NEWS
Verax AI Risk Assessment is live. See what's exposed
HuggingChat
HuggingChat
 
Risk Overview
Minimal Risk
3.3
/10
Text Generation
·
Conversational AI
·
Knowledge Assistant
·
Top Risks

Third-party inference providers may have different data handling standards not fully disclosed to users. Lack of explicit ZDR or post-deletion retention period. CLOUD Act exposure for US-stored data.

Mitigations

Strong explicit no-training policy for conversations. SOC 2 Type II certification. User-controlled conversation deletion. GDPR-compliant DPA available. Contact privacy@huggingface.co for rights requests.

Get started
Is your team using 
HuggingChat
 
safely?

Highest Risk Categories

The highest-scoring risk categories identified in this assessment.

3rd-Party Sharing

Data is not shared with model authors per HuggingChat policy. However, inference is routed through external Inference Providers (e.g., AWS, Azure-hosted models) who have their own data handling policies. Hugging Face itself is SOC 2 Type II certified and does not sell data. Standard provider sharing with contractual controls.
4
/10

Data Retention

Users can delete any conversation at any time from the UI. Conversation history is stored to allow access to past chats. No explicit ZDR policy stated. Deletion requests can be made via privacy@huggingface.co. Post-deletion retention period not explicitly specified in public docs.
4
/10

Legal Terms

Hugging Face is a French-American company (Delaware incorporated). Terms are relatively user-friendly. No prominent mandatory arbitration clause found in public terms. Disputes governed under Delaware law. No strong evidence of class action waiver. Liability cap is standard.
4
/10

Unlock the complete assessment

Run a free assessment to access the full AI tool risk analysis.
Start Free Assessment
Updated July 2026 • AI-assisted research • Reviewed by Verax • Report an issue

Reference Documentation

Official documentation and policies referenced as part of this assessment.