Privacy Policy
Last updated: 19 July 2026
Draft, pending full legal review. This describes HugFlight honestly as it exists today. A few sections will be refined as the product and its policies mature.
This policy describes how HugFlight (operated by Ripe Solutions) collects, uses, and protects your personal information, in line with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles.
1. What we collect
Account info — email address; if you sign in with Google, your Google account identifier and profile photo URL.
Profile info — your first name, and your locality (city/region level only — never a precise address or coordinates).
Hug content— the text you write when sending a Hug, its cargo type (e.g. “Hope & Encouragement”), and whether you chose to show your first name to the recipient.
Usage/analytics events — e.g. that an account was created or a Hug was sent. These never include message text, names, or email addresses.
Technical data — your IP address is used for anonymous rate-limiting on public pages (to prevent abuse), not stored against your identity.
We do not collect precise location data at any point — only the generalised locality you or a recipient chooses from a curated list.
2. How we use it
To operate the core experience (accounts, sending/receiving Hugs, the map), to moderate content before it's delivered or shown publicly, to send transactional emails (e.g. “someone sent you a Hug”) via Amazon SES, and to keep the platform safe — rate-limiting abuse, investigating reports, enforcing suspensions.
We do not sell your personal information, and we do not use it for third-party advertising.
3. Who we share it with
Anthropic (Claude API) — the text of every Hug you send is sent to Anthropic for automated moderation screening before the Hug is delivered or shown publicly.
Amazon Web Services — hosts our database and servers (Sydney, Australia region), and sends transactional email (Amazon SES).
Google — if you choose to sign in with Google, Google authenticates you; we only receive your email, name, and profile photo URL from that sign-in.
Sentry — error-tracking for our engineering team, with message text, names, emails, and other personal content scrubbed before any error report is sent.
We never publish a recipient's identity on the public map. A destination Hug's message text becomes public (after passing moderation); a person Hug's message never does.
4. How long we keep it
We retain your account and Hug data for as long as your account remains active. We're finalising specific retention periods for abandoned drafts, unclaimed invitations, and closed accounts, and will update this policy once those are set.
5. Your rights
You can update your profile information directly from your account settings at any time. For access, correction, or deletion requests beyond what's available there, contact us using the details below. Under Australian privacy law you generally have the right to access and correct your personal information, and to lodge a complaint with the Office of the Australian Information Commissioner (OAIC) if you believe we've mishandled it.
6. Children's privacy
HugFlight does not currently verify a user's age at registration. If you believe a child has provided us with personal information, please contact us and we will take appropriate action.
7. Security
We use industry-standard practices to protect your data — encrypted connections (TLS), rate limiting on public endpoints, and role-based access controls for anyone administering the platform. No online service can guarantee perfect security.
8. Changes to this policy
We may update this policy from time to time; the date at the top of this page reflects the most recent change.
9. Contact
Questions about this policy, or a privacy request? Contact Ripe Solutions at rob@ripesolutions.com.au.