Skip to document
HTO Labs
Your work, connectedYour dataPagesWorkroom
Apps, pages, and documentsExplore examples
Who it’s forPricing
Log inExplore HTO Labs
Home
Your work, connectedYour dataPagesWorkroom
Apps, pages, and documentsExplore examples
Who it’s forPricingRequest an invitationLog in
info@htobeyond.com
HTO Labs

Privacy Policy

Last updated 7 October 2026.

On this page

  • Our commitments
  • Who is responsible for your data
  • What we collect and why
  • Invitation requests
  • Demo bookings
  • Form spam protection
  • Your account
  • Your team and workspaces
  • What you put into HTO Labs
  • Services you connect
  • AI agents
  • Technical and security information
  • Legal basis
  • How we protect your data
  • Cookies
  • Who receives your data
  • International transfers
  • How long we keep data
  • Your rights
  • Complaints
  • Changes to this policy
On this page
  • Our commitments
  • Who is responsible for your data
  • What we collect and why
  • Invitation requests
  • Demo bookings
  • Form spam protection
  • Your account
  • Your team and workspaces
  • What you put into HTO Labs
  • Services you connect
  • AI agents
  • Technical and security information
  • Legal basis
  • How we protect your data
  • Cookies
  • Who receives your data
  • International transfers
  • How long we keep data
  • Your rights
  • Complaints
  • Changes to this policy

This policy explains how HTO & Beyond handles personal data when you use HTO Labs: the website at htolabs.com, the HTO Labs web app and the HTO Labs desktop app.

Our commitments

  • Your content is yours. The pages, chats, messages, tasks and files you create in HTO Labs belong to you and your team.
  • We do not sell your personal data or your content, and we do not use either for advertising.
  • We do not use your content to train AI models.
  • We do not look at your content. Our people access it only when you ask us to, for example to help with a support request, when it is necessary to keep HTO Labs secure or to investigate misuse, or when the law requires it. Access is limited to the people who need it for that task.
  • For a company's workspaces, we process content only on that company's instructions.

Who is responsible for your data

HTO & Beyond ApS
CVR DK46108043
Ålekistevej 184
2720 Vanløse, Denmark
info@htobeyond.com

We are the data controller for your account and for the technical data we collect to run and protect HTO Labs. When a company uses HTO Labs for its team, the company decides what its people put into their workspaces. For that workspace content we act on the company's behalf, as its data processor, under our Data Processing Agreement with it.

What we collect and why

Invitation requests

When you ask to try HTO Labs, we collect your name, email address, company, job title, and a description of what you want to try. We use these details to respond to your request and arrange an invitation. Resend delivers the request to our inbox. This does not create an account or subscribe you to a newsletter.

Demo bookings

When you book a demo, we send your name, email address, company, position, reason for the demo, chosen meeting time and time zone to Microsoft Bookings to arrange the call and send a Microsoft Teams calendar invitation. Public availability shows open meeting times; it does not show the contents of the host's calendar. Upstash stores meeting-time reservations and hashed request identifiers to prevent duplicate bookings. We do not send your name, email address, company, position or notes to Upstash. A booking does not subscribe you to a newsletter.

Form spam protection

To limit repeated invitation requests and demo bookings, Upstash also keeps short-lived counters identified by keyed hashes of IP and email addresses. The counters expire within 24 hours. Raw IP and email addresses and form contents are not stored in those counters.

Your account

When you create an account we collect your name, your email address and your password. Our authentication provider stores the password only in a form that cannot be read back. If you sign in with Google, Microsoft or Apple, we receive your name, your email address and an identifier for that account from them instead of a password. We use this to create your account, sign you in and contact you about your account.

Your team and workspaces

We store the teams and workspaces you create or join, who belongs to them, their roles, and the invitations sent. An invitation contains the email address of the person invited, and we send the invitation email to that address on the team's behalf.

What you put into HTO Labs

We store the pages, chats, messages, tasks and files that you and your team create, so that the people you share them with can see and work on them.

Services you connect

If you connect a workspace to another service, such as Meta or GitHub, we store the access that service grants and the content you choose to bring in. We use it only for what you asked HTO Labs to do with it. You can disconnect at any time.

