Hebbia
Graded against 804 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.
“User submitted prompts and files and generated artifacts.”
Watch: audit rights dpa residency
Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.
This segment restricts Customer from disclosing special categories of Processor Data to Hebbia except as set out in Annex I, and restricts Hebbia from processing or transferring Processor Data outside its country of origin unless appropriate transfer safeguards are in place, establishing geographic and categorical data processing limits.
This segment imposes obligations on Hebbia to maintain an SOC 2 Type II compliant risk-based information security governance program incorporating administrative, organizational, technical, and physical safeguards to protect the Services and customer data confidentiality, integrity, and availability.
This segment obligates Hebbia to permit Customer to audit CCPA compliance upon reasonable request by attesting to compliance with Section 6.2, requires Hebbia to provide attestation promptly or explain why it cannot, and obligates Customer to immediately notify Hebbia if it believes unauthorized processing is occurring.
Scores derived from 23 enriched findings — same verbatim citations as below. AI-generated, not legal advice.
How to read this page: Overall risk rates what Hebbia's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.
Policy benchmark
rubric v1.0 — how this is scoredBased on 107 verified, verbatim-cited findings below — read the citations.
Based on 148 verified, verbatim-cited findings below — read the citations.
Automated assessment against a published rubric — not legal advice.
Fully verified — complete core corpus captured and read in full.
- Privacy PolicyVerified - read in full - 78 citationsLast captured 2026-08-10
- Terms of ServiceVerified - read in full - 0 citationsLast captured 2026-08-07
Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.
Defines the processing purpose as providing LLM capabilities through the subprocessor's API within Hebbia's application, establishing the permitted use of personal data by this subprocessor.
" LLM capabilities through their API in Hebbia’s application."
This segment imposes obligations on Hebbia to implement multi-tiered data quality measures including unit testing and database schema validation, and to maintain data quality from the time customer data enters the services until it is presented, ensuring accuracy and integrity of personal data processing.
" Hebbia has a multi-tiered approach for ensuring data quality. These measures include: (i) unit testing to ensure quality of logic used to process API calls, (ii) database schema validation rules which execute against data before it is save..."
Defines sharing data with Sub-Processors as a processing activity subject to DPA permissions, establishes duration of processing tied to service provision and legal requirements, and identifies categories of data subjects and personal data, creating obligations regarding how long and for whom data is processed.
" Sharing data, including disclosure to Sub-Processors as permitted in this DPA Duration of Processing: Company will process Customer’s Personal Data as long as required (i) to provide the Services to Customer under the Agreement; (ii) for ..."
Specifies the processing purpose as LLM capabilities and email/document management through Google Workspace Enterprise, defining the authorized scope of subprocessor activity.
" Large language model (LLM) capabilities; email and document management capabilities through Google Workspace Enterprise"
This segment scopes Clause 6 to CCPA-subject Processor Data, defines the roles of Customer as Business and Hebbia as Service Provider under the CCPA, and incorporates CCPA-specific definitions (Business Purpose, Commercial Purpose, Consumer, etc.) into the DPA framework.
" Additional Provisions for Processor Data that is Subject to the CCPA Scope and Role of Parties. This Clause 6 shall only apply with respect to Processor Data that is subject to the CCPA. When processing Processor Data subject to the CCPA u..."
This segment defines 'Applicable Data Protection Law,' 'Controller,' 'processor,' 'data subject,' 'personal data,' 'processing,' 'CCPA,' and 'Processor Data,' establishing the scope of data protection obligations and the types of data subject to the DPA's restrictions and obligations.
" In this DPA, the following terms shall have the following meanings:" Applicable Data Protection Law " means all worldwide data protection and privacy laws and regulations applicable to the Processor Data, including, where applicable, EU/UK..."
This segment obligates Hebbia to permit Customer to audit CCPA compliance upon reasonable request by attesting to compliance with Section 6.2, requires Hebbia to provide attestation promptly or explain why it cannot, and obligates Customer to immediately notify Hebbia if it believes unauthorized processing is occurring.
"Hebbia will permit Customer, upon reasonable request, to take reasonable and appropriate steps to ensure that Hebbia processes Processor Data in a manner consistent with the obligations applicable to a “Business” under the CCPA by requestin..."
