← Back to Home

Privacy Policy

Last updated: March 8, 2026 · Effective immediately

1. Introduction

HalluTrace AI ("we", "our", "us", or "the Company") operates the hallutraceai.com website and the HalluTrace AI platform (collectively, the "Service"). This Privacy Policy explains how we collect, use, process, store, disclose, and protect your information when you access or use our Service.

By using the Service, you consent to the data practices described in this Privacy Policy. If you do not agree with any part of this policy, you should discontinue use of the Service immediately. This Privacy Policy should be read in conjunction with our Terms of Service.

2. Information We Collect

2.1 Account Information

When you create an account, we collect: your name, email address, hashed password (for email-based registration), or OAuth tokens and profile data (for Google sign-in). Organization details (name, slug) are collected if you create an organization.

2.2 Trace Data (User-Submitted Content)

When you use the Service, you submit trace data including: LLM inputs (prompts, questions), LLM outputs (responses), system prompts, RAG context, model names, session identifiers, message identifiers, and associated metadata. This data is processed to provide hallucination evaluation services. You are solely responsible for ensuring that the data you submit does not contain sensitive personal information (PII), protected health information (PHI), financial data, or any data that you are not authorized to share.

2.3 Evaluation Data

We generate and store evaluation results including: hallucination scores (0-100), evaluation reasons, feedback text, alert triggers, and aggregated analytics derived from your trace data.

2.4 Usage & Technical Data

We automatically collect: IP addresses, browser type and version, operating system, device information, referring URLs, pages visited, session duration, clickstream data, feature usage patterns, API call logs (endpoint, timestamp, response codes), and error logs.

2.5 Payment Information

Payment and billing information (credit card numbers, bank details) is collected and processed by our third-party payment processor, Stripe, Inc. We do not store your full payment card details on our servers. We store: transaction amounts, dates, Stripe customer IDs, subscription status, and billing account metadata.

2.6 Communication Data

We collect information from communications with us, including: support requests, feedback, bug reports, and any other correspondence sent via email or through the Service.

2.7 Referral Data

If you participate in our referral program, we collect: referral codes, referral link clicks, cookie data (7-day expiry), referred user associations, and commission earnings data.

3. How We Use Your Information

We use the information we collect for the following purposes:

  • Service Delivery: To provide, operate, and maintain the HalluTrace AI platform, including processing traces, running hallucination evaluations, and delivering results
  • Account Management: To create and manage your account, authenticate your identity, and process billing and payments
  • Alerts & Notifications: To send you email alerts, SMS alerts, and webhook notifications based on your configured thresholds and preferences
  • Service Improvement: To analyze usage patterns, diagnose technical issues, improve evaluation accuracy, optimize performance, and develop new features
  • Security: To detect, prevent, and respond to fraud, abuse, security incidents, and violations of our Terms of Service
  • Communication: To respond to your inquiries, send service announcements, security alerts, billing notifications, and other operational messages
  • Legal Compliance: To comply with applicable laws, regulations, legal processes, and government requests
  • Analytics: To generate aggregated, anonymized statistics and reports about Service usage for internal business purposes

4. Data Processing & Third-Party Sharing

4.1 Evaluation Processing

To perform hallucination evaluations, we transmit relevant portions of your trace data (inputs, outputs, system prompts) to third-party LLM providers through automated workflows. This processing is necessary to deliver the core functionality of the Service. We select providers based on their data handling practices, but we cannot guarantee the privacy practices of third-party providers.

4.2 Service Providers

We may share your information with trusted third-party service providers who assist us in operating the Service, including:

  • Cloud Infrastructure: For hosting, storage, and computational resources
  • Payment Processing: Stripe, Inc. for processing payments and managing subscriptions
  • Email Delivery: Amazon SES for sending transactional and alert emails
  • SMS Delivery: Twilio for sending SMS alert notifications
  • LLM Providers: For executing hallucination evaluation workflows

These providers are contractually obligated to use your information only to perform services on our behalf and in compliance with applicable data protection laws.

4.3 Legal & Safety Disclosures

We may disclose your information if required by law, regulation, legal process, or governmental request, or if we believe in good faith that disclosure is necessary to: (a) comply with applicable law or legal process, (b) protect the rights, property, or safety of HalluTrace AI, our users, or the public, (c) detect, prevent, or address fraud, security, or technical issues, or (d) enforce our Terms of Service.

4.4 Business Transfers

In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will notify you of any such change in ownership or control of your information.

4.5 No Sale of Personal Data

We do not sell, rent, or trade your personal data to third parties for their marketing purposes. We do not use your trace data to train AI models that are sold or licensed to third parties.

