Privacy Policy
Last updated: August 15, 2026
1. Introduction
Welcome to Hebbrix. We respect your privacy and are committed to protecting your personal data. This privacy policy will inform you about how we handle your personal data when you use our service.
2. Data We Collect
We collect and process the following data:
- Account Information: Email, name, and authentication credentials
- Usage Data: API requests, feature usage, and performance metrics
- Customer Content: Memories, prompts, outputs, documents, media, embeddings, profiles, graph data, corrections, feedback, decisions, outcomes, traces containing content, and support payloads you choose to provide or process
- Technical Data: IP address, browser type, and device information
3. How We Use Your Data
We use your data to:
- Provide and maintain our service
- Process and store your memories
- Operate and improve retrieval, reliability, security, and product features
- Send you service-related communications
- Analyze usage patterns to enhance the service
- Ensure security and prevent fraud
Hebbrix does not use Customer Content to train shared or general-purpose AI models. This no-training default covers stored content, embeddings, prompts, outputs, corrections, feedback, content-bearing traces, and support payloads. We do not sell Customer Content. Product improvement uses operational telemetry that does not contain Customer Content, aggregate statistics, and de-identified quality signals; Hebbrix does not silently opt Customer Content into a training or product-improvement corpus. Your own Outcome Memory data is used only to learn policies within your authorized account scope. Any future content-use program would require separate, explicit opt-in terms and an auditable consent record.
4. Data Storage and Security
Your data is stored securely using industry-standard encryption:
- Data is encrypted in transit using TLS/SSL
- Passwords are hashed using bcrypt
- Vector embeddings are stored in Qdrant with access controls
- Database backups are encrypted and stored securely
- We use AWS cloud infrastructure with enterprise-grade security
5. Data Sharing
We do not sell your personal data. We may share data with:
- AI Processing: Amazon Bedrock for memory extraction and OpenAI API for the limited prompts or content required by other features that use language-model processing. AWS and OpenAI state that customer inputs and outputs are not used to train their shared foundation models by default; Hebbrix does not opt Customer Content into model-improvement sharing
- Cloud Infrastructure: Amazon Web Services in the United States for hosting, storage, databases, backups, networking, email delivery, monitoring, and Bedrock model inference
- Operational Services: Stripe for billing, Sentry for error and reliability monitoring, Google for OAuth when you choose Google sign-in or a Google integration, and providers for integrations you explicitly enable; each receives only the data needed for that purpose
- Legal Requirements: When required by law or legal process
6. Your Rights
You have the right to:
- Access your personal data
- Correct inaccurate data
- Request deletion of your data
- Export your data in a portable format
- Opt-out of certain data processing
- Withdraw consent at any time
7. Data Retention
Active Customer Content is retained while your account or collection remains active. Collection deletion makes the collection inaccessible immediately and durably schedules cleanup of vectors, search indexes, profile derivatives, graph data, and stored objects. Account deletion starts a 90-day recoverable deletion window; eligible primary records are permanently purged after that window. Production application logs are retained for up to 90 days, hosted MCP logs for 30 days, automated database backups for 14 days, and service backup exports for up to 35 days. Deleted media object versions expire within one day. Backups are not edited record by record; deleted data ages out when the applicable encrypted backup expires. Anonymized security-event classifications and records required by law, fraud prevention, tax, or billing obligations may be retained longer without Customer Content where feasible.
8. Cookies and Tracking
We use essential cookies for authentication and session management. We do not use third-party advertising cookies.
9. Children's Privacy
Our service is not intended for children under 13. We do not knowingly collect data from children under 13.
10. International Data Transfers
The hosted Hebbrix service currently processes and stores primary service data in AWS US East (United States); customer-selectable data residency is not currently offered. Limited data sent to subprocessors may be processed in locations disclosed by those providers. If your organization requires a DPA, transfer terms, a BAA, a particular residency region, a SOC 2 report, or a contractual SLA, contact us before submitting regulated or sensitive data. Such terms apply only when separately signed; security controls or "HIPAA-ready" architecture do not by themselves constitute certification, a BAA, or regulatory compliance.
11. Changes to This Policy
We may update this privacy policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date.
12. Contact Us
If you have any questions about this Privacy Policy, please contact us at:
- Email: contact@hebbrix.com
- Support: contact@hebbrix.com
GDPR Rights
Users in the European Union may have rights under GDPR, including access, correction, deletion, portability, restriction, objection, and the right to lodge a complaint with a supervisory authority.
California Privacy Rights
California residents may have rights to know, correct, or delete personal information and to opt out of sale or sharing. Hebbrix does not sell personal information as described in this policy.