Legal
Privacy Policy
Effective 22 July 2026 · v1 · Controller: Hunta (UK) · [email protected]
What we collect.
- Account data: your name and email from the identity provider you choose (GitHub or Google). We request identity scopes only; we can never read your repositories or mailbox.
- Memory content: what you or your agents store in Hunta Gather. Encrypted per tenant (AES-256-GCM) with row-level isolation; processed solely to provide storage, retrieval, curation and attestation. Never used for model training; never sold.
- Usage metering: token counts per operation (deterministic, so you can verify your bill), plan state, and operational logs.
- Payment data: handled by Stripe; we never see or store card numbers.
Subprocessors. Stripe (payments) · Cloudflare (DNS/site hosting) · Neon (encrypted database) · Contabo (compute hosting) · Lago, self-hosted (usage metering) · emailit (transactional email) · GitHub / Google (sign-in only). The current list also lives in the Trust Center.
Retention. Memory content persists until you delete it (fact-level and memory-level deletion via API/console: supersede, invalidate, forget) or your account is deleted (tenant data removed within 30 days). Invoices and legally required records are kept as the law demands.
Your rights. Under UK/EU GDPR you can access, correct, export, or erase your personal data, and complain to the ICO or your local authority. Email us; we respond within 30 days. Data is processed in the UK/EU where practicable; where a subprocessor processes elsewhere, standard contractual clauses apply.
Cookies. The console uses strictly necessary session cookies only. The marketing site sets no tracking cookies.
Changes. Material changes notified via console or email.