Privacy Policy

Last updated: January 2025

1. Introduction

Hallucinot, Inc. ("Hallucinot," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI verification API service.

2. Information We Collect

2.1 Account Information

  • Email address
  • Name (if provided)
  • Authentication credentials
  • Billing information (processed by Stripe)

2.2 API Usage Data

  • API request timestamps and frequency
  • Request metadata (not content)
  • Response times and status codes
  • API key identifiers

2.3 Content You Submit

When you use our verification API, you submit content for analysis. This content is:

  • Processed in real-time for verification
  • Not stored permanently (retained for up to 30 days for debugging)
  • Never used to train AI models
  • Encrypted in transit and at rest

3. How We Use Your Information

  • To provide and maintain our verification service
  • To process transactions and send billing notifications
  • To monitor and improve service performance
  • To respond to customer support requests
  • To enforce our Terms of Service
  • To comply with legal obligations

4. Data Sharing

We do not sell your personal information. We may share data with:

  • Google Cloud Platform: Our infrastructure provider (SOC2, ISO 27001 certified)
  • Stripe: For payment processing (PCI-DSS Level 1 certified)
  • Law enforcement: When required by law or to protect our rights

5. Data Security

We implement industry-standard security measures:

  • TLS 1.3 encryption for all data in transit
  • AES-256 encryption for data at rest
  • Role-based access controls
  • Google Cloud Platform infrastructure

6. Data Retention

  • Account data: Retained while your account is active
  • Verification logs: 30 days for Starter, 1 year for Professional
  • Billing records: 7 years (legal requirement)
  • API request logs: 30 days

7. Your Rights

Depending on your location, you may have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Delete your data (right to be forgotten)
  • Export your data (data portability)
  • Object to processing
  • Withdraw consent

To exercise these rights, contact us at privacy@hallucinot.ai

8. GDPR Compliance

For users in the European Economic Area (EEA):

  • We process data under lawful bases (contract, legitimate interest, consent)
  • You can request a copy of your data at any time
  • You can request deletion of your data
  • Data transfers outside the EEA use Standard Contractual Clauses

9. CCPA Compliance

For California residents:

  • We do not sell personal information
  • You can request disclosure of data collected
  • You can request deletion of your data
  • You will not be discriminated against for exercising your rights

10. Cookies

We use essential cookies for authentication and session management. We do not use tracking or advertising cookies.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or through our service. Continued use after changes constitutes acceptance.

12. Contact Us

If you have questions about this Privacy Policy, please contact us:

  • Email: privacy@hallucinot.ai
  • Address: Hallucinot, Inc., [Address]