skip to content
back to the overview

the longer answer

trust, in detail.

What Hug knows. How it uses it. What you can change.

A fuller explanation of our practices across messaging platforms, including iMessage and Discord. Each topic links to the relevant privacy policy so you can follow the details.

01 / the same commitments

Across messaging platforms.

Hug is operated by TAICU, The Artificial Intelligence Company of the Universe, Inc. Our commitments about model training, data use, team access, and deletion apply across Hug’s messaging channels.

The route a message takes depends on the channel. Phone-number-based channels, such as iMessage and WhatsApp, use your phone number; Discord and Telegram use platform user IDs. Conversation identifiers and delivery systems also vary by channel. The homepage lists the current ways to reach Hug; channel availability can change.

Messaging platforms also handle messages under their own policies. A request to delete data from Hug concerns our systems; it does not automatically delete a platform’s copies or messages that other people in a shared conversation can see.

Private chat and shared space have different audiences. A direct conversation goes to Hug through your messaging platform. In a shared space, other participants can also see what you post, according to that platform’s permissions.

policy reference: scope & operator ↗

02 / memory & model training

Does chatting with Hug train a model?

We do not train our own models on your conversations. Hug uses existing AI models to process context and generate replies.

Memory works by saving information and bringing relevant context into a later interaction. For example, a note about an upcoming presentation can help Hug ask about it afterward. That changes the information supplied with a request; it does not update the model’s underlying weights.

Memory

Saved information → context for a future interaction.

Training

Training examples → changes to a model’s parameters.

Our privacy policy states that content submitted under the applicable Microsoft and OpenAI API terms is not used to train their foundation models, and that TypeSafe’s policy says it does not train or fine-tune models on its inputs.

Those training terms do not mean no data is processed or retained. Providers still process content to run the service, and Hug stores conversations, memory, and operational records as described below. Provider roles and applicable terms are listed in the privacy policy.

policy reference: AI processing ↗

03 / our research

Why is Hug a research project?

TAICU studies how AI behaves in ongoing relationships. Hug gives us a way to investigate memory, personality, proactive interaction, emotional expectations, and failures over time.

That includes questions such as what an AI should forget, how it should repair a misunderstanding, and when a check-in is welcome. These are questions about the behavior of the whole system, including its memory and interaction design.

Authorized team members may review conversation content to investigate failures, prevent abuse, and improve Hug. Research and product improvement should not be read as a promise that nobody ever sees a conversation. We disclose that access, and we do not train our own models on your chats.

Hug is an AI companion. It can make mistakes and is not a therapist, medical professional, or crisis service.

source: TAICU’s research agenda ↗ policy reference: how we use information ↗

04 / what exists about you

What does Hug process and store?

Conversation data includes both what you send and context Hug derives from it. A memory, a profile note, or an inference about a conversation is still personal data.

Data used to operate Hug
CategoryWhat it includesWhy it exists
IdentifiersPhone numbers or platform user IDs, plus conversation and delivery identifiers.To route messages to the right person or conversation.
ConversationsMessage text, reactions, quoted replies, and timestamps.To respond and keep the thread of a conversation.
Derived contextMemories, profile notes, texting preferences, relationship context, and follow-up signals.To provide continuity and shape how Hug participates.
Media descriptionsText extracted from media, such as a transcript or image description.To understand the media you send.
Operational recordsDelivery status, errors, logs and traces that can include content, and usage events.To operate, debug, secure, and improve the service.

Memory goes beyond a list of facts.

Stored context can include profile notes, texting style, open conversation threads, Hug’s reflections about a friendship, and signals about whether check-ins are welcome. These records can be wrong, which is one reason correction and deletion requests matter.

Photos, voice notes, and files.

As described in our privacy policy, incoming media is converted into text such as transcripts or descriptions. That text is retained in our systems; the original files are not stored on our servers and remain subject to the messaging platform’s storage policies.

Website and product analytics.

We use PostHog for basic analytics, with website events sent through our own domain. We do not use advertising trackers or third-party ad cookies. We do not collect your address book, browsing history, or precise location; Hug may know a place if you mention it.

policy reference: derived context ↗ policy reference: logs & analytics ↗ policy reference: media ↗

05 / where data goes

Which services help run Hug?

Conversation content is transmitted to providers for processing. Which services are involved depends on the channel and the feature—for example, a voice exchange uses different processing from a text-only reply.

