Skip to main content
Platform Review
PricingSign in
← All platforms
Enterprise Search / Productivity · hebbia.com

Hebbia

Graded against 804 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.

Overall riskMEDReviewed 2026-08-10
Creator: low · GRC: low · Counsel: low
creator band
Adequate
enterprise · Adequate
Exhibit A · Terms of Service · verbatim

User submitted prompts and files and generated artifacts.

highest-risk verified finding on prompt ownership — tap for the citation
78 verified findings8 policy surfaces2/2 core docs verified
Risk triage

Watch: audit rights dpa residency

Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.

0
high
5
medium
73
low
2/2
docs
Trains on your data?
Not yet assessed
no verified finding covers this surface yet
Who owns outputs?
Not yet assessed
no verified finding covers this surface yet
Commercial use?
Not yet assessed
no verified finding covers this surface yet
Every rating:verbatim-citedsnapshot-datedchange-loggedHow we keep ratings honest →
Risk by role
Select a role to tailor the summary and reorder the findings below.

Scores derived from 23 enriched findings — same verbatim citations as below. AI-generated, not legal advice.

How to read this page: Overall risk rates what Hebbia's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.

Creator lens
Your prompts, your outputs, your IP
ADEQUATE

Based on 107 verified, verbatim-cited findings below — read the citations.

Enterprise lens
Data use, retention, subprocessors, audit
ADEQUATE

Based on 148 verified, verbatim-cited findings below — read the citations.

Automated assessment against a published rubric — not legal advice.

Fully verifiedEnterprise Search / Productivity

Fully verified — complete core corpus captured and read in full.

Document status
  • Privacy Policy
    Verified - read in full - 78 citationsLast captured 2026-08-10
  • Terms of Service
    Verified - read in full - 0 citationsLast captured 2026-08-07
Tier conditions

Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.

plan language
Privacy & data use

Defines the processing purpose as providing LLM capabilities through the subprocessor's API within Hebbia's application, establishing the permitted use of personal data by this subprocessor.

" LLM capabilities through their API in Hebbia’s application."
📍 Privacy Policy › “Nature and Purpose of the Processing”Jump to exact text →
plan language
Privacy & data use

This segment imposes obligations on Hebbia to implement multi-tiered data quality measures including unit testing and database schema validation, and to maintain data quality from the time customer data enters the services until it is presented, ensuring accuracy and integrity of personal data processing.

" Hebbia has a multi-tiered approach for ensuring data quality. These measures include: (i) unit testing to ensure quality of logic used to process API calls, (ii) database schema validation rules which execute against data before it is save..."
📍 Privacy Policy › “Measures for ensuring data quality”Jump to exact text →
plan language
Data retention

Defines sharing data with Sub-Processors as a processing activity subject to DPA permissions, establishes duration of processing tied to service provision and legal requirements, and identifies categories of data subjects and personal data, creating obligations regarding how long and for whom data is processed.

" Sharing data, including disclosure to Sub-Processors as permitted in this DPA Duration of Processing: Company will process Customer’s Personal Data as long as required (i) to provide the Services to Customer under the Agreement; (ii) for ..."
📍 Privacy Policy › “Analyzing data, including product usage assessment”Jump to exact text →
tier-specific
Tier differences

Specifies the processing purpose as LLM capabilities and email/document management through Google Workspace Enterprise, defining the authorized scope of subprocessor activity.

" Large language model (LLM) capabilities; email and document management capabilities through Google Workspace Enterprise"
📍 Privacy Policy › “Nature and Purpose of the Processing”Jump to exact text →
plan language
Subprocessors & data sharing

This segment scopes Clause 6 to CCPA-subject Processor Data, defines the roles of Customer as Business and Hebbia as Service Provider under the CCPA, and incorporates CCPA-specific definitions (Business Purpose, Commercial Purpose, Consumer, etc.) into the DPA framework.

" Additional Provisions for Processor Data that is Subject to the CCPA Scope and Role of Parties. This Clause 6 shall only apply with respect to Processor Data that is subject to the CCPA. When processing Processor Data subject to the CCPA u..."
plan language
Audit rights / DPA / residency

This segment defines 'Applicable Data Protection Law,' 'Controller,' 'processor,' 'data subject,' 'personal data,' 'processing,' 'CCPA,' and 'Processor Data,' establishing the scope of data protection obligations and the types of data subject to the DPA's restrictions and obligations.

