airhugdocs
Open app

Help

Security and privacy

How Airhug handles business and customer data, what HIPAA compliance means for healthcare workspaces, which providers touch data, and what Airhug does not claim.

Principles#

  • Each workspace's data is separate. Numbers, knowledge, people, calls, messages and files belong to one workspace and are never used by another. Routing depends on the number that was dialed. A call to a number Airhug does not recognize gets a neutral AI with no business knowledge, never another business's.
  • Security is the same for every plan. Standard workspaces are not less secure than healthcare workspaces. The difference is which providers are used, not whether data is protected.
  • Call audio and transcripts stay in your workspace. Recordings live in encrypted object storage. They are never put in source code or shared between workspaces.
  • The AI does not give medical, legal or financial advice. It collects information, books, and hands off.
  • Access follows roles. Teammates see what their role allows. See team and roles.

HIPAA compliance#

A workspace has HIPAA compliance on when you choose a healthcare category. Everything that can touch patient information then has to run under a signed Business Associate Agreement (BAA).

PartHealthcare workspace (HIPAA on)Standard workspace (HIPAA off)
Hosting, storage, emailAWS, under AWS's BAAAWS
Text AIMicrosoft Azure OpenAI, under Microsoft's BAADirect AI provider APIs (OpenAI)
Voice AIAzure OpenAI realtime, under Microsoft's BAAxAI Grok voice, or OpenAI realtime
Phone callsAmazon Chime SDK plus LiveKit on AWS. See HIPAA phone calls.Twilio
TextingAWS messaging (in rollout)Twilio

A few background features (compliance research, lesson drafting fallbacks and voice cloning) are being moved onto BAA-covered providers for healthcare workspaces. Until that is finished, do not put patient information into those features.

What HIPAA compliance does not mean#

Airhug does not claim SOC 2 or any third-party certification. HIPAA compliance is about how the platform is built and which agreements are in place. You remain responsible for your own obligations as a covered entity or business associate, including your own policies, training and how your team uses Airhug. Do not put patient information into a chat app your organization has not covered.

Turning HIPAA on and off#

It turns on when you choose a healthcare category. It is one-way in the app. Support can turn it off only in narrow cases described in business type and HIPAA.

Providers that handle data#

This list can change. Email hello@airhug.ai for the current authoritative list.

ProviderUsed for
Amazon Web ServicesHosting, encrypted storage, email sending and receiving, Chime and LiveKit phone route for healthcare workspaces
Microsoft AzureAI for healthcare workspaces
OpenAIText and voice AI for standard workspaces
xAIVoice AI for standard workspaces
TwilioPhone numbers and texting for standard workspaces
StripePayments and invoices. Airhug does not store card numbers.
CloudflareDNS and the web console's hosting
GoogleOptional Google sign-in

Website chat privacy#

The chat widget key is public by design and works only on the approved website address. Staff notifications about a waiting visitor are generic and carry no visitor name, email or message.

Your voice recordings#

If you record a custom voice, the raw recording is a voiceprint. It is used only to create the voice, and it is deleted after the upload, whether or not it succeeded.

Deleting your data#

Deleting a workspace deletes its data, including numbers, conversations, people, files and website chat records. Open Settings → Danger zone. Ask hello@airhug.ai about retention questions before you delete.

Reporting a security issue#

Email hello@airhug.ai with details. Do not include patient information in the report.