# Privacy Policy — Hanzo

> How Hanzo collects, uses, discloses, and retains personal data across the Services, and the four data-use states that govern research and training.

Legal

# Privacy Policy

How Hanzo collects, uses, discloses, and retains personal data across the Services, and the four data-use states that govern research and training.

Draft, pending counsel review — not yet effective. Version 2026-07-22, last updated 2026-07-22.

This Privacy Policy explains how Hanzo AI, Inc. (“Hanzo,” “we,” “us,” or “our”) collects, uses, discloses, and retains personal data in connection with hanzo.ai, the Hanzo Console, consumer applications, account administration, Enso, our APIs and SDKs, model hosting, agents, tools, benchmarks, research programs, websites, and related services (the “Services”).

It also explains the separate choices that govern ordinary service processing, private AI research and training, and public data contribution.

## 1. Scope and our roles

For individual accounts, website visitors, account administration, billing, security, and Hanzo’s own research programs, Hanzo generally acts as a controller or business that determines why and how personal data is processed.

When a business customer uses the Services to process personal data in Customer Content, Hanzo generally acts as that customer’s processor or service provider. That processing is governed by the customer agreement and [Data Processing Addendum](https://hanzo.ai/legal/dpa), not by Hanzo’s independent decisions. The customer remains responsible for its notices, permissions, lawful bases, and instructions.

If a business customer separately elects to contribute Customer Content to Hanzo research, Hanzo may act as an independent controller for the specifically contributed copy and purpose, as disclosed at the time of contribution. Research use is not necessary to receive the core API or enterprise Services.

This Policy does not replace a specialized biometric, consumer-health, student-data, or other notice where one is required.

## 2. The four Hanzo data-use states

Hanzo’s systems must treat the following as separate states:

- Service Only. Data is used to provide the requested service, route the request, secure and support the platform, comply with law, and generate customer-visible usage and billing records. It is not used to train generalized Hanzo models or routers.

- Private Improvement. The user or customer permits specified data to be used internally for evaluation, debugging, and product improvement, but not to train generalized models unless the consent expressly includes training.

- Research and Training. The user or authorized organization affirmatively permits specified data to be used to train, fine-tune, evaluate, or optimize reusable Hanzo models and systems.

- Public Commons. The contributor separately chooses identified materials for public release under a stated dataset license. Private research permission alone never authorizes public release.

Business and API accounts default to Service Only. Consumer research and training participation must also be off by default unless Hanzo has implemented a jurisdictionally valid alternative reviewed by counsel. Settings must be granular, recorded, and easy to withdraw prospectively.

## 3. Personal data we collect

### 3.1 Data you provide

- Account and identity data: name, email address, organization, role, username, authentication information, account identifiers, and optional profile details.

- Billing and transaction data: billing address, tax information, subscription, credit balance, usage, invoice, and payment status. Payment-card details should be collected directly by our payment processor rather than stored by Hanzo.

- Inputs and Customer Content: prompts, instructions, files, text, code, images, audio, video, documents, datasets, retrieved content, and information accessed through connectors at your direction.

- Outputs and Actions: generated responses and media, tool calls, agent actions, code execution results, files created or modified, and communications sent at your direction.

- Feedback and support data: ratings, annotations, corrections, bug reports, survey responses, support conversations, and related content you deliberately submit.

- Research contribution data: materials you affirmatively contribute, the consent record, selected license, study responses, and any compensation or research-program administration data.

- Verification data: information used to verify age, identity, organization, eligibility, fraud risk, or account ownership. Hanzo should avoid collecting government IDs or facial templates unless necessary and covered by an appropriate notice and consent.

- Communications and marketing data: messages, event registrations, newsletter choices, and communication preferences.

### 3.2 Data generated by the Services

- Routing and inference telemetry: requested model or preset, candidate and selected model/provider, Enso policy version, routing scores, confidence or uncertainty estimates, samples, retries, verifier results, tool decisions, safety classifications, and stop/challenge/reroute decisions.

- Benchmark and evaluation data: benchmark or task identifiers, model and provider versions, prompts where licensed, outputs, correctness labels, judge or verifier results, seeds, decoding settings, cost, latency, token counts, failures, and provenance.