" In this DPA, the following terms shall have the following meanings:" Applicable Data Protection Law " means all worldwide data protection and privacy laws and regulations applicable to the Processor Data, including, where applicable, EU/UK..."
📍 Privacy Policy › “Definitions”Jump to exact text →
plan language
Audit rights / DPA / residency

This segment obligates Hebbia to permit Customer to audit CCPA compliance upon reasonable request by attesting to compliance with Section 6.2, requires Hebbia to provide attestation promptly or explain why it cannot, and obligates Customer to immediately notify Hebbia if it believes unauthorized processing is occurring.

"Hebbia will permit Customer, upon reasonable request, to take reasonable and appropriate steps to ensure that Hebbia processes Processor Data in a manner consistent with the obligations applicable to a “Business” under the CCPA by requestin..."
plan language
Audit rights / DPA / residency

This segment imposes obligations on Hebbia to implement accountability measures including data protection and information security policies, recording and reporting personal data breaches, assigning formal roles for security and privacy functions, and conducting regular third-party audits to ensure compliance with privacy and security standards.

" Hebbia has adopted measures for ensuring accountability, such as implementing data protection and information security policies across the business, recording and reporting Personal Data Breaches, and formally assigning roles and responsib..."
📍 Privacy Policy › “Measures for ensuring accountability”Jump to exact text →

Evidence appendix

Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.

High - 0
Medium - 5
Tier-specific - 1
Total citations - 78
Severity
Surface
Document
Tier
Audit rights / DPA / residency
High
" Prohibited Data. Customer shall not disclose any special categories of Processor Data to Hebbia for processing except where and to the extent expressly set out in Annex I of this DPA. Location of Processing. Processor Data that Hebbia processes under the Agreement may be processed in any country in which Hebbia, its Affiliates, partners and authorized Sub-Processors maintain facilities to perform the Services. Hebbia shall not process or transfer (directly or via onward transfer) Processor Data (nor permit such data to be processed or transferred) outside of its country of origin unless the transfer is in compliance with Applicable Data Protection Laws. Confidentiality of Processing . Hebbia shall ensure that any person that it authorises to process the Processor Data (including Hebbia's staff, agents and Sub-Processors) (an " Authorised Person ") shall be subject to a strict duty of confidentiality (whether a contractual duty or a statutory duty), and shall not permit any person to process the Processor Data who is not under such a duty of confidentiality."
Privacy Policy › “Definitions”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-08- View source
Permalink to this finding →
Automated analysis

This segment restricts Customer from disclosing special categories of Processor Data to Hebbia except as set out in Annex I, and restricts Hebbia from processing or transferring Processor Data outside its country of origin unless appropriate transfer safeguards are in place, establishing geographic and categorical data processing limits.

AI-generated interpretation, not legal advice.

Data retention
High
" Sharing data, including disclosure to Sub-Processors as permitted in this DPA Duration of Processing: Company will process Customer’s Personal Data as long as required (i) to provide the Services to Customer under the Agreement; (ii) for Company’s legitimate business needs; or (iii) by applicable law or regulation. Company Account Data and Company Usage Data will be processed and stored as set forth in Company’s privacy policy. Categories of Data Subjects: Customer’s employees, consultants, contractors, and/or agents. Categories of Personal Data: Company processes Personal Data contained in Company Account Data, Company Usage Data, and any Personal Data provided by Customer (including any Personal Data Customer collects from its end users and processes through its use of the Services) or collected by Company in order to provide the Services or as otherwise set forth in the Agreement or this DPA. Categories of Personal Data include name, email, job title, username, IP address for company device, and background check verification records (at discretion of Controller). Sensitive Data or Special Categories of Data: Customers are prohibited from providing sensitive personal data or special categories of data to Company, including without limitation, any data which reveals racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, or genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation."
Privacy Policy › “Analyzing data, including product usage assessment”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-08- View source
Permalink to this finding →
Automated analysis

Defines sharing data with Sub-Processors as a processing activity subject to DPA permissions, establishes duration of processing tied to service provision and legal requirements, and identifies categories of data subjects and personal data, creating obligations regarding how long and for whom data is processed.

