Privacy Policy
Last updated: August 8, 2026
This Privacy Policy explains how GetHug collects, uses, stores, discloses, and protects personal data when you create an account, use Python or graph workflows, save or publish content, create a public creator profile, contact support, consent to optional analytics, or otherwise interact with GetHug (the “Service”). It also explains your choices and privacy rights.
Please read this Privacy Policy together with the Cookie / Storage Notice, which describes essential browser storage, the optional Google Analytics implementation, and how to give, refuse, or withdraw analytics consent.
1. Controller and contact information
For purposes of applicable data-protection law, the controller responsible for personal data processed through GetHug is:
Data Controller: Federico Cosenza
Italy
Privacy contact: privacy@get-hug.com
General contact: info@get-hug.com
Support contact: support@get-hug.com
Account holders may also contact us through the GetHug Support Center or at support@get-hug.com. General inquiries may be sent to info@get-hug.com. Privacy and data-protection requests should be sent to privacy@get-hug.com.
2. Scope and current Service
GetHug currently provides tools for uploading, creating, editing, running, saving, and sharing Python scripts; creating and saving scientific graph projects and graph recipes; editing graph datasets; publishing optional creator profiles; making selected scripts and graph recipes available through public links; and contacting GetHug through account-based support threads.
GetHug does not currently offer paid credits, paid subscriptions, AI-powered script generation, MATLAB-to-Python conversion, advertising, behavioral advertising, or marketing profiling. Workflow content is not sent to an artificial-intelligence provider for removed or unavailable AI features.
3. Personal data we collect
a. Account and authentication data
When you create or use an account, we may collect your email address, password in hashed form, country, verification status, account status, account identifiers, signup and login timestamps, and related account-administration information. Where an account is suspended or reactivated, we may also process the status-change time, a user-facing suspension reason, the administrator account responsible for the change, an audit history of account-status actions, review-request timestamps, request-delivery status, and related transactional-email records.
b. Optional creator-profile data
If you create a creator profile, we may collect the profile-visibility setting, profile URL slug, display name, headline, profession or title, institution or company, location, website, LinkedIn profile, GitHub profile, Google Scholar profile, ORCID profile, biography, skills or tags, experience, education, publications, projects, awards, and other information you voluntarily enter into profile fields.
When you make a profile public, the selected information becomes available to anyone who can access the profile page. Your GetHug account email is not displayed by default, but it may become public if you voluntarily place it in public profile text, a link, script, recipe, or another public field.
Do not publish sensitive personal data, private contact details, credentials, access tokens, confidential information, or information about another person unless you have a lawful basis and authority to do so.
c. Public scripts, public graph recipes, and public activity information
When you make a Python script or graph recipe public, we may publish information associated with the item, including its title, description, tags, code or recipe configuration, public URL or slug, creator attribution, publication or update time, and information needed to let other people view, run, save, reuse, or open it through GetHug.
GetHug may display activity information associated with public content or creators, such as saves, completed runs, reuse counts, publication counts, or ranking information. These values may be aggregated, estimated, delayed, deduplicated, corrected, reset, or removed. They are not used to make decisions that produce legal or similarly significant effects about you.
d. Private workflow, uploaded, and saved content
When you use GetHug, we may process Python scripts, uploaded scripts, input files, graph data, datasets, graph settings, plot specifications, graph projects, graph recipes, execution parameters, temporary session information, generated output files, run logs, filenames, and related content required to provide the requested workflow.
If you choose to save content, we may store saved scripts, uploaded scripts, saved graph projects, saved graph recipes, graph datasets, generated files, metadata, and other user-selected content so you can reopen, edit, run, download, share, or manage it later.
e. Support and correspondence data
When you contact support, we may collect your account identifier, account email, selected category, subject, message text, thread status, priority, timestamps, replies, and related administrative notes needed to respond, investigate bugs, consider feature or library requests, maintain support history, and send service emails about replies or thread activity.
Support messages are not public. Do not include passwords, private keys, authentication tokens, unnecessary sensitive personal data, or confidential third-party information in support requests.
Support correspondence may occur through account-based support threads or by email to support@get-hug.com. Replies sent directly by email are delivered to the monitored support mailbox but may not be automatically inserted into the support thread displayed in your GetHug account.
Messages sent to info@get-hug.com, privacy@get-hug.com, or support@get-hug.com are routed using Cloudflare Email Routing to a monitored Google-hosted operational mailbox. Transactional service emails are sent through Resend. These providers may process sender and recipient addresses, message headers and content, and delivery or security metadata as needed to route, deliver, protect, and troubleshoot email.