This segment imposes obligations on Hebbia to implement accountability measures including data protection and information security policies, recording and reporting personal data breaches, assigning formal roles for security and privacy functions, and conducting regular third-party audits to ensure compliance with privacy and security standards.
" Hebbia has adopted measures for ensuring accountability, such as implementing data protection and information security policies across the business, recording and reporting Personal Data Breaches, and formally assigning roles and responsib..."
Evidence appendix
Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.
" Prohibited Data. Customer shall not disclose any special categories of Processor Data to Hebbia for processing except where and to the extent expressly set out in Annex I of this DPA. Location of Processing. Processor Data that Hebbia processes under the Agreement may be processed in any country in which Hebbia, its Affiliates, partners and authorized Sub-Processors maintain facilities to perform the Services. Hebbia shall not process or transfer (directly or via onward transfer) Processor Data (nor permit such data to be processed or transferred) outside of its country of origin unless the transfer is in compliance with Applicable Data Protection Laws. Confidentiality of Processing . Hebbia shall ensure that any person that it authorises to process the Processor Data (including Hebbia's staff, agents and Sub-Processors) (an " Authorised Person ") shall be subject to a strict duty of confidentiality (whether a contractual duty or a statutory duty), and shall not permit any person to process the Processor Data who is not under such a duty of confidentiality."
This segment restricts Customer from disclosing special categories of Processor Data to Hebbia except as set out in Annex I, and restricts Hebbia from processing or transferring Processor Data outside its country of origin unless appropriate transfer safeguards are in place, establishing geographic and categorical data processing limits.
AI-generated interpretation, not legal advice.
" Sharing data, including disclosure to Sub-Processors as permitted in this DPA Duration of Processing: Company will process Customer’s Personal Data as long as required (i) to provide the Services to Customer under the Agreement; (ii) for Company’s legitimate business needs; or (iii) by applicable law or regulation. Company Account Data and Company Usage Data will be processed and stored as set forth in Company’s privacy policy. Categories of Data Subjects: Customer’s employees, consultants, contractors, and/or agents. Categories of Personal Data: Company processes Personal Data contained in Company Account Data, Company Usage Data, and any Personal Data provided by Customer (including any Personal Data Customer collects from its end users and processes through its use of the Services) or collected by Company in order to provide the Services or as otherwise set forth in the Agreement or this DPA. Categories of Personal Data include name, email, job title, username, IP address for company device, and background check verification records (at discretion of Controller). Sensitive Data or Special Categories of Data: Customers are prohibited from providing sensitive personal data or special categories of data to Company, including without limitation, any data which reveals racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, or genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation."
Defines sharing data with Sub-Processors as a processing activity subject to DPA permissions, establishes duration of processing tied to service provision and legal requirements, and identifies categories of data subjects and personal data, creating obligations regarding how long and for whom data is processed.
AI-generated interpretation, not legal advice.
" Authorized Sub-Processors Customer acknowledges and agrees that Hebbia may (1) engage its Affiliates as well as the Authorized Sub-Processors on the List (defined below) to access and process Personal Data in connection with the Services and (2) from time to time engage additional third parties for the purpose of providing the Services, including without limitation the processing of Personal Data. By way of this DPA, Customer provides general written authorization to Hebbia to engage Sub-Processors as necessary to perform the Services. A list of Hebbia’s current Authorized Sub-Processors (the “List”) is available to Customer at https://trust.hebbia.ai/subprocessors . Such List may be updated by Hebbia from time to time. Hebbia will provide a mechanism to subscribe to notifications (which may include but are not limited to email notifications) of new Authorized Sub-Processors and Customer, if it wishes, will subscribe to such notifications where available. If Customer does not subscribe to such notifications, Customer waives any right it may have to receive prior notice of changes to Authorized Sub-Processors. At least ten (10) days before enabling any third party other than existing Authorized Sub-Processors to access or participate in the processing of Personal Data, Hebbia will add such third party to the List and notify subscribers, including Customer, via the aforementioned notifications. Customer may object to such an engagement by informing Hebbia in writing within ten (10) days of receipt of the aforementioned notice by Customer, provided such objection is in writing and based on reasonable grounds relating to data protection. "
This segment grants Hebbia a general written authorization from Customer to engage Affiliates and listed Authorized Sub-Processors to access and process Personal Data, and to engage additional third parties as needed for the Services, establishing the permissive framework for sub-processing arrangements.
