# Security and privacy

> How Airhug handles business and customer data, what HIPAA compliance means for healthcare workspaces, which providers touch data, and what Airhug does not claim.

Source: https://docs.airhug.ai/help/security-and-privacy
Last updated: 2026-09-29

## Principles

- **Each workspace's data is separate.** Numbers, knowledge, people, calls, messages and files belong to one workspace and are never used by another. Routing depends on the number that was dialed. A call to a number Airhug does not recognize gets a neutral AI with no business knowledge, never another business's.
- **Security is the same for every plan.** Standard workspaces are not less secure than healthcare workspaces. The difference is which providers are used, not whether data is protected.
- **Call audio and transcripts stay in your workspace.** Recordings live in encrypted object storage. They are never put in source code or shared between workspaces.
- **The AI does not give medical, legal or financial advice.** It collects information, books, and hands off.
- **Access follows roles.** Teammates see what their role allows. See [team and roles](https://docs.airhug.ai/setup/team-and-roles.md).

## HIPAA compliance

A workspace has HIPAA compliance on when you choose a healthcare category. Everything that can touch patient information then has to run under a signed Business Associate Agreement (BAA).

| Part | Healthcare workspace (HIPAA on) | Standard workspace (HIPAA off) |
| --- | --- | --- |
| Hosting, storage, email | AWS, under AWS's BAA | AWS |
| Text AI | Microsoft Azure OpenAI, under Microsoft's BAA | Direct AI provider APIs (OpenAI) |
| Voice AI | Azure OpenAI realtime, under Microsoft's BAA | xAI Grok voice, or OpenAI realtime |
| Phone calls | Amazon Chime SDK plus LiveKit on AWS. See [HIPAA phone calls](https://docs.airhug.ai/channels/hipaa-phone.md). | Twilio |
| Texting | AWS messaging (in rollout) | Twilio |

A few background features (compliance research, lesson drafting fallbacks and voice cloning) are being moved onto BAA-covered providers for healthcare workspaces. Until that is finished, do not put patient information into those features.

### What HIPAA compliance does not mean

Airhug does not claim SOC 2 or any third-party certification. HIPAA compliance is about how the platform is built and which agreements are in place. **You remain responsible for your own obligations as a covered entity or business associate**, including your own policies, training and how your team uses Airhug. Do not put patient information into a chat app your organization has not covered.

## Turning HIPAA on and off

It turns on when you choose a healthcare category. It is one-way in the app. Support can turn it off only in narrow cases described in [business type and HIPAA](https://docs.airhug.ai/setup/business-type-and-hipaa.md).

## Providers that handle data

This list can change. Email [hello@airhug.ai](mailto:hello@airhug.ai) for the current authoritative list.

| Provider | Used for |
| --- | --- |
| Amazon Web Services | Hosting, encrypted storage, email sending and receiving, Chime and LiveKit phone route for healthcare workspaces |
| Microsoft Azure | AI for healthcare workspaces |
| OpenAI | Text and voice AI for standard workspaces |
| xAI | Voice AI for standard workspaces |
| Twilio | Phone numbers and texting for standard workspaces |
| Stripe | Payments and invoices. Airhug does not store card numbers. |
| Cloudflare | DNS and the web console's hosting |
| Google | Optional Google sign-in |

## Website chat privacy

The chat widget key is public by design and works only on the approved website address. Staff notifications about a waiting visitor are generic and carry no visitor name, email or message.

## Your voice recordings

If you record a custom voice, the raw recording is a voiceprint. It is used only to create the voice, and it is deleted after the upload, whether or not it succeeded.

## Deleting your data

Deleting a workspace deletes its data, including numbers, conversations, people, files and website chat records. Open **Settings → Danger zone**. Ask [hello@airhug.ai](mailto:hello@airhug.ai) about retention questions before you delete.

## Reporting a security issue

Email [hello@airhug.ai](mailto:hello@airhug.ai) with details. Do not include patient information in the report.
