HULAHO

LiMiT · Deterministic workspace

Privacy and workspace data

The application uses an HttpOnly cookie to associate requests with a private workspace. Theme, mode and the last session identifier are stored in browser localStorage. Conversations, facts, documents, rules, learned functions, examples and translations are stored in the server SQLite database. This is server-side storage, not a promise that all data stays inside your browser.

Conversation and shared learning

Conversation learning is on by default for supported personal statements in deterministic chat. Pause it in Framework or say pause learning. Facts and learning receipts remain private to the workspace. Obvious secret-shaped statements are excluded by a heuristic, but chat transcripts still store the messages you send: do not paste credentials. Shared learning uses only explicitly contributed function names and numeric examples, with consent:true; use fictional, non-personal numbers. No transcripts, personal facts, documents, recovery keys or assistant replies are automatically published. Candidates require operator review before global activation. Withdraw removes pending contributions; previously published versions require operator retirement. Export includes your learning audit and contributions for inspection; import restores preferences and facts but does not restore undo authority or re-publish contributions.

Access and recovery

Workspace ownership is checked on private API operations. A downloaded recovery key grants access to the associated identity and should be kept secret. Removing browser cookies does not delete server records and can remove access to an existing workspace unless a recovery key is available.

Exports and deletion

The memory panel supports export and individual memory removal. The authenticated API also supports deleting sessions, documents, rules and the entire workspace. Learned functions can be removed with the forget skill command, subject to stored dependencies. A deleted live record may remain in operator-managed backups or logs until those copies are separately managed; this release does not promise a backup-erasure schedule.

Optional models and infrastructure

Deterministic operations do not call a language model. Explicitly selected Ollama requests send the current message and limited conversation history to the configured loopback model service. Hosting, reverse-proxy and backup infrastructure may also process request metadata. This page describes application behavior, not an independent audit of the operator infrastructure or a complete legal compliance assessment.

Operator information: LiMiT. Read the private-memory guide before deleting identity data.