Legal

Privacy Policy

Last updated: July 28, 2026

This Privacy Policy explains how Heyrmes ("Heyrmes," "we," "us," or "our") collects, uses, shares, and protects your information when you use our website, platform, and related services (collectively, the "Service"). Heyrmes provides AI-powered conversational sales agents that communicate with your end users across SMS, email, voice, and web chat.

By using the Service, you agree to the practices described in this Policy. If you do not agree, please do not use the Service.

1. Who We Are

Heyrmes is the business responsible for the personal information practices described in this Policy, except when we process personal information solely on behalf of a customer.

When a customer uses Heyrmes to communicate with its own end users, that customer determines why and how the end-user data is processed, and Heyrmes processes it as a service provider on the customer's behalf.

2. Information We Collect

Information you provide

  • Account data: name, email, password, company name, and role.
  • Billing data: billing name, address, and payment method details. Payments are processed by Stripe — we do not store your full card number on our servers.
  • Workflow content: prompts, knowledge base documents, agent configurations, and other content you upload or create.
  • Communications content: messages, call transcripts, and recordings exchanged between your AI agents and your end users through connected channels.
  • Support data: information you share when you contact us for help or feedback.

Information collected automatically

  • Usage data: pages visited, features used, clicks, and timestamps.
  • Device data: IP address, browser type, operating system, and device identifiers.
  • Cookies: see Section 11 for details.

Information from third parties

When you connect integrations such as Google Calendar, HubSpot, OpenAI, Twilio, LeadConnector, Pinecone, Mem0, or Hume AI, we receive data from those providers based on the permissions you grant. Data received from Google (such as Google Calendar) is subject to the additional restrictions described in Section 6, as is data received from HubSpot.

Voice calls, recordings, and transcripts

When voice features are enabled, calls may be recorded and transcribed so that the Service can conduct conversations, maintain conversation history, support requested workflows, monitor service quality, and troubleshoot problems. Where notice or consent is required by law, recording and transcription should begin only after the required notice has been provided and consent has been obtained.

Customers that configure or initiate calls through the Service are responsible for using the voice features lawfully, including providing required disclosures and obtaining any necessary consent from call participants. If you do not consent to recording, inform the caller or call recipient and do not continue using a recording-enabled call.

3. How We Use Your Information

We use personal data to:

  • Provide, operate, and maintain the Service.
  • Authenticate accounts and process payments through Stripe.
  • Run the AI workflows you configure, including sending and receiving messages through connected channels.
  • Improve the Service, debug issues, and develop new features. This does not apply to Google user data, which we use only as described in Section 6.
  • Prevent fraud, abuse, and security incidents.
  • Comply with legal obligations.
  • Send transactional emails and — only with your consent — marketing communications, which you can opt out of at any time.

4. Our Role in Processing Information

Heyrmes may handle personal information in different roles, depending on how the Service is used:

  • As a business — when we determine how personal information is used to operate accounts, provide support, secure the Service, process billing, and improve our products. Google user data is excluded from this product-improvement use and is processed only as described in Section 6.
  • As a service provider — when we process customer-provided data, communications, calendar information, or workflow content according to the customer's instructions and to provide the requested Service.
  • With consent — when applicable law requires permission, such as for certain marketing communications, non-essential cookies, or third-party integrations.

5. How We Share Information

We do not sell your personal data. We share information only with:

  • Stripe — our payment processor, which handles all billing and card data under its own privacy policy.
  • AI and channel providers — such as OpenAI, Twilio, LeadConnector, HubSpot, Pinecone, Mem0, and Hume AI, strictly to perform the operations you request. Google user data (for example, Google Calendar data) and HubSpot data are shared only as described in Section 6 and are never provided to Pinecone or Mem0 for long-term storage, profiling, or model improvement.
  • Infrastructure vendors — hosting, database, email, analytics, and error monitoring providers who help us run the Service.
  • Legal authorities — when required by law, court order, or to protect rights and safety.
  • Business transfers — in connection with a merger, acquisition, or sale of assets, subject to confidentiality.

6. Connected Service Data

Calendars

You may choose to connect a third-party calendar to the Service. Calendar access is optional and is activated only after an authorized user grants permission through the calendar provider's consent process.

Google Calendar

When you connect Google Calendar, we access and process Google user data only as necessary to provide the calendar and appointment-management features you request.

