Privacy Policy
Effective October 9, 2026
The short version. Hikma works inside the tools you connect, so it handles the data in them. We use that data to do the work you ask for and the background work you turn on. We do not sell it, we do not use it for advertising, and we do not train AI models on it. To do the work, we send it to the AI model providers and other vendors listed on our Subprocessors page. Some of those providers are based in China.
This Privacy Policy explains how Ibrahim Bajwa, doing business as Hikma ("Hikma", "we", "us") handles personal information when you use our websites, apps and services (the "Service").
Organizations. When Hikma is provided to an organization, that organization controls the data in its workspace, and we process it on the organization's behalf under our agreement with it. If you use Hikma through your employer, direct privacy requests about workspace data to them as well as to us.
1. Information we collect
Account information
Your name, email address and password (stored only as a one-way hash). If you sign in with Google or your organization's single sign-on, we also receive the identity details that provider shares, such as your name, email and account identifier. We also record which organization you belong to and your role in it.
Your content
What you send to Hikma and what Hikma produces for you: messages, instructions, files, generated documents and images, and the notes Hikma keeps about you and your work in Memory, which you can view and edit.
Data from connected services
When you connect a service, you choose to let Hikma access it as you.
- Through OAuth: Google (Gmail, Drive, Calendar, Sheets, Tasks), Microsoft (Outlook mail, OneDrive, SharePoint, Calendar), Slack, Salesforce and Notion. We store the access tokens these services issue, and we access the emails, files, messages, events, records and contacts that your permissions allow, as needed for the work.
- Through Hikma's browser: for websites without OAuth, you sign in inside a browser that Hikma runs for you. To keep you signed in, we store that site's cookies and site storage (your logged-in session), and Hikma sees the pages it visits for you.
- Through credentials: for self-hosted tools that need a username and password, we store the credentials you give us.
Location
We derive an approximate location (country and region) from your IP address when you sign up and sign in. We use it to protect your account and to choose the region of the internet address Hikma's browser uses, so that websites see you signing in from where you usually are.
Usage, device and log information
IP address, browser and device type, pages and features used, credits consumed, and error and performance logs.
Payment information
Payments are handled by Stripe. We receive your billing status and limited payment details, such as the card brand and last four digits. We never receive or store your full card number.
Communications
Messages you send us, such as support requests.
Mobile number and text messages
If you give us your mobile number, we use it only to text you about Hikma. Mobile numbers and text-messaging consent are never sold or shared with third parties or affiliates for marketing. See our Text Messages (SMS) page for how texting works and how to stop it.
2. How we use information
- To provide the Service: run the agent, take the actions you request in your connected tools, and show you results.
- For background work you enable: once a tool is connected, Hikma reads and indexes it on a recurring schedule, usually daily. It uses that to keep your Memory current, notice things that need your attention, and prepare suggested work for you to review.
- To operate the business: billing, customer support, and service announcements.
- For security: to keep the Service and its users safe, and to prevent fraud and abuse.
- To improve reliability: we use service metrics and logs to find and fix problems.
- To meet legal obligations and enforce our Terms.
We do not sell personal information or share it for cross-context behavioural advertising. We do not use your content, or data from your connected services, to train AI models.
3. AI model providers
To decide what to do and to write responses, Hikma sends the relevant parts of your content, including data from connected services, to an AI model provider.
- How the provider is chosen. Hikma picks a model automatically for each step, from the providers listed on our Subprocessors page. A routing model (Mistral) reads your current instruction to make that choice.
- Where they are. Several providers are headquartered outside the United States, including DeepSeek, Moonshot AI and Zhipu AI (Z.ai), which are based in China.
- How they handle it. Providers process this data under their API terms. Those terms may allow them to keep it for a limited time, for example for abuse monitoring.
4. Google user data
Hikma's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Google user data only to provide and improve the user-facing features you use Hikma for. That means doing the tasks you ask for, keeping your Memory, and preparing suggested work.
- We transfer it only to the subprocessors that make those features work, or as required by law, for security, or as part of a merger or acquisition.
- We never use it for advertising, and we never sell it.
- People at Hikma do not read it unless you ask us to (for example in a support request), it is needed for security or to comply with law, or it has been aggregated and anonymized for internal operations.
- We do not use it to develop, improve or train generalized AI or machine-learning models.
5. How we share information
- With subprocessors who host and run the Service for us, under contracts that limit their use of the data. They are listed on our Subprocessors page.
- At your direction. When Hikma acts for you, it shares content with whoever you are dealing with. For example, it sends an email to its recipients or posts a message in a Slack channel.
- Within your organization. Administrators of an organization workspace can see membership and usage. Content you share in the workspace is visible to its members.
- For legal reasons: to comply with law or valid legal process, or to protect the rights, safety and property of our users, the public or Hikma.
- In a business transfer, such as a merger or acquisition, subject to this policy.
6. Cookies and similar technologies
The Hikma app uses only cookies that the Service needs to work:
- hikma_session keeps you signed in. It expires after 24 hours.
- hikma-theme remembers your colour theme for up to a year.
The app also stores interface preferences in your browser's local storage. We do not use advertising or analytics trackers. Our marketing pages load typefaces from Google Fonts, which means your browser sends its IP address to Google when you visit them.
7. How long we keep information
- While your account is open. We keep account information, your content, Memory and connected-service data until you delete them or close your account.
- When you delete something. Chats and files you delete are removed from our active systems right away, and from file version history within 30 days.
- Backups and logs. Database backups are kept for up to 7 days, and service logs for up to 30 days.
- When you delete your account. Delete it from Settings › Account. Sign-in ends immediately and any subscription is cancelled. Your account, content, Memory, connected-service credentials and files are then deleted from our systems, usually within minutes, and from backups and version history within 30 days. Our payment processor keeps the billing records that tax and accounting law require. If your account belongs to an organization workspace, ask its administrator to remove you.
8. Security
- Encryption. Data is encrypted in transit. At rest, data is encrypted with keys managed by AWS. Connected-service tokens are kept in a dedicated secrets store.
- Isolation. Each Hikma session runs in its own isolated workspace and browser.
- Access. Access to production systems is restricted.
No system is perfectly secure. Report vulnerabilities to security@tryhikma.com.
9. International transfers
We are based in the United States, and we store data in the United States (AWS, us-east-1). Agent workspaces run on servers in Canada. AI model providers and other subprocessors process data in the countries listed on the Subprocessors page, including China. These countries may not have data-protection laws equivalent to those where you live.
10. Your rights and choices
- In the app. You can view and edit your Memory, delete chats and files, and delete your account (Settings › Account).
- Connected services. You can revoke Hikma's access to a connected service at any time from that service's own security settings. For Google, that is your Google Account's third-party connections page.
- By request. Depending on where you live, including the EEA, the UK and US states such as California, you may have the right to access, correct, delete or export your personal information, and to object to or restrict how it is used. Email privacy@tryhikma.com and we will respond within the time the law requires, usually 30 days. We may need to verify your identity first. We will not treat you differently for exercising these rights.
- Complaints. If you are in the EEA or UK, you can also complain to your local data-protection authority.
11. Children
Hikma is not for anyone under 18, and we do not knowingly collect personal information from children. If you believe a child has given us information, contact privacy@tryhikma.com and we will delete it.
12. Changes to this policy
We will post any changes here and update the effective date. If a change is material, we will notify you in the Service or by email before it takes effect.
13. Contact
Privacy questions and requests: privacy@tryhikma.com.