Privacy Policy

Effective Date: April 5, 2026 Last Updated: July 29, 2026 Version: 2.3


1. Introduction

TrentApps LLC, a Missouri limited liability company doing business as hiroi ("we", "us", "our"), operates the hiroi platform at https://hiroi.ai ("Service"). This Privacy Policy explains how we collect, use, disclose, and protect personal information across all channels of our omni-channel AI agent platform, including phone calls, SMS messaging, email, web chat widgets, and integrations with third-party services.

Controller identity and contact details:

TrentApps LLC (d/b/a hiroi) 117 S Lexington St, Ste 100 Harrisonville, MO 64701, United States privacy@hiroi.ai

We have not appointed a data protection officer; data protection questions are handled by the contact above. If we become required to designate a representative in the EU or UK under Article 27 GDPR, we will publish those details here.

This policy applies to:

  • Registered users (businesses and individuals who create hiroi accounts)
  • End contacts (individuals who receive calls, SMS, emails, or chat interactions initiated through the Service)
  • Website visitors who interact with AI agent chat widgets deployed by our customers

2. Data Controller and Processor Roles

Role Who For What Data
Data Controller hiroi Registered user account data
Data Controller Registered users (customers) Contact data and communication data generated by their AI agents
Data Processor hiroi Processing contact/communication data on behalf of registered users

Our Data Processing Agreement governs that processor relationship. It applies to every customer automatically on acceptance of the Terms of Service — no separate signature is needed, though we will countersign a copy on request.

Important: If you received a call, SMS, or email from a hiroi-powered AI agent, the business that deployed that agent is the data controller for your information. Contact that business directly to exercise data rights regarding their outreach.

3. Information We Collect

3.1 Account Information (Registered Users)

When you create an account, we collect:

Data Source Purpose
Email address Google, Apple, or Microsoft OAuth / magic link Account identification, notifications
Display name OAuth provider Personalization
Profile picture URL OAuth provider Avatar display
Authentication credentials OAuth token / magic link token Account access
Business name Account setup Organization management
Phone number Account setup (optional) Account security, support

3.2 Third-Party Integration Data

When you connect a third-party account (e.g., Microsoft 365), we may access:

Data Purpose Stored By hiroi
Email messages (read) Display in unified inbox, AI context Metadata only; content processed in-memory
Email send capability Send emails on your behalf Email logs only
Calendar events Schedule appointments, check availability Cached per session
Calendar write Create/modify appointments Event creation logs

We access third-party integration data only to perform the specific functions you activate. We do not store the full content of email messages beyond what is needed for in-session processing.

3.3 Contact Data

When you import or create contacts, we store:

Data Purpose Sensitivity
Name Contact identification Medium
Phone number(s) Call and SMS delivery High - PII
Email address(es) Email campaign delivery High - PII
Company/job title Personalization, enrichment Medium
Custom fields Your business use case Variable
Contact notes Context for AI agents Medium
Consent records TCPA/GDPR compliance High - legally required
Do-not-contact flags Compliance, opt-out tracking High - legally required
Interaction history Campaign analytics, AI context High

3.4 Communication Data

When your AI agents make calls, send SMS, or send emails, we collect:

Data Purpose Sensitivity
Call transcripts AI analysis, search, review High - may contain PII
Call metadata (duration, outcome, timestamps) Analytics, billing Medium
SMS message content (sent and received) Delivery, analytics, unified inbox High - may contain PII
Email content (sent and received) Delivery, analytics, unified inbox High - may contain PII
Delivery status and carrier responses Deliverability analytics Low
Call/SMS opt-out signals Compliance High - legally required

3.5 Agent Configuration Data

When you use the Service, we store:

  • AI agent configurations (name, personality, voice, system prompt)
  • Campaign settings and schedules
  • Phone number assignments
  • Widget site settings and domain safelists
  • Knowledge base documents
  • Email templates and campaign content

3.6 Usage and Analytics Data

We automatically collect:

  • Feature usage patterns (aggregate)
  • API request metadata (timestamps, response codes, latency)
  • Campaign performance metrics
  • Error and performance data

3.7 Payment Information

Payment processing is handled by Stripe. We store only:

  • Stripe customer identifier (not your card details)
  • Credit balance and transaction history (amounts, dates, actions)
  • Subscription tier and billing cycle

We do not store credit card numbers, CVVs, or bank account details.

