Data Privacy Overview
At Hedy, we understand that your conversations are more than just words—they’re confidential discussions, strategic planning sessions, and sensitive interactions that require the highest level of privacy protection. We’ve built our platform with privacy at its core, ensuring that your trust in us is well-placed through robust security measures and transparent data handling practices.
Our Privacy Commitment
Hedy is built on four fundamental privacy principles:
Zero Data Sales: We never sell your data to third parties. Your conversations and insights remain exclusively for your use.
End-to-End Security: All data is encrypted using TLS 1.3 during transmission and AES-256 at rest, protecting your information at every step.
AI Analysis Without Training: In the default cloud mode, our AI providers analyze your conversations without using them to train their models. On capable hardware, Local AI Processing keeps that analysis on your own device.
User Control: You maintain full control over your data, including the ability to delete it at any time.
What Data We Store
Transparency about data collection is crucial for building trust. Here’s a comprehensive overview of what we do and don’t collect:
Essential Data:
-
Account information
-
User preferences (session type, languages, custom prompts, contexts)
-
Session metadata (time, duration)
-
App usage statistics
Conversation Data:
Whether conversation data leaves your device is set by the Cloud Sync choice you made when you created your account, and you can change it later in Settings. It reaches our servers in two situations: when Cloud Sync is on, and when you explicitly share a session. With Cloud Sync on, we store the following session data on our secure servers so you can reach it from your other devices:
-
Transcripts of your conversations
-
Chat interactions with Hedy
-
Highlights
-
Summaries
-
Detailed Notes
We do NOT collect or store on our servers:
-
Audio recordings
-
Personal information beyond basic account details
For organizations requiring formal compliance documentation, access our Trust Center at trust.hedy.ai or through App Settings. The Trust Center includes Data Processing Agreements, Standard Contractual Clauses, Technical and Organizational Measures, and sub-processor documentation.
On-Device Audio Caching (Nemotron)
If you use the on-device Nemotron speech engine, available on every platform Hedy ships a native app for, Hedy briefly keeps each session’s audio in a temporary cache on your device while it processes. This helps Nemotron label speakers more accurately, and the audio is deleted afterward. It stays on your device and is never uploaded to our servers.
This is controlled by a setting called Temporary audio cache (Nemotron), which is on by default. You can turn it off in Hedy’s settings if you’d prefer Hedy not to hold any audio between processing steps. For more about Nemotron and Whisper, see Speech Recognition Providers.
How We Protect Your Data
Your data is protected through multiple layers of security. For infrastructure details, see Data Storage & Security.
-
Local Processing: Speech recognition happens on your device, so raw audio never leaves your phone without your permission. On capable hardware, Local AI Processing can run the entire pipeline (summaries, notes, and suggestions) on-device too, offline included
-
Encrypted Transmission: All data sent between your device and our servers uses industry-standard TLS encryption
-
Secure Storage: Sessions you sync to the cloud are stored on Google Cloud, in your account’s data region: the United States or the European Union
-
Access Controls: Strict internal policies limit employee access to user data
-
Zero-Trust Model: Any access to user data requires business justification, security approval, and is logged for audit.
-
Regular Security Reviews: We continuously monitor and update our security practices
Third-Party Partnerships and Data Security
Hedy works with a small number of technology partners for cloud hosting, AI processing, subscription billing, error monitoring, email and support. We choose them for their privacy and security commitments as much as for what they do, and each one is bound by a data protection agreement with us.
-
No training on your conversations: Our AI processing partners analyze your conversations only to answer the request. Our agreements prohibit them from using your content to train models, and they do not keep it once the request is done.
-
Your data region applies to AI processing too: If your account is in the EU data region, your synced conversations are stored in the EU and the AI analysis runs on infrastructure inside the EU. The EU data residency post explains what runs where.
-
Each partner gets only what it needs: The partners that handle billing, error monitoring and support do not receive the content of your conversations. Auto-recap emails, if you turn them on, go out through our email provider, which is based in the US.
-
Speech recognition runs on your device by default: Your audio is not sent anywhere for transcription. If you choose a cloud speech provider in Settings, the audio goes to that provider for transcription instead.
The current list of partners, with what each one processes and where, is published in our Trust Center. We update it whenever a partner changes.
Professional Use Cases
Different contexts require different privacy considerations:
Medical Consultations
Hedy has completed an independent HIPAA assessment as a Business Associate. For current compliance documentation, visit our Trust Center.
-
We recommend using Hedy primarily for note-taking and basic analysis
-
Enable local-only storage for sensitive patient information
-
Disable automatic email recaps
-
Manually review all AI-generated content before sharing
Journalism
We understand the critical importance of protecting journalistic sources. For maximum source protection:
-
Enable local-only storage to keep all data on your device
-
Disable automatic email recaps
-
Take advantage of our highlight feature to mark key quotes
Business Meetings
For business users concerned about confidentiality:
-
NDAs are respected through our strict data handling policies
-
Email invitations give access to a named person’s Hedy account. Public links are unlisted rather than private, so anyone you send one to can forward it
-
Our AI providers analyze your conversations without using them to train their models
Important: Always ensure you have proper consent before recording any conversation. Different jurisdictions have varying requirements for recording consent.
Your Data Control Options
We believe in giving you complete control over your data:
Individual Session Management
-
View and delete individual sessions
-
Export specific sessions in various formats
-
Control cloud sync settings per session
Hedy does not delete anything on a schedule. There is no automatic deletion and no retention timer, so your sessions stay until you delete them, either individually or by deleting your account.
Account-Level Controls
-
Manage cloud sync settings globally
-
Export all your data at once
-
Delete your entire account and associated data
-
Control AI analysis preferences with the AI Processing: Cloud AI, Local AI or Off
Regional Privacy Preferences
You can specify your data protection region in App Settings. Whether you’re under GDPR, CCPA, or other regional requirements, Hedy adapts its data handling to match your jurisdiction.
Need more details about specific privacy features? Check our other privacy articles or contact support@hedy.bot