5. Data Retention

We retain your data for the following periods based on your plan:

  • Free plan: Trace and evaluation data retained for 7 days
  • Pay as You Go: Trace and evaluation data retained for 90 days
  • MAX-T: Trace and evaluation data retained for 365 days
  • Zero Storage: If enabled, trace data is deleted immediately after evaluation processing is complete

Account information is retained for as long as your account is active and for a reasonable period thereafter to fulfill legal, accounting, and reporting obligations. Aggregated and anonymized data may be retained indefinitely. You may request deletion of your data at any time by contacting us; we will process such requests within 30 days, subject to legal retention requirements.

6. Data Security

We implement commercially reasonable technical and organizational security measures to protect your data, including:

  • Encryption in transit using TLS/SSL for all API and web traffic
  • Encryption at rest for stored data in our databases
  • API key hashing using industry-standard cryptographic algorithms
  • Access controls and role-based permissions
  • Regular security monitoring and logging
  • Network segmentation and firewall protection

However, no method of electronic transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. You acknowledge and accept the inherent risks of transmitting data over the internet. In the event of a data breach, we will notify affected users in accordance with applicable laws.

7. Cookies & Tracking

We use the following types of cookies and similar technologies:

  • Essential Cookies: Required for authentication, session management, and security. These cannot be disabled without affecting core functionality.
  • Referral Cookies: Used to track referral program attributions. These cookies have a 7-day expiry and use last-click attribution.
  • Preference Cookies: Used to remember your settings and preferences (e.g., selected project, sidebar state).

You can control cookies through your browser settings. Disabling essential cookies may prevent you from using certain features of the Service.

8. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Right to Access: Request a copy of the personal data we hold about you
  • Right to Rectification: Request correction of inaccurate or incomplete personal data
  • Right to Erasure: Request deletion of your personal data, subject to legal retention requirements
  • Right to Data Portability: Request your data in a structured, commonly used, machine-readable format (JSON export available on MAX-T plan)
  • Right to Restrict Processing: Request that we limit the processing of your personal data under certain circumstances
  • Right to Object: Object to the processing of your personal data for certain purposes
  • Right to Withdraw Consent: Withdraw your consent to data processing at any time, without affecting the lawfulness of processing based on consent before withdrawal

To exercise any of these rights, contact us at [email protected]. We will respond to your request within 30 days. We may ask you to verify your identity before processing your request.

9. International Data Transfers

Your data may be processed and stored in jurisdictions other than your own. By using the Service, you consent to the transfer of your data to other countries, which may have different data protection laws than your jurisdiction. We take reasonable steps to ensure that your data is treated securely and in accordance with this Privacy Policy regardless of where it is processed.

10. Children's Privacy

The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal data from a child under 18, we will take steps to delete such information promptly. If you believe we have collected data from a child, please contact us immediately.

11. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • The right to know what personal information we collect, use, disclose, and sell
  • The right to request deletion of your personal information
  • The right to opt-out of the sale of your personal information (we do not sell personal information)
  • The right to non-discrimination for exercising your privacy rights

To exercise these rights, contact us at [email protected].

12. European Privacy Rights (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data on the following legal bases:

  • Contractual Necessity: Processing necessary to perform our contract with you (providing the Service)
  • Legitimate Interests: Processing necessary for our legitimate business interests (improving the Service, fraud prevention, security)
  • Consent: Where you have given explicit consent to specific processing activities
  • Legal Obligation: Processing necessary to comply with applicable laws

You have all the rights listed in Section 8 above. You also have the right to lodge a complaint with your local data protection authority.

13. Data Breach Notification

In the event of a data breach that affects your personal data, we will notify you via email within 72 hours of becoming aware of the breach, or as required by applicable law. The notification will include: a description of the breach, the types of data affected, steps we are taking to address the breach, and recommendations for steps you can take to protect yourself.

14. Third-Party Links

The Service may contain links to third-party websites or services. We are not responsible for the privacy practices, content, or security of third-party websites. We encourage you to review the privacy policies of any third-party sites you visit.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will post the updated policy on this page with a revised "Last updated" date. We will make reasonable efforts to notify you of material changes via email or through the Service. Your continued use of the Service after any changes constitutes acceptance of the updated Privacy Policy.

16. Contact Information

For questions, concerns, or requests regarding this Privacy Policy or our data practices, contact us at:

HalluTrace AI — Privacy Team

Email: [email protected]

General: [email protected]

Website: hallutraceai.com