Loading...

Security & Privacy

At Hungreo, we take the security and privacy of your data seriously. This page outlines the measures we've implemented to protect your information.

Last Updated: November 2025

Our Commitment to Security

We implement industry-standard security practices to ensure your data is protected at all times. Our website is secured with HTTPS encryption, rate limiting, and comprehensive input validation.

Security Features

1. Data Protection

  • Encrypted Connections: All data transmitted between your browser and our servers is encrypted using HTTPS/TLS.
  • No Personal Data Collection: Our chatbot does not collect or store personal information (names, emails, phone numbers).
  • Secure Storage: Chat logs are stored in encrypted databases with automatic 90-day expiration.

2. Rate Limiting & Abuse Prevention

  • Chatbot Rate Limiting: Limited to 10 messages per minute to prevent spam and abuse.
  • Admin Protection: Login attempts limited to 5 per 15 minutes with automatic lockout.
  • File Upload Limits: Maximum 5 uploads per 10 minutes to prevent storage abuse.

3. Input Validation

  • XSS Prevention: All user input is sanitized to prevent cross-site scripting attacks.
  • File Type Validation: Only safe file types (PDF, DOCX, TXT) are allowed for uploads.
  • Message Length Limits: Chat messages limited to 1-1000 characters.

What Data We Collect

Chatbot Conversations

What we collect: Your questions, AI responses, timestamp, page context

Why we collect it: To improve chatbot accuracy and user experience

How long we keep it: 90 days (automatic deletion)

Who can access it: Admin only (not sold or shared with third parties)

Your rights: You can request deletion of your data at any time

No Personal Identification

We do not collect:

  • Names
  • Email addresses (except for admin login)
  • Phone numbers
  • IP addresses (used only for rate limiting, not stored long-term)
  • Location data

Third-Party Services

We use the following trusted third-party services:

ServicePurposeData Shared
OpenAIAI chatbot responsesUser messages (not stored by OpenAI)
VercelWebsite hostingNone (infrastructure only)
Upstash RedisChat log storageChat conversations
PineconeDocument search (RAG)Document embeddings

GDPR Compliance

Right to Access

Request a copy of your chat logs

Right to Deletion

Request deletion of your data

Right to Object

Opt-out of data collection

Data Minimization

We only collect what's necessary

Security Incident Response

If you discover a security vulnerability, please report it to:

Email: hungreo2005@gmail.com

We will:

  1. Acknowledge your report within 24 hours
  2. Investigate and confirm the issue
  3. Patch the vulnerability within 7 days (critical) or 30 days (non-critical)
  4. Notify affected users if necessary

Compliance & Certifications

HTTPS/TLS Encryption - All connections encrypted
OWASP Top 10 Protection - Mitigated common vulnerabilities
GDPR Compliant - User data rights respected
Regular Security Audits - Quarterly reviews

For security or privacy questions, contact: hungreo2005@gmail.com

Last Security Audit: November 2025 | Next Scheduled Audit: February 2026

This page is updated regularly. Last update: November 2025