PRIVACY POLICY

Effective Date: May 21, 2026

Last Updated: May 21, 2026

Halogen AI, Inc. ("Halogen AI," "we," "us," or "our") is committed to protecting the privacy and security of the personal information we collect from our business customers and their authorized users ("you" or "your"). This Privacy Policy describes how we collect, use, disclose, and protect information when you use Halogen Presence™, our Answer Engine Optimization (AEO) platform, and related services (collectively, the "Services").

By accessing or using our Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with this Privacy Policy, please do not use our Services.

1. Introduction

Halogen Presence™ helps businesses measure and improve how their brand is described and cited within the responses of generative AI assistants. To provide the Services, we collect certain information from you and your authorized users, transmit certain information to third-party AI providers and other service providers, and, at your direction, publish content to platforms you connect. This Privacy Policy explains those practices.

This Privacy Policy should be read together with our Terms of Service, Data Processing Addendum, and Cookie Policy.

2. Information We Collect

2.1 Information You Provide Directly

We collect the following categories of personal information that you provide to us:

  • Account Information: Business contact names, business email addresses (used for account login and authentication), company name, job title, and business phone numbers.
  • Payment Information: Billing details, payment card information (processed securely through our payment processor, Stripe), billing address, and subscription details.
  • Platform Inputs: Information you input into or configure within the Services, including tracked prompts and questions, your brand and competitor names, website URLs you submit for tracking or audit, sentiment dimensions, tags, and other configuration. This is the information the platform uses to measure and improve your visibility in AI-assistant answers.
  • Connected-Service Credentials: Where you choose to connect a third-party content management or publishing platform (such as WordPress, WordPress.com, or Wix), the credentials or access tokens needed to publish content at your direction. These are stored in encrypted form.
  • Communications: Information contained in your communications with us, including support requests, feedback, and other correspondence.

2.2 Information Collected Automatically

When you use our Services, we automatically collect:

  • Usage Data: Information about how you interact with our Services, including features used, actions taken, and time spent on the platform.
  • Log Data: IP addresses, browser type and version, device information, operating system, referring URLs, and access times.
  • Analytics Data: Performance metrics and usage patterns collected to operate and improve the Services, including through Google Analytics.

2.3 Information Generated by the Services

In the course of providing the Services, we generate and store information about your brand's presence in AI-assistant answers, including visibility results, citation and source data, sentiment analyses, audit results and scores, and AI-generated content drafts. This information is derived from your Platform Inputs together with responses from third-party AI providers and publicly available web sources.

3. How We Use Your Information

We use the collected information for the following purposes:

  • Service Provision: To provide, maintain, and improve our Services, including running visibility checks, performing audits, generating reports and content drafts, and publishing content to connected platforms at your direction.
  • Account Management: To create and manage your account, authenticate users, and provide customer support.
  • Payment Processing: To process payments, manage subscriptions, and send billing-related communications.
  • Communications: To send service-related announcements, technical notices, updates, security alerts, and support messages.
  • Analytics and Improvement: To analyze usage patterns, improve our Services, and develop new features.
  • Legal Compliance: To comply with applicable laws, regulations, and legal processes.
  • Security: To detect, prevent, and address technical issues, fraud, and security incidents.

4. AI Processing and Third-Party AI Providers

To deliver the core functionality of the Services, we transmit certain Platform Inputs — such as your tracked prompts, brand and competitor names, and related context — to third-party generative AI providers, currently Anthropic (Claude), OpenAI (GPT models), and Google (Gemini). These providers process that information to generate the answers and signals we measure.

Your use of these AI providers through the Services is also subject to those providers' own terms and privacy policies. Whether information transmitted to an AI provider is retained or used to improve or train that provider's models is determined by that provider's own policies and by our configuration with them; we encourage you to review the applicable AI provider's privacy policy and terms for details. We ask that you do not submit personal information that is not necessary for the Services.

We also retrieve and analyze publicly available content from websites you submit for audit or tracking. You are responsible for ensuring you are authorized to have those websites accessed and analyzed.

5. Data Sharing and Disclosure

5.1 Service Providers and Subprocessors

We share information with trusted third-party service providers who assist us in operating the Services. These currently include:

  • Anthropic, OpenAI, and Google: AI providers used to generate and measure brand visibility in AI-assistant answers (see Section 4).
  • Stripe: Payment processing and billing management.
  • Vercel: Application hosting and infrastructure.
  • Neon: Database hosting and storage.
  • Resend: Transactional and report email delivery.

These providers are contractually obligated to protect your information and may only use it to perform services on our behalf. A current list of our subprocessors is maintained in connection with our Data Processing Addendum.

5.2 Connected Services (Publishing at Your Direction)

Where you connect a third-party content management or publishing platform (such as WordPress, WordPress.com, or Wix) and direct us to publish content, we transmit that content and the necessary credentials to the connected platform to fulfill your request. Your use of those platforms is governed by their own terms and privacy policies.

5.3 Legal Requirements

We may disclose your information if required to do so by law or in response to court orders, subpoenas, or other legal processes; requests from government authorities or law enforcement; or to protect our rights, property, or safety, or that of others.

5.4 Business Transfers

In the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of that transaction. We will provide notice before your information becomes subject to a different privacy policy.