- Research Run Records: project and run identifiers, repository and revision, status, gates, configurations, environment and hardware, model and dataset versions, attempts, metrics, logs, artifacts, costs, timings, failures, uploader identity, integrity hashes, supersession history, and provenance submitted to /v1/research or generated by Hanzo research systems.

- Research features: embeddings, activation-derived features, capability estimates, model profiles, disagreement patterns, recovery/damage labels, workflow representations, and other features derived from contributed or lawfully obtained data.

- Usage and device data: IP address, approximate location derived from IP, browser, operating system, device type, identifiers, timestamps, pages and features used, referral information, and interaction events.

- Logs and security data: authentication events, API calls, error reports, crash information, abuse indicators, network and system logs, and investigation records.

- Cookie and advertising data: cookie identifiers and consent choices. Hanzo should not deploy nonessential cookies in jurisdictions requiring consent until consent is obtained.

### 3.3 Data from other sources

We may receive data from organization administrators, identity and payment providers, integrations you enable, model and infrastructure providers, security and fraud services, public sources, licensed datasets, research partners, and contributors.

If Hanzo trains or fine-tunes its own generative models using public, licensed, synthetic, or contributed datasets, Hanzo will maintain source and rights documentation and publish legally required training-data summaries. Public availability does not by itself eliminate privacy, copyright, or other legal obligations.

### 3.4 Sensitive and regulated data

Inputs can reveal health, race or ethnicity, religion, sexual orientation, citizenship or immigration status, political beliefs, precise location, financial information, biometric information, or other sensitive data. Do not submit regulated or sensitive data unless the feature and your agreement expressly support it and you have all required permissions.

Hanzo does not use sensitive personal data to infer characteristics, train generalized systems, or publish datasets without the applicable explicit permission and safeguards. Voice, face, and likeness features are addressed in the [Biometric, Voice, and Likeness Notice](https://hanzo.ai/legal/biometric-voice). Consumer health data is addressed in the [Consumer Health Data Privacy Policy](https://hanzo.ai/legal/consumer-health).

## 4. How Enso and third-party models process requests

Enso may use an Input and request metadata to select among models, providers, prompts, reasoning methods, tools, samples, and verification workflows. A quality or research mode may send the same or transformed request to multiple approved providers, compare candidate responses, and run additional evaluators.

Accordingly, Customer Content may be disclosed to the model and infrastructure providers necessary to fulfill the request. Hanzo identifies providers and processing locations in its [Subprocessor Register](https://hanzo.ai/legal/subprocessors) and offers provider or region restrictions where stated in the applicable plan or order form.

Hanzo requires processors and subprocessors to process personal data under contract and appropriate instructions. If you independently connect or direct Hanzo to an external service not managed as a Hanzo subprocessor, that service may process data under its own terms and privacy policy.

## 5. Why we process personal data and our legal bases

Where the GDPR or similar law applies, Hanzo relies on the legal bases below. The exact basis depends on the context and jurisdiction.

Purpose

Typical data

Typical legal basis

Create and administer accounts; authenticate users

account, identity, organization, logs

contract; legitimate interests; legal obligation

Provide inference, routing, hosting, tools, agents, storage, support, and requested Actions

Customer Content, routing telemetry, integration data

contract; steps requested before contract; customer instructions

Meter usage, invoice, process payment, and administer credits

account, billing, usage

contract; legal obligation; legitimate interests

Secure the Services; prevent fraud, abuse, and unauthorized access; investigate incidents

account, content reasonably necessary for investigation, device and log data

legitimate interests; legal obligation; vital interests where applicable

Debug and maintain the Services

errors, limited content context, telemetry

contract; legitimate interests

Produce private aggregate analytics and service statistics

usage and de-identified or aggregated telemetry

legitimate interests; consent where required for cookies

Send essential service notices

contact and account data

contract; legal obligation

Send marketing

contact, preferences, website activity

consent where required; otherwise legitimate interests with opt-out

Conduct optional private studies or use identified Customer Content for generalized model/router training

contributed content, feedback, research features, consent record

consent; a separate written research agreement; legitimate interests only where documented, expected, necessary, and lawful

Publish a selected contribution to Verified Commons

selected materials, attribution if chosen, provenance, license

separate contribution agreement; consent for applicable personal data

Comply with law, enforce agreements, and establish or defend claims

relevant account, transaction, content, and log data

legal obligation; legitimate interests

Hanzo will not rely on “performance of a contract” to justify generalized model training when training is not necessary to provide the service requested. If Hanzo relies on legitimate interests for an AI-research activity, it will document necessity, reasonable expectations, balancing, safeguards, and the right to object. Special-category personal data requires an additional lawful condition.