AI-generated interpretation, not legal advice.
" Hebbia maintains an SOC 2 Type II compliant risk-based information security governance program. The framework for Hebbia’s security program includes administrative, organizational, technical, and physical safeguards reasonably designed to protect the Services and confidentiality, integrity, and availability of Customer Data."
This segment imposes obligations on Hebbia to maintain an SOC 2 Type II compliant risk-based information security governance program incorporating administrative, organizational, technical, and physical safeguards to protect the Services and customer data confidentiality, integrity, and availability.
AI-generated interpretation, not legal advice.
"Hebbia will permit Customer, upon reasonable request, to take reasonable and appropriate steps to ensure that Hebbia processes Processor Data in a manner consistent with the obligations applicable to a “Business” under the CCPA by requesting that Hebbia attest to its compliance with this Section 6.2 of the DPA. Following any such request, Hebbia will promptly provide that attestation or notice about why it cannot provide it. If Customer reasonably believes that Hebbia is engaged in the processing of Processor Data that is not authorized under this DPA, Customer will immediately notify Hebbia of such belief, and the parties will work together in good faith to remediate the allegedly violative processing activities, if necessary."
This segment obligates Hebbia to permit Customer to audit CCPA compliance upon reasonable request by attesting to compliance with Section 6.2, requires Hebbia to provide attestation promptly or explain why it cannot, and obligates Customer to immediately notify Hebbia if it believes unauthorized processing is occurring.
AI-generated interpretation, not legal advice.
" Only personal data that is uploaded to Hebbia by the data controller (or its authorized users) for the purposes of large LLM inference will be processed."
This segment restricts the types of personal data processed by Reducto, Inc. to only what is uploaded by the data controller or authorized users for LLM inference purposes, limiting this subprocessor's data handling scope.
AI-generated interpretation, not legal advice.
" Large language model (LLM) capabilities; email and document management capabilities through Google Workspace Enterprise"
Specifies the processing purpose as LLM capabilities and email/document management through Google Workspace Enterprise, defining the authorized scope of subprocessor activity.
AI-generated interpretation, not legal advice.
" User submitted prompts and files and generated artifacts."
Defines the subject matter as 'User submitted prompts and files and generated artifacts,' scoping the specific personal data and content processed by Elasticsearch under the DPA.
AI-generated interpretation, not legal advice.
" Datadog does not process personal data."
This segment disclaims that Datadog does not process personal data, which is a substantive legal statement limiting the company's obligations under data processing and privacy regulations by asserting no personal data processing occurs.
AI-generated interpretation, not legal advice.
" Hebbia has deployed secure methods and protocols for transmission of confidential or sensitive information over public networks. Databases housing sensitive customer data are encrypted at rest. Hebbia uses only recommended secure cipher suites and protocols to encrypt all traffic in transit and Customer Data is securely encrypted with strong ciphers and configurations when at rest."
This segment imposes obligations on Hebbia to use secure transmission protocols, encrypt databases at rest using strong ciphers, and encrypt all data in transit, establishing specific technical security requirements for protecting customer data.
AI-generated interpretation, not legal advice.
" Used for embedding and re-ranking user data and system data."
This segment defines the nature and purpose of MongoDB's processing as embedding and re-ranking user data and system data, specifying the processing activity performed by this subprocessor.
AI-generated interpretation, not legal advice.
" privacy@hebbia.ai "
Provides the privacy contact email address (privacy@hebbia.ai) for the data protection contact at Hebbia Inc., establishing the communication channel for data protection inquiries.
AI-generated interpretation, not legal advice.
" Name, Username, Email, Job Title, Company device identifiers (e.g. serial number), and IP Address"
Enumerates specific categories of personal data processed (Name, Username, Email, Job Title, Company device identifiers, IP Address), defining the scope of personal data subject to processing obligations and restrictions.
AI-generated interpretation, not legal advice.
" LLM capabilities through their API in Hebbia’s application."
Defines the processing purpose as providing LLM capabilities through the subprocessor's API within Hebbia's application, establishing the permitted use of personal data by this subprocessor.
