Frequently asked questions

Straight answers, grouped by theme, in the spirit of the rest of the site. For the harder questions a careful buyer asks (is a private model good enough, what if you disappear, why only £39), see our honest answers. If your question isn't here, write to [email protected] and we'll answer it plainly.

Privacy & your data

Do you keep my data?

No, that is the whole point. We process what you send, then delete it, so there is no conversation or document stored to leak, sell, or be compelled to hand over. Documents and API requests are never stored; the only thing kept is the web-chat history you choose to save, encrypted on your own device, never on our servers, and erased the instant you delete it. What we do not keep, no one can take.

Where is my data stored?

Your conversation history stays on your own device, never on our servers; what you send for inference is processed on hardware we own and never leaves it. The only disclosed sub-processors are Stripe (payments) and Cloudflare (transport metadata); neither receives your prompts or responses. More on our security page.

Does Hush AI train its models on my data?

No. Your content is never used to train models or analysed for marketing. Web-chat history is stored encrypted locally on your own device so you can return to it, and deleted when you delete it. API requests aren't stored at all.

Does my data go through Big Tech (OpenAI, Google, Microsoft)?

No. Hush runs its own models on its own hardware, with no third-party AI API in the chain, so your content never passes through a Big Tech system. And because we store none of your conversations or documents, there is nothing for anyone to be compelled to hand over.

What can Cloudflare see?

We use Cloudflare only for edge TLS and DDoS protection. It handles connection metadata such as your IP address and the time and URL of a request, and your traffic passes through its edge in transit. Cloudflare is not an AI sub-processor, is never sent your saved conversations or documents, does not store your prompts or responses, and never uses anything for training. The AI itself runs only on hardware we own. We are also building browser-side sealing so that, over time, the edge only ever handles an encrypted envelope. Full detail is on our security page.

Can my messages be intercepted in transit?

Between your device and our edge, traffic travels over TLS 1.3 with a hybrid post-quantum key exchange (X25519 with ML-KEM-768), so a network eavesdropper on the wire cannot read it; from our edge to hardware we own it is re-encrypted over TLS 1.2/1.3. On our side there is no conversation or document stored to intercept later: prompts and documents are processed, then gone.

What happens to my data if you are hacked, subpoenaed, or shut down?

There is nothing of yours on our servers to take. We store no prompts, no documents and no chat content; your history lives encrypted on your own device. A breach, a court order or the company winding down cannot surrender data we never held. Payments sit with Stripe, and your account details are the minimum needed to run the service. What we do not keep, no one can take.

How do I delete my data or account?

Your chat history is on your device, so deleting a conversation removes it at the source, and clearing it in the app or your browser wipes it entirely. To close your account and erase the limited account data we hold, or to exercise any GDPR right, write to [email protected]. See the privacy page.

Do you use cookies, trackers or analytics?

No third-party advertising or analytics trackers. The site uses your browser local storage only for functional preferences such as light or dark theme and accessibility settings, never to profile you. Payments are handled by Stripe; the full, short sub-processor list is on the security page.

Security

Is my connection quantum-safe?

Yes, on the connection. Your browser and our edge negotiate a hybrid post-quantum key exchange (X25519 with ML-KEM-768), verified live, so traffic captured today cannot be unlocked later by a future quantum computer. That is protection against harvest now, decrypt later. Our HushUp messenger adds post-quantum end-to-end encryption on top.

Is the HushUp messenger really end-to-end encrypted?

Yes. HushUp, our separate private messenger (in public beta), is end-to-end encrypted with post-quantum protection: messages are sealed on your device, so nobody but the participants, including us, can read them. See HushUp.

Where does the AI actually run?

On hardware we own and operate in the UK, not a third-party cloud and not a Big Tech API. Nothing you send is passed to OpenAI, Google, Microsoft or any other AI provider; our public AI sub-processor list is empty.

Using Hush

What can I do with Hush?

One private workspace of tools: chat with our models, edit and fill PDFs, draft and review documents, analyse spreadsheets, transcribe audio, run private search, and prepare meetings. See the platform overview.

