Privacy Policy
HUG Project AI ("the Service") is a reference tool for professionals working in child protection in Thailand: police officers, prosecutors, social workers, medical staff and partner organisations. It answers questions from approved guidelines and nothing else. The Service is provided by the HUG Project ("HUG", "we") and operated on HUG's behalf by Movaci Co., Ltd. ("Movaci"), which acts as HUG's data processor. This policy explains what personal data the Service handles, why, and the rights available to you under Thailand's Personal Data Protection Act B.E. 2562 (PDPA).
1. Data we process
- Account data: username, full name, email address, phone number, job title and the agency or organisation you work for. Accounts are created by administrators; there is no public registration.
- Security data: a password hash (never the password itself), a short-lived token hash while a password-reset or activation link is outstanding, and, if you enable it, a two-factor authentication secret and hashed backup codes.
- Usage data: the questions you ask, the language and guideline used, whether the answer came from the cache, your rating of an answer (helpful / not helpful), and any problem report you submit.
- Technical data: for each sign-in, the IP address, country and (where available) city, browser and version, operating system, device class, screen size, time zone and language of the browser, together with a record of sign-in successes and failures. This is used for security, abuse control and support.
Please do not enter personal data about children, victims, suspects or cases into the question box. The Service is designed to be asked about procedures and guidance, not about individual cases. Questions are stored as usage data and are sent to the AI provider described in section 3.
2. Why we process it
To provide the Service to authorised professionals (performance of the arrangement under which you were given access), to protect the Service and its users from misuse (legitimate interest), to improve the guidance offered by reviewing which questions are asked and how answers are rated (legitimate interest), and to meet legal obligations where they apply.
3. AI processing
Answers are generated by sending your question, together with the text of the selected guideline, to the Anthropic API (Anthropic PBC, United States), which acts as a processor. Under Anthropic's API terms, data sent to the API is not used to train its models and is retained by Anthropic only for a limited period for abuse monitoring. No other AI or search service is used, and the model is instructed to answer only from the guideline text; it has no access to the internet or to any other data.
4. Where the data lives and who sees it
The Service runs on infrastructure operated by Movaci in Thailand, behind Cloudflare, Inc., which provides network security and may process IP addresses and connection metadata in transit. Account and usage data are visible to HUG administrators for the purposes above. Aggregated statistics (numbers of questions by day, language, agency and guideline) may be shared with HUG's partners and funders without identifying individuals. We do not sell personal data and do not share it with anyone else except the processors named here or where the law requires.
5. Retention
Account data is kept while your account is active and deleted when an administrator removes the account. Question and sign-in records are kept for one year for security review and service improvement, then removed automatically. Cached answers are kept for up to a year and are visible only to the person who asked, except answers to the published example questions. Raw model output kept for diagnostics is removed after 30 days. Problem reports are kept until resolved plus one year.
6. Your rights
Under the PDPA you may request access to your personal data, correction of inaccurate data, deletion where the law permits, restriction or objection to processing, and a copy of your data in a portable form. You can view and correct your own name, contact details and agency from your profile page. For anything else, contact HUG at the address below; we answer within 30 days. You may also lodge a complaint with the Personal Data Protection Committee of Thailand.
7. Security
Configuration and credentials are stored outside the web root; passwords are hashed with bcrypt; password recovery uses single-use links sent by email; sessions are cookie-based, encrypted in transit and expire after eight hours of inactivity; two-factor authentication is available and can be required by an administrator; sign-in, password recovery and administrative actions are rate-limited; administrators must re-enter their password for destructive actions; and no third-party scripts or assets are loaded except, when enabled, Cloudflare's bot check on the sign-in page. Report security concerns to [email protected].
8. Changes and contact
We will post updates to this policy here with a revised date. Data protection contact: HUG Project, Chiang Mai, Thailand · [email protected]. Technical operator: Movaci Co., Ltd., Chiang Mai, Thailand · [email protected].

