> ## Documentation Index
> Fetch the complete documentation index at: https://docs.usehence.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Trust and control

> What your assistant never sees, what Hence stores, how to disconnect, and what is committed but not yet built.

<Note>
  The execution layer is still being built. This page separates what is true of the design from what
  is implemented, because the difference is the only part of a privacy page worth reading.
</Note>

## What your assistant never sees

**No credential ever enters your assistant's context, or the model's.** Not a password, not a
one-time code, not a token for a third party. When Hence needs one, it sends your assistant a link;
you open it and enter the value on a single-use page on our domain, and it goes from your browser
into the one form it was requested for.

Your assistant sees what you would tell a person helping you: which errand is running, what question
is pending, what the result was. That last part is not nothing — a result can carry an APR, a
balance or a match formula, and those pass through the conversation like any other answer, subject
to whatever your assistant's provider retains. What it never holds is a credential, a one-time code
or a third-party token, and screenshots of signed-in pages are referenced rather than handed over.

## What Hence stores

When an errand runs, it records the task and its steps, the receipt for each act, the values it read
and where they came from, the audit trail for each single-use credential fill, and the screenshots
and any statements it downloaded. Figures an errand establishes about you — an APR, a match formula
— are written into your financial profile, which is the same profile the rest of Hence reads.

**No retention period is stated here, because none has been set.** Rather than invent one, this page
says so. When a retention rule exists it will be stated on this page, with the date it took effect.

## Asking for erasure

To ask what is held about you, or to ask for it to be erased, write to
[privacy@usehence.com](mailto:privacy@usehence.com).

**Erasure completes within 30 days for application data, plus up to 28 days for relational backup
erasure and up to 30 days for R2 lifecycle erasure.** Nothing about it is instant, and we will not
claim otherwise: for that window, copies survive in backups we cannot reach individually, and they
age out rather than being picked out. How long we keep your data while you are a customer and how
long an erasure takes are different questions, and the paragraph above answers the first.

<Warning>
  **The execution layer's own stores are not in that path yet, because they do not exist yet.** Task
  records, receipts, single-use-fill audit trails, and the screenshots and statements in object
  storage each have to be named in the erasure routine explicitly — it enumerates stores rather than
  relying on a cascade, so a store nobody adds is a store nobody erases. Each is committed to land
  with the code that creates it, not as a follow-up. Until the pilot's stores are built and wired,
  an erasure request reaches the rest of Hence.
</Warning>

## Screenshots are not redacted during the pilot

<Warning>
  **Screenshots taken during the pilot are stored unredacted.** An authenticated account page is
  captured as it appears, account numbers included, and stored on our side. Screenshots are
  referenced rather than pasted into your assistant's transcript by default, but they are not
  masked.

  Redacting at capture is a committed change and is the stated gate before access widens beyond the
  current pilot group — not a later nicety.
</Warning>

## How to revoke a connection

Remove the Hence connector in your host's settings. It stops being able to call us at that moment,
and no further errand can be started through it.

<Warning>
  **Disconnecting does not yet purge stored data or cancel runs already in flight.** Both are
  committed rules and neither is implemented today. Until they are: cancel any task you want stopped
  before you disconnect ([how to stop a task](/tasks/stopping-a-task)), and write to
  [privacy@usehence.com](mailto:privacy@usehence.com) to ask for erasure.
</Warning>

## Who can run errands right now

Access is gated to accounts on our own company domain during the pilot, and it is evaluated on our
side for the signed-in user at the moment a tool is called. Anyone may add the connector and
complete the consent flow; if access is not enabled, every tool refuses cleanly and says so.

Everything on this page — the unredacted screenshots most of all — is confined by that gate to
accounts inside the company while the pilot runs.

## The limits that do not move

* Hence does not move money between your accounts.
* Hence does not sign anything, elect anything, or prove your identity on your behalf.
* Hence does not enter a credential itself; every credential is entered by you, once, on our page.
* An errand that meets a hard stop — an active debt lawsuit, identity theft, insolvency, an
  irreversible tax election — stops and points you at a professional.

## How to report a problem

A suspected security issue: [security@usehence.com](mailto:security@usehence.com). A privacy
request, or a question about what is held about you:
[privacy@usehence.com](mailto:privacy@usehence.com).

Anything else — a result you cannot reconcile, or a page here that does not match what you see —
goes to whoever invited you to the pilot. A public support address will be listed here when the
pilot opens.