AI-generated interpretation, not legal advice.
" Contact person’s name, position and contact details: "
Introduces the contact person responsible for data protection at Hebbia Inc., as required by the DPA's identification obligations for the data importer.
AI-generated interpretation, not legal advice.
" Search and indexing functions within Hebbia’s application which enables efficient retrieval of data."
Defines the nature and purpose as search and indexing functions enabling efficient retrieval of data within Hebbia's application, characterizing and limiting the authorized processing activity for this subprocessor.
AI-generated interpretation, not legal advice.
" Encryption-at-rest is automated using AWS’s transparent disk encryption, which uses industry standard AES-256 encryption to secure all volume (disk) data. All keys are fully managed by AWS."
This segment establishes the obligation to use AWS automated AES-256 transparent disk encryption for all volume data at rest, with key management fully handled by AWS, ensuring protection of stored personal data.
AI-generated interpretation, not legal advice.
" Hebbia has a multi-tiered approach for ensuring data quality. These measures include: (i) unit testing to ensure quality of logic used to process API calls, (ii) database schema validation rules which execute against data before it is saved to our database. Hebbia applies these measures across the board, both to ensure the quality of any Usage Data that Hebbia collects and to ensure that the Hebbia Platform is operating within expected parameters. Hebbia ensures that data quality is maintained from the time a Customer sends Customer Data into the Services and until that Customer Data is presented or exported."
This segment imposes obligations on Hebbia to implement multi-tiered data quality measures including unit testing and database schema validation, and to maintain data quality from the time customer data enters the services until it is presented, ensuring accuracy and integrity of personal data processing.
AI-generated interpretation, not legal advice.
Clause detail — protections, your obligations, and coverage
Every clause below is a verbatim quote from Hebbia's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.
✅ Protections found
31 verified clausesClauses in Hebbia's policies that work in your favour — commitments the platform made to you.
- Audit rights, DPA & residency
“Role and Scope of Processing Roles of the Parties . The parties acknowledge and agree that for the purposes of this DPA Customer is the controller with respect to the processing of Processor Data, and Hebbia shall process Processor Data only as a processor on…”
This segment establishes the roles of the parties (Customer as controller, Hebbia as processor), imposes an obligation on Hebbia to process Processor Data only as instructed and only as described in Annex I, and requires…
📍 Privacy Policy › “Definitions”Jump to exact text → - Audit rights, DPA & residency
“" Personal Data " means information, which is protected as "personal data", "personally identifiable information" or "personal information" under any applicable Data Protection Laws. For the avoidance of doubt, with respect to US Data Protection Laws, “Persona…”
This segment defines 'Personal Data' and 'Processor Data,' specifying what information is protected under the DPA (including exclusions for de-identified and publicly available data) and scoping the data subject to Hebbi…
📍 Privacy Policy › “Definitions”Jump to exact text → - Subprocessors & data sharing
“Customer acknowledges that certain Sub-Processors are essential to providing the Services and that objecting to the use of a Sub-Processor may prevent Hebbia from offering the Services to Customer. If Customer reasonably objects to an engagement in accordance…”
This segment establishes the procedure and consequences where Customer objects to a Sub-Processor engagement: Hebbia must offer a commercially reasonable alternative, Customer may discontinue the affected Service if none…
📍 Privacy Policy › “Definitions”Jump to exact text → - Subprocessors & data sharingsale/sharing of personal data
“Additional Provisions for Processor Data that is Subject to the CCPA Scope and Role of Parties. This Clause 6 shall only apply with respect to Processor Data that is subject to the CCPA. When processing Processor Data subject to the CCPA under this DPA, the pa…”
This segment scopes Clause 6 to CCPA-subject Processor Data, defines the roles of Customer as Business and Hebbia as Service Provider under the CCPA, and incorporates CCPA-specific definitions (Business Purpose, Commerci…
📍 Annex IIJump to exact text → - Audit rights, DPA & residency
“Transfers of European Processor Data Scope and Role of the Parties. This Clause 5 shall only apply with respect to Processor Data subject to EU/UK Data Protection Law. Restricted Transfers. The parties agree that where and to the extent the transfer of Proces…”
This segment scopes Clause 5 to EU/UK Data Protection Law and imposes an obligation on the parties to apply Standard Contractual Clauses (EU SCCs) for Restricted Transfers of Processor Data from Customer (data exporter)…
📍 Privacy Policy › “Definitions”Jump to exact text → - Audit rights, DPA & residency
“Hebbia shall permit Customer or its appointed third party auditors to audit Hebbia's compliance with this DPA, and shall make available to Customer all relevant information, policies, procedures, records, and staff necessary for Customer or its third party aud…”
This segment grants Customer the right to audit Hebbia's DPA compliance (including through third-party auditors) and requires Hebbia to make available all relevant information and personnel, while limiting audit frequenc…
📍 Privacy Policy › “Audit”Jump to exact text →
+ 25 more verified clauses of this kind on this platform, cited in full in the report.