AI-generated interpretation, not legal advice.

Subprocessors & data sharing
High
" Authorized Sub-Processors Customer acknowledges and agrees that Hebbia may (1) engage its Affiliates as well as the Authorized Sub-Processors on the List (defined below) to access and process Personal Data in connection with the Services and (2) from time to time engage additional third parties for the purpose of providing the Services, including without limitation the processing of Personal Data. By way of this DPA, Customer provides general written authorization to Hebbia to engage Sub-Processors as necessary to perform the Services. A list of Hebbia’s current Authorized Sub-Processors (the “List”) is available to Customer at https://trust.hebbia.ai/subprocessors . Such List may be updated by Hebbia from time to time. Hebbia will provide a mechanism to subscribe to notifications (which may include but are not limited to email notifications) of new Authorized Sub-Processors and Customer, if it wishes, will subscribe to such notifications where available. If Customer does not subscribe to such notifications, Customer waives any right it may have to receive prior notice of changes to Authorized Sub-Processors. At least ten (10) days before enabling any third party other than existing Authorized Sub-Processors to access or participate in the processing of Personal Data, Hebbia will add such third party to the List and notify subscribers, including Customer, via the aforementioned notifications. Customer may object to such an engagement by informing Hebbia in writing within ten (10) days of receipt of the aforementioned notice by Customer, provided such objection is in writing and based on reasonable grounds relating to data protection. "
Privacy Policy › “Definitions”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-08- View source
Permalink to this finding →
Automated analysis

This segment grants Hebbia a general written authorization from Customer to engage Affiliates and listed Authorized Sub-Processors to access and process Personal Data, and to engage additional third parties as needed for the Services, establishing the permissive framework for sub-processing arrangements.

AI-generated interpretation, not legal advice.

Audit rights / DPA / residency
High
" Hebbia maintains an SOC 2 Type II compliant risk-based information security governance program. The framework for Hebbia’s security program includes administrative, organizational, technical, and physical safeguards reasonably designed to protect the Services and confidentiality, integrity, and availability of Customer Data."
Privacy Policy › “Measures for internal IT and IT security governance and management”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-08- View source
Permalink to this finding →
Automated analysis

This segment imposes obligations on Hebbia to maintain an SOC 2 Type II compliant risk-based information security governance program incorporating administrative, organizational, technical, and physical safeguards to protect the Services and customer data confidentiality, integrity, and availability.

AI-generated interpretation, not legal advice.

Audit rights / DPA / residency
High
"Hebbia will permit Customer, upon reasonable request, to take reasonable and appropriate steps to ensure that Hebbia processes Processor Data in a manner consistent with the obligations applicable to a “Business” under the CCPA by requesting that Hebbia attest to its compliance with this Section 6.2 of the DPA. Following any such request, Hebbia will promptly provide that attestation or notice about why it cannot provide it. If Customer reasonably believes that Hebbia is engaged in the processing of Processor Data that is not authorized under this DPA, Customer will immediately notify Hebbia of such belief, and the parties will work together in good faith to remediate the allegedly violative processing activities, if necessary."
Source: Privacy Policy- Snapshot 2026-06-08- View source
Permalink to this finding →
Automated analysis

This segment obligates Hebbia to permit Customer to audit CCPA compliance upon reasonable request by attesting to compliance with Section 6.2, requires Hebbia to provide attestation promptly or explain why it cannot, and obligates Customer to immediately notify Hebbia if it believes unauthorized processing is occurring.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Only personal data that is uploaded to Hebbia by the data controller (or its authorized users) for the purposes of large LLM inference will be processed."
Privacy Policy › “Types of Personal Data Processed”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-08- View source
Permalink to this finding →
Automated analysis

This segment restricts the types of personal data processed by Reducto, Inc. to only what is uploaded by the data controller or authorized users for LLM inference purposes, limiting this subprocessor's data handling scope.

AI-generated interpretation, not legal advice.

