HAL Privacy Policy
This Privacy Policy describes how HAL ("we", "our", "the service"), a product of Hal-PA Inc, collects, uses, and protects your information when you use the HAL app or visit gethal.com.
By using HAL, you agree to the practices described here. If you do not agree, please do not use the service.
What we collect
When you create an account and use HAL, we collect:
- Account information: email address, password (hashed by our authentication provider), name, username, optional avatar, and optional location (city, country).
- Conversations: messages you exchange with AI models and with human specialists or Hals through the service.
- Mailbox: if you use HAL's built-in email, we store the messages in your inbox (sender, subject, body, attachments, and read/archived state) so we can display and organize them for you. You can archive or permanently delete any message at any time — see Your rights below.
- Connected accounts: if you choose to connect an external calendar (Google, Microsoft/Outlook, or Apple via CalDAV), link a Telegram chat, or connect Uber to request rides, we store the access tokens or credentials needed to keep that connection working, and we exchange with that service the data the feature needs — calendar events to show and add them, a message to deliver to your Telegram chat, a pickup point and destination to price and request a ride. You can disconnect any of these at any time, which revokes our access.
- Files you upload: images, PDFs, and audio recordings you send to HAL. These are stored to be shown back to you and to provide context to the AI.
- Application material: if you apply to become a Hal or a specialist, the documents you upload in support of that application — credentials, certificates, identification where a regulated field requires it. These are kept in a private bucket, are read only by the people reviewing applications, and are deleted with your account.
- Precise location, only when you ask for it: three features use your device's exact position, and each one starts with you. Sending your location in a chat writes the coordinates into the message, so they are stored in that conversation and sent to the AI model like any other text. Asking the camera what building it is pointing at sends your position and compass heading to Google's geocoding service. Requesting a ride sends your pickup point and destination to Uber. HAL does not track your position in the background and does not keep a location history of its own.
- Memory and identity profile: information you share that HAL persists to personalize future conversations (preferences, interests, communication style). A filter runs on the server before anything is written: if a memory item contains an email address, a phone number, a long digit run, a stated proper name or a social handle, the write is rejected — not redacted, rejected — and nothing is stored.
- Notification tokens: if you allow push notifications, we store the device token needed to deliver them.
- Payment metadata: when you buy coins or take a subscription (Basic, Pro or Founders), Stripe processes the payment. We store transaction records (amount, currency, date) but never your card details.
- Usage data: which tier you used, which model responded, ratings you gave to sessions. Used to improve the service and to learn which AI works best for you.
- Technical data: IP address, device type, browser, and request timestamps. Failed sign-in attempts are recorded against the originating IP address, in our own database, so that a brute-force attempt can be slowed down before it reaches any account. Those records are deleted after 90 days by a job that runs every day.
- If you have no account: the public gethal.com/become form stores the name, email address, field and one-sentence answer you enter, so that we can write to you if you stop halfway through the application. It asks for nothing else, and no documents. To have that row removed, write to us.
What we do NOT collect
- Credit card numbers, CVVs, or any other raw payment instrument data — Stripe handles all card information.
- Plaintext passwords — only secure hashes managed by our authentication provider.
- Personally identifying information in your memory or identity profile — the write is rejected at the server before it is stored.
- Your position in the background. The three location features above each run once, when you start them, and HAL keeps no location history.
- Your device's contacts or photo library.
- Your microphone, except when you start it: a recorded voice note, or a live voice conversation you open. We do not listen otherwise, and there is no wake word.
- Your device's local calendar. We read an external calendar only if you deliberately connect one, and only the events needed to show and manage your schedule inside HAL.
How we use your information
- To provide and operate the HAL service.
- To route your conversations to the appropriate AI model or human specialist.
- To personalize responses based on your preferences and conversation history.
- To process payments and manage subscriptions.
- To send transactional emails (welcome messages, payment receipts, account approvals).
- To detect abuse, fraud, and security threats.