📋 Rules you must follow
0 verified clausesWhat Hebbia requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.
No user-conduct rule has been verified in Hebbia's published policies yet.
What the policies actually cover
4 topics- Product telemetry & usage tracking4 clauses
- Sale or sharing of personal data1 protective1 clause
- Deletion rights & post-termination survival4 protective5 clauses
- Breach-notification promises1 protective2 clauses
66 further verified clauses are cited on this page but not yet assigned a topic.
Cross-clause notes
Verified retention clauses point in different directions: the Privacy Policy, Privacy Policy › “Analyzing data, including product usage assessment” describes broad or open-ended retention, while the Privacy Policy, Privacy Policy › “Measures for ensuring data minimisation” describes deletion or erasure. Which clause controls in a given situation is not resolved by the documents' text alone — this is surfaced as an ambiguity, treated as Caution.
Automated cross-reference against the published rubric — not legal advice.
Clause intelligence
Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.
The clause imposes arbitration, class-action waiver, or jury-trial waiver terms.
“Please read these Terms of Service (the “Terms”) and our Privacy Policy (“Privacy Policy”) carefully because they govern your use of the Site and our artificial intelligence-powered productivity and research services accessible via the Site offered by us. To make these Terms easier to read, the Site, and our services are collectively called the “Services”. Important notice regarding arbitration for U.S. Customers...”Open source citation
The clause imposes arbitration, class-action waiver, or jury-trial waiver terms.
“Please read these Terms of Service (the “Terms”) and our Privacy Policy (“Privacy Policy”) carefully because they govern your use of the Site and our artificial intelligence-powered productivity and research services accessible via the Site offered by us. To make these Terms easier to read, the Site, and our services are collectively called the “Services”. Important notice regarding arbitration for U.S. Customers...”Open source citation
The clause imposes arbitration, class-action waiver, or jury-trial waiver terms.
“Please read these Terms of Service (the “Terms”) and our Privacy Policy (“Privacy Policy”) carefully because they govern your use of the Site and our artificial intelligence-powered productivity and research services accessible via the Site offered by us. To make these Terms easier to read, the Site, and our services are collectively called the “Services”. Important notice regarding arbitration for U.S. Customers...”Open source citation
The clause imposes arbitration, class-action waiver, or jury-trial waiver terms.
“Please read these Terms of Service (the “Terms”) and our Privacy Policy (“Privacy Policy”) carefully because they govern your use of the Site and our artificial intelligence-powered productivity and research services accessible via the Site offered by us. To make these Terms easier to read, the Site, and our services are collectively called the “Services”. Important notice regarding arbitration for U.S. Customers...”Open source citation
The clause permits sale of personal data or information.
“Additional Provisions for Processor Data that is Subject to the CCPA Scope and Role of Parties. This Clause 6 shall only apply with respect to Processor Data that is subject to the CCPA. When processing Processor Data subject to the CCPA under this DPA, the parties acknowledge and agree that Customer is a Business and Hebbia is a Service Provider for the purposes of the CCPA. For the purpose of this Clause 6, "Bus...”Open source citation
Tier matrix
Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.
| Tier | Surface | Verdict | Risk | Citations |
|---|---|---|---|---|
| All applicable tiers | governing law disputes | conditional | MEDIUM | 4 |
| All applicable tiers | privacy data use | conditional | MEDIUM | 5 |
| All applicable tiers | subprocessors data sharing | conditional | MEDIUM | 1 |
| Team / Business | commercial use | worsens | HIGH | 5 |
| Team / Business | privacy data use | worsens | HIGH | 1 |
Policy evolution
Open full timelineBefore/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.
data sharing improved from high/sale or sell to medium/third party or vendor sharing.