Tier differences
High
" Large language model (LLM) capabilities; email and document management capabilities through Google Workspace Enterprise"
Privacy Policy › “Nature and Purpose of the Processing”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-08- View source
Permalink to this finding →
Automated analysis

Specifies the processing purpose as LLM capabilities and email/document management through Google Workspace Enterprise, defining the authorized scope of subprocessor activity.

AI-generated interpretation, not legal advice.

Prompt / input ownership
NeutralHigh
" User submitted prompts and files and generated artifacts."
Privacy Policy › “Subject Matter of the Processing”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-08- View source
Permalink to this finding →
Automated analysis

Defines the subject matter as 'User submitted prompts and files and generated artifacts,' scoping the specific personal data and content processed by Elasticsearch under the DPA.

AI-generated interpretation, not legal advice.

Privacy & data use
FavorableHigh
" Datadog does not process personal data."
Privacy Policy › “Types of Personal Data Processed”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-08- View source
Permalink to this finding →
Automated analysis

This segment disclaims that Datadog does not process personal data, which is a substantive legal statement limiting the company's obligations under data processing and privacy regulations by asserting no personal data processing occurs.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Hebbia has deployed secure methods and protocols for transmission of confidential or sensitive information over public networks. Databases housing sensitive customer data are encrypted at rest. Hebbia uses only recommended secure cipher suites and protocols to encrypt all traffic in transit and Customer Data is securely encrypted with strong ciphers and configurations when at rest."
Privacy Policy › “Measures of pseudonymisation and encryption of personal data”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-08- View source
Permalink to this finding →
Automated analysis

This segment imposes obligations on Hebbia to use secure transmission protocols, encrypt databases at rest using strong ciphers, and encrypt all data in transit, establishing specific technical security requirements for protecting customer data.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Used for embedding and re-ranking user data and system data."
Privacy Policy › “Nature and Purpose of the Processing”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-08- View source
Permalink to this finding →
Automated analysis

This segment defines the nature and purpose of MongoDB's processing as embedding and re-ranking user data and system data, specifying the processing activity performed by this subprocessor.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" privacy@hebbia.ai "
Privacy Policy › “Matt Aromatorio, Head of Security,”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-08- View source
Permalink to this finding →
Automated analysis

Provides the privacy contact email address (privacy@hebbia.ai) for the data protection contact at Hebbia Inc., establishing the communication channel for data protection inquiries.

AI-generated interpretation, not legal advice.

Privacy & data use
NeutralHigh
" Name, Username, Email, Job Title, Company device identifiers (e.g. serial number), and IP Address"
Privacy Policy › “Types of Personal Data Processed”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-08- View source
Permalink to this finding →
Automated analysis

Enumerates specific categories of personal data processed (Name, Username, Email, Job Title, Company device identifiers, IP Address), defining the scope of personal data subject to processing obligations and restrictions.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" LLM capabilities through their API in Hebbia’s application."
Privacy Policy › “Nature and Purpose of the Processing”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-08- View source
Permalink to this finding →
Automated analysis

Defines the processing purpose as providing LLM capabilities through the subprocessor's API within Hebbia's application, establishing the permitted use of personal data by this subprocessor.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Contact person’s name, position and contact details: "
Privacy Policy › “233 Spring St, Floor 9 New York, NY 10013”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-08- View source
Permalink to this finding →
Automated analysis

Introduces the contact person responsible for data protection at Hebbia Inc., as required by the DPA's identification obligations for the data importer.

AI-generated interpretation, not legal advice.

Privacy & data use
NeutralHigh
" Search and indexing functions within Hebbia’s application which enables efficient retrieval of data."
Privacy Policy › “Nature and Purpose of the Processing”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-08- View source
Permalink to this finding →
Automated analysis

Defines the nature and purpose as search and indexing functions enabling efficient retrieval of data within Hebbia's application, characterizing and limiting the authorized processing activity for this subprocessor.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Encryption-at-rest is automated using AWS’s transparent disk encryption, which uses industry standard AES-256 encryption to secure all volume (disk) data. All keys are fully managed by AWS."
Privacy Policy › “Measures for the protection of data during storage”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-08- View source
Permalink to this finding →
Automated analysis

This segment establishes the obligation to use AWS automated AES-256 transparent disk encryption for all volume data at rest, with key management fully handled by AWS, ensuring protection of stored personal data.

