Privacy Policy
This policy explains what HopIt receives when you create an account and synchronize a workspace, why we use it, and the controls you retain.
Effective and last updated July 13, 2026
HopIt is operated by Robert Gordon in Newfoundland and Labrador, Canada. In this policy, “HopIt,” “we,” and “us” refer to the HopIt service and its operator.
1. Information we collect
- Account information: identifiers and profile information supplied by Clerk or your chosen sign-in provider, such as your name, email address, avatar, verification state, and account identifier.
- Workspace content: project names, source files, file metadata, revisions, activity records, collaboration records, and object-storage references you choose to synchronize.
- Device and security information: device names, public keys, scoped session records, authentication events, request metadata, IP addresses, and diagnostic logs used to operate and protect the service.
- Billing information: plan, subscription status, Stripe customer and subscription references, and billing events. HopIt does not receive or store your full payment-card number.
- Communications: information you include when requesting support or responding to service notices.
2. How we use information
We use information to authenticate users, provision accounts, synchronize and restore workspaces, enforce tenant boundaries and plan limits, process subscriptions, prevent abuse, diagnose failures, provide support, comply with law, and improve the reliability of HopIt.
3. Source-code and encryption boundaries
HopIt stores workspace content in cloud infrastructure so it can synchronize across your devices. Designated secret paths may be encrypted on your device before upload when you configure HopIt’s client-encryption features. Do not assume every ordinary source file is end-to-end encrypted. Account, path, revision, usage, and billing metadata remains available to the service as needed to operate it.
4. Service providers and sharing
We share information only as needed to run HopIt, complete a transaction, comply with law, or protect users and the service. Current infrastructure providers include:
- Clerk for account authentication and session management.
- Cloudflare for database, object storage, network, and Worker infrastructure.
- Vercel for application hosting and delivery.
- Stripe and Link for checkout, subscriptions, merchant-of-record services, tax handling, fraud prevention, transaction support, and refunds.
- Google when you choose Sign in with Google. HopIt requests basic identity information used to authenticate your account.
We do not sell personal information or workspace content, and we do not use workspace content for third-party advertising.
5. International processing
HopIt is operated from Canada, while service providers may process information in Canada, the United States, and other locations where they operate. Those locations may have different data-protection laws than your home jurisdiction.
6. Retention and deletion
We retain account and workspace information while your account is active and as reasonably necessary to provide the service, resolve disputes, maintain security, and meet legal or accounting requirements. Deleting a project or account may not immediately remove information from encrypted backups or provider records. Stripe or Link may retain transaction records under their own legal obligations.
A downgrade or quota block does not delete your cloud data. You may export accessible project content while your account remains available. To request account deletion or assistance with an export, contact support@hopit.dev.
7. Your choices and rights
Depending on your location, you may have rights to access, correct, export, restrict, object to, or delete personal information. You may also withdraw consent where consent is the basis for processing. We may need to verify your identity before completing a request.
8. Security
HopIt uses scoped sessions, tenant-level access controls, private object storage, transport encryption, and local journaling safeguards. No system can guarantee absolute security. Keep your account and devices secure, use trusted devices, and notify us promptly if you believe your account has been compromised.
9. Children
HopIt is not directed to children under 13. You must be old enough to consent to data processing and enter a binding agreement where you live, or use HopIt with the authorization of a parent or legal guardian.
10. Changes
We may update this policy as the service or legal requirements change. We will revise the effective date and provide additional notice when a material change requires it.
11. Contact
For privacy questions or requests, email support@hopit.dev. HopIt is operated in Newfoundland and Labrador, Canada.