Privacy policy

Effective date: August 24, 2026 · Last updated: August 24, 2026

Who we are

Heyline (Builts AI) provides an AI receptionist service for small businesses: it answers a business's phone calls, responds using information the business provides, and books appointments into the business's calendar. Contact: privacy@heyline.ai.

Information we collect

From business owners (our customers):

  • Account details: name, email, business name, phone number.
  • Business information you provide or that we read from your public website (services, hours, location, FAQs) to configure your receptionist.
  • Billing details, processed by our payment provider (Stripe); we do not store card numbers.

From people who try Heyline before creating an account:

  • The website address you enter, and the business information we read from that public website (business name, trade, services, hours, location) to build a sample receptionist for you to try.
  • If you place a test call in your browser, the transcript of that test conversation — kept so it can carry into your account if you decide to sign up.
  • Basic usage data about the attempt (which entry point you used, whether you placed a test call, whether the receptionist was later claimed) so we can understand and improve the sign-up experience. We do not collect your contact details at this stage unless you choose to create an account.

From every visitor to heyline.ai:

  • Website analytics. We use DataFast, a web analytics service, to understand how people find and use heyline.ai: the pages you view, the site or campaign that referred you, your browser and device type, your approximate location (country and region), and actions you take on the site such as starting a test call or creating an account. DataFast sets a first-party cookie holding a random visitor id so a return visit can be recognized as the same browser; it does not contain your name or email.
  • If you create an account, we identify you to the analytics service by a random account identifier — never by your name or email — so we can see which pages lead to sign-ups. If you subscribe, the subscription is linked to the visit that led to it so we can understand which channels bring customers.

From callers to a business using Heyline:

  • Call audio (when recording is enabled by the business), transcripts, caller phone number, and details the caller shares to book an appointment or leave a message (such as name and callback number).
  • If you have contacted this business before, Heyline recognizes your phone number against that business's own record of its prior calls, messages, and appointments, so the receptionist can greet you by name and avoid re-asking for details you have already given (such as your name and callback number). This recognition is per business — your number is never matched across different businesses that use Heyline.
  • Calls answered by Heyline begin with a disclosure that the caller is speaking with an AI assistant and that the call may be recorded.

Google user data

If you connect your Google Calendar, Heyline requests the minimum scopes needed to book appointments on your behalf: checking your free/busy availability and creating or updating events on calendars you own. Heyline never lists your calendar and never reads any event it did not create — it reads back only the appointments it booked for you, to confirm one still exists before moving it. It has no access to your email or any other Google data.

We use this access only to:

  • Check open time slots while a caller is on the phone, and
  • Create appointment events (with the caller's name, number, and job description) on your calendar.

Heyline's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We never sell Google user data, never use it for advertising, and never allow humans to read it except with your consent, for security, or to comply with law. You can disconnect Google Calendar at any time from your dashboard or via your Google account settings, which revokes our access.

AI and Limited Use.Heyline's receptionist is powered by AI. The open time slots computed from your free/busy data are passed to the AI model that speaks with your caller, so it can offer those times out loud. Our use of that data adheres to the Limited Use requirements: we do not use, transfer, or sell Google user data — raw, aggregated, or derived — to create, train, or improve any generalized or foundational artificial-intelligence or machine-learning model, and we do not transfer it to any third-party service that would use it for that purpose.

How we use and share information

We use the information above solely to provide the service: answering calls, booking appointments, and sending you call summaries. We share data only with the service providers that make the product work — voice and telephony infrastructure, AI model providers (to generate the receptionist's responses), hosting, email delivery, and web analytics — each bound to process it only on our instructions. We do not sell personal information.

Retention and deletion

Call recordings and transcripts are retained while the business's account is active, or until the business deletes them. When you close your account, we delete your data, including stored Google tokens, within 30 days. Records of anonymous “try it before signing up” attempts (the website you entered and the sample receptionist we built) are kept to help us understand and improve our sign-up experience; they hold no account contact details. You may request deletion at any time at privacy@heyline.ai.

If you delete one of your receptionists from your dashboard, that receptionist's data is deleted immediately — its call records, transcripts and recordings (including the copies held by our voice provider), messages, appointments, and caller directory — and its phone number is released. Any Google Calendar connection for that receptionist is disconnected and our access revoked at the same time; appointments already created on your calendar remain there. Deleting a receptionist is permanent and cannot be undone.

Security

Data is encrypted in transit and at rest. Google refresh tokens are additionally encrypted at the application layer. Access to production systems is limited and logged.

Changes

We will post any changes to this policy on this page and update the date above. Questions: privacy@heyline.ai.