“Additional Provisions for Processor Data that is Subject to the CCPA Scope and Role of Parties. This Clause 6 shall only apply with respect to Processor Data that is subject to the CCPA. When processing Processor Data subject to the CCPA under this DPA, the parties acknowledge and agree that Customer is a Business and Hebbia is a Service Provider for the purposes of the CCPA. For the purpose of this Clause 6, "Business", "Business Purpose", "Commercial Purpose", "Consumer," "Personal Information", "Process," "Sell", "Service Provider", and "Share" have the meanings given to them in the CCPA. Responsibilities . Customer discloses or otherwise makes available Processor Data to Hebbia for the limited and specific purpose of Hebbia carrying out the Permitted Purposes. Hebbia shall: (i) comply with its applicable obligations under the CCPA; (ii) provide the same level of protection as required under the CCPA; (iii) notify Customer if it can no longer meet its obligations under the CCPA; (iv) not “sell” or “share” (as such terms are defined by the CCPA) Processor Data; (v) not retain, use, or disclose Processor Data for any purpose (including any commercial purpose) other than the Permitted Purpose or as otherwise permitted under the CCPA; (vi) not retain, use, or disclose Processor Data outside of the direct business relationship between Customer and Hebbia or as otherwise permitted under the CCPA; and (vii) unless otherwise permitted by the CCPA, not combine Processor Data with Personal Information that Hebbia: (a) receives from, or on behalf of, another person, or (b) collects from its own, independent consumer interaction.”Before citation
“Authorized Sub-Processors Customer acknowledges and agrees that Hebbia may (1) engage its Affiliates as well as the Authorized Sub-Processors on the List (defined below) to access and process Personal Data in connection with the Services and (2) from time to time engage additional third parties for the purpose of providing the Services, including without limitation the processing of Personal Data. By way of this DPA, Customer provides general written authorization to Hebbia to engage Sub-Processors as necessary to perform the Services. A list of Hebbia’s current Authorized Sub-Processors (the “List”) is available to Customer at https://trust.hebbia.ai/subprocessors . Such List may be updated by Hebbia from time to time. Hebbia will provide a mechanism to subscribe to notifications (which may include but are not limited to email notifications) of new Authorized Sub-Processors and Customer, if it wishes, will subscribe to such notifications where available. If Customer does not subscribe to such notifications, Customer waives any right it may have to receive prior notice of changes to Authorized Sub-Processors. At least ten (10) days before enabling any third party other than existing Authorized Sub-Processors to access or participate in the processing of Personal Data, Hebbia will add such third party to the List and notify subscribers, including Customer, via the aforementioned notifications. Customer may object to such an engagement by informing Hebbia in writing within ten (10) days of receipt of the aforementioned notice by Customer, provided such objection is in writing and based on reasonable grounds relating to data protection.”After citation
Latest stance: third party or vendor sharing on privacy data use
“Authorized Sub-Processors Customer acknowledges and agrees that Hebbia may (1) engage its Affiliates as well as the Authorized Sub-Processors on the List (defined below) to access and process Personal Data in connection with the Services and (2) from time to time engage additional third parties for the purpose of providing the Services, including without limitation the processing of Personal Data. By way of this DPA, Customer provides general written authorization to Hebbia to engage Sub-Processors as necessary to perform the Services. A list of Hebbia’s current Authorized Sub-Processors (the “List”) is available to Customer at https://trust.hebbia.ai/subprocessors . Such List may be updated by Hebbia from time to time. Hebbia will provide a mechanism to subscribe to notifications (which may include but are not limited to email notifications) of new Authorized Sub-Processors and Customer, if it wishes, will subscribe to such notifications where available. If Customer does not subscribe to such notifications, Customer waives any right it may have to receive prior notice of changes to Authorized Sub-Processors. At least ten (10) days before enabling any third party other than existing Authorized Sub-Processors to access or participate in the processing of Personal Data, Hebbia will add such third party to the List and notify subscribers, including Customer, via the aforementioned notifications. Customer may object to such an engagement by informing Hebbia in writing within ten (10) days of receipt of the aforementioned notice by Customer, provided such objection is in writing and based on reasonable grounds relating to data protection.”Open timeline citation