## 6. AI research and training

### 6.1 What optional research can include

If you opt in, the disclosed data may be used to develop and evaluate Enso Scout, Critic, Controller, Conductor, Genome, capability models, verifiers, safety systems, model hosting, datasets, and other Hanzo research. Depending on your selection, this may include Inputs, Outputs from one or more candidate models, reasoning or tool traces, feedback, correctness labels, benchmark provenance, routing features, embeddings, activation-derived features, cost, token use, and latency.

### 6.2 What opting out means

If research is disabled, Hanzo may still process data to provide the service, route the request, meter usage, prevent abuse, comply with law, and investigate errors or incidents. It may use aggregate statistics or information rendered non-personal under applicable law, but it will not use Customer Content to train generalized models or routers.

Safety review is not a hidden training override. Material reviewed for safety or security may be retained and analyzed for that specific purpose, but generalized training requires the separately stated permission.

### 6.3 Withdrawal and deletion

You may withdraw research permission for future use in your settings or by contacting [privacy@hanzo.ai](mailto:privacy@hanzo.ai). Withdrawal does not invalidate processing lawfully completed before withdrawal. Hanzo will stop placing the affected data into new training runs and will delete or quarantine eligible source records according to its provenance and deletion procedures.

Because trained models contain distributed learned parameters rather than a simple database of source records, removal from a completed model may require model retirement, retraining, machine unlearning, output filtering, or another technically and legally appropriate remedy. Hanzo will evaluate valid legal requests rather than treating completed training as automatically anonymous or categorically exempt.

### 6.4 Public research and Verified Commons

Hanzo may publish aggregate or properly de-identified research findings. Publishing identifiable, pseudonymous, or user-contributed content requires the applicable authority, privacy basis, and contribution terms. Hashing or removing an account ID alone does not make data anonymous.

Private research permission does not permit public release. A public contribution flow will identify the selected material, intended repository, attribution choice, dataset license, revocation limitations, and whether third parties may copy and redistribute the data.

## 7. How we disclose personal data

We may disclose data to:

- Model and inference providers selected or permitted for the request;

- Cloud, storage, database, network, observability, security, and support providers that operate the Services;

- Payment, tax, identity, fraud, and billing providers;

- Integration providers you enable or direct us to use;

- Professional advisers, auditors, insurers, and research service providers bound by appropriate obligations;

- Your organization and administrators, including workspace content and usage under organizational control;

- Authorities or other parties when reasonably necessary to comply with law, protect rights and safety, investigate fraud or abuse, or establish or defend legal claims;

- Transaction participants in a merger, financing, acquisition, reorganization, bankruptcy, or asset transfer, subject to applicable law and appropriate confidentiality; and

- The public or research repositories, only for information authorized for publication or aggregate/de-identified findings.

We do not sell personal data for money. We do not share personal data for cross-context behavioral advertising or process it for targeted advertising unless this Policy and the relevant interface expressly say otherwise and provide legally required opt-outs. Hanzo will honor applicable Global Privacy Control signals for sale, sharing, and targeted-advertising opt-outs.

## 8. Cookies and similar technologies

Hanzo uses necessary technologies for authentication, security, load balancing, preferences, and core functionality. Analytics, personalization, or marketing technologies are described in the [Cookie Notice](https://hanzo.ai/legal/cookies).

Where required, nonessential cookies remain disabled until consent. You can withdraw consent through the cookie settings. A browser privacy signal does not necessarily withdraw an affirmative research contribution, so research settings remain separately available; however, Hanzo will honor universal opt-out signals for purposes covered by applicable U.S. law.

