H.O.L.L.I.D.A.Y.

Privacy

Effective 19 September 2026.

Who holds your data

Holliday Labs LLC, a limited liability company registered in Texas, United States. For anything on this page, including deleting what we hold, write to trev@holliday.io.

This website

holliday.io has no advertising tracking, no analytics and no third-party scripts, which is why you have not been asked to accept cookies. Fonts are served from our own domain. If you join the early-access list, we keep the email address you give us and a line about what you run, if you add one. The demos are recordings of real answers.

Signing in

Signing in keeps a session in your browser so the app knows it is you; it is necessary for the service and used for nothing else. The app also remembers a few preferences in your browser (voice on or off, volume, whether you have seen a hint). Nothing in your browser is read by anyone else.

What we keep about your workspace

Your account: your email address, your name if you told us, your workspace name and the short business description you gave at setup.

Your sources: what you connected and the settings for it. Credentials, webhook URLs and API keys are encrypted at rest with AES-256-GCM, tied to your workspace so a stored key cannot be read by another, decrypted only in memory to serve your request, never shown to the model and never written to logs.

Your files: files you upload or sync are stored until you remove them, because she reads them whole to answer. Google Sheets and Docs are read from the link you gave each time you ask, not copied.

Your business data: everything else is read when you ask and kept for minutes, not stored.

Answers: each question and her answer are kept so you can reopen them from History and take them with you. You can turn keeping off in Settings → Account; answers are then not stored at all. Pictures rendered for exports are cached for fifteen minutes; files you share through a link (Slack, a phone push, a webhook) live at an unguessable address for seven days, or a year when embedded in a Notion page you asked her to create; files saved to your synced folder wait in an outbox for seven days.

Memory: what she remembers about your business lives in a memory you can read, edit and delete in Settings → Memory.

Usage: for each answer we record its cost to us, token counts and timing, so your allowance can be shown as a percentage. You never see money and we never bill above your plan.

Actions: the places you listed, your schedules and watches, and an audit log of every send, export, schedule run and watch that fired, which you can see.

Feedback: a message you send from Settings → Feedback is emailed to us with your email address, workspace name, plan, the page you were on and your browser, so we can fix it without a back-and-forth.

Who else touches your data, and why

The AI provider. Answering a question means sending it, and the data needed to answer it, to the model. We reach models through OpenRouter, and every request carries an instruction that it may only be routed to providers who do not collect or train on it. Providers may hold a short abuse-monitoring window under their own policies. Nothing you say trains a shared model. On the Own key plans, requests go to the provider of the key you gave us instead.

Voice. Her spoken lines are synthesised by OpenAI from the text of the answer only. On the Own key + voice plan, by ElevenLabs on your account.

Hosting. Your workspace data lives in a database hosted by Supabase in Ashburn, Virginia, United States. Answers, exports and pictures are computed on our own server, hosted by Contabo in St. Louis, Missouri, United States. The website is served by Vercel. Encrypted backups of the database are taken daily and replaced daily.

Payments. Stripe, with Link as the merchant of record. Stripe holds your payment details; we never see your card number, only that a subscription is active and which plan it is.

Delivery. Emails she sends for you, and feedback to us, go through Resend. Phone pushes go through ntfy.sh to the topic you chose. Slack, Discord, webhook and Notion deliveries go to the exact addresses you listed, and to nowhere else.

We do not sell your data, and we do not share it with anyone outside this list.

Security

Every workspace is isolated at the database level; an answer can only reach the workspace it belongs to. Secrets are encrypted at rest as described above. Traffic is encrypted in transit. The model has no way to read a stored key back, and instructions hidden inside your data are treated as data, flagged and ignored.

Deleting and taking your data

Any answer can be taken with you as Excel, CSV, a picture or a PDF. “Start over” in Settings → Account wipes your sources, keys, files, memory and answers; emailing us deletes your account and everything in it, and we confirm when it is gone. A workspace that never chose a plan is deleted after seven days. Purchase records and receipts are kept by Stripe and Link under their own retention rules.

Children

Holliday is not for anyone under 18, and we do not knowingly keep data about children.

Changes

If this page changes, the date at the top changes with it, and material changes are announced in the app or by email before they take effect.

Back to holliday.io