AI agents

In the desktop app, agents such as Codex, Claude, Gemini and Grok run on your own computer and are signed in with your own accounts. What you send them goes from your computer to that provider under your agreement with them. An API key you add for an agent is kept in your computer's own key store (the Keychain on a Mac, Credential Manager on Windows) and is not sent to us.

Technical and security information

Our hosting and database services process technical information such as your IP address, browser, device, pages visited, times and security logs. We use it to deliver, maintain and protect HTO Labs.

Legal basis

We process your account, team and workspace data to provide HTO Labs to you under our agreement. We process technical and security information, and send invitations for a team, on the basis of our legitimate interest in running a secure service that teams can use together. Where the law requires your consent, we ask for it.

We do not sell personal data, we do not use it for advertising, and we do not make decisions about you by automated means alone.

We handle invitation requests on the basis of our legitimate interest in responding to people who ask to try HTO Labs.

How we protect your data

Everything sent between you and HTO Labs is encrypted in transit. Our database is encrypted at rest. Access to the systems that hold your data is limited to the people who run HTO Labs. If a security incident affects your personal data, we will tell you and the authorities as the law requires.

Cookies

We use only the cookies and similar storage needed to keep you signed in, keep your session secure and remember interface choices such as whether the sidebar is open. We do not use analytics or advertising cookies. If that changes, we will ask for your consent first.

Who receives your data

We use service providers that receive only what they need to do their part:

  • Supabase, for sign-in and our database, in Frankfurt, Germany.
  • Vercel, which hosts the website and may process requests in the United States.
  • Resend (Plus Five Five, Inc.), which delivers website invitation requests to our inbox and may process them in the United States.
  • Microsoft, for demo bookings and Teams meeting invitations.
  • Upstash, Inc., for website booking coordination and spam protection.
  • Google, Microsoft or Apple, if you choose to sign in with them.
  • Meta or GitHub, if you choose to connect them.

We may also share information with professional advisers, or with public authorities when the law requires it or when we need to protect legal rights.

International transfers

Some of these providers process personal data outside the EU or EEA. Where that happens we rely on an adequacy decision, the EU Standard Contractual Clauses or another lawful safeguard. Contact us if you want more information about a transfer that concerns your data.

How long we keep data

  • Website invitation requests: only as long as needed to handle your request and the related follow-up.
  • Account, team and workspace data: while your account or your team's use of HTO Labs continues. When an account or workspace is deleted, we delete the related data within 30 days.
  • Invitations that are not accepted: until they expire or are withdrawn.
  • Security logs and support conversations: only as long as needed for security, support or legal purposes.

We may keep specific records longer when the law requires it or when we need them to establish, exercise or defend a legal claim.

Your rights

Depending on the circumstances, you may have the right to:

  • access the personal data we hold about you,
  • correct inaccurate or incomplete data,
  • request deletion,
  • restrict how we process data,
  • object to processing based on our legitimate interests,
  • receive data you provided in a structured, commonly used, machine-readable format where the portability right applies,
  • withdraw consent at any time where processing relies on consent, and
  • complain to a supervisory authority.

If your data is in a workspace that a company controls, we will pass your request to that company and help it respond. Send a request to info@htobeyond.com. We may ask for information needed to confirm your identity, and we normally respond within one month.

Complaints

You may complain to the Danish Data Protection Agency, Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, Denmark. If you live in another EU or EEA country, you may also contact the supervisory authority there.

Changes to this policy

We may update this policy when HTO Labs or the law changes. We publish the current version here, and we tell account holders about changes that matter.

See also our Terms of Service and our Data Processing Agreement.

HTO Labs

HTO Labs. Work seamlessly with AI.

HTO Labs

  • Overview
  • Your data
  • Pages
  • Workroom

Explore

  • What you can create
  • Who it’s for
  • Pricing
  • FAQ
  • Request an invitation
  • Log in

Contact

  • Get in touch
  • Book a demo

Legal & company

  • Privacy
  • Terms
  • Data processing
  • HTO & Beyond

© 2026 HTO & Beyond