## 9. Retention

Hanzo retains personal data only as long as necessary for the stated purpose, contractual commitments, security, disputes, and legal obligations. The production implementation must match the following published schedule before this Policy becomes effective:

Data

Proposed standard retention

Account and workspace profile

account life; deletion within 30 days after closure, subject to legal holds and backup cycle

Consumer conversation content

until the user deletes it or closes the account; backend deletion within 30 days, unless a shorter product setting applies

API/enterprise request and response content

up to 30 days for support and abuse monitoring by default; zero-retention or customer-configured period where contracted

Routing and usage telemetry without raw Customer Content

up to 24 months for operations, billing analysis, and reliability research

Nonpersonal standardized Benchmark Records and provenance

for the life of the registry or research program, including longitudinal comparison, replication, cache-before-spend, and model-drift analysis

Nonpersonal Research Run Records, integrity hashes, and supersession history

for the life of the research registry; public visibility is controlled separately from retention

Research artifacts containing Customer Content, personal data, secrets, or licensed material

the applicable service, customer, consent, study, or license period; never made public merely because run metadata is retained

Security and abuse logs

normally 90 days; up to 12 months or longer when connected to an active incident, legal obligation, or dispute

Billing, tax, and transaction records

seven years or the period required by applicable law

Support records

three years after resolution, unless needed for an active dispute

Opted-in private research source data

up to two years unless a shorter consent or study term applies; then delete or lawfully de-identify

Research provenance, consent, and withdrawal records

life of the relevant dataset/model plus six years, as necessary to prove rights and honor withdrawal

Public Commons contributions

according to the selected public license; Hanzo can remove future distributions but cannot guarantee deletion of third-party copies

Biometric identifiers or templates

no longer than necessary for the stated feature, and in all events as required by applicable biometric law; see separate notice

Cookie identifiers

as listed in the [Cookie Notice](https://hanzo.ai/legal/cookies), generally no longer than 13 months for nonessential analytics

Backups

overwritten on a rolling basis, targeted within 90 days after primary deletion

These are proposed commitments and must not be published until engineering verifies them. Legal holds, fraud prevention, chargebacks, security incidents, and mandatory records may justify longer retention. Data rendered anonymous under applicable law may be retained without the same limits.

## 10. Security

Hanzo uses administrative, technical, and organizational measures designed to protect personal data, including access controls, encryption in transit and at rest where appropriate, secrets management, tenant separation, audit logging, vulnerability management, backups, incident response, and subprocessor diligence.

No system is perfectly secure. Users must protect credentials, configure integrations and agents carefully, and avoid submitting unsupported regulated data. Business security measures and incident-notification obligations are described in the DPA and applicable order form.

## 11. Your rights and choices

Depending on your location, you may have rights to:

- know whether and how we process personal data;

- access and receive a portable copy;

- correct inaccurate data;

- delete personal data;

- restrict processing;

- object to processing based on legitimate interests;

- withdraw consent;

- opt out of sale, sharing, targeted advertising, or qualifying profiling;

- limit certain uses of sensitive personal information;

- obtain information about or opt out of qualifying automated decision-making;

- appeal a denied request; and

- complain to a regulator or supervisory authority.

Submit requests through [PRIVACY REQUEST PORTAL—REQUIRED BEFORE PUBLICATION] or [privacy@hanzo.ai](mailto:privacy@hanzo.ai). Authorized agents may submit requests where permitted. We may verify identity using information proportionate to the request; we will not require account creation or unnecessary sensitive information merely to exercise an opt-out right.

We will respond within the legally required period, generally one month under the GDPR and 45 days under many U.S. state laws, subject to permitted extensions. We do not discriminate against users for exercising privacy rights.

Marketing emails include an unsubscribe mechanism. Research and public-contribution choices are managed separately from marketing and cookies.

## 12. Automated processing and profiling

Enso automatically selects computational resources and workflows. This affects which model processes a request, response quality, cost, latency, and the generated Output; it is not designed by Hanzo to make legal or similarly significant decisions about the user.

Hanzo may use automated systems for fraud prevention, safety enforcement, and account protection, with human review and appeal where required. Customers that use Hanzo in employment, credit, insurance, healthcare, education, housing, or another significant-decision context are responsible for separate compliance and may do so only under an appropriate written agreement.

## 13. International transfers

Hanzo is based in the United States and may process data in the United States and other countries listed in the [Subprocessor Register](https://hanzo.ai/legal/subprocessors). Where required, Hanzo uses the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum or other approved mechanism, transfer-impact assessments, and supplementary safeguards.

