hedwigaihedwigaihedwigai
hedwigAI Inc.

Privacy Policy

This Privacy Policy explains how hedwigai Inc. ("we") collects, uses, and protects information when you visit our website or use the services we operate (together, the "Services"). It is written to be read, not skimmed past. If anything here is unclear, write to us at hello@hedwigai.com.

What this policy covers

This policy covers our website and the accounts of people who sign up directly. When you sign up directly, you also accept our Terms of Service, which govern your use of the Services, our respective rights over the content you put into them, billing, and liability. This policy does not repeat those terms.

If your organization reached us through a business agreement, that agreement and its data processing addendum govern the data your organization puts into the Services, and they take precedence over this policy wherever the two differ. In that arrangement we act as a processor on your organization's instructions.

Information we collect

Information you give us. When you sign up, contact us, or request a demo, you give us your name, work email, company, and anything you choose to write in a message. If you buy a paid plan, our payment processor collects your payment details; we receive a record of the transaction, not your full card number.

Information collected automatically. Our servers log the IP address, browser, device type, referring page, and pages requested for every visit. We use these logs to keep the Services secure, available, and debuggable. This is the only category we collect without asking first, and we cannot run the Services without it.

Analytics and product usage. How you move through the website, and how you use the signed-in product, including a replay of your session. See cookies, analytics, and session replay below for exactly what runs, what it captures, and who receives it.

What you put into the product. Documents, prompts, and the outputs generated for you. We process this to run the Services for you, and, where your contract asks us to, to train a model for your organization alone. See model training below.

Cookies, analytics, and session replay

Strictly necessary cookies keep your session signed in and remember your theme and your cookie choice. They are always on, because the site does not work without them.

On this website, one vendor sees anything beyond that. If you are in the European Economic Area, the United Kingdom or Switzerland, it runs only if you accept it in the cookie banner. Elsewhere it runs unless you opt out. Either way, if you decline or opt out, it captures nothing.

PostHog gives us product analytics and session replay: which pages you visit, how you got here, and a reconstruction of what a page looked like as you moved through it. Data goes to PostHog, hosted in the United States.

What a replay captures. Session replay runs on this website and inside the signed-in product. Anything you type into a field is masked in your browser before it is sent, so we do not see what you type. Text already displayed on the page is not masked, which means that in the product, the documents and outputs on your screen can appear in a replay. Replays are retained for 30 days and then permanently deleted. If you would rather we did not record your sessions, write to hello@hedwigai.com and we will turn replay off for your account.

If you arrived from one of our ads. When you reach us by clicking a Google ad, the link carries a click identifier from Google, and any campaign tags on the link. We keep them in a first-party cookie for up to 30 days. If you then create an account, we record the sign-up in PostHog with that identifier, and PostHog passes the identifier to Google Ads so we can see which ads led to sign-ups. Google receives the click identifier and the time of the sign-up; it does not receive your name, your email, or anything you put into the product. If you did not arrive from an ad, or you declined or opted out of cookies, nothing is sent to Google.

That is the whole list. We run no advertising tags, no retargeting pixels, no Google Analytics, and nothing that tries to identify you or your company from your IP address.

You can change your mind at any time, and withdrawing is as easy as accepting: . Clearing cookies in your browser also resets the choice. We honor Global Privacy Control signals as an opt-out.

We do not sell or share your information

We do not sell personal information, and we do not share it for cross-context behavioral advertising or targeted advertising. We do not use advertising tags or trackers, and we honor Global Privacy Control signals. The only third parties that receive personal information are the service providers described in this policy, each engaged under terms that restrict them to processing on our behalf. We never sell or share what you put into the product, under any circumstances.

How we use information

To create and run your account, provide the Services, process payments, answer support requests, keep the Services secure and free of abuse, measure and improve what we build, market the Services to businesses, and comply with the law.

We do not make decisions with legal or similarly significant effects about you using automated processing alone.

Our legal bases (EEA and UK)

We rely on contract to give you the Services you signed up for; legitimate interests to secure the Services, prevent abuse, and market to businesses; consent for the analytics and session replay cookies, which you may withdraw at any time; and legal obligation where the law requires us to retain or disclose information.

