You press send
Your message travels to HaloChat over TLS 1.3 with a hybrid post-quantum key exchange — X25519 + ML-KEM-768 — combining classical and post-quantum protection.
Halo
HALOCHAT / TECHNICALSThe boring stuff, explained plainly.
No hand-waving. This is the request path, with boundaries at every step — and why a genuinely private AI service costs more and can feel less instant than the free alternatives.
The request path
Your message travels to HaloChat over TLS 1.3 with a hybrid post-quantum key exchange — X25519 + ML-KEM-768 — combining classical and post-quantum protection.
The email address you supply (personal or otherwise) is simply an access credential: it authenticates your access, helps measure your usage, and supports service delivery. HaloChat does not need a personal profile or your personal details to answer your question.
Your request is checked and sent through the service’s protected processing path. Only the context needed to answer is sent to an eligible AI model or search provider.
No AI model can read an encrypted message. Thus, your message needs to be decrypted briefly inside the processing boundary so the request can be understood and an answer can be produced.
The response travels back over an encrypted connection. Halo does not keep a persistent server-side archive of your prompts or answers.
Where browser storage is supported on your device, history remains encrypted there; otherwise, it lasts only for the session.
The privacy boundary
Conversations on HaloChat are never used to train models.
Halo does not build a training collection from ordinary customer conversations.
Halo does not keep a persistent server-side archive of your prompts or answers. Where browser storage is supported, history stays encrypted on your device; otherwise, it lasts only for the session.
The email address you supply (personal or otherwise) is simply an access credential: it authenticates your access, helps measure your usage, and supports service delivery. You are the customer, not the product.
Encryption protects your message while it travels.
No AI model can read an encrypted message. It must be decrypted briefly for processing, then the answer is encrypted again on its way back.
“Not stored by Halo” is not the same as “never processed.” Ask any AI service how it handles processing, retention, and training before sending sensitive material.
Some frontier providers say they “cannot rule out that de-identified data derived from usage of our products helped improve our models.” That is not an admission that anyone read a particular user’s work. It is a reminder that de-identified does not mean commercially irrelevant.
Removing your name or account details does not remove the value of your code, research, strategy, or business knowledge. It may still be retained, reviewed, or used to improve a model, depending on the provider’s settings and terms.
Why privacy is not cheap
Privacy means paying for the less convenient choices: encrypted transmission, protected processing, device-held history, limited account information, and a service that does not keep your conversations around to make the next answer easier to generate.
That can affect turnaround time and memory. If HaloChat does not keep a server-side conversation archive, a thread may need to be sent again from your encrypted device history. Preparing and securely processing that context can take longer, and longer conversations can require more work.
| Privacy question | Common provider pattern | HaloChat approach |
|---|---|---|
| Model improvement | Some services offer an opt-out for new chats, subject to their terms and exceptions. | Halo does not build a training collection from ordinary customer conversations. |
| De-identification | Names or account details may be removed before retained data is reviewed or used for model improvement. | Halo’s promise is more direct: ordinary customer conversations are not used to build a Halo training collection. |
| Chat history | Training controls may be separate from account history, temporary retention, or review processes. | No persistent Halo server-side archive; history stays encrypted on your device when supported, or is session-only otherwise. |
| Settings | Controls vary by product, account type, region, and settings path. | HaloChat’s privacy boundary does not depend on finding and enabling a customer-side training toggle. |
| Processing | Encrypted messages still need to be decrypted briefly for a model to produce an answer. | Same technical reality: requests are processed briefly, then the answer is encrypted on its way back. |
Read the exact provider policy before sending sensitive material. “Paid” alone is not a privacy guarantee.
HaloChat is not designed to be the cheapest or fastest option for every request, and it does not pretend to be.
Two products, two boundaries
HaloChat is designed for consumer questions and personal work. The minimum context needed for a live request may be sent to an eligible AI model or search provider, and the request is processed briefly.
HaloBusiness is being designed for customers whose proprietary work should not enter a frontier lab’s shared model-improvement ecosystem. Its planned per-customer Guard and Primary environment keeps the request path inside the customer boundary after handoff.
See the HaloBusiness boundaryThe short version
No Halo training collection built from customer conversations. No persistent Halo prompt/completion archive. Your email is used for account authentication and service delivery. You are the customer, not the inventory.
That a request is never decrypted for processing, that privacy is free (or easy), or that device-held history gives you instant server-side memory. Privacy can mean more deliberate processing and more turnaround time.
Still have questions?
Ask our limited service guide about HaloChat’s privacy boundary, processing, and availability.