AI-generated interpretation, not legal advice.

Privacy & data use
FavorableHigh
" Hebbia has a multi-tiered approach for ensuring data quality. These measures include: (i) unit testing to ensure quality of logic used to process API calls, (ii) database schema validation rules which execute against data before it is saved to our database. Hebbia applies these measures across the board, both to ensure the quality of any Usage Data that Hebbia collects and to ensure that the Hebbia Platform is operating within expected parameters. Hebbia ensures that data quality is maintained from the time a Customer sends Customer Data into the Services and until that Customer Data is presented or exported."
Privacy Policy › “Measures for ensuring data quality”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-08- View source
Permalink to this finding →
Automated analysis

This segment imposes obligations on Hebbia to implement multi-tiered data quality measures including unit testing and database schema validation, and to maintain data quality from the time customer data enters the services until it is presented, ensuring accuracy and integrity of personal data processing.

AI-generated interpretation, not legal advice.

Clause detail — protections, your obligations, and coverage

Every clause below is a verbatim quote from Hebbia's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.

✅ Protections found

31 verified clauses

Clauses in Hebbia's policies that work in your favour — commitments the platform made to you.

  • Audit rights, DPA & residency
    Role and Scope of Processing Roles of the Parties . The parties acknowledge and agree that for the purposes of this DPA Customer is the controller with respect to the processing of Processor Data, and Hebbia shall process Processor Data only as a processor on…

    This segment establishes the roles of the parties (Customer as controller, Hebbia as processor), imposes an obligation on Hebbia to process Processor Data only as instructed and only as described in Annex I, and requires…

    📍 Privacy Policy › “Definitions”Jump to exact text →
  • Audit rights, DPA & residency
    " Personal Data " means information, which is protected as "personal data", "personally identifiable information" or "personal information" under any applicable Data Protection Laws. For the avoidance of doubt, with respect to US Data Protection Laws, “Persona…

    This segment defines 'Personal Data' and 'Processor Data,' specifying what information is protected under the DPA (including exclusions for de-identified and publicly available data) and scoping the data subject to Hebbi…

    📍 Privacy Policy › “Definitions”Jump to exact text →
  • Subprocessors & data sharing
    Customer acknowledges that certain Sub-Processors are essential to providing the Services and that objecting to the use of a Sub-Processor may prevent Hebbia from offering the Services to Customer. If Customer reasonably objects to an engagement in accordance…

    This segment establishes the procedure and consequences where Customer objects to a Sub-Processor engagement: Hebbia must offer a commercially reasonable alternative, Customer may discontinue the affected Service if none…

    📍 Privacy Policy › “Definitions”Jump to exact text →
  • Subprocessors & data sharingsale/sharing of personal data
    Additional Provisions for Processor Data that is Subject to the CCPA Scope and Role of Parties. This Clause 6 shall only apply with respect to Processor Data that is subject to the CCPA. When processing Processor Data subject to the CCPA under this DPA, the pa…

    This segment scopes Clause 6 to CCPA-subject Processor Data, defines the roles of Customer as Business and Hebbia as Service Provider under the CCPA, and incorporates CCPA-specific definitions (Business Purpose, Commerci…

  • Audit rights, DPA & residency
    Transfers of European Processor Data Scope and Role of the Parties. This Clause 5 shall only apply with respect to Processor Data subject to EU/UK Data Protection Law. Restricted Transfers. The parties agree that where and to the extent the transfer of Proces…

    This segment scopes Clause 5 to EU/UK Data Protection Law and imposes an obligation on the parties to apply Standard Contractual Clauses (EU SCCs) for Restricted Transfers of Processor Data from Customer (data exporter)…

    📍 Privacy Policy › “Definitions”Jump to exact text →
  • Audit rights, DPA & residency
    Hebbia shall permit Customer or its appointed third party auditors to audit Hebbia's compliance with this DPA, and shall make available to Customer all relevant information, policies, procedures, records, and staff necessary for Customer or its third party aud…

    This segment grants Customer the right to audit Hebbia's DPA compliance (including through third-party auditors) and requires Hebbia to make available all relevant information and personnel, while limiting audit frequenc…

    📍 Privacy Policy › “Audit”Jump to exact text →

+ 25 more verified clauses of this kind on this platform, cited in full in the report.