Who we share information with

We share information with vendors who process it on our behalf, under contract, only for the task we hired them for: cloud hosting and infrastructure, our payment processor, email delivery, customer support tooling, and, if you accept cookies, PostHog. A current sub-processor list and a signed data processing addendum are available from security@hedwigai.com.

We also disclose information when the law compels it, and to protect the rights and safety of hedwigai, our users, or the public. If we are ever acquired or merged, information transfers with the business, and this policy continues to apply until you are told otherwise.

Model training and inference

We never train a shared model on your content. Nothing you put into the Services is used to train a model that any other customer can reach, or that we, any inference provider, or any other model provider trains on or reuses outside your organization. This includes any model trained on aggregated, anonymized, or de-identified data derived from your content; we do not do this.

How your content reaches a model. To generate Output, we send your Input to inference providers that host and run open-weight models on our behalf: DeepInfra, Groq, and Cerebras, each processing in the United States. We do not send your content to OpenAI, Anthropic, or any other frontier model developer. See Security for the architecture.

Each of these providers is engaged as a subprocessor under terms that prohibit them from training on or otherwise reusing your content, and that limit retention to what is needed to run the request and detect abuse.

We do train models for you, when your contract says so. Bespoke model training is one of the Services we sell. Where your organization has engaged us for it, we train on the data your agreement identifies, and the resulting model serves your organization alone. Ownership of the model and its weights, the scope of that training, what it may use, and how long the model and its training data are kept are set by your agreement and its data processing addendum, not by this policy.

If you signed up directly rather than through a business agreement, we do not train any model on your content.

How long we keep information

Product analytics events are retained for no more than 12 months. Session replays are retained for 30 days and then deleted. Server logs are retained for 90 days. Account and contact records are kept while your account is active and for as long afterwards as we need them for tax, accounting, and legal purposes.

When you ask us to delete your data, we remove it from live systems within 30 days. Copies may persist in encrypted backups until those backups age out on their normal rotation; they are never restored into live systems for any purpose other than disaster recovery.

Your rights

Wherever you live, you may ask us to give you a copy of your personal information, correct it, delete it, or send it to another provider. You may object to or ask us to restrict processing that relies on our legitimate interests, and you may withdraw consent to cookies at any time without affecting what came before.

If you are in California, you additionally have the right to know what we collect and why, to delete it, to correct it, to opt out of any sale or sharing of it, and not to be treated differently for exercising any of these rights. As explained above, we neither sell nor share it. We do not use sensitive personal information for inferring characteristics.

To exercise any of these, write to hello@hedwigai.com. We answer within 30 days and may ask you to verify your identity first. An authorized agent may act for you with written permission. If your data reached us through your employer's account, we will forward your request to them, since they decide what happens to it.

If you are in the EEA or UK and think we have handled your data badly, you may complain to your local supervisory authority. We would rather you told us first.

International transfers

We operate in the United States, and our vendors may process information there. When we move personal information out of the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses and the UK Addendum, together with technical measures such as encryption in transit and at rest.

Content you put into the product is a different matter: it stays pinned to the region you choose, and is not replicated out of it. We offer United States, European Union, and India data residency.

Security

We encrypt data with AES-256 at rest and TLS 1.3 in transit, isolate each customer in their own logical tenant, scope access to the least privilege that works, and monitor continuously. No system is perfectly secure, and we will not pretend otherwise. You are responsible for keeping your account credentials confidential and for telling us promptly at security@hedwigai.com if you suspect someone else has them. Our full posture is on the Security page.

Children

The Services are built for business use by adults. We do not knowingly collect personal information from anyone under 18. If we learn that we have, we delete it.

Changes to this policy

We may update this policy. When we do, we revise the date below, and where the change is material, we tell you before it takes effect. Continuing to use the Services after that means you accept the revised policy.

Contact us

Questions about this policy go to hello@hedwigai.com. Security questionnaires and data processing addenda go to security@hedwigai.com. You may also write to hedwigai Inc., 2261 Market Street STE 10486, San Francisco, CA 94114.

Date last modified July 10, 2026