tinab.com
Privacy
Cloudhil flashes firmware you send onto real MCU benches, then erases them. This page is the privacy policy for the site, the HTTPS API, and the remote MCP connector at https://cloudhil.tinab.com/mcp.
What we collect
- Firmware images for the duration of a flash job (ELF/BIN/HEX, max 2 MiB).
- Job results: mailbox words, UART capture, board id, status. No voucher strings.
- Waitlist notes (max 500 characters). Emails, if given, are stored hashed.
- Client IP addresses hashed before storage. Rate limits use the live IP, then drop it.
- Agent API key hashes (the raw
ch_key is shown once and not stored in clear). - OAuth client ids, redirect URIs, hashed authorization codes, hashed access and refresh tokens.
Do not put secrets in firmware or in waitlist notes. Do not send payment-card data: Pay With Prompt handles vouchers on their side.
How we use it
Firmware is copied to the flash host (a Raspberry Pi on a private mesh), programmed, observed for at most 20 seconds, then erased. Temporary files on the Pi are deleted after the job. Oneshot jobs leave the MCU erased.
OAuth exists so Claude (and other MCP clients) can connect without pasting an API key. Consent creates a Cloudhil agent key bound to that grant. Tool arguments (board, ELF, voucher) are processed to run the job and are not used to train models here.
Storage and retention
Job metadata and events live in SQLite on the Cloudhil VPS. Firmware bytes are not kept as a long-term library: they sit in a temp file for the job, then are removed. Waitlist notes stay until you ask us to delete them. Expired OAuth codes and refresh tokens are purged.
Third parties
- Pay With Prompt — voucher verify only, before a flash. The voucher is never logged.
- Anthropic — if you add the Cloudhil connector in Claude, their client calls our MCP URL and our OAuth endpoints from their infrastructure.
- The flash host is our Raspberry Pi. The debug probe is never exposed (no GDB, no SSH for clients).
Cookies
HTML forms (feedback, OAuth consent) set an HttpOnly CSRF cookie. The MCP endpoint does not use cookies; it uses a Bearer token after OAuth.
Contact
Questions or deletion requests: contact@cloudhil.tinab.com. Do not email firmware or secrets.