Hugging Face
Hugging Face · Model API · US · huggingface.co
services/huggingface.yamlVendor data-handling terms
“Data Security/Privacy Hugging Face does not store any user data for training purposes. We do not store the request body or response when routing requests through Hugging Face. Logs are kept for debugging purposes for up to 30 days, but no user data or tokens are stored. For more information on how your data is handled, please refer to the Data Security Policies of each provider.”
“Upon cancellation of your Account, we will use commercially reasonable efforts to delete your information and Content of your own Repositories, whether public or private, within 90 days.”
“LOCATION OF PROCESSING AND DATA TRANSFERS The Company and its servers are located in the United States. / Personal Information collected by the Services may be stored and processed in the United States or any other country in which the Company or its affiliates, subsidiaries or agents maintain facilities.”
Domains and endpoints
observed means seen in Unseen deployments; vendor-documented means listed by the vendor. Vendors do not publish complete lists.
| Host | Role | Source |
|---|---|---|
| huggingface.co | app | vendor-documented |
| api-inference.huggingface.co | api | vendor-documented |
| router.huggingface.co | api | vendor-documented |
| hf.co | app | vendor-documented |
Assessment
Reasoning: The model hub, plus inference routed to third-party providers and Spaces apps built by the community. Hugging Face itself does not train on or store request content, but routed requests land with whichever provider serves the model, and public repositories and Spaces are visible to everyone. US hosting.
Flags: Requests routed to third-party providers · Public repositories and Spaces by default · US hosting · Assessed 2026-09-16. The assessment is Unseen's; the terms above are the vendor's.
Changelog
- 2026-09-16Documented. Training, retention and location terms verified against the Hugging Face inference security documentation, terms of service and privacy policy.
- 2026-09-16Added with vendor-documented domains.
Corrections
Pull request on GitHub, or the form below. Changes are reviewed and recorded in the changelog.