📋 Rules you must follow

0 verified clauses

What Hebbia requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.

No user-conduct rule has been verified in Hebbia's published policies yet.

What the policies actually cover

4 topics
  • Product telemetry & usage tracking4 clauses
  • Sale or sharing of personal data1 protective1 clause
  • Deletion rights & post-termination survival4 protective5 clauses
  • Breach-notification promises1 protective2 clauses

66 further verified clauses are cited on this page but not yet assigned a topic.

Cross-clause notes

Ambiguity — Caution

Verified retention clauses point in different directions: the Privacy Policy, Privacy Policy › “Analyzing data, including product usage assessment” describes broad or open-ended retention, while the Privacy Policy, Privacy Policy › “Measures for ensuring data minimisation” describes deletion or erasure. Which clause controls in a given situation is not resolved by the documents' text alone — this is surfaced as an ambiguity, treated as Caution.

Automated cross-reference against the published rubric — not legal advice.

Clause intelligence

Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.

324
clauses
16
patterns
16
stances
privacy sharing · 12dispute resolution · 4
dispute resolutionMEDIUMTerms of Service › “Last updated: Dec 12, 2025”

The clause imposes arbitration, class-action waiver, or jury-trial waiver terms.

Please read these Terms of Service (the “Terms”) and our Privacy Policy (“Privacy Policy”) carefully because they govern your use of the Site and our artificial intelligence-powered productivity and research services accessible via the Site offered by us. To make these Terms easier to read, the Site, and our services are collectively called the “Services”. ‍Important notice regarding arbitration for U.S. Customers...
Open source citation
dispute resolutionMEDIUMTerms of Service › “Last updated: Dec 12, 2025”

The clause imposes arbitration, class-action waiver, or jury-trial waiver terms.

Please read these Terms of Service (the “Terms”) and our Privacy Policy (“Privacy Policy”) carefully because they govern your use of the Site and our artificial intelligence-powered productivity and research services accessible via the Site offered by us. To make these Terms easier to read, the Site, and our services are collectively called the “Services”. ‍Important notice regarding arbitration for U.S. Customers...
Open source citation
dispute resolutionMEDIUMTerms of Service › “Last updated: Dec 12, 2025”

The clause imposes arbitration, class-action waiver, or jury-trial waiver terms.

Please read these Terms of Service (the “Terms”) and our Privacy Policy (“Privacy Policy”) carefully because they govern your use of the Site and our artificial intelligence-powered productivity and research services accessible via the Site offered by us. To make these Terms easier to read, the Site, and our services are collectively called the “Services”. ‍Important notice regarding arbitration for U.S. Customers...
Open source citation
dispute resolutionMEDIUMTerms of Service › “Last updated: Dec 12, 2025”

The clause imposes arbitration, class-action waiver, or jury-trial waiver terms.

Please read these Terms of Service (the “Terms”) and our Privacy Policy (“Privacy Policy”) carefully because they govern your use of the Site and our artificial intelligence-powered productivity and research services accessible via the Site offered by us. To make these Terms easier to read, the Site, and our services are collectively called the “Services”. ‍Important notice regarding arbitration for U.S. Customers...
Open source citation
privacy sharingHIGHAnnex II

The clause permits sale of personal data or information.

Additional Provisions for Processor Data that is Subject to the CCPA Scope and Role of Parties. This Clause 6 shall only apply with respect to Processor Data that is subject to the CCPA. When processing Processor Data subject to the CCPA under this DPA, the parties acknowledge and agree that Customer is a Business and Hebbia is a Service Provider for the purposes of the CCPA. For the purpose of this Clause 6, "Bus...
Open source citation

Tier matrix

Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.

TierSurfaceVerdictRiskCitations
All applicable tiersgoverning law disputesconditionalMEDIUM4
All applicable tiersprivacy data useconditionalMEDIUM5
All applicable tierssubprocessors data sharingconditionalMEDIUM1
Team / Businesscommercial useworsensHIGH5
Team / Businessprivacy data useworsensHIGH1

Policy evolution

Open full timeline

Before/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.

improvedhigh materialityJun 17Jul 10, 2026

data sharing improved from high/sale or sell to medium/third party or vendor sharing.

