hal
Product
OverviewHow it fits together SupportChat, inbox & help center SalesProduct-led CRM & pipeline FocusOne clear priority WorkDrafts & follow-through
Founders Support teams Founder-led sales
Pricing Docs
EN English SL Slovenščina HR Hrvatski
Log in Start free
Product
Overview Support Sales Focus Work
Solutions
Founders Support teams Founder-led sales
Pricing Docs
Language
EN English SL Slovenščina HR Hrvatski
Theme
Log in Start free

Privacy Policy

Last updated: September 2026

What this policy covers

This policy explains what personal data HAL collects when you use chatwithhal.com, the HAL dashboard, and the HAL chat widget — what we do with it, who we share it with, and the choices you have. Plain language on purpose.

Who is responsible

HAL is the data controller for data described here. For anything privacy-related — questions, requests, or a complaint — write to privacy@chatwithhal.com and a human will answer.

What we collect

Two perspectives matter: your team (the customers who pay us) and your visitors (the people who chat on your site).

Account data

Name, email, password (hashed), workspace settings, billing metadata handled by Stripe, and support correspondence. We ask for the minimum needed to run your workspace.

Visitor data

When someone chats on a site using HAL: messages they send, pages they visit, browser language, and — only if you identify them — the traits your product pushes (email, name, plan, custom properties). Before identification this data is anonymous to us.

Conversation data

Chat messages, email conversations, attachments, internal notes, CSAT ratings, and the operational metadata (timestamps, assignments) that make an inbox work.

Product analytics

Product usage events (feature adoption, aggregate counts) processed by PostHog on EU hosting. Session recording is disabled. We measure how features are used, not individual browsing histories.

How we use data

We use the data above for exactly these purposes:

  • Operating the service — inboxes, CRM, knowledge bases, automations, and the widget itself
  • AI features — drafting replies and answering visitor questions, grounded in your content (see AI processing below)
  • Billing — invoicing, plan limits, and preventing abuse
  • Security — fraud prevention, rate limiting, and protecting accounts
  • Product improvement — aggregated, non-identifying patterns that tell us what to build next

Legal bases (GDPR Art. 6)

We process personal data under these bases:

Contract

Providing the service you signed up for — storing conversations, sending your emails, running your workspace.

Legitimate interest

Security, abuse prevention, and aggregate product improvement — always balanced against your rights.

Consent

Optional things: marketing email, non-essential cookies, and visitor AI features where required. Withdraw anytime; withdrawal does not affect prior processing.

AI processing of visitor messages

When AI features are enabled for your project, visitor messages may be processed to draft replies, answer questions, and classify priority. Here is exactly what that means.

How it works

Message content, relevant knowledge base excerpts, and conversation context are sent to Anthropic’s Claude models to produce a draft. Drafts cite their sources and carry a confidence score before anyone sees them.

Your data is not training data

Your conversations and your visitors’ messages are never used to train models — not by us, not by Anthropic. Processing is transient: it produces your draft, nothing else.

Humans stay in charge

Drafts require agent approval by default. Auto-send and visitor-facing AI answers are opt-in, confidence-thresholded, and can be disabled per project at any time.

Visitor control

The widget discloses AI use to visitors, who can opt out of AI answers with one tap (stored per visitor). EU AI Act transparency requirements are built into the widget, not bolted on.

Subprocessors

A short list, each bound by data processing agreements:

  • Anthropic (Claude) — AI models for reply suggestions and visitor answers. Content is processed to produce drafts and is not used to train their models.
  • PostHog — Product analytics, EU-hosted. No session recording.
  • Stripe — Payments. Card data goes to Stripe, never to us.
  • Railway — EU infrastructure hosting for the API and database.
  • Cloudflare — EU content delivery, static hosting for this site, and encrypted backups.

How long we keep data

Conversation history follows your plan (30 days on Free, longer on paid tiers — unlimited on Pro and above). Account data lives until you delete it. Deleted accounts enter a 30-day grace period, after which data is permanently removed. Backups roll off on the same cycle.

Where data lives

Storage and infrastructure are in the European Union. Our hosting (Railway), CDN (Cloudflare), and analytics (PostHog EU) all operate EU data centers. AI processing may occur outside the EU with Anthropic under the EU Standard Contractual Clauses and their API data handling commitments; your content is not used for model training.

Your rights

Under GDPR you have:

  • Access — See what personal data we hold about you.
  • Rectification — Correct anything inaccurate.
  • Erasure — Delete your account and data, with a 30-day grace window to change your mind.
  • Portability — Export everything in machine-readable JSON — one click in settings, no support ticket.
  • Objection — Object to processing based on legitimate interest; we will stop unless we have compelling grounds.

Email privacy@chatwithhal.com or use the in-app export and deletion tools. We respond within 30 days. You may also complain to your local data protection authority — we would rather fix it first.

Children

HAL is a business tool and is not directed at children under 16. We do not knowingly collect their data; if one slips through, we delete it on request.

Changes to this policy

Material changes are announced by email and in the dashboard before they take effect, and the date above changes. Continued use after that means you accept the update.

Contact

Privacy questions, requests, and complaints: privacy@chatwithhal.com.

hal

The customer platform for builders. Support the customer. Move the deal.

Product

Support Sales Overview Focus Work Pricing

Solutions

Founders Support teams Founder-led sales

Developers

Documentation Widget setup API reference MCP server
© 2026 HAL. All rights reserved.
Privacy Terms EU compliance
EN English SL Slovenščina HR Hrvatski