When a suspended user requests additional information or human review after entering the correct password, GetHug may record the request and send an internal notification to the support inbox through the configured transactional-email provider. The notification may contain the GetHug user ID, account email, account status, recorded suspension reason and timestamps needed to identify and review the decision. The account email may be configured as the reply address so GetHug can respond to the affected user.
f. Technical, operational, and security data
We may collect technical and operational information such as IP-address-related server logs, browser and device information, request timestamps, pages or endpoints accessed, authentication events, workflow and job metadata, execution status, error records, rate-limit events, download events, security events, and other diagnostic information needed to operate, protect, troubleshoot, and improve the Service.
g. Cookies and essential browser storage
We use an essential session cookie and limited localStorage or sessionStorage for authentication, request security, workflow continuity, graph-session resumption, interface state, and storage of your cookie preference. Details, names, purposes, and typical durations are provided in the Cookie / Storage Notice.
h. Optional Google Analytics data
Only after you grant analytics consent, GetHug loads Google Tag Manager container
GTM-WRTCTNLN, which loads the Google Analytics 4 measurement tag
G-ZXY6QZG7YG. The current implementation measures page loads only. Browser-history page
changes, scrolls, outbound clicks, site search, video engagement, file downloads, and form interactions
are disabled in Enhanced Measurement. Custom GetHug workflow events are not currently connected to
operation-success paths.
GetHug has disabled Google Signals, collection of user-provided data, granular location and device data, and advertising personalization in all available regions. GetHug has not configured Google Analytics User-ID and has not linked the property to Google Ads, Google AdSense, Google Ad Manager, Display & Video 360, Search Ads 360, or another advertising product.
GetHug's Google Analytics property is linked to the verified Google Search Console domain property for
get-hug.com for organic-search reporting. This connection may make Search Console information
such as search queries, impressions, clicks, and landing-page performance available in Google Analytics
reports. The connection does not add a separate tracking tag, cookie, browser-storage technology, or
advertising-product integration to GetHug.
Analytics data may include a pseudonymous browser identifier stored in first-party _ga
cookies, a session identifier, page path, page title, sanitized page URL, sanitized referrer, date and
time, session statistics, language, country- or region-level location, and general browser, operating
system, and device-category information. Because granular location and device collection is disabled,
Google Analytics is not configured to collect city, detailed browser user-agent strings, device brand,
device model, device name, minor browser or operating-system versions, platform minor version, or screen
resolution for new data.
Google states that IP addresses are used at collection time to determine the appropriate collection location and geographic information and are discarded before being logged in Google Analytics.
GetHug does not intentionally send names, email addresses, account identifiers, profile slugs, filenames,
uploaded files, scripts, source code, datasets, graph specifications, support-message content, URL query
strings, or URL fragments to Google Analytics. GetHug removes query strings and fragments from the page
URL and referrer configured for Analytics. Google Analytics email redaction and URL-query-parameter
redaction are also enabled as supplementary safeguards for the following parameter names:
email, email_address, first_name,
last_name, name, user_id, token,
access_token, api_key, key, code,
session, and session_id. Automated redaction is best-effort and does not replace
GetHug's obligation not to send personal data to Analytics.
4. Public visibility and search engines
Creator profiles, scripts, and graph recipes are private unless you use the relevant controls to make them public. Public content may be viewed without signing in, shared through its public URL, linked from other websites, copied or saved by other users, and indexed or cached by search engines, web archives, browsers, security services, or third parties outside GetHug's control.
For pages that you choose to make public, GetHug may also expose selected public information in page metadata and machine-readable structured data, including page titles, descriptions, canonical URLs, creator attribution, social-preview metadata, preview images, and JSON-LD. This information is derived from content or profile information that is already intentionally public and is used to help search engines, browsers, social platforms, and other services understand, index, or preview the public page. Private account and workflow content is not intended to be exposed through public SEO metadata.
Making an item private, deleting it, changing a profile slug, or deleting your account is intended to stop future availability through GetHug after the change is processed. While an account is suspended, GetHug also makes public creator profiles, scripts, and graph recipes owned by that account unavailable without deleting the underlying publication state solely because of the suspension. Reactivation is intended to restore their previous availability unless the content was separately made private, removed, or restricted. These changes may not immediately remove copies, screenshots, saved versions, search-engine caches, web archives, browser caches, or links held by other people or services.
5. How we use personal data
We may use personal data to:
- Create, verify, authenticate, secure, and administer accounts.
- Provide requested Python, graph, dataset-editing, saving, sharing, and download functionality.
- Create and display public creator profiles at the user's request.
- Publish and serve public scripts and graph recipes through shareable links.
- Calculate and display public-content activity counters and creator statistics.
- Save, reopen, edit, run, copy, download, and manage user-selected content.
- Create and maintain temporary workflow sessions and processing environments.
- Receive, investigate, respond to, and retain support requests and correspondence.
- Send account verification, password-reset, security, support-reply, and other essential service messages.