- To comply with legal obligations.
How we share your information
HAL operates as a hub between you, AI providers, and human specialists. Specifically:
- AI providers: your messages and uploaded files are sent to one of our AI providers (Anthropic, OpenAI, Google, xAI, DeepSeek, Moonshot AI) to generate responses. The specific provider rotates based on tier, availability, and your preferences, and the app always shows which one is answering. Each provider processes your data under its own terms; the API terms we operate under commit them not to train their models on it. That is their commitment rather than something we can enforce, and we say so rather than presenting it as ours.
- Live voice: when you open a live voice conversation, your browser negotiates the audio connection directly with OpenAI — we mint a short-lived token and step out of the path. That audio never passes through our servers, which also means we cannot show it to you or delete it on your behalf; deletion there is governed by OpenAI's terms.
- Connected services you enable: a calendar (Google, Microsoft, Apple), Telegram, or Uber — HAL exchanges the data that feature needs with that provider, and only while you keep the connection linked.
- Google Maps and OpenStreetMap: when a feature needs to turn a position into an address, or a city name into a country, the coordinates or the place name go to Google's geocoding service or to OpenStreetMap's Nominatim. Nothing that identifies you is sent with them.
- Human specialists and Hals: when you escalate a conversation to a human or book a specialist, that person sees the conversation history and your identity profile. They are bound by our terms to keep this information confidential.
- The Library, if you publish to it: HAL has a shared library that the network writes together. Publishing a file to it is a deliberate act, and it copies that file to a public location with a link anyone can open, whether or not they have a HAL account. Removing it from the Library deletes the copy, and so does deleting your account.
- Stripe: processes all payments. Subject to Stripe's privacy policy.
- Resend: sends transactional emails on our behalf.
- Supabase: hosts our database, authentication and file storage.
- Vercel: hosts our application servers.
We do not sell your personal information to anyone. We do not share your data with advertisers.
Data retention
We keep your account data for as long as your account is active. If you delete your account (see below), we permanently remove your personal data from our systems — the files as well as the records that point at them.
We retain de-identified transaction records and Stripe payment events for up to 7 years to comply with tax and accounting laws. Those rows are not deleted but unlinked: the reference to you is set to null, and nothing that remains identifies you personally.
Records of failed sign-in attempts, which contain IP addresses, are deleted after 90 days by a job that runs every day. Beyond that we keep no log store of our own; request logs live with Vercel and Supabase and are subject to their retention periods rather than ours, and we would rather say that than describe a purge we do not run.
Your rights
You can, at any time, directly from within the HAL app:
- Review what information HAL has stored about you (in the Memory and Identity sections of your profile).
- Delete individual memory items.
- Delete individual emails from your mailbox. Archiving keeps a message but hides it from your inbox; deleting removes it permanently from our systems and it cannot be recovered.
- Disconnect any linked calendar, Telegram or Uber at any time, which revokes HAL's access to that service.
- Remove anything you published to the Library, which deletes the public copy.
- Edit your identity profile.
- Download a copy of your data by contacting us.
- Delete your entire account and all associated data. See how to delete your account.
If you are in the European Economic Area, the United Kingdom, or California, you have additional rights under GDPR and CCPA respectively, including the right to access, correct, or restrict processing of your personal data. To exercise these rights, contact us at hello@gethal.com.
Children
HAL is intended for users 18 years of age or older. We do not knowingly collect information from children under 18. If you believe a child has provided us with personal information, please contact us and we will delete it.
Security
We use industry-standard security practices to protect your data, including encryption in transit (HTTPS), secure password hashing, row-level access controls in our database, and limited access to production systems.
No method of transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
Changes to this policy
We may update this Privacy Policy from time to time. The latest version will always be at gethal.com/privacy. Material changes will be communicated through the app or by email.
Contact
For any privacy-related question or request, email us at hello@gethal.com.
Last updated: September 2026 · HAL is a product of Hal-PA Inc · gethal.com