Latest stance: sale or sell on commercial use
“Additional Provisions for Processor Data that is Subject to the CCPA Scope and Role of Parties. This Clause 6 shall only apply with respect to Processor Data that is subject to the CCPA. When processing Processor Data subject to the CCPA under this DPA, the parties acknowledge and agree that Customer is a Business and Hebbia is a Service Provider for the purposes of the CCPA. For the purpose of this Clause 6, "Business", "Business Purpose", "Commercial Purpose", "Consumer," "Personal Information", "Process," "Sell", "Service Provider", and "Share" have the meanings given to them in the CCPA. Responsibilities . Customer discloses or otherwise makes available Processor Data to Hebbia for the limited and specific purpose of Hebbia carrying out the Permitted Purposes. Hebbia shall: (i) comply with its applicable obligations under the CCPA; (ii) provide the same level of protection as required under the CCPA; (iii) notify Customer if it can no longer meet its obligations under the CCPA; (iv) not “sell” or “share” (as such terms are defined by the CCPA) Processor Data; (v) not retain, use, or disclose Processor Data for any purpose (including any commercial purpose) other than the Permitted Purpose or as otherwise permitted under the CCPA; (vi) not retain, use, or disclose Processor Data outside of the direct business relationship between Customer and Hebbia or as otherwise permitted under the CCPA; and (vii) unless otherwise permitted by the CCPA, not combine Processor Data with Personal Information that Hebbia: (a) receives from, or on behalf of, another person, or (b) collects from its own, independent consumer interaction.”Open timeline citation
Latest stance: arbitration or waiver on governing law disputes
“Please read these Terms of Service (the “Terms”) and our Privacy Policy (“Privacy Policy”) carefully because they govern your use of the Site and our artificial intelligence-powered productivity and research services accessible via the Site offered by us. To make these Terms easier to read, the Site, and our services are collectively called the “Services”. Important notice regarding arbitration for U.S. Customers: when you agree to these terms you are agreeing (with limited exception) to resolve any dispute between you and hebbia through binding, individual arbitration rather than in court. Please review carefully section 16 “dispute resolution” below for details regarding arbitration.”Open timeline citation
Latest stance: third party or vendor sharing on privacy data use
“Authorized Sub-Processors Customer acknowledges and agrees that Hebbia may (1) engage its Affiliates as well as the Authorized Sub-Processors on the List (defined below) to access and process Personal Data in connection with the Services and (2) from time to time engage additional third parties for the purpose of providing the Services, including without limitation the processing of Personal Data. By way of this DPA, Customer provides general written authorization to Hebbia to engage Sub-Processors as necessary to perform the Services. A list of Hebbia’s current Authorized Sub-Processors (the “List”) is available to Customer at https://trust.hebbia.ai/subprocessors . Such List may be updated by Hebbia from time to time. Hebbia will provide a mechanism to subscribe to notifications (which may include but are not limited to email notifications) of new Authorized Sub-Processors and Customer, if it wishes, will subscribe to such notifications where available. If Customer does not subscribe to such notifications, Customer waives any right it may have to receive prior notice of changes to Authorized Sub-Processors. At least ten (10) days before enabling any third party other than existing Authorized Sub-Processors to access or participate in the processing of Personal Data, Hebbia will add such third party to the List and notify subscribers, including Customer, via the aforementioned notifications. Customer may object to such an engagement by informing Hebbia in writing within ten (10) days of receipt of the aforementioned notice by Customer, provided such objection is in writing and based on reasonable grounds relating to data protection.”Open timeline citation
Capture recency
- Privacy Policy:Last captured 2026-08-10· verified 2026-08-10
- Terms of Service:Last captured 2026-08-07· verified 2026-08-07
Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.
↑ 211 more findings this quarter vs last (311 vs 100). First scan: June 2026.
Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Hebbia's policies — no human edits the data.
Need this for procurement or legal diligence?
Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.
Every finding above is a verbatim quote from Hebbia's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.