Security & privacy

Phone calls carry personal information. We treat them that way.

How HayAICall handles data during the beta. This page describes our practices; it is not a certification or legal advice.

Least information by default

The AI only receives what you mark as shareable for that call. Unshared details are never sent to the AI model, and it is instructed never to invent or guess information.

Honest by design

Every call starts with the assistant saying who it calls for — a named person or organization. By default it introduces itself as calling on their behalf, optionally by a name you choose, without volunteering that it is an AI; you can have it announce itself as an AI assistant instead. It never claims to be you, and never denies being an AI if asked.

Encrypted storage in Tokyo

Accounts, transcripts and recordings are stored encrypted on AWS in the Tokyo region (ap-northeast-1).

Retention you control

Personal call content is deleted after 90 days. Organizations set their own retention period.

Role-based access

Organization members only see the calls their role allows; teams are separated. Owners and admins control membership.

Audit log

Template, policy, membership and approval changes are recorded with who did what and when.

AI processing

Speech recognition, language and speech synthesis run on AWS services (Amazon Transcribe, Amazon Bedrock, Amazon Polly). Some model inference currently runs in AWS US regions; inputs are not used to train models.

Telephony

Calls are placed through a telephony provider. Webhooks we send to organizations are signed with HMAC-SHA256 so receivers can verify them.

Questions

Contact hello@hayaicall.com. Organizations evaluating HayAICall can request details of our data handling.