Higher Order Computing Company Privacy Policy
Version 1.2
This Privacy Policy explains how Higher Order Computing Company, a Delaware corporation, 8 The Green, Ste 8, Dover, DE 19901 ("HOC", "we", "us") collects, uses, discloses, and protects personal data when you use Bender, the HOC API, the Bender command-line tool, the Bender website, BendHub, and prepaid credits (the "Services"), and what rights you have. It also covers the daily version check that the Bend command-line tool makes to BendHub. It applies to personal data about you as an account holder. It also explains how we handle the content of the Bend files you submit and the results we return ("Customer Content"), which we process on your behalf under the Bender Terms of Service; where that content contains personal data about other people, you are the controller of it and we act on your instructions.
The Services are for developers, professionals, and businesses, and are not directed to anyone under 18.
1.Personal data we collect
1.1 Data you give us
- Account data: your GitHub numeric id, username, and avatar, received from GitHub when you sign in. We do not receive or store your GitHub password.
- Email address, if your GitHub profile makes it available or you enter it during checkout.
- Billing data for bank-transfer purchases: the legal name of the payer, company name, billing address and country, contact email, and tax identification number.
- Payment data: our payment processor, Stripe, collects your card or bank details directly. We receive and keep only what we need to run the Services: the card brand and last four digits, a card fingerprint that identifies the physical card without revealing its number, the payment processor's identifiers, and the amounts, dates, and status of each payment, refund, and dispute.
- Preferences: the data-sharing mode of each API key, auto top-up settings, and your acceptance or withdrawal of these Terms and of the data sharing program.
- Communications: anything you send us by email or through a support channel.
1.2 Data we collect automatically
- Log data: IP address, browser or client type and version, and the date and time of each sign-in, purchase, consent, API key creation, and command-line login. We record the IP address and client at those events so that we can investigate fraud and payment disputes.
- Usage data: for every run of the Services, the API key used, the product or feature, the units consumed, the rate applied, the data-sharing mode in effect, the amount charged, the resulting balance, and a description of the run. We keep these as a ledger of your account.
- Command-line login data: the machine name your command-line tool reports when it asks to be authorized.
- Cookies: a session cookie that keeps you signed in, a short-lived cookie that protects the sign-in flow, and a short-lived cookie that returns you to the page you were on after signing in. We do not use advertising or analytics cookies.
1.3 Customer Content
- Inputs: the Bend source files and other content you submit to the Services.
- Outputs: the files and results the Services return.
- In private mode, the default, we retain Inputs and Outputs only as long as needed to run the job and return the result, plus 30 days in transient logs used to debug failures and to detect abuse, after which they are deleted unless we are legally required to keep them. In shared mode, we retain them for the period and purposes described in the Bender Data Sharing Terms.
1.4 BendHub
- What you publish on BendHub, meaning packages, the names and versions that point to them, and posts, is public, together with your GitHub username and the time you published it; so are the vote totals on each post. We record your GitHub id with each of these and with each of your votes. A package published without an account carries no username. What you publish on BendHub is not Customer Content: you publish it to make it public.
- Access log: our web server records the IP address, the time, the address requested, and the request headers other than cookies and credentials of every request to hub.bend-lang.com.
- Version check: once a day, the Bend command-line tool asks BendHub whether a newer version exists, whether or not you have an account, and sends its version, your operating system, and your processor architecture. We record them with the IP address and the time, to count Bend's installations by version and platform. They are not linked to any account.
1.5 Data from other sources
- GitHub, for the account data described above.
- Stripe, for payment status, fraud signals such as early fraud warnings, card details as described above, and dispute notices.
We do not buy data about you, and we do not collect data from data brokers.
2.How we use personal data
We use personal data to:
- Provide the Services: sign you in, run jobs, return results, keep your balance and activity ledger accurate, deliver API keys to your command-line tool, and publish on BendHub what you choose to publish there, under your username.
- Count Bend's installations by version and platform from its version checks.
- Take payments, issue receipts and invoices, apply refunds, and settle amounts you owe.
- Prevent and investigate fraud, abuse, and payment disputes, including enforcing purchase limits per account and per card and screening billing countries against sanctions rules.
- Respond to your requests and communicate with you about the Services, including notices required by the Terms.
- Improve the Services, using aggregated or de-identified data, and, only with your consent, Customer Content under the data sharing program.
- Comply with law, including financial record-keeping, tax, sanctions, and law-enforcement requests.
- Establish, exercise, and defend legal claims.
2.1 Legal bases (EEA, UK, Switzerland, Brazil)
- Performance of a contract: providing the Services, taking payment, keeping your ledger, publishing on BendHub what you publish there.
- Legal obligation: financial record-keeping, tax, sanctions screening, responding to lawful requests.
- Legitimate interests: securing the Services, preventing fraud and abuse, defending disputes, improving the Services with aggregated data, keeping BendHub's packages available to everyone who depends on them, counting Bend's installations. We balance these interests against your rights.
- Consent: the data sharing program. You may withdraw at any time with effect for the future.
We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects. Automated fraud controls may pause a purchase or an account; a person reviews any resulting restriction on request.
3.How we disclose personal data
We disclose personal data only as follows:
- Service providers acting on our instructions: Stripe for payments, GitHub for sign-in, Anthropic and OpenAI as the model providers that process Customer Content to return results under agreements that prohibit training on it, and providers of hosting, encrypted backups, and operational alerts. This is our current list of subprocessors; we update this notice when we add one.
