Legal

Privacy notice

Halvr processes account and model-traffic data to operate the spend control service. Request content retention is controlled per project; metadata-only is the lowest-retention mode. Halvr does not sell personal data.

Effective July 14, 2026

Data Halvr receives

Halvr receives account details, workspace configuration, billing status, support messages, and technical data needed to authenticate and operate the service. When traffic is routed through the proxy, Halvr receives the provider request, selected model, response status, usage, latency, and any customer or feature identifiers the account chooses to attach.

Provider credentials are encrypted at rest and decrypted only when Halvr sends a request to the provider selected by the customer. Raw credentials are not returned through the dashboard or included in usage events.

  • Account data: name, email address, authentication records, team membership, and workspace settings.
  • Traffic data: model, provider, token usage, cost, latency, cache state, routing decision, and attribution metadata.
  • Optional content: request and response bodies only when the project retention mode permits them.
  • Commercial data: plan, subscription, invoice, and payment status supplied by the payment processor.
  • Operational data: IP address, user agent, security events, service logs, and dependency health signals.

Why the data is used

Halvr uses the data to authenticate users, proxy model requests, enforce budgets and policies, calculate cost, deliver alerts, investigate errors, secure the service, provide support, and meet legal obligations. Halvr does not sell personal data or use customer prompts to train a general-purpose model.

Retention choices

Each project has a request-retention mode. Metadata-only keeps operational fields without request or response bodies. Redacted retention removes common secrets and sensitive fields before storage. Full retention keeps the captured request and response for the configured period. Account owners are responsible for choosing a mode that matches their users, contracts, and law.

When an account is closed, Halvr deletes or de-identifies customer data within a commercially reasonable period, except where records must be retained for security, billing, dispute resolution, or law. Backups age out on their normal retention schedule.

Service providers and model providers

Halvr uses infrastructure and service providers for hosting, databases, Redis, analytics storage, object storage, email, and payments. Current production components may include PostgreSQL, Redis, ClickHouse Cloud, Cloudflare R2, Resend, and Dodo Payments. These providers process data only to deliver their contracted service to Halvr.

Model requests are sent to OpenAI, Anthropic, Google, or a custom endpoint only as directed by the customer. The selected provider's terms and data practices apply to that provider-side processing.

Security and international processing

Halvr uses encrypted transport, encrypted provider credentials, tenant-scoped authorization, signed webhooks, least-retention controls, and audit records. No system is immune from failure, so customers should avoid sending data that is not needed for the model task and should use metadata-only retention when content storage is unnecessary.

Halvr and its service providers may process data in countries other than the user's country. Where required, Halvr will use an appropriate transfer mechanism and contractual safeguards.

Requests and contact

Depending on location, a person may have rights to access, correct, delete, restrict, or export personal data, or object to certain processing. Account owners can manage much of the project data in the product. Other privacy requests can be sent to privacy@halvr.io. Halvr may verify the request before acting on it.