Privacy Policy
Last updated: July 16, 2026
Hebrah, Inc. (“Hebrah,” “we,” “us,” or “our”) respects your privacy. This Privacy Policy explains how we collect, use, disclose, and protect personal information when you use:
- our public marketing website at hebrah.com (the “Site”);
- the Hebrah operator dashboard and integrator documentation (the “Dashboard”); and
- the Hebrah control plane API, hosted MCP, and related services (together with the Dashboard, the “Platform”).
This policy applies to visitors, demo and contact inquiries, and registered Platform users. If you use Live environments that process protected health information (“PHI”), additional terms, including a Business Associate Agreement (“BAA”), may apply.
1. Information we collect
A. Information you provide
- Contact form: name, email, optional company, and message.
- Demo request form: name, work email, company, and message.
- Platform account: name, email, password (stored hashed), organization details, and team membership.
- Billing: billing contact and subscription details (payment card data is collected by Stripe, not stored on our servers).
- Support: messages and information you send through support channels.
B. Information collected automatically
When you use the Site or Platform, we may collect:
- Log and security data: IP address, browser type, device information, pages visited, timestamps, and similar technical data for security, abuse prevention, and operations.
- Product analytics: first-party usage events on the Site (page views, outbound link clicks, and form conversion events such as demo or contact submissions) via our self-hosted OpenPanel instance. We do not use advertising pixels or cross-site ad trackers.
- Rate-limiting data: IP-based request counts to prevent spam and abuse on public forms.
- Session and authentication data: session cookies and related identifiers when you sign in to the Dashboard.
- Usage and telemetry: API activity, webhook delivery metadata, VM usage metering, and audit events related to your organization’s use of the Platform.
We do not use third-party advertising trackers on the marketing site. Product analytics runs on infrastructure we operate (OpenPanel, self-hosted).
C. Customer content and PHI
Sandbox environments use synthetic, generated data. You should not submit real PHI to Sandbox unless we authorize it in writing.
Live environments may process PHI you or your organization submit. When PHI is involved, processing is governed by our BAA and applicable law, in addition to this policy.
2. How we use information
We use personal information to:
- provide, operate, and improve the Site and Platform;
- create and manage accounts, organizations, and team access;
- process demo requests and contact inquiries;
- send product announcements and service-related communications you request or that are necessary for your account;
- process subscriptions and metered usage billing;
- deliver webhooks, APIs, MCP tools, and provisioning services;
- detect, prevent, and respond to fraud, abuse, and security incidents;
- maintain audit logs and compliance records;
- comply with legal obligations; and
- enforce our Terms of Service.
We do not sell your personal information.
3. How we share information
We may share personal information with:
- Service providers: hosting, email, bot protection, payment processing, and infrastructure operations on our behalf.
- Your organization: if you are a team member, account admins may see information associated with your org.
- Legal and safety: when required by law, to protect rights and safety, or to respond to lawful requests.
- Business transfers: in connection with a merger, acquisition, or sale of assets, subject to this policy.
Current processors relevant to the Site include:
- Resend: contact and demo email delivery.
- Cloudflare Turnstile: bot protection on contact, demo, and privacy-contact forms (production).
- OpenPanel (self-hosted): first-party product analytics for the marketing site.
- Stripe: payment processing and subscription billing (Platform).
These processors handle data under their own terms and privacy policies. We require them to process data only as needed to provide services to us.
We may also share aggregated or de-identified information that cannot reasonably identify you.
4. Cookies and similar technologies
We use:
- Essential cookies: to maintain Dashboard sessions and authenticate users.
The marketing site uses a fixed light theme. We do not use non-essential marketing cookies on the Site.
You can control cookies through your browser settings. Disabling essential cookies may limit Platform functionality.
5. Retention
We retain personal information for as long as needed to:
- provide the services you request;
- maintain your account and billing records;
- comply with legal, tax, and accounting obligations;
- resolve disputes and enforce agreements; and
- meet security and audit requirements.
Contact and demo data are retained while relevant to our communications with you, unless you request deletion or a longer period is required by law.
Audit logs and usage records may be retained for security and compliance purposes according to our internal policies.
6. Security
We implement technical and organizational measures designed to protect personal information, including access controls, encryption in transit, hashed credentials and API keys, rate limiting, and security headers.
No method of transmission or storage is completely secure. You are responsible for safeguarding your account credentials and API keys.
7. Your choices and rights
Depending on where you live, you may have rights to:
- access personal information we hold about you;
- correct inaccurate information;
- delete certain information;
- object to or restrict certain processing;
- withdraw consent where processing is consent-based; and
- receive a portable copy of your data.
Marketing emails: unsubscribe using the link in our emails or contact us.
Account data: contact us or use Dashboard settings where available.
California residents: we do not sell personal information. You may have additional rights under the CCPA/CPRA.
EEA/UK residents: we process data based on contract performance, legitimate interests (e.g., security), consent (where applicable), and legal obligations. You may lodge a complaint with your local supervisory authority.
To exercise your rights, contact us using the details below. We may need to verify your identity.
8. International transfers
We are based in the United States. If you access our services from outside the U.S., your information may be transferred to, stored, and processed in the U.S. and other countries where we or our processors operate. We take steps designed to ensure appropriate safeguards where required by law.
9. Children
Our services are not directed to children under 13 (or 16 in certain jurisdictions). We do not knowingly collect personal information from children. Contact us if you believe we have collected a child’s information.
10. Third-party links
The Site may link to third-party websites (e.g., LinkedIn, documentation hosts, Stripe checkout). We are not responsible for their privacy practices. Review their policies before providing information.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version on the Site and revise the “Last updated” date. Material changes may also be communicated by email or in-product notice. Continued use after changes become effective constitutes acknowledgment of the updated policy.
12. Contact us
Privacy questions or requests:
You may also use the contact form on our About page.
For Platform users processing PHI in Live environments, privacy questions about PHI may also be addressed through your organization’s BAA contact with Hebrah.