← Back to Haawke Hash

Privacy Policy

Last updated: August 16, 2026
Note on this document: This policy was drafted to accurately describe how Haawke Hash actually works, including a data-handling detail (permanent public hash registration, see §4) that most privacy policy templates don't address. It has not yet been reviewed by a qualified attorney. Treat it as an accurate technical description of our practices, not as a substitute for legal sign-off before relying on it for formal compliance purposes.

This policy explains how Haawke Neural Technology ("Haawke," "we," "us") collects, uses, and discloses information when you use Haawke Hash, Haawke AI, and related services (the "Service"). It is written to comply with the EU General Data Protection Regulation (GDPR) for users in the European Economic Area, and applies to all users of the Service regardless of location.

1. Who We Are

Haawke Neural Technology is the data controller for the personal data described in this policy. For any privacy question, request, or complaint, contact us at craif@haawke.com.

2. What We Collect

Account data

If you create an account to obtain an API key, we (via our authentication provider, Clerk) collect your email address and a unique user identifier. We do not collect your name, address, or payment card details directly — any billing information is handled by our payment processor, if and when paid tiers are enabled.

Usage data

We store your API key's tier, label, creation date, and aggregate usage counters (requests and tokens per day). We do not store a history of your individual requests beyond what is needed to enforce rate limits.

Content you submit

When you send a message to Haawke AI, that message (your "prompt") is transmitted to our inference provider to generate a response. Prompts and responses are not stored in a persistent conversation log on our servers after the request completes, with one exception described in §4 below.

Technical data

Our infrastructure provider (Cloudflare) automatically logs standard technical data for security and abuse prevention, such as IP address, request timestamps, and browser user-agent, consistent with Cloudflare's own privacy practices.

3. Legal Basis for Processing

4. Cryptographic Provenance — Please Read This Section

Haawke Hash's core feature is different from a typical AI product's data handling, and it has a real consequence for your privacy rights that we want to be upfront about.

When you use Haawke AI, a SHA-256 cryptographic hash of the AI-generated response is calculated and submitted to verify.haawke.com, a public provenance registry that anchors hash records to the Bitcoin blockchain. If you choose to enable prompt hashing, a hash of your prompt is submitted the same way and linked to the response's record.

What this means for you: A cryptographic hash is a one-way fingerprint — it cannot be reversed to reveal your original prompt or the AI's response. However, once a hash is anchored to the Bitcoin blockchain, that record is permanent and cannot be deleted, altered, or removed by us, by you, or by anyone — this is the entire point of the feature, which exists to provide tamper-proof, independently verifiable proof of when content was generated. If someone already possesses the original text, they can confirm it matches a public record, but the record itself never exposes the text to anyone who doesn't already have it.

Because this record is immutable by design, your right to erasure (GDPR Art. 17) cannot be exercised over an already-anchored hash. It can be exercised over the account and usage data described in §2, and over any as-yet-unanchored prompt hash (submission is opt-in). We are disclosing this limitation clearly rather than promising a deletion capability we cannot technically provide.

5. Who We Share Data With

We use the following sub-processors to operate the Service:

We do not sell your data. We do not share content data with third parties beyond what's needed to generate a response (i.e., sending your prompt to our inference provider) and the public, hash-only provenance registration described in §4.

6. International Data Transfers

Our infrastructure and sub-processors operate in the United States. If you are located in the EEA, your data may be transferred to and processed in the US. Our sub-processors maintain appropriate safeguards for such transfers (such as Standard Contractual Clauses); contact us if you'd like details on a specific sub-processor's safeguards.

7. Data Retention

Account data is retained for as long as your account is active, plus a reasonable period afterward for legal and security purposes. Usage counters reset daily and are not retained long-term in identifiable form beyond current billing/rate-limit needs. Provenance hash records, as explained in §4, are permanent.

8. Your Rights (GDPR)

Subject to the limitation described in §4, you have the right to:

To exercise any of these rights, email craif@haawke.com.

9. Cookies

We use only the session cookies/tokens necessary for authentication, set by our authentication provider (Clerk). We do not use advertising or tracking cookies.

10. Children's Privacy

The Service is not directed at children under 16, and we do not knowingly collect data from them.

11. Security

We use industry-standard measures (encrypted transport, access-controlled key storage) to protect your data, but no system is completely secure, and we cannot guarantee absolute security.

12. Changes to This Policy

We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above.

13. Contact

Haawke Neural Technology — craif@haawke.com