HuggingChat — privacy & data policy

Provider: Hugging Face. PromptPrivacy score: 83/100. Last verified August 26, 2026.

What happens to your data?

Hugging Face routes your chat requests to third-party inference providers over encrypted TLS/SSL connections without saving request or response bodies. Hugging Face does not use your data to train models. Your conversation history is retained in your account for convenience until you choose to delete it via the UI.

Does it train on your data?

Hugging Face does not store any user data or prompt inputs for model training purposes.

Can you opt out?

Hugging Face does not use user data for model training, so an opt-out for training is unnecessary. Users can delete individual chats at any time in the UI and can email Hugging Face to exercise additional legal privacy rights.

Data retention

Conversation history is stored so users can access past chats and remains until deleted by the user from the interface. Hugging Face does not store request or response bodies when routing requests. Debug logs are kept for up to 30 days and do not contain user data or tokens.

Encryption & security

Data in transit is encrypted using TLS/SSL when routed through Inference Providers. In addition, Hugging Face Hub is SOC 2 Type 2 certified. Encryption at rest is not specifically detailed.

Is it safe for work?

HuggingChat offers strong default privacy protections for general use because Hugging Face does not train on inputs or store request bodies during routing. However, organizations should note that inference is handled by third-party model providers with independent privacy terms, and no dedicated enterprise DPA or administrative controls are specified.

Source policy: https://raw.githubusercontent.com/huggingface/chat-ui/main/PRIVACY.md