Hanzo will rely on the EU–U.S. Data Privacy Framework only if and while Hanzo is listed as an active participant covering the relevant data. Until then, the Privacy Policy and DPA must not claim Data Privacy Framework certification.

## 14. Children

The Services are intended for people at least 18 years old. Hanzo does not knowingly collect personal data from children through the general Services. If you believe a child has provided data, contact [privacy@hanzo.ai](mailto:privacy@hanzo.ai). We will investigate and delete it where appropriate.

Any future K–12 or under-18 offering requires separate terms, age assurance, parental or school authorization, data minimization, and compliance with COPPA, FERPA, state student-privacy laws, and applicable European child-consent rules before launch.

## 15. U.S. state disclosures

During the preceding 12 months, Hanzo may have collected the categories described in Section 3, used them for the purposes in Section 5, and disclosed them to the recipient categories in Section 7. These may map to statutory categories such as identifiers, customer records, commercial information, internet activity, geolocation approximated from IP, audio/visual information, professional information, inferences, sensitive personal information, and Customer Content.

Hanzo does not sell personal data and does not share it for cross-context behavioral advertising. If this changes, Hanzo must update this Policy in advance, implement legally required opt-outs, honor Global Privacy Control, and obtain consent where required. Hanzo does not use or disclose sensitive personal information for purposes outside those permitted by California law without providing the required right to limit.

California residents may request the categories and specific pieces of personal information collected, sources, purposes, recipient categories, correction, deletion, and portability, and may use an authorized agent. Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, and other covered-state residents may have similar rights, including appeal rights and opt-outs for targeted advertising, sale, or qualifying profiling. Rights vary by law and exemptions.

Hanzo will process recognized universal opt-out mechanisms as required. Research consent and public-dataset contribution remain separate opt-in choices rather than “sale” opt-outs.

## 16. European disclosures

EEA users may contact [privacy@hanzo.ai](mailto:privacy@hanzo.ai) to exercise GDPR rights and may lodge a complaint with their local supervisory authority. Hanzo will identify its Article 27 EU representative and Data Protection Officer, if required, before actively offering the Services to individuals in the EEA:

- EU representative: [REQUIRED BEFORE EEA LAUNCH OR DOCUMENTED EXEMPTION]

- Data Protection Officer: [NAME/CONTACT OR DOCUMENTED DETERMINATION THAT DPO IS NOT REQUIRED]

Hanzo will conduct a data-protection impact assessment where processing—such as large-scale monitoring, sensitive-data processing, biometric processing, or significant automated decision-making—is likely to create high risk. Hanzo will maintain records of processing, legitimate-interest assessments where used, and transfer-impact assessments.

## 17. AI-specific transparency

Hanzo identifies when users are interacting directly with AI. Where required, Hanzo will provide or preserve machine-readable marking of AI-generated or manipulated content and support disclosure for synthetic media and deepfakes.

If Hanzo places its own general-purpose AI model on the EU market, Hanzo will maintain required technical documentation, copyright compliance policies, and public training-content summaries. If Hanzo publicly releases or substantially modifies a generative AI system in California, it will publish the training-data documentation required by California Civil Code section 3111. This Privacy Policy is not a substitute for those model-specific disclosures.

## 18. Changes to this Policy

We may update this Policy to reflect product, legal, or operational changes. We will post the effective date and provide additional notice for material changes. We will not retroactively convert previously collected service-only data into training data through a quiet policy change. A materially expanded research or public-release purpose requires a new lawful basis and, where applicable, a new affirmative choice.

## 19. Contact

Hanzo AI, Inc.
[CONFIRM REGISTERED/PRIVACY NOTICE ADDRESS]
1828 Golden Gate Avenue
San Francisco, California 94115, USA

- Privacy requests and questions: privacy@hanzo.ai

- Data Protection Officer: dpo@hanzo.ai [ACTIVATE OR REMOVE BEFORE PUBLICATION]

- Security reports: security@hanzo.ai

- General support: support@hanzo.ai

Publication gate: The statements in this draft are legal commitments. Hanzo must verify the product settings, retention jobs, provider contracts, consent ledger, deletion pipeline, GPC behavior, mailboxes, entity address, and regional representatives before publication.