Information we access

Depending on the permissions you grant, the Service may access:

  • Your Google account name and email address.
  • Your calendars and calendar identifiers.
  • Calendar availability, including free and busy time periods.
  • Event information, including titles, descriptions, dates, times, time zones, locations, attendees, and event identifiers.

How we use Google Calendar data

We use Google Calendar data to provide scheduling functionality requested and configured by you, including:

  • Checking calendar availability and identifying available time slots.
  • Displaying relevant appointments and event information.
  • Creating appointments based on customer requests and your scheduling instructions.
  • Rescheduling, updating, or cancelling appointments.
  • Allowing your authorized agents, including configured AI-powered agents, to perform these actions on your behalf.

We do not use Google Calendar data for advertising, user profiling, creditworthiness decisions, or purposes unrelated to the scheduling features requested by you. We do not use Google user data to develop, improve, or train generalized or non-personalized artificial intelligence or machine learning models.

Storage and security

We store the account information and authorization credentials needed to maintain your Google Calendar connection. OAuth access and refresh tokens are encrypted before storage. Calendar information is processed only as needed to perform the requested scheduling operation. We apply reasonable administrative, technical, and organizational safeguards to protect this information from unauthorized access, loss, misuse, or disclosure.

Sharing and disclosure

We do not sell Google user data. We do not share or transfer Google user data to third parties except when necessary to provide the requested calendar functionality, when directed by you, or when required by applicable law. The only third parties that may process Google user data on our behalf are the AI providers (OpenAI and Hume AI) that interpret and execute the scheduling instructions you configure, and infrastructure vendors that host or secure the Service. These providers are required by contract to protect this information and use it only to provide their contracted services — not to develop, improve, or train their own AI or machine learning models, and not for advertising or profiling.

Retention, disconnection, and deletion

We retain Google account connection information only for as long as your integration remains active or as otherwise necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. You may disconnect Google Calendar through the Service or revoke access through your Google Account permissions. You may also contact us using the details in Section 15 to request deletion of Google Calendar data retained by us, subject to applicable legal requirements.

Google API Limited Use

Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

HubSpot

You may choose to connect a HubSpot account to the Service. HubSpot access is optional and is activated only after an authorized HubSpot administrator installs the Heyrmes AI Connector and grants permission through HubSpot's consent screen.

Information we access

Depending on the permissions granted, the Service may access:

  • Contact records, including names, email addresses, phone numbers, and associated contact properties.
  • Company records associated with those contacts.
  • Deal records, including pipelines, stages, amounts, and deal associations.
  • Conversation threads and messages in your HubSpot inbox, including live chat, Facebook Messenger, Instagram, SMS, and email conversations.
  • Owner records and meeting availability used for scheduling.
  • Your HubSpot account identifier and the authorization credentials needed to keep the connection active.

How we use HubSpot data

We use HubSpot data only to provide the features you configure, including:

  • Keeping contact information consistent between HubSpot and Heyrmes.
  • Reading incoming messages so your configured AI agents can respond on the same HubSpot conversation thread.
  • Creating deals and writing notes to the contact timeline when your workflows instruct us to.
  • Checking availability and creating meetings when scheduling features are used.

We do not use HubSpot data for advertising, user profiling, or purposes unrelated to the features you request. We do not use HubSpot data to develop, improve, or train generalized or non-personalized artificial intelligence or machine learning models.

Storage and security

We store the account information and authorization credentials needed to maintain your HubSpot connection. OAuth access and refresh tokens are encrypted before storage. Incoming messages and the records needed to continue a conversation are retained so that conversation history remains available in Heyrmes. We apply reasonable administrative, technical, and organizational safeguards to protect this information from unauthorized access, loss, misuse, or disclosure.

Sharing and disclosure

We do not sell HubSpot data. We do not share or transfer HubSpot data to third parties except when necessary to provide the functionality you request, when directed by you, or when required by applicable law. The only third parties that may process HubSpot data on our behalf are the AI providers (such as OpenAI and Hume AI) that generate the responses you configure, and infrastructure vendors that host or secure the Service. These providers are required by contract to protect this information and use it only to provide their contracted services — not to develop, improve, or train their own AI or machine learning models, and not for advertising or profiling.

Retention, disconnection, and deletion

We retain HubSpot connection information only for as long as the integration remains active or as otherwise necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. You may disconnect HubSpot from within the Service, or uninstall the Heyrmes AI Connector from your HubSpot account settings. On disconnection we stop accessing your HubSpot account and remove the stored authorization credentials. You may also contact us using the details in Section 15 to request deletion of HubSpot data retained by us, subject to applicable legal requirements.

