Effective Date: December 28, 2025
Last Updated: December 28, 2025
Overview
hAI Bash ("we," "us," "our," or "Company") operates the hAI Bash Chrome extension (the "Extension"). This Privacy Policy explains how the Extension collects, uses, discloses, and safeguards your information when you use our browser extension.
The Extension is committed to protecting your privacy and ensuring you have a positive experience with our product.
1. Information We Collect
1.1 Voice and Text Input
When you interact with the Extension, we collect:
- Voice recordings that you provide through the microphone feature
- Text input that you type into the Extension interface
- Chat messages and prompts you submit for AI processing
These inputs are collected only when you explicitly provide them.
1.2 Page Context Data
To provide personalized assistance and partner site detection, we collect:
- Active tab URL and domain - to identify which website you're visiting
- Page metadata - limited information about the current webpage structure
1.3 Data NOT Collected
The Extension does NOT collect:
- Your browsing history (except the current active tab)
- Personally identifiable information unless you voluntarily provide it
- Cookies or tracking identifiers
- Local storage data from visited websites
2. How We Use Your Information
2.1 Health Data Processing
Health-related information and medical contexts are processed with enhanced security:
- Voice input and text related to health matters are routed exclusively to AWS Bedrock running in ca-central-1 (Canada central region)
- Processing occurs within Canadian jurisdiction to comply with PIPEDA requirements
- Data is processed using encrypted connections
2.2 Non-Health Transcription
Transcription of non-health voice input may use Cloudflare Workers AI (Whisper) for voice-to-text conversion.
3. Data Retention and Deletion
- Health data input: Deleted immediately after processing completes
- AWS Bedrock: Data purged within 24 hours of processing
- Cloudflare Workers: Data purged within 1 hour (non-health data only)
- Local storage: Cleared when browser closes or manually cleared
4. Third-Party Services
AWS Bedrock
- Purpose: Health data AI processing
- Location: Canada Central Region (ca-central-1)
- Compliance: PIPEDA-compliant service provider
Cloudflare Workers AI
- Purpose: Non-health voice-to-text transcription only
- Note: Health-related audio never uses this service
5. PIPEDA Compliance
hAI Bash implements all 10 principles of PIPEDA:
- Accountability: Clear data handling procedures
- Identifying Purposes: Disclosed in this policy
- Consent: Your use constitutes consent as described
- Limiting Collection: Only necessary information collected
- Limiting Use: Data used only for stated purposes
- Accuracy: Accurate records maintained
- Safeguards: Encryption and secure protocols
- Openness: Full transparency in this policy
- Individual Access: Right to access your data
- Challenging Compliance: Contact us with concerns
6. Your Rights
- Right to Access: Request access to your personal information
- Right to Correction: Request correction of inaccurate information
- Right to Deletion: Request deletion of personal information
- Right to Withdraw Consent: Disable or uninstall the Extension at any time
7. Extension Permissions
The Extension requires these Chrome permissions:
- activeTab, tabs: Identify current website for partner site detection
- storage: Store chat history and preferences locally
- scripting: Interact with webpages for automation
- sidePanel: Display the chat interface
- tabCapture: Enable voice input recording
8. Contact Information
For questions about this Privacy Policy or to exercise your rights:
Email: privacy@haibash.com
Privacy Commissioner of Canada:
Website: https://www.priv.gc.ca/
Phone: 1-800-282-1376
← Back to hAI Bash