Security & privacy
Phone calls carry personal information. We treat them that way.
How HayAICall handles data during the beta. This page describes our practices; it is not a certification or legal advice.
Least information by default
The AI only receives what you mark as shareable for that call. Unshared details are never sent to the AI model, and it is instructed never to invent or guess information.
Honest by design
Every call starts with the assistant saying who it calls for — a named person or organization. By default it introduces itself as calling on their behalf, optionally by a name you choose, without volunteering that it is an AI; you can have it announce itself as an AI assistant instead. It never claims to be you, and never denies being an AI if asked.
Encrypted storage in Tokyo
Accounts, transcripts and recordings are stored encrypted on AWS in the Tokyo region (ap-northeast-1).
Retention you control
Personal call content is deleted after 90 days. Organizations set their own retention period.
Role-based access
Organization members only see the calls their role allows; teams are separated. Owners and admins control membership.
Audit log
Template, policy, membership and approval changes are recorded with who did what and when.
AI processing
Speech recognition, language and speech synthesis run on AWS services (Amazon Transcribe, Amazon Bedrock, Amazon Polly). Some model inference currently runs in AWS US regions; inputs are not used to train models.
Telephony
Calls are placed through a telephony provider. Webhooks we send to organizations are signed with HMAC-SHA256 so receivers can verify them.
Questions
Contact hello@hayaicall.com. Organizations evaluating HayAICall can request details of our data handling.