3.8 Activity Logs

For security and audit purposes, we log:

  • Authentication events (login, logout, failed attempts)
  • Account changes (settings updates, agent modifications)
  • Campaign creation, launch, and completion events
  • IP addresses and user agents for security events

4. How We Use Your Information

Purpose Legal Basis
Operate and deliver the Service Contract performance
Process AI calls, SMS, and email campaigns Contract performance
Store and manage contact records Contract performance
Authenticate and secure accounts Legitimate interest
Prevent abuse, spam, and regulatory violations Legitimate interest + legal obligation
Send essential account notifications Contract performance
Generate aggregate analytics and campaign reports Contract performance
Process payments and manage credits Contract performance
Comply with legal obligations (TCPA, CAN-SPAM, etc.) Legal obligation
Maintain call transcripts and summaries Contract performance + legal obligation

We do not use your data for:

  • Selling to third parties
  • Advertising or marketing profiling of our customers
  • Training AI models on your contact data or conversation content

4.1 Call Transcription

hiroi does not record or store call audio. Speech is transcribed as the call happens, and only the resulting text — the transcript, summary, and any data the agent collected — is retained. Transcripts are processed to:

  • Provide you with a searchable record of conversations
  • Enable AI agents to maintain context across calls
  • Generate call summaries and outcome data
  • Support quality review and compliance auditing

Audio is transmitted to our telephony and speech providers to carry and transcribe the call in real time, and is not persisted by hiroi afterward. Transcripts are retained per the schedule in Section 6.

4.2 Voice in the Chat Widget

When a website visitor speaks to a hiroi chat widget, the captured microphone audio is streamed to a speech-to-text provider (Microsoft Azure Speech or Azure OpenAI; OpenAI where a deployment is configured to use it directly) for real-time transcription, and the assistant's reply is streamed to a text-to-speech provider (Microsoft Azure by default, or ElevenLabs where the assistant owner selects an ElevenLabs voice). Visitor audio is not stored by hiroi; the resulting transcript is retained as conversation data. Synthesized reply audio may be held briefly in a short-lived cache so it can be played back, and expires automatically.

5. Third-Party Data Sharing

We share data with the following service providers:

Provider Data Shared Purpose
Microsoft Azure All application data (encrypted) App hosting (US East 2); Azure SQL Database; Azure AI Content Safety; Azure Maps (where local search is enabled)
Azure OpenAI Conversation content, call and chat transcripts, system prompts, knowledge base content, document and query text for embeddings, voice audio for transcription Primary AI provider. Response generation, embeddings, speech-to-text
Azure Speech (Microsoft) Voice audio (widget and phone) Speech-to-text and text-to-speech
Azure Communication Services Phone numbers, call audio, call metadata, SMS content, email addresses and content Calls, SMS, email delivery
OpenAI Conversation content, transcripts, system prompts, text for embeddings, voice audio for transcription — only where a deployment is configured to call OpenAI directly rather than Azure OpenAI AI response generation, embeddings, speech-to-text
Anthropic Conversation content, transcripts, system prompts — where an assistant is configured to use a Claude model AI response generation
ElevenLabs The text of assistant replies, where the assistant owner selects an ElevenLabs voice Text-to-speech
Google OAuth tokens; calendar and email data when the integration is enabled Authentication; Google Workspace integration
Apple OAuth tokens Authentication
Microsoft (Entra ID / Graph) OAuth tokens; calendar, email, Teams and directory data when the integration is enabled Authentication; Microsoft 365 integration
Stripe Customer ID, payment method tokens, transaction data Payment processing
Cloudflare Network traffic metadata, IP addresses CDN, DNS, DDoS protection

Which AI and speech providers actually receive your data depends on how your assistants are configured. The hosted hiroi cloud routes AI processing through Azure OpenAI by default.

For a complete list of sub-processors, see our Subprocessors page.

We do not sell your personal information to third parties.

6. Data Retention

We keep personal data only as long as we need it. Some categories are deleted on an automated schedule by a daily retention job; others are kept for as long as your account exists, because they are the records you are using the Service to maintain, and are deleted when you delete them or when your account is deleted. The table states which is which, so you know what is enforced automatically and what is under your control.

Data Type Default Retention How it ends After Retention
Conversation data (widget chat, including transcripts) 1 year Automated daily job Permanently deleted
IP addresses 90 days Automated daily job Anonymized (set to null)
Activity logs 2 years Automated daily job Permanently deleted
Data export files 7 days Automated daily job Permanently deleted
Sign-in attempts, OAuth state, webhook events, outbound-integration delivery logs 7–30 days Automated daily job Permanently deleted
Account data Until you delete your account, then a 30-day grace period Automated after grace period Permanently deleted
Contact records Until you delete them, or until account deletion Deleted by you / with the account Permanently deleted
Call records and transcripts Until you delete them, or until account deletion Deleted by you / with the account Permanently deleted
SMS message content Until you delete it, or until account deletion Deleted by you / with the account Permanently deleted
Email content Until you delete it, or until account deletion Deleted by you / with the account Permanently deleted
Consent, opt-out and do-not-contact records Kept for the life of the account, and may be kept after deletion of the underlying contact where needed to keep honouring an opt-out Manual / legal review Retained only as long as legally justified
Payment and transaction records Up to 7 years Manual / legal review Retained for tax and accounting obligations

Shortening retention. Registered users can set a shorter retention period for conversation data in account settings (minimum 7 days), which the automated job then applies to that account. You can delete contacts, conversations, and call and message records at any time from the dashboard, and you can request deletion of anything else by contacting privacy@hiroi.ai. Deleting your account removes the personal data associated with it after the 30-day grace period, subject to the legal retention exceptions above.

