store card details)
- A study profile, if you choose to fill one in (your level, background, goals and interests)
How We Use Your Data
- To provide and improve the HippoKit service
- To manage your subscription and billing
- To communicate service updates
How We Process Uploaded Files
When you upload a file, we use AI sub-processors to read it and generate your study content. Your uploaded files and the content derived from them are processed by Google Cloud / Vertex AI (Gemini for reading and generation, and Cloud Vision for image screening) and, as a fallback during generation, by Anthropic (Claude). These providers process your content under enterprise API terms and, per those terms, do not use your content to train their public or foundation models.
Shared Courses & Learner Data
HippoKit lets a user publish a kit they own as a tracked, shareable course. If you open such a course and enroll, we collect the email address you provide and your progress in the course — which formats you start and complete, and quiz scores recorded as numbers only. We do not store your quiz answers or any free text you enter while studying.
The HippoKit user who shared the course (the “course owner”) can see your email address and your progress so they can track completion. For a shared course, that owner acts as an independent data controller for the learner data they collect, and is responsible for using it lawfully. HippoKit acts as the processor that hosts and secures that data on their behalf.
Your email is used only to identify your enrollment; internally we also keep a one-way hash of it so we can recognize a returning learner without exposing the address. Your email is never shown to other learners and never appears on any public page, in our sitemap, or in search results — tracked course pages are excluded from indexing.
You have the right to erasure. On the course page you can choose “Remove my data” to delete your email and progress for that course at any time; the course owner can also remove a learner. We retain learner enrollment data for up to 18 months after your last activity and then delete it automatically, and we hard-delete erased records on a daily schedule. To exercise any data right, you can also contact hello@hippokit.ai.
Study Profile and Personalization
If you fill in a study profile or turn on “Tune for me”, we use it to adapt the kits we generate for you. HippoKit learns from your past kits only if you turn that on; if you turn it off again, what it learned is deleted. In Settings you can download a copy of your profile or delete it at any time.
Access Tokens for AI Assistants
If you create an access token to use HippoKit from an AI assistant, the token is shown to you once and we store only a one-way hash of it, so we cannot show it again. We record when a token is created, last used and revoked. You can revoke a token at any time in Settings.
Public Kits and the Gallery
Unless you set a kit to private, a completed kit is public: it can be opened by anyone with its link, may be listed in our sitemap, and can be found by search engines. This includes kits generated from a document you uploaded. You can set a kit to private at any time from its share menu, which takes it off the public web. If you submit a kit to the gallery and it is approved, it is shown under the name you choose, or anonymously. Your email address is never shown on a public kit or in the gallery. You can ask us to remove a gallery kit by contacting hello@hippokit.ai.
Analytics
We use Google Analytics for Firebase to understand how the product is used — for example, which formats are opened and where sign-up fails. These events do not include your email address, your topics or the content of your kits.
We send account and billing messages, and occasional product emails. Every product email has an unsubscribe link, and you can change which emails you receive on the email preferences page.
Content Moderation
To keep HippoKit safe and lawful, we automatically scan uploaded files and the text we extract from them to detect and block prohibited content (such as illegal material or content depicting child sexual abuse, terrorism, or other serious harm). Uploads that fail these checks are rejected and logged. See our Terms of Service for what is and is not allowed.
Data Retention
We retain your uploads and the content we generate from them for as long as needed to provide the service. You can delete a kit or your account at any time, and you may request deletion of your data by contacting us; we delete the associated content on your request.
Data Security
All data is encrypted in transit (TLS) and at rest. We use Google Cloud Platform infrastructure with enterprise-grade security controls. We never sell your data, and our AI sub-processors do not use your content to train their public or foundation models.
Contact
For privacy inquiries, contact us at hello@hippokit.ai.