Privacy Policy
Last updated: August 14, 2026
1. Who we are
Hy3 operates hy3.app ("Hy3", "we", "us"). Hy3 is a free AI chat website with no accounts, no payments and no user database.
Questions about this policy: support@hy3.app.
This policy describes what actually happens when you use the chat, including the parts that are outside our control.
2. What happens to a message you send
When you press Send, your message and the recent messages in the same conversation are posted to an endpoint on hy3.app running on Cloudflare Workers. For ordinary requests that require a model-generated answer, our server adds our API credential and forwards the conversation to our AI provider, SiliconFlow (siliconflow.cn), which runs the model that produces the answer and streams it back to your browser. A small number of questions about the service's identity receive a fixed answer directly from hy3.app's server; those requests are not sent to SiliconFlow or another third-party AI provider, but each still counts as one chat toward your allowance.
For requests sent to SiliconFlow, your messages and the generated answers are processed on infrastructure in mainland China, where SiliconFlow operates, regardless of where you are. If that is not acceptable to you, please do not use the chat.
SiliconFlow also applies automated content safety review to what passes through its API. A message can be refused by that review; when that happens we show a neutral notice and do not record the reason or the text.
3. What this site does not keep
Hy3's application code does not intentionally persist your prompts, the model's answers, or the model's intermediate reasoning in its application database or Durable Objects. They pass through request memory and remain in your browser tab while it is open. Refreshing the page or pressing "Clear chat" removes the browser copy. Production logging must exclude message content; if that cannot be verified, chat stays disabled.
For requests sent to SiliconFlow, this statement covers our code only. It is not an end-to-end claim: SiliconFlow processes the same text under its own policy, described in the next section, and we cannot and do not promise anything on its behalf.
4. Our AI provider
Model-generated answers on Hy3 are produced by the model deepseek-ai/DeepSeek-R1-0528-Qwen3-8B via SiliconFlow's API. A small number of questions about the service's identity instead receive a fixed answer directly from hy3.app's server; those requests are not sent to SiliconFlow or another third-party AI provider, but each still counts as one chat toward your allowance.
SiliconFlow's own terms and privacy policy govern what it does with API traffic, including content safety review and the technical metadata it retains (such as request metadata, usage counts and source IP information). Those documents are published at api-docs.siliconflow.cn and are the authoritative statement of its practices. Consult them directly rather than relying on a summary here, because their commitments are theirs to make and to change.
If we change provider or model, this section and our technical records are updated to name the real one.
5. Cookies and identifiers we do use
Hy3 does not ask you to create an account. It recognises a browser only to apply a daily allowance and to reduce automated abuse.
- __Host-hy3_vid — an essential cookie holding a random value we generate and sign. It does not contain your name, email address, chat messages or answers; we use it to count your daily allowance. Maximum lifetime one year; deleting it gives you a new browser identity and allowance, while network and site-wide limits still apply.
- hy3_consent — an essential cookie recording whether you accepted or declined statistics. Maximum six months; you can change it at any time via "Privacy choices" in the footer.
- Cloudflare Turnstile — not active in the first public release. We retain it as an abuse-control option; if enabled later, Cloudflare will process the human-verification challenge under its privacy documentation.
- Derived identifiers — before any counter is stored, your browser identifier and your IP address are put through a one-way keyed hash. The counting service receives only those irreversible digests; it never receives your raw IP address, your cookie value, your prompt or your answer.
6. Statistics (only if you accept)
Google Analytics 4 and Microsoft Clarity are optional. Nothing from either is loaded, and no statistics cookie is written, unless you accept the banner. Declining does not affect the chat or your allowance.
If you accept, we send only low-cardinality events and buckets: which page was viewed, that a message was submitted, that an answer started or completed, and which category of error or limit occurred. We never send prompts, answers, reasoning, IP addresses, cookie values, verification tokens or API keys.
In Clarity session recordings the whole chat area — your input, your messages, the answers and any error text — is masked, so the recording shows the layout and not the content.
You can withdraw consent at any time from "Privacy choices" in the footer. We stop collecting and remove the first-party statistics cookies we can reach; data already held by Google or Microsoft follows their retention settings.
7. How long we keep things
Our own retention, in full:
- Prompts, answers and model reasoning — not intentionally persisted in our application database or Durable Objects; production logging must exclude this content and chat stays disabled until that is verified.
- Per-address rate-limit timestamps — entries older than 60 seconds are deleted on every check; an idle limiter clears itself within about 10 minutes.
- Active-stream records — deleted when the answer ends; an abandoned one is cleared within 120 seconds.
- Daily allowance counters and one-way turn digests — kept up to 48 hours after the end of the UTC day they belong to, then deleted.
- Anonymous daily aggregates and service price snapshots — up to 31 days. These contain no user identifier.
- Application logs — production is configured to record enumerated status values only, without message content or user identifiers; target retention 7 days or the shortest period the platform allows. Chat remains disabled unless that no-content logging configuration is verified.
- __Host-hy3_vid — up to 1 year. hy3_consent — up to 6 months.
One honest caveat: the Cloudflare storage our counters live in supports point-in-time recovery for roughly 30 days. So when we say a counter was deleted, we mean deleted by the application — we are not claiming the underlying platform makes it instantly unrecoverable.
8. Other processors
Cloudflare hosts the site, terminates TLS, provides the storage used for counters, and processes connection metadata such as your IP address in the course of delivering the site. If we enable Turnstile later, Cloudflare will also process that check.
9. Please don't send sensitive information
Do not type passwords, government identifiers, payment card details, health information, or confidential business material into the chat. A third party processes everything you send, and no setting on this site changes that.
10. Children
Hy3 is intended for adults (18+) and is not directed at children.
11. Your rights
Because there is no account and no stored conversation, we usually hold nothing that identifies you. If you believe we do, contact us at support@hy3.app and we will respond in line with applicable data protection law. Requests about data held by SiliconFlow, Google or Microsoft are directed to them.
12. Changes
If this policy changes we update the date at the top. Material changes to who processes your messages, or where, will be stated plainly rather than buried.