- Detect abuse, enforce limits, moderate public content, investigate incidents, administer account suspensions and reactivations, receive and document review requests, send internal review notifications, provide suspension explanations and human review, and protect users and the Service.
- Debug, maintain, and improve the reliability, accessibility, security, and usability of the Service.
- Measure aggregate site and page usage through Google Analytics only after consent.
- Comply with legal obligations and establish, exercise, or defend legal claims.
6. Lawful bases for processing
a. Contract and steps taken at your request
We process account, workflow, saved-content, public-sharing, creator-profile, and support information where necessary to provide the Service or take steps you request, including creating an account, running a workflow, saving content, publishing content, or responding to support.
b. Legitimate interests
We may process personal data where necessary for legitimate interests in operating, securing, troubleshooting, moderating, documenting, and improving GetHug; preventing fraud or abuse; maintaining service reliability; responding to support; measuring public-content activity using first-party operational records; and protecting legal rights, provided those interests are not overridden by your rights and freedoms.
c. Legal obligations
We may process or retain personal data where necessary to comply with applicable law, lawful requests, court orders, regulatory duties, content-removal duties, accounting obligations that may apply, or other legal requirements.
d. Consent
Optional Google Analytics processing is based on your consent where consent is required by applicable law. Analytics is disabled by default. You may refuse or withdraw consent without losing access to essential GetHug features and without affecting the lawfulness of processing that occurred before withdrawal. Advertising-storage, advertising-user-data, and advertising-personalization consent remain denied in the current implementation.
7. Cookie preference and consent records
GetHug stores a first-party localStorage entry named gh_consent_v1 to remember and document
your choice. It records the consent-format version, whether analytics is granted or denied, confirmation
that marketing remains denied, and the time the choice was updated. The preference is treated as an
essential storage item because it is needed to respect and demonstrate your choice.
The current consent interface makes rejection and acceptance directly available, provides detailed settings, and provides a persistent control to review the choice. A stored preference expires after approximately 180 days, may be replaced sooner when the consent format or processing materially changes, and may also disappear if you clear browser storage. When no valid preference is available, the banner is shown again.
8. Temporary workflow storage
GetHug may create temporary session folders, isolated or containerized execution environments, or other short-term storage containing scripts, uploaded files, graph data, datasets, processing instructions, intermediate files, output files, and technical records needed to perform requested workflows.
Temporary workflow storage is not permanent storage. It is subject to operational cleanup and may be deleted automatically after a limited period. Some technical records may be retained longer where reasonably necessary for security, abuse prevention, troubleshooting, incident investigation, service integrity, or legal compliance.
9. Saved and persistent content
Content you choose to save may remain available in your account until you delete it, your account is deleted, a documented retention or cleanup rule applies, the Service is changed or discontinued, or retention is required for legal, security, dispute, or backup-integrity reasons.
GetHug is not a guaranteed backup or archive. Keep independent copies of scripts, datasets, graphs, recipes, outputs, profile text, and other content you need to retain.
10. Retention
We keep personal data only for as long as reasonably necessary for the purposes described in this Policy, taking into account the nature and sensitivity of the data, processing purpose, security and fraud risks, user choices, account status, backup cycles, dispute needs, and legal requirements.
- Account data: generally retained while the account is active and for a reasonable period afterward where needed for security, recovery, compliance, or dispute handling.
- Temporary workflow data: retained for short-term processing and removed under operational cleanup rules, subject to limited security, troubleshooting, and legal exceptions.
- Saved private content: generally retained until you delete it, the account is deleted, or a retention or cleanup rule applies.
- Public profiles and public content: generally retained while published and afterward only as needed to process deletion, backups, abuse records, legal claims, or security obligations. Third-party caches and copies are outside our direct control.
- Support threads: retained while reasonably necessary to provide support, maintain conversation history, investigate recurring problems, protect rights, and comply with legal or security requirements.
- Security, moderation, account-status, and review-request records: suspension reasons, administrator attribution, status-change timestamps, audit history, review-request timestamps, notification-delivery records, and related operational records may be retained where reasonably necessary to review decisions, prevent repeated requests, detect misuse, investigate incidents, enforce the Terms, comply with law, or defend claims.
- Analytics consent preference: normally retained for approximately 180 days from the recorded update, unless changed, invalidated, or cleared earlier.
- Analytics cookies: Google documents a default expiration of up to two years for
_gaand_ga_<container-id>, subject to browser limits, renewal behavior, deletion, and withdrawal of consent. - Google Analytics user and event data: configured for two months. “Reset on new user activity” is disabled, so the retention period is not restarted by later activity. Google's retention control does not affect most standard reports based on aggregated data, which may remain available longer under Google's service rules.