- Banks and card networks, through Stripe, when a payment is disputed: records of your account, purchases, sign-ins, terms acceptance, and usage relevant to the dispute.
- Authorities and other third parties when the law requires it, to comply with a legal obligation or lawful request, to protect the rights, property, or safety of HOC, its customers, or others, or to detect or prevent fraud or illegal activity.
- A successor in a merger, acquisition, financing, reorganization, or sale of assets, with notice to you where the law requires it.
- Anyone you direct us to share with.
- Everyone, for what you publish on BendHub, as described in Section 1.4.
We do not sell personal data, and we do not share it for cross-context behavioral advertising. We do not disclose Customer Content to anyone except the model providers needed to run your jobs, and never for their own training.
4.International transfers
HOC is in the United States and processes and stores data there. Our subprocessors may process data in the United States and in other countries. When we transfer personal data out of the European Economic Area, the United Kingdom, Switzerland, or Brazil, we rely on the European Commission's standard contractual clauses, the UK addendum to them, the standard clauses approved by Brazil's data protection authority, or an adequacy decision, as applicable, and we require the same of our subprocessors.
5.Retention
- Account data: for as long as your account is open. When you close it, we anonymize your profile: your GitHub id and username are replaced with placeholders, and your email and card references are deleted. That includes the GitHub id and username recorded with what you published on BendHub and with your votes there.
- Financial records: purchases, ledger entries, invoices, refunds, disputes, tax data, and terms and consent records are kept for five years after the transaction or the closure of your account, whichever is later, to meet accounting, tax, and dispute-resolution obligations. After you close your account they remain linked only to an anonymized identifier and to our payment processor's customer reference, which we keep so that refunds and reversals can still be processed.
- Log data at sign-in, purchase, and consent events: kept with the financial records they support.
- Usage ledger: kept with the financial records.
- Customer Content: as stated in Section 1.3 and in the Bender Data Sharing Terms.
- Command-line login codes: deleted when the key is delivered, and in any case within ten minutes.
- Backups: encrypted copies of our database are kept for up to 30 days and then overwritten.
- BendHub: packages you publish stay available, since other packages and programs depend on each one by the hash of its files; names and posts stay too. The GitHub id and username recorded with them and with your votes are kept while your account is open, and anonymized when you close it, as for account data.
- BendHub access log: up to ten years.
- Version checks: for as long as we use them to count installations.
We keep data longer when a law, a legal hold, or an open dispute requires it, and we keep a record of erasure requests to show that we honored them.
6.Your rights
Depending on where you live, you may have the right to:
- Know what personal data we hold about you and access it.
- Correct inaccurate data.
- Delete your data, subject to the retention required by law.
- Receive a copy of your data in a portable format.
- Object to, or ask us to restrict, processing based on legitimate interests.
- Withdraw consent where processing is based on consent, without affecting processing before withdrawal.
- Not be discriminated against for exercising your rights.
- Complain to a supervisory authority, such as a data protection authority in the EEA, the Information Commissioner's Office in the UK, the Autoridade Nacional de Proteção de Dados in Brazil, or the California Privacy Protection Agency.
You can exercise most of these rights yourself: your account page shows your data and activity, the keys page lets you revoke keys, the data sharing page lets you withdraw consent, and the close-account action deletes and anonymizes what the law allows us to delete. For anything else, or to appeal a decision, contact us at contact@higherorderco.com. We will verify your identity, normally by asking you to sign in with the GitHub account concerned, and respond within the time the applicable law allows (one month under the GDPR, extendable by two months for complex requests; forty-five days under the CCPA, extendable once). An authorized agent may act for you with proof of authority.
6.1 California
For residents of California, the categories of personal information we have collected in the preceding twelve months are: identifiers (GitHub id and username, email, IP address); commercial information (purchases, balances, refunds, disputes); internet or network activity (log and usage data); financial information as described in Section 1.1; geolocation at country level inferred from IP address and billing country; and professional information (company name and tax id for bank-transfer purchases). We collect them from you, from your devices, and from GitHub and Stripe, for the purposes in Section 2, and we disclose them to the service providers in Section 3 for business purposes. We do not sell or share personal information as those terms are defined in the California Consumer Privacy Act, and we have not done so in the preceding twelve months. We do not knowingly collect personal information of anyone under 16. The data sharing program is a financial incentive under that Act; its notice is in the Bender Data Sharing Terms. You may designate an authorized agent to make requests on your behalf. HOC also treats a Global Privacy Control or similar opt-out preference signal as a valid request to opt out of the sale or sharing of personal information, to the extent it applies.
7.Security
We protect data with encryption in transit, encrypted backups, hashed session tokens and API keys, cookie protections against cross-site attacks, access controls that limit who at HOC can reach production systems, and logging of administrative actions. Card and bank details never reach our systems; Stripe holds them. No system is perfectly secure, and you should keep your API keys and GitHub credentials confidential and revoke a key you believe has been exposed.
8.Children
The Services are not directed to, and must not be used by, anyone under 18. If you believe a person under 18 has given us personal data, contact us at contact@higherorderco.com and we will delete it.
9.Changes to this Policy
We may update this Privacy Policy from time to time. When we do, we will publish an updated version and effective date on this page, unless another type of notice is required by applicable law.
10.Controller and contact
The controller of personal data about account holders is Higher Order Computing Company, a Delaware corporation, 8 The Green, Ste 8, Dover, DE 19901. Contact us at contact@higherorderco.com or by post at the address above.