privacy policy
hug's whole product is remembering you, so this document matters more here than most places. it describes what data exists about you, why it exists, where it goes, and how to make it disappear.
effective july 2, 2026
1. introduction
This Privacy Policy describes how the operator of the Hug service ("we", "us", or "our") collects, uses, discloses, and protects personal data when you use Hug, an artificial intelligence companion available through iMessage, Telegram, and Discord, and when you visit talk2hug.com (together, the "Service"). We act as the data controller for the personal data described in this Policy.
This Policy is incorporated into our Terms & Conditions. Capitalized terms not defined here have the meanings given to them in the Terms.
2. information you provide to us
We collect the following information directly from you when you use the Service:
- Channel identifiers. Your phone number if you talk to or join the waitlist for Hug on iMessage, your Telegram user ID if you use Telegram, or your Discord user ID if you use Discord.
- Identity details you choose to share. Your name, and anything else you tell Hug about yourself in conversation.
- Message content. The text of your messages, your reactions (such as tapbacks), and quoted replies.
- Media. Photos, voice notes, videos, and files you send, which we process as described in Section 8.
3. information we create about you
The defining feature of the Service is memory. To make Hug consistent between conversations, our systems derive and store the following data from your conversations:
- Memories. Discrete facts you have shared, stored with timestamps so they can be revised or invalidated when they go stale.
- Profile notes. Running notes on who you are and how the friendship is going.
- Style fingerprint. A description of how you like to text, so Hug can match your rhythm.
- Relationship state. Hug's read on the current state of your conversations, including open threads it intends to follow up on.
- Hug's journal, opinions, and interests. Hug keeps its own reflections about each friendship, forms per-relationship opinions, and tracks topics it is curious about.
- Receptivity signals. Whether proactive messages land well or are ignored, so Hug backs off appropriately.
We disclose this category in detail because most services do not. All of it is personal data, all of it exists solely to operate the Service, and all of it is deleted with the rest of your data.
4. information collected automatically
- Delivery and technical logs. Message timestamps, delivery status, and error logs needed to run the Service reliably.
- Usage events. Aggregate product events (for example, that a message was sent or received) recorded in our analytics with IP based geolocation disabled.
- Website data. talk2hug.com uses PostHog for basic product analytics. We do not use advertising trackers or third party ad cookies.
5. information we do not collect
We do not collect:
- your contacts or address book;
- your precise location (we only know a city or timezone if you mention it);
- your browsing history;
- advertising identifiers or cross site tracking data;
- biometric data; or
- the original files of media you send, which are not retained on our servers (see Section 8).
6. how we use information and our lawful bases
We process personal data for the following purposes, relying on the following lawful bases where the law of your jurisdiction (including the GDPR) requires one:
- To operate the waitlist (steps requested before entering a contract): recording your request through your chosen messaging channel and preventing duplicate entries.
- To provide the Service (performance of a contract): generating replies, maintaining memory, and delivering messages.
- To send proactive messages (performance of a contract and, where required, consent): initiating check-ins and follow-ups, which you can stop at any time as described in the Terms.
- To secure, debug, and improve the Service (legitimate interests): investigating failures, preventing abuse, and understanding usage patterns, including through review of conversation content by authorized personnel, in order to improve the Service.
- To comply with legal obligations (legal obligation): responding to valid legal process.
We do not use your personal data for advertising, and we do not make automated decisions about you that produce legal or similarly significant effects.
7. AI processing
Hug's replies are generated by large language models running on the Microsoft Azure OpenAI Service. Voice notes are transcribed using OpenAI's transcription API. Your conversation content is transmitted to these providers for processing.
Under the applicable API terms of both providers, content submitted through their APIs is not used to train their foundation models. We do not train our own models on your conversations either.
8. photos, voice notes, and files
When you send media, our systems convert it into text: a transcript of a voice note, or a written description of an image or document. Only that text is retained in our systems. The original files are not stored on our servers and remain wherever your messaging platform stores them, subject to that platform's own policies.
9. service providers
We share personal data with a small number of service providers who process it on our behalf, under contract, and only as needed to run the Service:
- Linq (Linq App, Inc., United States): iMessage delivery. privacy policy.
- Microsoft Azure OpenAI Service (Microsoft Corporation, United States): language model inference. privacy statement.
- OpenAI (OpenAI, L.L.C., United States): voice note transcription. privacy policy.
- Render (Render Services, Inc., United States): application hosting and database. privacy policy.
- PostHog (PostHog, Inc., United States): product analytics, with IP geolocation disabled. privacy policy.
Telegram and Discord are independent platforms, not our processors. When you talk to Hug there, your messages also pass through their infrastructure under their own privacy policies.
11. data retention and deletion
We retain your channel identifier while your waitlist request is active and retain Service data for as long as you use the Service, because the memory is the product. You can ask us to delete either at any time:
- One thing: ask Hug to forget a specific fact, and the corresponding memory is invalidated.
- Everything: ask Hug to forget everything, or email us, and your messages, memories, and profile are deleted from our production systems promptly, and from encrypted backups as they expire within thirty (30) days.
Blocking Hug on your messaging platform permanently stops all outbound contact. We may retain minimal records where required by law.
12. security
Personal data is encrypted in transit and stored in access controlled infrastructure. Access to conversation data within our team is restricted to what is necessary to operate, debug, improve, and secure the Service. No method of transmission or storage is completely secure, and we cannot guarantee absolute security; our approach is to keep the surface small: few providers, no advertising technology, and no data we do not need.
13. international data transfers
Our infrastructure and service providers are located in the United States. If you use the Service from outside the United States, your personal data will be transferred to and processed in the United States. Where required, transfers are protected by appropriate safeguards, including the standard contractual clauses embedded in our providers' data processing agreements.
14. your rights
Depending on where you live, you may have some or all of the following rights regarding your personal data:
- Access and portability: obtain a copy of the personal data we hold about you.
- Rectification: correct inaccurate data (telling Hug the correct fact also works; it revises its memory).
- Erasure: have your data deleted, as described in Section 11.
- Restriction and objection: restrict or object to certain processing, including proactive messages.
- Withdrawal of consent: where processing is based on consent, withdraw it at any time.
- Complaint: lodge a complaint with your local data protection authority.
If you are a California resident, you additionally have the rights to know, delete, and correct under the CCPA, and the right to opt out of the sale or sharing of personal data. We do not sell or share personal data as defined by the CCPA, and we do not discriminate against you for exercising any right. To exercise any right, ask Hug directly in the chat or email waris@asent.app. We respond to verified requests within the time required by applicable law.
15. children's privacy
The Service is not directed to children under thirteen (13) years of age, or under the higher minimum age applicable in your jurisdiction, and we do not knowingly collect personal data from them. If we learn that we have collected personal data from a child below the applicable minimum age, we will delete it and terminate the conversation.
16. changes to this policy
We may update this Policy from time to time. The updated version will be posted on this page with a revised effective date. If a change meaningfully reduces your privacy, we will notify you through the Service before it takes effect.
17. contact
Questions, concerns, or requests regarding this Policy or your personal data may be directed to waris@asent.app.