11. Sharing and recipients
We do not sell personal data. We do not share personal data for cross-context behavioral advertising. We do not currently use advertising networks or payment processors in connection with the Service.
We may disclose personal data:
- To hosting, infrastructure, storage, backup, email-delivery, email-routing, mailbox, security, domain, content-delivery, and technical service providers acting on our behalf.
- To Google Ireland Limited, Google LLC, or other Google entities identified in applicable Google terms, only for optional Google Tag Manager and Google Analytics services after consent.
- To the public when you intentionally publish a creator profile, script, graph recipe, or other public content.
- To other users where a feature allows them to view, run, save, copy, or reuse public content.
- To professional advisers where reasonably necessary and subject to appropriate confidentiality duties.
- Where required by law, court order, regulatory request, or lawful governmental demand.
- Where reasonably necessary to enforce the Terms, investigate abuse, address illegal or infringing content, protect rights or safety, or respond to a security incident.
- In connection with a merger, acquisition, financing, reorganization, or sale of all or part of the Service, subject to applicable safeguards.
Google's own processing, security, subprocessor, retention, and transfer practices are governed by the applicable Google service terms and privacy documentation. GetHug has accepted the applicable Google data processing terms for the Analytics account, disabled the optional Analytics account data-sharing settings, and configured no advertising-product links. GetHug periodically reviews these settings.
12. International transfers
Personal data may be processed or stored outside the country where you are located, including countries where infrastructure, email, security, or analytics providers operate. Google Analytics data may be processed in the United States or other countries.
Where applicable law requires transfer safeguards, GetHug and its providers may rely on an adequacy decision, the EU-U.S. Data Privacy Framework where applicable to a certified recipient, standard contractual clauses, supplementary measures, or another legally permitted transfer mechanism. The availability and applicability of a particular mechanism may change and is reviewed as appropriate.
13. Security
We use technical and organizational measures designed to protect personal data, including account authentication, password hashing, transport encryption, request-validation controls, access restrictions, security logging, infrastructure hardening, consent gating for optional analytics, and other measures appropriate to the nature of the Service. No internet-based service, execution environment, transmission method, or storage system can guarantee absolute security.
You are responsible for protecting credentials, reviewing content before making it public, removing secrets from scripts and files, and promptly reporting suspected unauthorized access.
14. Your privacy rights
Depending on applicable law, you may have rights to request access, correction, deletion, restriction, objection, portability, withdrawal of consent, and information about processing. You may also have the right to lodge a complaint with a competent supervisory authority.
Users in the European Economic Area may lodge a complaint with their local data-protection authority. In Italy, the competent authority is the Garante per la protezione dei dati personali.
To exercise a right, contact privacy@get-hug.com. We may need to verify your identity and clarify the request. Rights are subject to applicable conditions, exceptions, and retention obligations.
15. California and other U.S. state privacy disclosures
If a U.S. state privacy law applies to GetHug and your information, you may have rights to know or access, correct, delete, obtain a portable copy of certain personal information, opt out of certain processing, and receive equal service when exercising applicable rights.
Categories described in this Policy may include identifiers; account and authentication information; internet or electronic-network activity; professional or education-related information voluntarily placed in a creator profile; user-submitted content; support correspondence; country- or region-level location and general browser or device-category information associated with consented analytics; and limited operational or engagement inferences.
GetHug does not sell personal information and does not share personal information for cross-context behavioral advertising or targeted advertising. GetHug does not currently use sensitive personal information to infer characteristics, and it does not offer a financial incentive in exchange for personal information. Because GetHug does not engage in those sale, sharing, or targeted-advertising practices, Global Privacy Control does not currently trigger a separate advertising opt-out, although analytics consent can always be refused or withdrawn.
16. Automated decision-making
GetHug may automatically apply rate limits, security checks, workflow validation, public-content counters, and creator-ranking calculations. Administrator-controlled account suspension and reactivation decisions are not made solely by the automated login or session-enforcement code. GetHug does not currently use solely automated processing to make decisions about individuals that produce legal or similarly significant effects.
17. Children
GetHug is not directed to children under 16. We do not knowingly collect personal data from a child in violation of applicable law. A person who has not reached the age required to enter the Terms in their jurisdiction may use the Service only with the involvement and authorization of a parent or legal guardian. Contact us if you believe a child has provided personal data unlawfully.
18. Changes to this Privacy Policy
We may update this Policy to reflect changes in the Service, public-sharing features, processing practices, analytics configuration, providers, security measures, or legal obligations. We will update the “Last updated” date and provide additional notice or request renewed consent where required.
19. Contact
Questions, complaints, and privacy-rights requests may be directed to:
Data Controller: Federico Cosenza
Italy
Privacy: privacy@get-hug.com
General inquiries: info@get-hug.com
Support: support@get-hug.com