HAL Privacy Disclosure
Last Updated: December 7, 2025
Summary
HAL is designed with privacy-first architecture. Our application code does not store your conversations. However, the infrastructure we run on (Cloudflare) may retain request logs that we cannot control or delete.
What HAL Is
Alpha Status
HAL is currently in alpha. It's being actively developed and tested. Things may change, break, or improve without notice.
HAL stands for Human-AI Loop. It's not a chatbot. It's not a companion. It's a place where you can be yourself and try to understand why things hurt so much — or at least try to.
The "loop" matters: HAL is designed to hold space and reflect back, not to generate content or complete tasks. The human remains in the loop — HAL supports your own processing, but doesn't replace it.
HAL is not therapy and is not a substitute for professional care.
The Roadmap
Right now, HAL is AI-only. We're building toward a Human-AI Loop that includes a second human in the background — a clinician, a lawyer, or another professional depending on context — available when the person chatting wants one involved.
The loop isn't just human-to-AI. It's human-to-AI-to-human.
We're building a new type of AGI from non-AGI. The intelligence isn't in the AI alone — it's in the loop.
What We Do Store
In-Memory Only (Temporary)
- Conversation history: Last 6 messages per session (with PII redacted)
- Session ID: Random UUID generated in your browser
- Message timestamps: For session expiry only
This data exists only in RAM and is lost when:
- Your session expires (30 minutes of inactivity)
- The Cloudflare Worker restarts or redeploys
- You close your browser
Never Stored by Our Code
- Names, emails, phone numbers
- Addresses or location data
- IP addresses
- User agent strings
- Cookies or tracking tokens
- Social Security numbers
- Credit card numbers
- Any other personally identifying information
Automatic PII Redaction
HAL automatically detects and redacts personal information before storing anything:
| PII Type | Example | Stored As |
|---|---|---|
| [email protected] | [EMAIL_REDACTED] | |
| Phone | 555-123-4567 | [PHONE_REDACTED] |
| SSN | 123-45-6789 | [SSN_REDACTED] |
| Credit Card | 1234-5678-9012-3456 | [CARD_REDACTED] |
| IP Address | 192.168.1.1 | [IP_REDACTED] |
| Full Name | My name is John Smith | my name is [NAME_REDACTED] |
| Address | 123 Main Street | [ADDRESS_REDACTED] |
If PII is detected, HAL will warn you to avoid sharing personal information.
Important: Cloudflare Infrastructure Logging
HAL runs on Cloudflare Workers. While our application code does not store your conversations, Cloudflare's infrastructure may retain request logs that include:
- Request/response bodies (your messages and HAL's responses)
- IP addresses
- Timestamps
- Request metadata
Per Cloudflare's Privacy Policy, Workers logs may be retained for up to 7 days. We have no control over Cloudflare's infrastructure logging and cannot access or delete these logs.
What This Means for You
| Layer | What Happens |
|---|---|
| Our Application Code | Doesn't store conversations. PII is redacted. Sessions expire. |
| Cloudflare Infrastructure | May retain request logs for up to 7 days. We can't control this. |
For Maximum Privacy
- Don't share identifying information (name, email, phone, address)
- Describe feelings and situations, not specific identifiable details
- Use HAL for reflection, not for storing sensitive information
The AI Model
HAL uses AI models provided by Cloudflare Workers AI. Currently:
- Model: Qwen 2.5 Coder 32B (or similar)
- Training: RLHF + Supervised Fine-Tuning
- Type: Prompt-based (not fine-tuned specifically for HAL)
- Platform: Cloudflare Workers AI
The model may change as we evaluate options. HAL's behavior is guided by a system prompt, not by custom training data.
What HAL Is Not
- Not therapy: HAL is not a substitute for professional mental health care
- Not HIPAA compliant: Do not share protected health information
- Not a medical device: HAL does not diagnose, treat, or provide medical advice
- Not anonymous: While we don't track you, Cloudflare may log requests
If You're in Crisis
HAL is not equipped for crisis intervention. If you're experiencing thoughts of self-harm or suicide, please contact:
- 988 Suicide and Crisis Lifeline: Call or text 988 (US)
- Crisis Text Line: Text HOME to 741741
- Emergency Services: Call 911
Technical Details
For developers and security researchers, the full privacy implementation is documented in our GitHub repository.
Key files:
functions/api/chat.js- Backend with PII detection and session managementPRIVACY.md- Detailed privacy documentationtests/privacy.test.js- Privacy protection tests
Contact
For privacy questions about HAL:
- Email: [email protected]
- Subject: "HAL Privacy Inquiry"
For general Sum1 Solutions privacy policy, see our main privacy policy.