HAL Privacy Policy
This Privacy Policy describes how HAL ("we", "our", "the service"), a product of Hal-PA Inc, collects, uses, and protects your information when you use the HAL app or visit gethal.com.
By using HAL, you agree to the practices described here. If you do not agree, please do not use the service.
What we collect
When you create an account and use HAL, we collect:
- Account information: email address, password (hashed by our authentication provider), name, username, optional avatar, and optional location (city, country).
- Conversations: messages you exchange with AI models and with human specialists or Hals through the service.
- Files you upload: images, PDFs, and audio recordings you send to HAL. These are stored to be shown back to you and to provide context to the AI.
- Memory and identity profile: information you share that HAL persists to personalize future conversations (preferences, interests, communication style). Personally identifying information (real names, emails, phone numbers, addresses, document numbers, social handles) is automatically filtered out before being stored.
- Payment metadata: when you purchase coins or subscribe to HAL+, Stripe processes the payment. We store transaction records (amount, currency, date) but never your card details.
- Usage data: which tier you used, which model responded, ratings you gave to sessions. Used to improve the service and to learn which AI works best for you.
- Technical data: IP address, device type, browser, and request timestamps, automatically logged and purged after 90 days.
What we do NOT collect
- Credit card numbers, CVVs, or any other raw payment instrument data — Stripe handles all card information.
- Plaintext passwords — only secure hashes managed by our authentication provider.
- Personally identifying information in your memory or identity profile — automatically filtered out at write time.
- Location data beyond the optional city/country you provide in your profile.
- Contacts, photos library, calendar, microphone (except when you explicitly press record), or any other device data we don't need.
How we use your information
- To provide and operate the HAL service.
- To route your conversations to the appropriate AI model or human specialist.
- To personalize responses based on your preferences and conversation history.
- To process payments and manage subscriptions.
- To send transactional emails (welcome messages, payment receipts, account approvals).
- To detect abuse, fraud, and security threats.
- To comply with legal obligations.
How we share your information
HAL operates as a hub between you, AI providers, and human specialists. Specifically:
- AI providers: your messages and uploaded files are sent to one of our AI providers (Anthropic, Google, OpenAI, xAI, DeepSeek) to generate responses. The specific provider rotates based on tier, availability, and your preferences. AI providers process your data under their own privacy policies and do not use it to train their models.
- Human specialists and Hals: when you escalate a conversation to a human or book a specialist, that person sees the conversation history and your identity profile. They are bound by our terms to keep this information confidential.
- Stripe: processes all payments. Subject to Stripe's privacy policy.
- Resend: sends transactional emails on our behalf.
- Supabase: hosts our database and authentication infrastructure.
- Vercel: hosts our application servers.
We do not sell your personal information to anyone. We do not share your data with advertisers.
Data retention
We keep your account data for as long as your account is active. If you delete your account (see below), we permanently remove your personal data from our systems.
We retain de-identified transaction records and Stripe payment events for up to 7 years to comply with tax and accounting laws. None of this retained data identifies you personally after account deletion.
Server logs containing IP addresses and request metadata are automatically purged after 90 days.
Your rights
You can, at any time, directly from within the HAL app:
- Review what information HAL has stored about you (in the Memory and Identity sections of your profile).
- Delete individual memory items.
- Edit your identity profile.
- Download a copy of your data by contacting us.
- Delete your entire account and all associated data. See how to delete your account.
If you are in the European Economic Area, the United Kingdom, or California, you have additional rights under GDPR and CCPA respectively, including the right to access, correct, or restrict processing of your personal data. To exercise these rights, contact us at hello@gethal.com.
Children
HAL is intended for users 18 years of age or older. We do not knowingly collect information from children under 18. If you believe a child has provided us with personal information, please contact us and we will delete it.
Security
We use industry-standard security practices to protect your data, including encryption in transit (HTTPS), secure password hashing, row-level access controls in our database, and limited access to production systems.
No method of transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
Changes to this policy
We may update this Privacy Policy from time to time. The latest version will always be at gethal.com/privacy. Material changes will be communicated through the app or by email.
Contact
For any privacy-related question or request, email us at hello@gethal.com.
Last updated: May 2026 · HAL is a product of Hal-PA Inc · gethal.com