Hippocampus Back to sign in

Privacy notice

Version 1.1 · effective 2026-09-16

1. Who is responsible

Thalius AI AB (organisation number 559528-5635, VAT SE559528563501), Stockholm, Sweden, is the controller for the personal data described in this notice.

Privacy contact: [email protected]. We answer privacy requests within one month.

This notice covers:

  • visitors to this site;
  • people who sign up for or use the Hippocampus cloud service;
  • people who join the beta notification list or send the Corporate form;
  • partners in our referral programme.

It does not cover the documents customers upload to the Service. For those, the customer is the controller and we are its processor under the data processing agreement.

2. What we collect and why

Who Data Purpose Legal basis (GDPR Art. 6)
Every site visitor Page, day, campaign tags (UTM source and campaign), referral link, and a salted one-way hash of the IP address Count visits and sign-ups by page and campaign, and brake abuse, without identifying anyone Legitimate interest
Site visitors who allow analytics or marketing Analytics events and identifiers set by the tools in section 3; the first-touch cookie Understand which pages and campaigns lead to sign-ups Consent
People who join the beta notification list Email; name and company if the form asks; the words you agreed to and when; where you first came from (campaign tags, referral link, referrer site, entry page) Email you when the beta opens Consent
People who send the Corporate form Work email, organisation, company size, message, where you first came from Answer and follow up Legitimate interest; steps before a contract
People who create an account from this site Email and the campaign tag of the sign-up, passed to the application Create the account; count sign-ups by source Contract; legitimate interest
Account holders Name, email, organisation, sign-in events, plan, credit usage Provide and bill the Service, prevent abuse Contract
Users of the Service Questions asked and answers given, with the signed-in user attached Conversation history, support, security audit Contract; legitimate interest (security)
Paying customers Billing contact, invoices, payment records Billing and accounting Contract; legal obligation
Referral partners Name, email, referral link, sign-ups attributed to the link, partner portal account Run the referral programme Contract

We do not collect special categories of personal data on purpose, and we do not sell personal data.

Do you have to give us data? No. Without an email address we cannot create an account, add you to the beta list or answer the Corporate form. Declining cookies does not limit the site.

Where data comes from. Most data comes from you. The campaign tag of a sign-up is passed from this site to the application, and the source of a referral comes from the link you followed.

3. Cookies and similar technologies

Without your consent, this site sets no cookies. If Cloudflare Web Analytics is switched on, it measures page loads without cookies and without identifying you (legitimate interest). The site also keeps three things in your browser’s own storage:

  • your consent choice (local storage);
  • your light or dark theme (local storage);
  • where this visit came from, so that a form you send during the same visit carries it (session storage, cleared when you close the tab).

With your consent, given in the banner and changeable at any time from “Cookie settings” in the footer, we may use the tools below. The banner appears only while at least one of them is switched on.

Tool Category What it does
th_ft first-party cookie Analytics or marketing Remembers for 90 days the campaign or referral link that first brought you here, so a later sign-up can be attributed to it. It holds no name or email and is removed when you withdraw consent.
PostHog (EU cloud) Analytics Page views, events, the path from visit to sign-up, and heatmaps where enabled. Before consent it runs in memory only, with no cookie.
Google Analytics 4 Analytics Visit and campaign measurement with IP anonymisation and Google Consent Mode. Loads only after consent.
Google Tag Manager Analytics or marketing Loads measurement or advertising tags only for the categories you allowed, with Google Consent Mode.

4. Who receives data

  • Service providers that process data for us under data processing agreements:
    • Cloudflare, which delivers this site and the application;
    • our hosting for this site and its content system;
    • the analytics tools in section 3;
    • the providers listed on the sub-processors page for the Service itself;
    • the payment provider named at checkout.
  • Authorities, when the law requires it.
  • A buyer or successor, if the business is transferred, under the same protections.

Referral partners see only counts of sign-ups attributed to their link, never who signed up.

5. Transfers outside the EU/EEA

Documents and the knowledge structure of the Service are stored in the EU (Finland). Some providers, including Google, Cloudflare and the AI model providers used by default, are based in the United States. Transfers rely on the EU–US Data Privacy Framework where the provider is certified, and otherwise on Standard Contractual Clauses with a transfer risk assessment. Corporate customers can choose EU-hosted or customer-hosted inference. You can ask us for a copy of the safeguards.

6. How long we keep data

Data Retention
Visit counts with hashed IP 26 months
Analytics tool data 26 months, or the tool’s shorter setting
th_ft cookie 90 days in your browser
Beta notification list Until the beta opens and we have told you, or until you withdraw consent, whichever comes first
Corporate enquiries 2 years from the last contact
Account data and conversation logs While the account exists; deleted within 30 days of account deletion, and from backups within 90 days
Invoices and payment records 7 years (Swedish Bookkeeping Act)
Referral partner data While the partnership lasts, plus 3 years

After that, data is deleted or anonymised.

7. Security

Data is encrypted in transit and at rest. Documents in the Service are encrypted with per-document keys bound to the tenant. Access to personal data is limited to the people who need it, and security-relevant operations are logged. Details are on the security page.

If a breach is likely to put your rights at risk, we notify the Swedish Authority for Privacy Protection (IMY) within 72 hours and tell you without undue delay.

8. Your rights

You have the right to:

  • access your personal data and get a copy;
  • have it corrected;
  • have it erased;
  • restrict its processing;
  • receive it in a portable format;
  • object to processing based on legitimate interest, and to direct marketing at any time;
  • withdraw consent at any time, without affecting processing before the withdrawal.

Write to [email protected]. We do not charge unless a request is manifestly unfounded or excessive. If your data sits in a customer’s tenant, we forward your request to that customer.

You can also complain to the Swedish Authority for Privacy Protection (IMY), Box 8114, 104 20 Stockholm, [email protected], www.imy.se, or to the authority where you live or work.

9. Automated decisions

We make no decisions with legal or similarly significant effects on you based solely on automated processing. The AI features of the Service are described in the AI Act disclosure.

10. Children

The site and the Service are for professional use and are not directed at children under 16.

11. Changes

When we change this notice, we update the version and effective date above. Material changes are announced on this site at least 30 days before they apply and, for account holders, by email.