Privacy
What we collect, why we are allowed to, who else sees it, and how to make us stop. Written to be read rather than to satisfy a checklist, though it satisfies the checklist too.
Last updated 10 September 2026
1.Who is responsible for your data
BigHugger is the data controller for everything described here. Questions, requests and complaints go to privacy@bighugger.com, and a person reads that address.
If you are in the EU or UK and you think we have handled your data badly, you can complain to your national data protection authority. We would rather you told us first, because we can usually fix it the same day.
2.What we collect
Four things, and it is worth being precise about each.
Your account. An email address, a password stored only as a PBKDF2 hash, and optionally a display name. If you sign in with GitHub we also store your numeric GitHub user id, your GitHub username, and the verified email address we matched you on. We never receive your GitHub password and we ask only for read access to your profile and email.
What you ask for. Your searches, your questions, the threads they belong to, and any workbooks you generate. This is the product; without it there is nothing to show you when you come back.
Requests for access. If you ask to join, we keep the address you gave and whatever you wrote in the box next to it, until we either let you in or you ask us to delete it.
Your IP address, briefly. Anyone can search from the landing page without an account, so we count searches against the address they came from to stop one script spending our inference budget. The count is keyed by day and expires about twenty six hours later. We do not build a profile from it, we do not join it to your account, and we cannot tell you what you searched for anonymously last week because we no longer have it.
Things we do not collect: analytics, advertising identifiers, location beyond whatever an IP address implies, and anything at all from a tracking pixel. There are none on this site.
3.Why we are allowed to hold it
Under the GDPR every use of your data needs a lawful basis. Ours are contract for anything without which the product does not work, which covers your account, your searches and your saved threads; and legitimate interests for keeping the service standing up, which covers the rate limiting described above and our server logs. Where we rely on legitimate interests we have weighed them against your privacy, and we think counting requests per address for a day is about as light as abuse prevention gets.
We do not rely on consent for anything today, because nothing here is optional tracking. If that changes you will be asked, properly, before it starts.
5.How long we keep it
Your account and its contents stay until you delete them or ask us to. Anonymous rate-limit counters expire after roughly twenty six hours. Access requests are kept until the request is resolved, and we clear the declined ones periodically. Payment records are kept as long as tax law requires, which is seven years in most places.
6.Where it goes
Our servers and every processor above are in the United States, so if you are in the EU or UK your data is transferred there. Those transfers rely on the European Commission’s Standard Contractual Clauses, or on the EU-US Data Privacy Framework where the processor is certified under it.
7.What you can ask us to do
Whoever and wherever you are, you can ask for a copy of what we hold, ask us to correct it, ask us to delete it, ask us to stop a particular use, or ask for it in a form you can take elsewhere. You will not be charged and you will not be treated differently for asking.
Email privacy@bighugger.com. We aim to answer within a few days and the legal limit is one month. You can export your own threads and workbooks from Settings at any time without asking anyone.
8.Security
Passwords are hashed with PBKDF2 and never stored in a readable form. Session cookies are HttpOnly and SameSite, so a script on another site cannot read or replay them. API keys are shown once and stored hashed. None of this makes a system unbreakable, and if we ever do suffer a breach that puts you at risk we will tell you and the regulator inside 72 hours.
9.Children
This is a tool for people who work with machine learning models, and it is not meant for anyone under 16. We do not knowingly collect anything from a child. If you believe we have, write to us and it will be deleted.
10.Changes
When this policy changes the date at the top changes with it. If a change actually affects what happens to your data, rather than fixing a sentence, we will email account holders before it takes effect.