Privacy
Hailey is an AI gateway run by DDG. People use it to chat, and DDG's websites and other services call it through its API. This page says what Hailey keeps when they do.
Transcripts are kept by default
Every request is answered by an AI engine. By default, the engine writes a full transcript of each request to Hailey's server. The transcript holds the prompt, any images or files sent with it, the answer, and any tool use. It has no fixed deletion date. We keep transcripts so we can continue a conversation, investigate errors and abuse, and fix problems. Only Hailey's operators can read them. Nobody else can, and we never sell them.
Sending personal data through Hailey means it will be kept, unless the request asks for less, as described in the next section.
Keeping less: retain_days
Each API request can say how long its transcript is kept:
retain_days | What happens |
|---|---|
| not sent | Standard retention, as described above. |
-1 | Do not retain. The engine writes no transcript. The prompt, images and answer exist only while the request runs. |
1 – 365 | The transcript is written, then deleted automatically after that many days. Deletion runs once a day. |
Send it as hailey.retain_days or retain_days in a chat completion, or as the
X-Hailey-Retain-Days header. For an action, send retain_days in the action
body. The response confirms the setting: the X-Hailey-Retention header on chat completions
and retention on action results. A shared-workspace conversation needs its transcript in
order to continue, so it can't be combined with retain_days.
Details for developers.
Some actions are never retained, whatever the request says. kyc-verify (ID and selfie
checks) is one of them. For those actions, Hailey logs only the verdict, the score and the timing.
What else Hailey keeps
- Your account: email, name, and your password, stored scrambled so we can't read it. API keys are also stored scrambled. We keep only the first few characters, so you can tell keys apart.
- Web chats: your conversations and the files you attach. They stay in your account until you delete them.
- Projects: the context files and settings you give a project, until you change or delete them.
- Generated images: images you create, kept with your account.
- Usage records: for every call, the time, model, project, token counts and cost. For actions, also the verdict, score and timing. Never the content.
- Server logs: IP address, browser, the page or endpoint, and the time. They are rotated monthly and kept compressed for a few months.
Who processes requests
Hailey's models are Anthropic's Claude models. To produce an answer, each request (text, images and files) is sent to Anthropic, which processes it under its own commercial terms and policies. We don't send your data to anyone else, except where the law requires it.
If a website sent your data
When a DDG website uses Hailey, for example to check an ID or draft a listing, that website decides what it sends and how long Hailey keeps it. Its own privacy notice explains what it does. Hailey acts on the website's behalf: it keeps the data only as described on this page.
Your choices
- Delete chats in the web app at any time.
- Use
retain_dayson any API call. - Ask us to delete your account. We will remove the account, chats, projects, keys and transcripts linked to it. Usage records without content may be kept for billing.