7. Where Information Is Processed

Heyrmes and its service providers may process information in the United States and other countries where we or our service providers operate. Privacy and data protection laws in those locations may differ from the laws where you live. We use reasonable contractual, organizational, and technical measures designed to protect personal information wherever it is processed.

8. Data Retention

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, to provide the Service, and to satisfy legal, security, accounting, dispute-resolution, and enforcement requirements. The retention period depends on the type of information and how the Service is used.

  • Account and billing information: retained while the account is active and afterward when required for billing records, fraud prevention, disputes, or legal compliance.
  • Workflow and communication content: retained while needed to provide the configured workflows or until the customer deletes the content or closes the account, subject to legal and backup requirements.
  • Call recordings and transcripts: retained according to the customer's use of the Service and configuration, and deleted when no longer needed for the requested service, legal compliance, security, or dispute resolution.
  • Integration credentials: retained while the integration is connected and removed or disabled when the integration is disconnected, subject to limited security and backup retention.
  • Usage and security logs: retained for a limited period appropriate for maintaining, securing, and troubleshooting the Service.
  • Backups: deleted information may remain in protected backups until those backups are overwritten or expire under our backup schedule.

You can request deletion of your account and personal information by emailing privacy@heyrmes.com. We may retain information when an applicable exception or legal obligation permits or requires us to do so.

9. Data Security

We use reasonable administrative, technical, and physical safeguards designed to protect your information, including encryption in transit, access controls, and regular reviews. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

10. Your Rights

Depending on your state of residence and subject to applicable exceptions, you may have the following rights regarding your personal information:

  • Know and access — request information about the categories, sources, purposes, and recipients of personal information we process, and request a copy of that information.
  • Correct — ask us to correct inaccurate personal information.
  • Delete — ask us to delete personal information we have collected about you.
  • Portability — request a portable copy of certain personal information.
  • Opt out — opt out of targeted advertising, the sale or sharing of personal information, or certain profiling where those rights apply.
  • Limit use of sensitive information — request limits on certain uses or disclosures of sensitive personal information where applicable.
  • Non-discrimination — receive equal service and pricing when you exercise an applicable privacy right.
  • Appeal — appeal our decision on a privacy request where state law provides that right.

How to submit a privacy request

To exercise any of these rights, email privacy@heyrmes.com and describe the right you want to exercise, the account or business involved, and the information reasonably needed to locate your records. Do not send passwords, OAuth tokens, or other account secrets with your request.

We may ask you to verify your identity or authority using information associated with the account. An authorized agent may submit a request where permitted by law, but we may require proof of authorization and may verify the request directly with you. If we process your information solely for a Heyrmes customer, we may direct your request to that customer or assist the customer in responding.

We will respond within the period required by applicable law. If we deny a request, we will explain the reason when required. Where state law provides a right to appeal, you may appeal by replying to our decision or emailing privacy@heyrmes.com with "Privacy Appeal" in the subject line.

11. Cookies and Tracking

We use cookies and similar technologies to keep you signed in, remember your preferences, secure the Service, and understand how it is used. We use:

  • Essential cookies — required for authentication and security. The Service will not work without these.
  • Preference cookies — remember your settings, such as theme and language.
  • Analytics cookies — help us understand usage and improve the Service.

You can control or disable cookies through your browser settings. Blocking essential cookies may prevent parts of the Service from working properly.

12. Third-Party Services

The Service integrates with third-party products (including Google Calendar, Stripe, OpenAI, Twilio, LeadConnector, Pinecone, Mem0, and Hume AI). Those providers operate under their own terms and privacy policies, which we do not control. We encourage you to review them. Google user data is handled under the additional Limited Use restrictions described in Section 6, regardless of which of these providers is involved.

13. Children's Privacy

The Service is intended for businesses and is not directed to children under 13. We do not knowingly collect personal information directly from children under 13. If you believe a child under 13 has provided personal information to us, please contact us so we can review and delete it as appropriate.

14. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above and, if the changes are material, notify you through the Service or by email. Continued use of the Service after the changes take effect means you accept the updated Policy.

15. Contact Us

For any questions about this Privacy Policy or your personal data, contact us at privacy@heyrmes.com.