Before · high
Additional Provisions for Processor Data that is Subject to the CCPA Scope and Role of Parties. This Clause 6 shall only apply with respect to Processor Data that is subject to the CCPA. When processing Processor Data subject to the CCPA under this DPA, the parties acknowledge and agree that Customer is a Business and Hebbia is a Service Provider for the purposes of the CCPA. For the purpose of this Clause 6, "Business", "Business Purpose", "Commercial Purpose", "Consumer," "Personal Information", "Process," "Sell", "Service Provider", and "Share" have the meanings given to them in the CCPA. Responsibilities . Customer discloses or otherwise makes available Processor Data to Hebbia for the limited and specific purpose of Hebbia carrying out the Permitted Purposes. Hebbia shall: (i) comply with its applicable obligations under the CCPA; (ii) provide the same level of protection as required under the CCPA; (iii) notify Customer if it can no longer meet its obligations under the CCPA; (iv) not “sell” or “share” (as such terms are defined by the CCPA) Processor Data; (v) not retain, use, or disclose Processor Data for any purpose (including any commercial purpose) other than the Permitted Purpose or as otherwise permitted under the CCPA; (vi) not retain, use, or disclose Processor Data outside of the direct business relationship between Customer and Hebbia or as otherwise permitted under the CCPA; and (vii) unless otherwise permitted by the CCPA, not combine Processor Data with Personal Information that Hebbia: (a) receives from, or on behalf of, another person, or (b) collects from its own, independent consumer interaction.
Before citation
After · medium
Authorized Sub-Processors Customer acknowledges and agrees that Hebbia may (1) engage its Affiliates as well as the Authorized Sub-Processors on the List (defined below) to access and process Personal Data in connection with the Services and (2) from time to time engage additional third parties for the purpose of providing the Services, including without limitation the processing of Personal Data. By way of this DPA, Customer provides general written authorization to Hebbia to engage Sub-Processors as necessary to perform the Services. A list of Hebbia’s current Authorized Sub-Processors (the “List”) is available to Customer at https://trust.hebbia.ai/subprocessors . Such List may be updated by Hebbia from time to time. Hebbia will provide a mechanism to subscribe to notifications (which may include but are not limited to email notifications) of new Authorized Sub-Processors and Customer, if it wishes, will subscribe to such notifications where available. If Customer does not subscribe to such notifications, Customer waives any right it may have to receive prior notice of changes to Authorized Sub-Processors. At least ten (10) days before enabling any third party other than existing Authorized Sub-Processors to access or participate in the processing of Personal Data, Hebbia will add such third party to the List and notify subscribers, including Customer, via the aforementioned notifications. Customer may object to such an engagement by informing Hebbia in writing within ten (10) days of receipt of the aforementioned notice by Customer, provided such objection is in writing and based on reasonable grounds relating to data protection.
After citation
Aug 10, 2026data sharingMEDIUM

Latest stance: third party or vendor sharing on privacy data use

Authorized Sub-Processors Customer acknowledges and agrees that Hebbia may (1) engage its Affiliates as well as the Authorized Sub-Processors on the List (defined below) to access and process Personal Data in connection with the Services and (2) from time to time engage additional third parties for the purpose of providing the Services, including without limitation the processing of Personal Data. By way of this DPA, Customer provides general written authorization to Hebbia to engage Sub-Processors as necessary to perform the Services. A list of Hebbia’s current Authorized Sub-Processors (the “List”) is available to Customer at https://trust.hebbia.ai/subprocessors . Such List may be updated by Hebbia from time to time. Hebbia will provide a mechanism to subscribe to notifications (which may include but are not limited to email notifications) of new Authorized Sub-Processors and Customer, if it wishes, will subscribe to such notifications where available. If Customer does not subscribe to such notifications, Customer waives any right it may have to receive prior notice of changes to Authorized Sub-Processors. At least ten (10) days before enabling any third party other than existing Authorized Sub-Processors to access or participate in the processing of Personal Data, Hebbia will add such third party to the List and notify subscribers, including Customer, via the aforementioned notifications. Customer may object to such an engagement by informing Hebbia in writing within ten (10) days of receipt of the aforementioned notice by Customer, provided such objection is in writing and based on reasonable grounds relating to data protection.
Open timeline citation
Aug 10, 2026data sharingHIGH

