Security at Hedy AI

Your conversations are private. Your intelligence is protected.

Core Security Principles

🔒 Privacy by Design

Speech recognition runs locally on your device. Your conversation audio never leave your control unless you explicitly share it.

🎛️ User Control

You decide what's shared, what's synced, and what's deleted. Your data, your rules.

🔍 Transparent Operations

Clear documentation about how we handle data, who we work with, and what protections are in place.

Compliance & Certifications

GDPR Valid

Full compliance with European data protection regulations including Data Processing Agreements and Standard Contractual Clauses.

SOC 2 Type II Certification: Q1 2026

Comprehensive security controls audit covering security, availability, processing integrity, confidentiality, and privacy. Currently undergoing certification.

HIPAA Certification: Q1 2026

Healthcare data protection compliance for medical conversations. Business Associate Agreements will be available. Currently undergoing certification.

Trust Center and Documentation

Access comprehensive security documentation, compliance certificates, and legal agreements.

Data Protection & Privacy

On-Device Processing

Your conversation audio stays on your device by default. Speech recognition powered by on-device models, with audio recordings remaining on your device unless explicitly shared.

Optional Cloud Storage

You can decide if you want to store your conversations only on your own device or sync it to our secure cloud servers so you can access it across multiple devices.

Transient AI Processing

Data is sent anonymously to our AI processing partners and is not stored or used for training AI models.

How We Protect Your Data

  • End-to-End Encryption: All data transmission uses TLS 1.3
  • Encryption at Rest: AES-256 encryption for stored data
  • Zero Training on Your Data: Your conversations are never used to train AI models
  • Temporary Processing: Cloud analysis happens in memory, not stored

Frequently Asked Questions

Is my meeting data used to train AI models?

No. We have strict agreements with all AI providers prohibiting the use of your data for training. Your conversations are processed only to provide immediate insights, then discarded.

Where is my data stored?

Audio recordings: Only on your device

Transcripts & summaries: On your device, or in encrypted GCP storage if cloud sync is enabled

Account data: Encrypted in Google Cloud Platform data centers

Can Hedy employees access my conversations?

No. We follow a zero-trust model with no default access to production data. Any access requires business justification, security approval, and is logged for audit.

How do I delete all my data?

Go to Account Settings → Delete Account. All your session data on our servers will be permanently removed within 30 days.