Privacy Policy
In plain English: We do not sell your data, mine it, or train models on it, ever. Documents and API requests are processed, then wiped, never stored. The one thing that persists is the web-chat history you choose to save, encrypted on your own device, never on our servers, and erased the instant you delete it. What we do not keep, no one can take. The detail below says exactly the same thing in the language your DPO needs.
1. Who we are
Hush AI is a UK-based provider of private artificial intelligence services. We operate under the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018. Our founder and data protection contact is Dr W.J Carter (legal name Dr Arsallan Ahmed), reachable at [email protected] or for privacy-specific matters at [email protected].
We are registered with the UK Information Commissioner's Office (ICO) as a data controller. Our registration reference is ZC126901.
2. What this policy covers
This policy explains what personal data we collect when you use hush-ai.uk or our associated AI services, why we collect it, how we use it, and what rights you have. If you are accessing Hush AI as part of a business contract with your employer (a "Customer Organisation"), the terms of our Data Processing Agreement with that organisation may supplement this policy, in which case the DPA terms prevail.
3. What personal data we collect
We collect the minimum personal data necessary to operate the service.
When you create an account
- Your name and work email address
- Your organisation name
- A password you choose (stored only as a cryptographic hash, we cannot recover or view it)
- The tier or plan you are on
When you use the service
- Timestamp of each request
- An internal identifier for your account
- The AI model you selected
- The number of tokens (units of text) your request consumed
- The HTTP response code and processing latency
- Your IP address at the time of the request (retained for 30 days for security monitoring, then removed from the log; the remaining usage metadata is kept for 12 months)
Your conversation content, the honest version
- API requests: prompt and response content is processed in memory on our UK infrastructure and discarded once the response is returned. It is not stored.
- Web chat: your conversation history is saved encrypted on your own device so you can return to it, search it, and organise it. It never reaches our servers. It is never used to train models and never analysed for marketing. Deleting a conversation removes it from your device immediately.
- We never store cookies for tracking, advertising, or third-party analytics. We use only a single session cookie, strictly necessary to keep you logged in.
- To understand whether our website works, we keep anonymous tallies of key events (a pilot form submitted, a checkout started) on our own hardware, no IP address, no identifier, no cookie attached to any of them.
4. Why we process this data, lawful basis
Under Article 6 UK GDPR, our lawful bases are:
- Contract (Article 6(1)(b)): to provide you with the service you signed up for.
- Legitimate interests (Article 6(1)(f)): to keep the service secure, prevent abuse, enforce usage quotas, and bill accurately. You can object to this processing at any time; where you do, we will cease processing unless we can demonstrate compelling legitimate grounds.
- Legal obligation (Article 6(1)(c)): to retain certain records where UK law requires it.
We do not rely on consent as a lawful basis, because providing a fully functional account requires the data above. We do not process special-category data (health, racial, religious, biometric, etc.) about you as an account holder. If your use of the service involves processing such data about third parties, your organisation is the controller of that processing, not Hush AI.
5. Where your data is processed and stored
All inference processing occurs on hardware we own and physically control. Your prompt and response content is processed in memory and is not stored on our servers; any chat history you keep is held locally on your own device, not by us. We do not use cloud providers (AWS, Azure, GCP, or any other) and we do not use third-party AI APIs. No third party ever processes your prompt or response content.
Two third parties process limited personal data so the service can operate, and we disclose them honestly: Stripe (payment processing, your name, email, and card details are handled by Stripe and never touch our servers) and Cloudflare (edge TLS and DDoS protection, processes IP addresses and connection metadata; not an AI sub-processor and never sent your saved data). The full list, with what each processes, is on our Security page.
6. How long we keep it
- Account records (name, email, organisation, password hash): while your account is active, plus 90 days after closure, then deleted.
- Usage logs (timestamps, token counts, latency): 12 months, then deleted. IP addresses are removed from these logs after 30 days. On written request from your organisation, we can provide an export of these logs at any time, free of charge.
- API prompt and response content: not stored.
- Web-chat conversation history: kept until you delete it; gone from rotating backups within 30 days of deletion.
- Financial records (invoices, payments): 6 years as required by HMRC.
7. Your rights
Under UK GDPR, you have the right to:
- Ask what data we hold about you (right of access)
- Correct inaccurate data (right of rectification)
- Have your data deleted (right to erasure)
- Restrict our processing (right to restriction)
- Receive your data in a portable format (right to portability)
- Object to processing based on legitimate interests
- Not be subject to solely automated decisions that significantly affect you, we do not make such decisions about you as an account holder
To exercise any of these, email [email protected]. We respond within 30 days, usually much sooner.
If you are unhappy with our response, you can complain to the Information Commissioner's Office at ico.org.uk or by phone on 0303 123 1113.
8. Children
Hush AI is not intended for use by individuals under 18. We do not knowingly collect personal data about children. If we learn that we have, we will delete it promptly.
9. Changes to this policy
We will post any material changes here at least 30 days before they take effect, and email registered account holders. The current version and effective date appear at the top of this page.
10. Contact
Privacy enquiries: [email protected]
Support: [email protected]
General enquiries: [email protected]
Security and vulnerability reports: [email protected]
Hush AI is a drafting and summarisation assistant. It is not a source of medical, legal, or financial advice. Always verify AI-generated outputs before acting on them.
← Back to Hush AI