Hypar
hypar.ioHypar presents significant risks for professional use due to incomplete privacy documentation, vague data handling practices, and lack of enterprise-grade controls. The privacy policy is incomplete, missing critical sections on data retention, third-party sharing, and compliance frameworks. The terms grant Hypar broad rights to user content and authorize human review of private materials without clear limitations.
AI Transparency Facts
Independent analysis by TermsWatchdog · © 2026 TermsWatchdog
Input Data Ownership
Users retain ownership of their content, but grant Hypar broad usage rights including storage, parsing, display, and sharing with other authorized users. The license grants are extensive for service provision.
Output Data Ownership
Users can obtain ownership of results by downloading them, but Hypar retains broad management rights over aggregations and results including indefinite storage. The ownership model is complex and potentially confusing.
Training Data Usage
Hypar personnel may use private materials to create aggregations and results for maintaining and improving services, but the policy lacks clear boundaries on AI model training or machine learning uses.
Data Retention & Deletion
Hypar will delete user material within 90 days of account cancellation, but retains broad rights to store aggregations and results indefinitely. Users must request data copies within 90 days of termination.
Third-Party Data Sharing
The privacy policy appears incomplete and cuts off mid-sentence when describing data sharing practices. This creates significant uncertainty about third-party data sharing arrangements and controls.
Opt-Out Rights
Users can access, update, alter, or delete basic user information by contacting support. The policy mentions control over information collection but lacks specific opt-out mechanisms for different data uses.
Compliance & Certifications
No compliance frameworks or security certifications are mentioned. The policy references GDPR and CCPA but doesn't claim compliance or provide evidence of certifications like SOC 2, ISO 27001, or others.
Model Explainability & Auditability
No information provided about model transparency, explainability features, or enterprise auditing capabilities for AI-generated content or recommendations.
Security Practices & Breach History
Minimal security information provided. Only mentions maintaining security logs and basic account security obligations for users. No details on encryption, access controls, or incident response procedures.
Enterprise vs. Consumer Risk Delta
The service offers both free and paid tiers with different capabilities, but the data handling practices appear to be the same across tiers. No enterprise-specific privacy or security features are described.
Human Review of User Inputs
Hypar explicitly reserves broad rights for personnel to access and review private materials for service maintenance and improvement, with limited safeguards or restrictions on this access.
Regulatory & Litigation Exposure
Hypar reserves rights to cooperate with law enforcement and disclose user information when legally required. Users must waive claims against Hypar for law enforcement cooperation actions.
PII & SPI Data Inventory
Hypar collects standard user information including name, email, address, and payment data. Technical data includes IP addresses and usage logs. The policy states they don't intentionally collect sensitive data but acknowledges users may store it.
You've read all 15 risk ratings for Hypar. Create a free account to see the exact policy wording behind each rating.