Privacy Policy

Last updated 18 June 2026

How Hardhaus handles your data. The guiding principle is simple: your content stays in the region and is never stored.

1. The short version

Your inference is processed inside Hardhaus's managed service boundary in eu-north-1. We do not log or store your prompts or completions. We keep only the structural metadata needed to run and bill the Service — token counts, latency, and cost.

2. What we collect

Account data from your identity provider (email, the provider you used, display name) — never a password. Usage metadata per request (model, token counts, latency, cost, status). An append-only audit trail of mutating actions (e.g. key and endpoint changes). We do NOT collect prompt or completion content.

3. Where your data runs

Inference is performed inside Hardhaus's managed service boundary in eu-north-1, and our processing commitments apply to operations performed within it — including our own agents and their approved supporting services. Applications you select yourself sit outside that boundary: we control access and authorized disclosure to them, and our commitments do not extend automatically to them or to their model providers. Operational data (account, usage, audit) is hosted in the EU.

4. Retention

Usage and audit records are retained for the period required by applicable law and our compliance obligations, then permanently erased. When you close your account, your keys are revoked and the account is deactivated; data is purged after the retention period.

5. Your rights

Under the GDPR you may request access to, correction of, or erasure of your personal data, subject to legal retention requirements. You can export a content-free usage and audit trail at any time, and manage notification preferences from your profile.

6. Contact

Questions about privacy or a data request? Reach us at privacy@hardhaus.ai. We respond to verified requests within the timeframes required by applicable law.