Backups. Deleted data may persist in encrypted database backups until those backups age out of the backup rotation cycle. Backups are not used to restore individual deleted records.

7. Your Rights

Depending on your jurisdiction, you may have the following rights:

7.1 Right to Access

Request a copy of all personal data we hold about you. Use the "Export My Data" feature in account settings, or contact us.

7.2 Right to Rectification

Update your account information through your profile settings.

7.3 Right to Erasure

Delete your account through account settings. Deletion includes a 30-day grace period. After the grace period, all personal data is permanently removed, subject to legal retention requirements.

7.4 Right to Data Portability

Export your data in machine-readable format (JSON) through your account settings.

7.5 Right to Restrict Processing

Request restriction of processing of your data in certain circumstances.

Where processing is based on consent, withdraw consent at any time through your account settings.

7.7 Right to Object

Object to processing based on legitimate interest by contacting privacy@hiroi.ai.

7.8 Automated Decision-Making

AI-generated calls, messages, and chat responses constitute automated processing. You can request human review of decisions that significantly affect you.

8. Data Security

We implement appropriate technical and organizational measures to protect your data:

  • Encryption in transit: All data transmitted via TLS 1.2+
  • Encryption at rest: AES-256 database encryption (Azure SQL Transparent Data Encryption)
  • Call transcript security: Transcripts stored under the same database encryption as all other application data; access restricted to members of the owning organization
  • Access controls: Role-based access, principle of least privilege
  • Authentication security: Server-side session management, CSRF protection, rate limiting, optional passkeys and TOTP two-factor authentication
  • API key security: Keys hashed with PBKDF2-SHA256, never stored in plaintext
  • Token security: OAuth and integration tokens encrypted at rest with Fernet
  • Audit logging: Authentication events, account and configuration changes, and administrative actions are logged

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. For more details, see our Security Policy.

8.1 Breach Notification

If we become aware of a personal data breach affecting your data, we will notify you without undue delay and, where we act as processor, no later than 72 hours after becoming aware of it, together with the information you need to meet your own notification obligations. See Section 5.6 of our Data Processing Agreement.

9. Cookies

We use cookies and similar technologies as described in our Cookie Policy.

10. International Data Transfers

Your data may be processed outside your country of residence. Our primary infrastructure is in the United States (Azure US East 2). We ensure appropriate safeguards for international transfers:

  • Standard Contractual Clauses (SCCs) for transfers from the EEA/UK to the United States
  • Data processing agreements with all sub-processors
  • Evaluation of recipient country data protection laws
  • Supplementary technical measures (encryption in transit and at rest)
Provider Location Transfer Mechanism
Microsoft Azure / Azure OpenAI / ACS United States (East 2) SCCs, EU-US Data Privacy Framework
OpenAI United States SCCs, DPA
Anthropic United States SCCs, DPA
ElevenLabs United States SCCs, DPA
Google United States SCCs, EU-US Data Privacy Framework
Apple United States SCCs, DPA
Stripe United States SCCs, EU-US Data Privacy Framework
Cloudflare Global (edge nodes) SCCs, EU-US Data Privacy Framework

Transfer mechanisms are those the relevant provider makes available under its own data processing terms; we rely on the provider's current published terms rather than certifying them ourselves. Where we transfer data from the UK, the UK International Data Transfer Addendum to the SCCs applies; for Switzerland, the SCCs apply with the Swiss amendments.

11. Children's Privacy

The Service is not directed to individuals under 18 years of age. We do not knowingly collect personal information from children. If we learn we have collected such information, we will promptly delete it.

12. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have additional rights under CCPA as amended by CPRA:

12.1 Right to Know

You have the right to request disclosure of the personal information we collect, use, and share. See Section 3 for categories of information collected.

12.2 Right to Delete

Request deletion of your personal information, subject to certain exceptions. Use the account deletion feature or contact us.

12.3 Right to Correct

Request correction of inaccurate personal information.

12.4 Right to Opt-Out of Sale or Sharing

We do not sell personal information. We do not share personal information for cross-context behavioral advertising.

