Security & Privacy
At Hungreo, we take the security and privacy of your data seriously. This page outlines the measures we've implemented to protect your information.
Last Updated: November 2025
Our Commitment to Security
We implement industry-standard security practices to ensure your data is protected at all times. Our website is secured with HTTPS encryption, rate limiting, and comprehensive input validation.
Security Features
1. Data Protection
- Encrypted Connections: All data transmitted between your browser and our servers is encrypted using HTTPS/TLS.
- No Personal Data Collection: Our chatbot does not collect or store personal information (names, emails, phone numbers).
- Secure Storage: Chat logs are stored in encrypted databases with automatic 90-day expiration.
2. Rate Limiting & Abuse Prevention
- Chatbot Rate Limiting: Limited to 10 messages per minute to prevent spam and abuse.
- Admin Protection: Login attempts limited to 5 per 15 minutes with automatic lockout.
- File Upload Limits: Maximum 5 uploads per 10 minutes to prevent storage abuse.
3. Input Validation
- XSS Prevention: All user input is sanitized to prevent cross-site scripting attacks.
- File Type Validation: Only safe file types (PDF, DOCX, TXT) are allowed for uploads.
- Message Length Limits: Chat messages limited to 1-1000 characters.
What Data We Collect
Chatbot Conversations
What we collect: Your questions, AI responses, timestamp, page context
Why we collect it: To improve chatbot accuracy and user experience
How long we keep it: 90 days (automatic deletion)
Who can access it: Admin only (not sold or shared with third parties)
Your rights: You can request deletion of your data at any time
No Personal Identification
We do not collect:
- Names
- Email addresses (except for admin login)
- Phone numbers
- IP addresses (used only for rate limiting, not stored long-term)
- Location data
Third-Party Services
We use the following trusted third-party services:
| Service | Purpose | Data Shared |
|---|---|---|
| OpenAI | AI chatbot responses | User messages (not stored by OpenAI) |
| Vercel | Website hosting | None (infrastructure only) |
| Upstash Redis | Chat log storage | Chat conversations |
| Pinecone | Document search (RAG) | Document embeddings |
GDPR Compliance
Right to Access
Request a copy of your chat logs
Right to Deletion
Request deletion of your data
Right to Object
Opt-out of data collection
Data Minimization
We only collect what's necessary
Security Incident Response
If you discover a security vulnerability, please report it to:
Email: hungreo2005@gmail.com
We will:
- Acknowledge your report within 24 hours
- Investigate and confirm the issue
- Patch the vulnerability within 7 days (critical) or 30 days (non-critical)
- Notify affected users if necessary
Compliance & Certifications
For security or privacy questions, contact: hungreo2005@gmail.com
Last Security Audit: November 2025 | Next Scheduled Audit: February 2026
This page is updated regularly. Last update: November 2025
