Legal
Privacy Policy
Halo is designed to answer a narrow security question: whether a user, trusted device and location context satisfy a rule for a sensitive action. This policy explains how information is handled across the website, mobile app, browser extension and Halo services.
Effective August 17, 2026
Information we collect
- Account and contact information you provide when registering or requesting access.
- Security configuration such as trusted zones, device identifiers, consent records and verification preferences.
- Verification and approval events needed to provide decisions, alerts and account history (for example merchant checks, password-manager approvals and connected-app requests).
- Limited technical information such as browser, device, regional network information, logs and diagnostics.
Location data
Halo is built for verification rather than continuous surveillance. While the app is open, Halo may use your location to verify sensitive requests against your trusted radius and, when Halo Plus household features are enabled, to share your latest live location with your household owner. Precise transaction coordinates are not retained by the verification decision record as a movement history.
How information is used
- Provide location-aware approve, challenge, block and audit decisions.
- Operate Halo Password Manager, 2FA / connected-app approvals, My Halo configuration and account security.
- Detect spoofing, unauthorized device use and anomalous activity related to verification requests.
- Maintain reliability, investigate errors and support account recovery.
Sharing
Halo does not sell personal information. Information is shared only with service providers required to operate the product, connected services you authorize, enterprise partners involved in a requested verification, or legal and security stakeholders when required to protect users and comply with law.
Halo Password Manager
When you use Halo Password Manager, Halo processes the website origin, login label, username, encrypted password secret, linked-browser information and approval history needed to provide the feature. A paired browser may save or update a login after you confirm the prompt and may receive a searchable index containing website, label and username metadata. Password values are released only after a separate, short-lived approval for the exact website and request.
The browser extension stores its revocable pairing token locally. It does not store saved password values in extension storage. Halo does not use password-manager data for advertising and does not send saved website origins to third-party favicon services.
Password security and retention
Password values are transmitted over encrypted connections and stored as server-side encrypted secrets. Halo Password Manager is not described as a zero-knowledge or end-to-end encrypted vault because Halo's protected server systems perform authorized secret access. Linked browsers expire or can be revoked, and approval, security and diagnostic records may be retained for fraud prevention, legal compliance and service integrity.
Only install the extension from an official Halo listing or download provided by Halo, review every approval in the Halo app, and reject requests you did not initiate. A compromised unlocked browser or device may still expose information visible to that device.
Your controls
You can manage trusted locations, privacy mode, alerts, connected services and device access in Halo. Password Manager settings let you unpair the current browser without deleting saved logins, or permanently delete all saved password items and their encrypted secrets after a separate Halo approval. To delete your Halo account, use Settings → Stored data → Delete my Halo data in the mobile app, or follow the instructions at /account-deletion. Deletion removes the user account and associated application records subject to security, fraud-prevention, legal, and regulatory retention obligations.
