Privacy policy

Who we are

Heyline (operated by Builts AI) provides an AI receptionist service for small businesses: it answers a business’s phone calls, responds using information the business provides, and books appointments into the business’s calendar. Contact: privacy@heyline.ai.

Information we collect

From business owners (our customers)

From people who try Heyline before creating an account

From callers to a business using Heyline

Google user data

If you connect your Google Calendar, Heyline requests the minimum scopes needed to book appointments on your behalf: checking your free/busy availability and creating or updating events on calendars you own. Heyline does not read the contents of your existing calendar events, your email, or any other Google data.

We use this access only to:

Heyline’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We never sell Google user data, never use it for advertising, and never allow humans to read it except with your consent, for security, or to comply with law. You can disconnect Google Calendar at any time from your dashboard or via your Google account settings, which revokes our access.

How we use and share information

We use the information above solely to provide the service: answering calls, booking appointments, and sending you call summaries. We share data only with the service providers that make the product work — voice and telephony infrastructure, AI model providers (to generate the receptionist’s responses), hosting, and email delivery — each bound to process it only on our instructions. We do not sell personal information.

Retention and deletion

Call recordings and transcripts are retained while the business’s account is active, or until the business deletes them. When you close your account, we delete your data, including stored Google tokens, within 30 days. Records of anonymous “try it before signing up” attempts (the website you entered and the sample receptionist we built) are kept to help us understand and improve our sign-up experience; they hold no account contact details. You may request deletion at any time at privacy@heyline.ai.

Security

Data is encrypted in transit and at rest. Google refresh tokens are additionally encrypted at the application layer. Access to production systems is limited and logged.

Changes

We will post any changes to this policy on this page and update the date above. Questions: privacy@heyline.ai.