# Privacy Policy **Human Loop Technologies Ltd** ("we", "our", or "us") operates the Human Loop platform. This Privacy Policy explains how we collect, use, and safeguard your information when you use our service. --- ## 1. Data We Collect **Account Data:** When you register, you provide your email address and chosen display name. This is stored in our user database and is not associated with your vault or therapeutic content. **Vault Content:** Your vault is a personal, encrypted filesystem containing your conversations with the AI companion. The vault is encrypted at rest using LUKS2 with AES-256-XTS. Your encryption keys are never stored on our servers — you hold the sovereign key. **Usage Metadata:** We collect operational metrics such as session start/end times, message counts, and vault size. These are stored in an unencrypted sidecar file alongside your vault and are not cross-referenced with your identity. **Communication with Therapists:** When you are paired with a therapist, messages you send through the platform are routed to your paired therapist. We do not read or process the content of those messages. --- ## 2. How We Use Your Data - To authenticate you and maintain your account - To deliver your encrypted vault on session start and sync it back on session end - To enable your therapist to curate your AI companion's behavior within your vault - To operate safety triage on messages (scanning for crisis indicators) — content is evaluated but not stored long-term after triage - To improve service reliability and session quality We do not sell your personal data. We do not use your conversations for model training. --- ## 3. Data Retention **Vaults:** Your vault remains stored (encrypted) on our object storage as long as your account is active. You may request deletion at any time, which irreversibly deletes your vault image and all associated data. **Account Data:** Retained for as long as your account is active. Upon account deletion, all personally identifying information is removed within 30 days. **Safety Triage Logs:** Short-term operational logs used for safety review are retained for a maximum of 90 days. --- ## 4. Security Your vault is encrypted using LUKS2 with `aes-xts-plain64` and a PBKDF2 key derivation function. The vault is mounted inside an isolated container with no network access. Sessions idle out after 10 minutes of inactivity. We use HTTPS/TLS for all data in transit. Our infrastructure runs behind a WireGuard VPN with no public exposure of internal services. --- ## 5. Your Rights Under GDPR and applicable law, you have the right to: - **Access** your personal data - **Rectify** inaccurate data - **Erase** your vault and account ("right to be forgotten") - **Port** your data (export your vault contents) - **Object** to specific processing To exercise any of these rights, contact us at **privacy@thehumanloop.eu**. We will respond within 30 days. --- ## 6. Third-Party Services We use the following third-party infrastructure providers: | Provider | Purpose | Data Shared | |----------|---------|-------------| | Anthropic | AI model (API) | Messages sent for inference only; no training | | Hetzner | Virtual machine hosting | System logs, uptime | | Cloudflare | DNS and DDoS protection | DNS query logs | These providers are data processors under our DPA. We do not transfer personal data outside the EU without appropriate safeguards. --- ## 7. Children Our service is not intended for users under the age of 16. We do not knowingly collect data from minors. --- ## 8. Changes to This Policy We may update this policy from time to time. We will notify you of material changes via email and by updating the "Last Updated" date below. Continued use of the service after changes constitutes acceptance. --- ## 9. Contact **Human Loop Technologies Ltd** Email: privacy@thehumanloop.eu --- *Last Updated: 2026-04-21*