Last updated 28 August 2026
Privacy policy
Hellow AI answers the phone for small home-services businesses. This policy explains exactly what data that involves, who processes it, how long it is kept and how to get it removed.
Who this covers
Hellow AI (“we”) provides an AI phone receptionist, operated through the Hellow AI Fulfillment console at https://app.usehellow.com. Two kinds of people use it: agency staff who configure and operate receptionists, and the owners and managers of the businesses those receptionists answer for.
Where a business signs up for Hellow AI to answer its phone, that business is the controller of its callers’ data and we process it on their instructions.
What we collect
- Account data. Email address, display name, and the role you hold in an agency or a client organisation.
- Business configuration. What you tell the receptionist: business name and address, opening hours, services and prices, escalation contacts and their phone numbers, frequently asked questions, and phone routing settings.
- Call data. For each answered call: the caller’s number, the time and duration, a transcript, a summary, an outcome, a quality grade, and — when call recording is switched on for that business — an audio recording.
- Integration data. When a business connects Google Calendar or a CRM, the access is held by our integration broker and used only to read availability and write the appointments the receptionist books.
- Billing status. Whether a subscription is active, and the identifiers our payment provider uses. We never see or store card numbers.
- Operational data. Usage and cost totals, audit entries recording who changed what, and delivery records for the emails we send.
What we use it for
- Answering calls the way a business configured, and booking or capturing the work.
- Notifying the business when a call needs a human.
- Testing every configuration change against scripted callers before it goes live.
- Producing the monthly report a business receives about its own calls.
- Keeping the service secure, billed correctly, and auditable.
We do not sell personal data, we do not use it for advertising, and we do not use call content to train general-purpose models.
Google user data
If a business connects Google Calendar, we request only the calendar events scope. That access is used for one purpose: reading availability so the receptionist does not double-book, and writing appointments it books on that business’s behalf.
Hellow AI’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer Google user data to others except as necessary to provide this service, we do not use it for advertising, and no human reads it except where required to resolve a support request the customer raised, for security, or to comply with the law. A business can disconnect Google Calendar at any time from its integrations screen, which revokes our access.
Who processes it with us
We use a small number of subprocessors, each for a single purpose:
- Supabase — database, authentication and private storage for recordings.
- Vapi — telephony and the live voice assistant.
- Anthropic — generating call summaries, quality grades and report copy.
- Resend — transactional email.
- Inngest — running background jobs such as grading and monthly reports.
- Nango — holding calendar and CRM authorisations.
- Whop — checkout, subscriptions and payment processing.
Call recording and consent
Recording is configured per business and can be switched off. Where recording is on, the receptionist reads a disclosure at the start of the call, and a business operating in a two-party consent jurisdiction cannot switch that disclosure off. The business is responsible for the legality of recording in its own jurisdiction; we provide the controls and the disclosure.
How long we keep it
- Recordings are deleted automatically once the retention window that business chose has passed. The window can be anywhere from one day to ten years and is enforced by a nightly job.
- Transcripts, summaries and grades are kept for the life of the account, because they are the record of what the service did.
- Configuration versions and audit entries are immutable and kept for the life of the account.
- Account data is deleted on request, subject to records we must keep for tax and accounting.
How it is protected
- Every table enforces row-level security, so one business cannot read another’s data.
- Recordings live in a private bucket and are served only through links signed for five minutes.
- Provider credentials are held server-side and never reach a browser.
- Every configuration change is recorded with who made it and when.
Your rights
You can ask for a copy of your data, ask us to correct it, or ask us to delete it. Business owners can read and export their own calls and reports from the portal at any time. For anything else, write to ops@hellowai.demo and we will respond within 30 days.
Children
Hellow AI is a business tool and is not directed at anyone under 16.
Changes
If this policy changes materially we will tell account holders by email before the change takes effect. The date at the top of this page always reflects the current version.
Contact
Questions about this policy, or about data we hold: ops@hellowai.demo.