Help
Security and privacy
How Airhug handles business and customer data, what HIPAA compliance means for healthcare workspaces, which providers touch data, and what Airhug does not claim.
Principles#
- Each workspace's data is separate. Numbers, knowledge, people, calls, messages and files belong to one workspace and are never used by another. Routing depends on the number that was dialed. A call to a number Airhug does not recognize gets a neutral AI with no business knowledge, never another business's.
- Security is the same for every plan. Standard workspaces are not less secure than healthcare workspaces. The difference is which providers are used, not whether data is protected.
- Call audio and transcripts stay in your workspace. Recordings live in encrypted object storage. They are never put in source code or shared between workspaces.
- The AI does not give medical, legal or financial advice. It collects information, books, and hands off.
- Access follows roles. Teammates see what their role allows. See team and roles.
HIPAA compliance#
A workspace has HIPAA compliance on when you choose a healthcare category. Everything that can touch patient information then has to run under a signed Business Associate Agreement (BAA).
| Part | Healthcare workspace (HIPAA on) | Standard workspace (HIPAA off) |
|---|---|---|
| Hosting, storage, email | AWS, under AWS's BAA | AWS |
| Text AI | Microsoft Azure OpenAI, under Microsoft's BAA | Direct AI provider APIs (OpenAI) |
| Voice AI | Azure OpenAI realtime, under Microsoft's BAA | xAI Grok voice, or OpenAI realtime |
| Phone calls | Amazon Chime SDK plus LiveKit on AWS. See HIPAA phone calls. | Twilio |
| Texting | AWS messaging (in rollout) | Twilio |
A few background features (compliance research, lesson drafting fallbacks and voice cloning) are being moved onto BAA-covered providers for healthcare workspaces. Until that is finished, do not put patient information into those features.
What HIPAA compliance does not mean#
Airhug does not claim SOC 2 or any third-party certification. HIPAA compliance is about how the platform is built and which agreements are in place. You remain responsible for your own obligations as a covered entity or business associate, including your own policies, training and how your team uses Airhug. Do not put patient information into a chat app your organization has not covered.
Turning HIPAA on and off#
It turns on when you choose a healthcare category. It is one-way in the app. Support can turn it off only in narrow cases described in business type and HIPAA.
Providers that handle data#
This list can change. Email hello@airhug.ai for the current authoritative list.
| Provider | Used for |
|---|---|
| Amazon Web Services | Hosting, encrypted storage, email sending and receiving, Chime and LiveKit phone route for healthcare workspaces |
| Microsoft Azure | AI for healthcare workspaces |
| OpenAI | Text and voice AI for standard workspaces |
| xAI | Voice AI for standard workspaces |
| Twilio | Phone numbers and texting for standard workspaces |
| Stripe | Payments and invoices. Airhug does not store card numbers. |
| Cloudflare | DNS and the web console's hosting |
| Optional Google sign-in |
Website chat privacy#
The chat widget key is public by design and works only on the approved website address. Staff notifications about a waiting visitor are generic and carry no visitor name, email or message.
Your voice recordings#
If you record a custom voice, the raw recording is a voiceprint. It is used only to create the voice, and it is deleted after the upload, whether or not it succeeded.
Deleting your data#
Deleting a workspace deletes its data, including numbers, conversations, people, files and website chat records. Open Settings → Danger zone. Ask hello@airhug.ai about retention questions before you delete.
Reporting a security issue#
Email hello@airhug.ai with details. Do not include patient information in the report.