5.5 With Your Consent

We may share your information for any other purpose with your explicit consent.

5.6 No Sale of Personal Information

We do not sell your personal information for money. To the extent any disclosures described above constitute "sharing" or "selling" under applicable U.S. state privacy laws, you may exercise the opt-out rights described in Section 9.

6. Legal Basis for Processing (GDPR)

For customers in the European Economic Area, we process personal data based on the following legal grounds:

  • Contract Performance: Processing necessary to fulfill our contractual obligations to provide the Services.
  • Legitimate Interests: Processing necessary for our legitimate business interests, including improving our Services, securing our platform, and conducting business analytics.
  • Legal Obligations: Processing necessary to comply with applicable laws and regulations.
  • Consent: Where we have obtained your explicit consent for specific processing activities.

7. Data Retention

We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy:

  • Account Information: Retained for the duration of your active subscription.
  • Platform Inputs and Generated Output: Retained throughout your subscription period and for a limited period thereafter, after which it is deleted or anonymized, subject to legal retention requirements.
  • Payment Information: Retained as required for accounting, tax, and legal compliance purposes.
  • Communications: Retained as necessary for business records and legal compliance.
  • Public Audit Records: Anonymous results generated through our public website audit tool are retained only for a limited period and then automatically deleted.

After the retention period, we will securely delete or anonymize your personal information.

8. Data Security

We implement appropriate technical and organizational measures to protect your personal information, including:

  • Access Controls: Role-based access controls and authentication mechanisms to ensure only authorized personnel can access personal information.
  • Encryption: Encryption of data in transit, and encryption at rest for sensitive items such as connected-service credentials.
  • Security Monitoring: Regular security assessments and monitoring for potential vulnerabilities.
  • Incident Response: Established procedures for responding to security incidents.

While we strive to protect your information, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security.

9. Your Rights and Choices

9.1 Rights Under GDPR (European Economic Area)

If you are located in the EEA, you have the following rights: access, rectification, erasure, restriction of processing, data portability, objection to processing based on legitimate interests, and the right to withdraw consent where processing is based on consent.

9.2 Rights Under U.S. State Privacy Laws

  • California (CCPA/CPRA): Right to know, delete, correct, opt-out of sale/sharing, and non-discrimination.
  • Other State Laws: Similar rights may apply under Virginia, Colorado, Connecticut, and other state privacy laws.

9.3 Canadian Privacy Rights

Canadian residents have rights under PIPEDA and applicable provincial laws, including the right to access and correct personal information.

9.4 Exercising Your Rights

To exercise any of these rights, please contact us at privacy@halo-gen.ai. We will respond to your request within the timeframe required by applicable law (generally within 30 days). Where you are an authorized user of a business customer, we may direct your request to that customer, who controls the relevant data.

10. International Data Transfers

We operate primarily from the United States and store the data underlying the Services in the United States. However, because the Services rely on third-party AI providers and other service providers, certain information — including Platform Inputs transmitted to AI providers — may be processed in, or transmitted to, jurisdictions outside the United States and Canada, including jurisdictions whose data protection laws may differ from those in your own.

Where we transfer personal data internationally, we rely on appropriate safeguards as required by applicable law, which may include Standard Contractual Clauses or the data-transfer mechanisms maintained by our service providers. If you are accessing our Services from outside the United States, please be aware that your information will be transferred to and processed in the United States and potentially other jurisdictions.

11. Cookies and Tracking

We and our service providers use cookies and similar technologies to operate, secure, and analyze the Services, including Google Analytics for usage analytics. You can manage cookies and tracking technologies through your browser settings. For more detail, see our Cookie Policy. Our Services do not currently respond to "Do Not Track" signals from web browsers.

12. Children's Privacy

Our Services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child under 18, we will take steps to delete such information.

13. Updates to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws. We will notify you of any material changes by posting the updated policy on our website, updating the "Last Updated" date, and, for material changes, sending notification to your registered email address. Your continued use of our Services after such modifications constitutes your acceptance of the updated Privacy Policy.

14. Contact Information

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

Halogen AI, Inc.
1545 NE 90th St, Seattle, WA 98115
Email: privacy@halo-gen.ai

For EU/EEA residents, you also have the right to lodge a complaint with your local supervisory authority.

15. California Privacy Rights Disclosure

This section applies to California residents and supplements the information in this Privacy Policy.

Categories of Personal Information Collected

In the past 12 months, we have collected the categories of personal information described in Section 2 of this Privacy Policy.

Sale and Sharing of Personal Information

  • Sale: We do not sell personal information for money as defined under the CCPA/CPRA.
  • Sharing: We may share personal information through the use of cookies and analytics tools, including Google Analytics, for cross-context behavioral advertising purposes. You have the right to opt out of such sharing, as described below.

Opt-Out Rights

To opt out of the sharing of your personal information, you may adjust your browser settings to reject cookies, use Global Privacy Control (GPC) signals where supported, or contact us at privacy@halo-gen.ai.

Sensitive Personal Information

We do not collect or process sensitive personal information as defined under the CPRA for the purpose of inferring characteristics about you.

Acknowledgment: By using our Services, you acknowledge that you have read and understood this Privacy Policy and agree to its terms.