Microsoft Azure OpenAI
Language models that generate replies.
TypeSafe
The Jev decision model, including whether and when to reply.
OpenAI
Transcription of incoming voice notes.
Cartesia
Audio synthesis for voice replies.
Photon
Message delivery.
Microsoft Azure
Application hosting and database infrastructure.
Cloudflare
Website hosting, content delivery, and the website analytics proxy.
Axiom
Operational logs and traces, which can include message content.
PostHog
Product and website analytics.

The privacy policy links to the providers’ policies and describes their roles. Independent messaging platforms, including Discord, also process messages under their own terms.

We do not sell personal data or use it for advertising. The privacy policy also describes other disclosures, including legal obligations, protecting people and the service, and a merger, acquisition, or sale of assets.

policy reference: providers & their policies ↗ policy reference: other disclosures ↗

06 / access & security

Can people read my conversations?

Authorized personnel may review conversation content to operate, debug, improve, and secure Hug. Access within our team is restricted to what is needed for those purposes. Operational logs and traces can contain message content too.

Personal data is encrypted in transit and held in access-controlled infrastructure. That does not mean content is inaccessible to Hug: our systems and providers process it to deliver the service. We do not promise absolute security.

Our infrastructure and service providers are located in the United States, while the website is served through Cloudflare’s global network. The policy explains international transfers and applicable safeguards.

policy reference: security & team access ↗ policy reference: international transfers ↗

07 / your controls

Access, correction, and deletion.

Email waris@hug.wtf to ask about, obtain a copy of, correct, or delete your personal data. Include the platform you use and your account identifier so we can locate it and verify the request. You do not need to post sensitive information in a public channel.

You can ask Hug to forget a specific fact. As described in the policy, this invalidates the corresponding memory; it is distinct from deleting the original message or all other records.

How long does data remain?

  1. While you use Hug

    Service data is retained to provide conversation continuity. A waitlist identifier is retained while the request is active.

  2. After a deletion request

    The privacy policy provides for prompt deletion of messages, memories, and profiles from production systems.

  3. Within 30 days

    The policy describes backups, logs, and traces expiring within 30 days. Operational logs and traces also have a rolling 30-day retention period.

Minimal records may be retained when legally required. Your messaging platform’s own retention is separate. Blocking Hug or removing it from a shared space does not itself request deletion of stored data.

Your rights depend on where you live and may include access, portability, correction, erasure, restriction, objection, withdrawal of consent, and a complaint to a data protection authority. The policy gives the full terms and explains how requests are handled.

policy reference: retention & deletion ↗ policy reference: your rights ↗

08 / channel-specific guidance

Discord: a closer look.

The data commitments above also apply to Discord conversations. The extra consideration in a server is that channel access and participation settings are different controls.

What can Hug receive?

Discord permissions determine which channels Hug can access. In accessible channels, Hug can receive messages even when nobody mentions it. Limiting when it replies is not the same as limiting which messages reach its systems.

Access

Set through Discord channel permissions. Controls where Hug can receive messages.

Participation

Set through Hug’s channel setup. Controls when it joins a conversation.

How does it participate?

  • Normal mode: mentions and direct replies invoke Hug.
  • Ambient mode: Hug can process other messages and join without a mention.
  • Threads: Hug can reply in focused threads, and thread conversations can use ambient behavior.

For channel managers.

  • Use Discord permissions to choose the channels Hug can access.
  • Use /setup status to inspect settings and /setup mode normal for mention-and-reply participation in a channel. Existing thread conversations can still use ambient behavior.
  • Use /social-dms off to disable private check-ins originating from the server.
  • Removing Hug stops new messages from that server reaching it. Contact us separately about stored data.

For individual members.

Tell Hug don't dm me in a direct message or a message addressed to Hug to opt out of private check-ins. You can also contact us for access, correction, or deletion requests. Include your Discord user ID privately in the request.

Server messages are visible to other people with access to that space. A server administrator’s decision to add Hug does not make the conversation private between you and Hug.

read the privacy policy that applies to Hug ↗

09 / accountability

Questions deserve a human answer.

Contact waris@hug.wtf if something here is unclear, if you have a data request, or if Hug behaved in a way that concerns you. This applies whether you talk to Hug privately, share a space with it, or manage a community.

This guide summarizes the privacy policy and terms. The policy includes our registered contact address, the full terms of our data practices, and how changes are communicated. If a change meaningfully reduces privacy, the policy provides for notice through the service before it takes effect.