Do I need to install anything?

No, Hush runs in your browser. You can optionally install it as an app straight from the browser, or on Android download the app, with nothing to approve in an app store and updates arriving automatically. See the app page.

Is Hush AI a medical device or an ambient scribe?

No to both. Hush doesn't listen to consultations or generate clinical notes. It drafts administrative documents under professional review, on the administrative side of the MHRA boundary. If you need a scribe, buy a registered one, here's why we're deliberately not one, and Hush can sit alongside it.

How is Hush different from ChatGPT, Copilot, Gemini or Claude?

They're excellent products from Big Tech, on clouds that, on their consumer tiers, keep a copy of what you type and may use it to train the next model; their business tiers offer training opt-outs, so check the tier you are on. Hush runs on hardware it owns, keeps no conversations or documents, never trains on your data, and gives a one-click audit export. See the honest comparisons, including what each does better than us.

Can I use ChatGPT or Copilot for confidential client work?

For public consumer AI, the answer from your own regulator is usually no. NHS guidance and trust policies, for example, state that patient-identifiable or confidential data must not be entered into public generative AI tools such as ChatGPT. The same duty of confidence binds solicitors, accountants and HR. That is the gap Hush fills: it runs on hardware we own, keeps no conversations or documents, and never trains on what you type, so you can use AI on the work you are otherwise not allowed to paste into a public tool.

Does it work with EMIS and SystmOne?

It works alongside them with no integration, copy and paste, no IT project, nothing for your clinical-system supplier to approve.

Compliance & legal

Are you GDPR-compliant, and who is the data controller?

Yes. For your account data (the minimum needed to run the service) we are the data controller, registered with the ICO (ZC126901). For the content you submit, your prompts and their responses, your organisation is the controller and Hush acts as a processor on your instructions, under a Data Processing Agreement signed before any live data flows. Detail on the security page.

Can I get an audit trail for my DPO?

Yes, an audit log of your usage in one click, CSV or JSON. Your own GDPR Article 30 / IG evidence pack, yours to keep.

Where are you based, and does the US CLOUD Act apply?

Hush AI is a UK company (HUSH AI LIMITED, Companies House 17278687) running on hardware we own in the UK, with no US parent. The US CLOUD Act reaches US-owned providers wherever data sits; because we are not US-owned and store no content, that lever does not apply here. This is the gap the French Senate hearing exposed for Big Tech.

What was the French Senate hearing about Microsoft?

In June 2025, Microsoft France's director of public and legal affairs was asked at a French Senate hearing, under oath, whether he could guarantee that data held for French citizens would never be passed to US authorities. He answered, "No, I cannot guarantee it." Under the US CLOUD Act a US-owned provider can be compelled regardless of where data is stored. Microsoft says it has never happened; the point is they could not promise it would not. Hush runs on hardware we own, with no US parent, so that question does not arise here. Read what was said.

What certifications do you hold?

We publish our status openly, including what we don't yet hold. Cyber Essentials and the NHS DSPT self-assessment are in progress; pilots run under your own DPIA. We'd rather say that plainly than imply assurances we don't have. See procurement.

Pricing, trial & company

How much does it cost?

From £39/month (Personal), £99 (Professional, all tools), £399 (Practice, up to five users). Free two-week pilot, no card. Full pricing here, or estimate your savings.

How does the free trial work?

A free two-week trial run entirely in writing, no card, no calls, up to five logins the same day. Capped at five pilots at a time because the hardware is finite. You decide at the end; no conversation or document is retained if you don't continue.

Who is behind Hush AI?

It's operated by HUSH AI LIMITED, founded by a doctor, Dr W.J Carter, running on hardware we own.

Do you have customers or case studies yet?

We are early, and we would rather be straight than borrow someone else's numbers. Instead of case studies, the free two-week pilot generates your own evidence: a written report from your own audit-log export (documents drafted, active users, hours saved) that is yours to keep whether or not you continue. The company is verifiable today at Companies House (17278687) and the ICO (ZC126901). Every business starts somewhere, and we would rather earn your trust on your own work than on a testimonial you cannot check.