Latest stance: sale or sell on commercial use

Additional Provisions for Processor Data that is Subject to the CCPA Scope and Role of Parties. This Clause 6 shall only apply with respect to Processor Data that is subject to the CCPA. When processing Processor Data subject to the CCPA under this DPA, the parties acknowledge and agree that Customer is a Business and Hebbia is a Service Provider for the purposes of the CCPA. For the purpose of this Clause 6, "Business", "Business Purpose", "Commercial Purpose", "Consumer," "Personal Information", "Process," "Sell", "Service Provider", and "Share" have the meanings given to them in the CCPA. Responsibilities . Customer discloses or otherwise makes available Processor Data to Hebbia for the limited and specific purpose of Hebbia carrying out the Permitted Purposes. Hebbia shall: (i) comply with its applicable obligations under the CCPA; (ii) provide the same level of protection as required under the CCPA; (iii) notify Customer if it can no longer meet its obligations under the CCPA; (iv) not “sell” or “share” (as such terms are defined by the CCPA) Processor Data; (v) not retain, use, or disclose Processor Data for any purpose (including any commercial purpose) other than the Permitted Purpose or as otherwise permitted under the CCPA; (vi) not retain, use, or disclose Processor Data outside of the direct business relationship between Customer and Hebbia or as otherwise permitted under the CCPA; and (vii) unless otherwise permitted by the CCPA, not combine Processor Data with Personal Information that Hebbia: (a) receives from, or on behalf of, another person, or (b) collects from its own, independent consumer interaction.
Open timeline citation
Aug 7, 2026dispute termsMEDIUM

Latest stance: arbitration or waiver on governing law disputes

Please read these Terms of Service (the “Terms”) and our Privacy Policy (“Privacy Policy”) carefully because they govern your use of the Site and our artificial intelligence-powered productivity and research services accessible via the Site offered by us. To make these Terms easier to read, the Site, and our services are collectively called the “Services”. ‍Important notice regarding arbitration for U.S. Customers: when you agree to these terms you are agreeing (with limited exception) to resolve any dispute between you and hebbia through binding, individual arbitration rather than in court. Please review carefully section 16 “dispute resolution” below for details regarding arbitration.
Open timeline citation
Aug 3, 2026data sharingMEDIUM

Latest stance: third party or vendor sharing on privacy data use

Authorized Sub-Processors Customer acknowledges and agrees that Hebbia may (1) engage its Affiliates as well as the Authorized Sub-Processors on the List (defined below) to access and process Personal Data in connection with the Services and (2) from time to time engage additional third parties for the purpose of providing the Services, including without limitation the processing of Personal Data. By way of this DPA, Customer provides general written authorization to Hebbia to engage Sub-Processors as necessary to perform the Services. A list of Hebbia’s current Authorized Sub-Processors (the “List”) is available to Customer at https://trust.hebbia.ai/subprocessors . Such List may be updated by Hebbia from time to time. Hebbia will provide a mechanism to subscribe to notifications (which may include but are not limited to email notifications) of new Authorized Sub-Processors and Customer, if it wishes, will subscribe to such notifications where available. If Customer does not subscribe to such notifications, Customer waives any right it may have to receive prior notice of changes to Authorized Sub-Processors. At least ten (10) days before enabling any third party other than existing Authorized Sub-Processors to access or participate in the processing of Personal Data, Hebbia will add such third party to the List and notify subscribers, including Customer, via the aforementioned notifications. Customer may object to such an engagement by informing Hebbia in writing within ten (10) days of receipt of the aforementioned notice by Customer, provided such objection is in writing and based on reasonable grounds relating to data protection.
Open timeline citation

Capture recency

  • Privacy Policy:Last captured 2026-08-10· verified 2026-08-10
  • Terms of Service:Last captured 2026-08-07· verified 2026-08-07

Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.

↑ 211 more findings this quarter vs last (311 vs 100). First scan: June 2026.

Claim this profile

Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Hebbia's policies — no human edits the data.

Need this for procurement or legal diligence?

Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.

Every finding above is a verbatim quote from Hebbia's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.