12.5 Right to Limit Use of Sensitive Personal Information

Where we process sensitive personal information (such as call transcripts that may contain sensitive disclosures), you may request that we limit processing to what is necessary to provide the Service.

12.6 Right to Non-Discrimination

We will not discriminate against you for exercising your CCPA/CPRA rights.

12.7 Notice at Collection

The categories of personal information we collect, the sources, the purposes, and the categories of recipients are set out in Sections 3, 4 and 5 of this policy. We collect identifiers (name, email, phone number, IP address), commercial information (transaction and credit history), internet activity (feature usage, request metadata), audio and electronic information (voice audio processed in real time for transcription, and the resulting transcripts), professional information (company, job title), and inferences drawn by AI agents in the course of a conversation. We do not collect biometric identifiers, precise geolocation, or government identifiers, and we do not use personal information for purposes materially different from those disclosed here.

12.8 Sensitive Personal Information

We do not collect sensitive personal information for the purpose of inferring characteristics. Conversation and call transcripts may incidentally contain information a person chooses to disclose. We use it only to provide the Service, which is a permitted use that does not trigger the right to limit under CPRA — but you may still ask us to restrict it under Section 12.5.

12.9 How to Exercise

Contact privacy@hiroi.ai or use self-service tools in your account settings. We acknowledge requests within 10 business days and respond to verifiable requests within 45 days, extendable once by a further 45 days where reasonably necessary (we will tell you if we need the extension). An authorized agent may submit a request on your behalf with written permission that we can verify.

12A. Other U.S. State Privacy Rights

If you are a resident of a U.S. state with a comprehensive privacy law (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others as they take effect), you have rights to access, correct, delete, and obtain a portable copy of your personal data, and to opt out of targeted advertising, sale, and profiling with legal or similarly significant effects. We do not sell personal data, do not share it for targeted advertising, and do not use it for profiling that produces legal or similarly significant effects.

Where your state law provides a right to appeal a refused request, you may appeal by replying to our decision or writing to privacy@hiroi.ai with "Appeal" in the subject line. We will respond to an appeal within 45 days and, if we deny it, tell you how to contact your state attorney general.

13. TCPA and Telemarketing Compliance

We store consent records provided by our customers (registered users) to support their TCPA compliance obligations. Customers are responsible for obtaining, maintaining, and providing evidence of consent.

13.2 Do Not Call Registry

hiroi does not scrub contact lists against the National DNC Registry. Customers are responsible for maintaining compliance with DNC obligations for their contact lists.

13.3 Opt-Out Processing

When a contact sends an opt-out keyword (e.g., "STOP", "UNSUBSCRIBE") via SMS, or requests not to be called during a phone interaction, hiroi automatically flags that contact as do-not-contact. This flag is visible to the customer and prevents further automated outreach to that contact through our platform.

14. Contact Agent Privacy (End Contacts)

If you are an individual who received a call, SMS, or email from a hiroi-powered AI agent:

  • The business that deployed the AI agent is the data controller for your information
  • hiroi acts as a data processor on behalf of that business
  • To exercise your data rights (access, deletion, opt-out), contact the business directly
  • To report abuse or unwanted contact, email abuse@hiroi.ai with the phone number or email address used to contact you

15. Widget End-User Privacy

When you interact with an AI agent chat widget on a third-party website:

  • The agent owner (registered user) is the data controller for your conversation
  • hiroi processes your data as a data processor on behalf of the agent owner
  • hiroi collects IP address and user agent for rate limiting and abuse prevention
  • The agent owner's privacy policy governs collection of your data on their website

Agent owners deploying hiroi widgets are responsible for:

  • Including a privacy policy that discloses the use of an AI agent and data collection practices
  • Obtaining any necessary consent from website visitors
  • Providing mechanisms for visitors to exercise data subject rights
  • Ensuring lawful use of the AI agent in their jurisdiction

16. Changes to This Policy

We may update this Privacy Policy periodically. We will notify you of material changes via:

  • Email notification to your registered email address
  • Prominent notice within the Service
  • Updated "Last Updated" date at the top of this page

Your continued use of the Service after changes constitutes acceptance of the updated policy.

17. Contact

For privacy-related inquiries:

TrentApps LLC (d/b/a hiroi) — Privacy 117 S Lexington St, Ste 100 Harrisonville, MO 64701, United States Email: privacy@hiroi.ai

If you are in the EEA or the UK and believe we have not resolved your concern, you have the right to lodge a complaint with your local supervisory authority.

Cookie Preferences

We use essential cookies to make our service work. You can choose to enable optional cookies for a better experience. Learn more

Cookie Preferences

Essential

Required for the service to function

Always On

Analytics

Help us understand how the service is used