Privacy Policy
This Privacy Policy explains how Heidi collects, uses, shares, and protects your personal data when you use our AI meeting copilot and related services.
1. Overview and scope
Heidi is an AI meeting copilot, a "Meeting OS" that, with your action, joins your video meetings through a recording bot, then records, transcribes, and analyzes them. Heidi provides live in-call coaching and real-time room scoring (such as Pulse, Trust, and Impact signals), prepares you before meetings, and drafts or executes follow-ups afterwards. To do this, Heidi processes personal data, and we take that responsibility seriously.
This Privacy Policy describes what personal data we collect through our website (hi-heidi.ai), our application (app.hi-heidi.ai), and the services connected to them, how we use and share that data, the legal bases on which we rely, and the rights and choices available to you. It applies to visitors, account holders, and the meeting participants whose information may be processed when a Heidi user records or analyzes a meeting.
Heidi is built EU-first. Our infrastructure is hosted in Europe and our practices are designed around the EU General Data Protection Regulation (GDPR). Where we act as a controller of your personal data, the controller is ID Digital Lab, 17 Rue de Rosheim, 67000 Strasbourg, France. Where we process meeting content and connected data on behalf of a business customer, we generally act as that customer's processor under their instructions and the terms of our agreement with them.
2. Information you provide to us
When you create an account or interact with Heidi, you give us certain information directly. This includes your account and profile details, such as your name, email address, password credentials, organization or team name, role, and any preferences or settings you configure.
If you subscribe to a paid plan, our payment processor Stripe collects and processes your billing details (such as card information and billing address) to complete the transaction. Heidi does not store full card numbers; that data is handled by Stripe under its own security standards.
We also collect information you provide when you contact us for support, respond to surveys, or otherwise communicate with us, including the content of those messages and any attachments you choose to send.
3. Meeting content: audio, video, transcripts, summaries, and scores
The core of Heidi's service involves meeting content. When you direct Heidi to join a meeting, our bot captures the meeting's audio and, where applicable, video. From that recording, Heidi generates transcripts and AI-produced outputs such as summaries, action items, coaching notes, and real-time room scores (for example, Pulse, Trust, and Impact signals).
This meeting content may include the personal data of everyone present in the meeting, not just the Heidi account holder. It can contain voices, faces, names, opinions, and any other information spoken or shown during the session. Because this is sensitive material, we apply the security and retention measures described later in this policy and restrict how it is used.
Meeting content is processed to deliver the features you request and is not used to train foundation or general-purpose AI models. Our AI and voice vendors are contractually restricted from using your content to train their models.
4. Connected data: calendar, contacts, emails, and CRM
Heidi becomes more useful when you connect it to the tools you already use. If you choose to connect an integration, we access and process data from those sources so Heidi can prepare for meetings, enrich contact intelligence, and draft or execute follow-ups.
Depending on what you connect, this may include calendar events and invitee lists (to know which meetings to join and to prep you beforehand), contacts (to power contact intelligence), email content and metadata (to draft and send follow-ups), and CRM records (to log outcomes and keep your systems in sync).
You control which integrations are connected and can disconnect them at any time from your settings. When you disconnect an integration, Heidi stops accessing new data from that source; data already processed is handled according to the retention rules in this policy.
5. Usage, device, and log data
When you use Heidi, we automatically collect certain technical information. This includes usage data (such as features accessed, meetings processed, and actions taken within the app), device and browser information (such as device type, operating system, and browser version), and log data (such as IP address, timestamps, and diagnostic or error information).
We use this information to operate and secure the service, understand how Heidi is used, troubleshoot problems, and improve performance and reliability. It is not the substance of your meetings; it is the operational data that keeps the product running well.
Where required, we use cookies and similar technologies for authentication, preferences, and analytics. You can manage cookies through your browser settings, though disabling some may affect how the service works.
6. How we use your information
We use the information described above to provide and operate Heidi: to join, record, and transcribe your meetings; to generate summaries and real-time room scores; to deliver live coaching; and to power agentic preparation before meetings and follow-ups after them. We also use it to provide contact intelligence and to keep your connected calendar, CRM, and communications tools in sync.
Beyond delivering these features, we use information to authenticate users, provide customer support, process payments, communicate service and account notices, maintain and improve the reliability and quality of the product, and protect the security and integrity of Heidi and our users.
We do not use your meeting content or connected data to train foundation or general-purpose AI models, and we contractually restrict our AI, voice, and recording vendors from doing so. Any improvement of the service is carried out with appropriate safeguards and never involves selling your personal data.
7. Legal bases for processing (GDPR)
Where the GDPR applies, we rely on the following legal bases to process your personal data. We process data to perform our contract with you, that is, to provide the Heidi service you have signed up for and to deliver the features you request.
We rely on legitimate interests to secure and improve the service, prevent fraud and abuse, and communicate with you about your account, provided those interests are not overridden by your rights and freedoms. Where required by law, for example, for certain uses of connected data or optional cookies, we rely on your consent, which you may withdraw at any time. We also process data where necessary to comply with our legal obligations.
Where Heidi processes meeting content and connected data on behalf of a business customer, that customer determines the purposes and legal bases as controller, and Heidi acts as processor under the customer's instructions.
8. How we share your information
We do not sell your personal data. We share it only in the circumstances described here.
We use trusted sub-processors to deliver the service, each engaged under contractual data-protection terms, including Stripe (payment processing), alongside vetted providers for our meeting-recording infrastructure (itself SOC 2, HIPAA and ISO 27001 certified), EU cloud hosting and database, AI and language-model processing, and voice. These vendors process data only to provide their services to us and are restricted from using your meeting content to train their models. A current, full sub-processor list is available to business customers on request.
Meeting content may also be visible to other participants and to the account or workspace on whose behalf a meeting is recorded, for example, recordings, transcripts, and summaries may be shared within your team according to your settings. We may disclose information to comply with valid legal requests, court orders, or applicable law, and to protect the rights, safety, and security of Heidi, our users, and the public. Finally, if Heidi is involved in a merger, acquisition, financing, or sale of assets, personal data may be transferred as part of that transaction, subject to the protections of this policy.
9. Google user data and Limited Use
When you choose to connect a Google account, Heidi accesses certain Google user data through Google APIs so it can deliver the features you request. Depending on the permissions you grant, this may include your Google Calendar events and invitee lists (to know which meetings to join and to prepare you beforehand), your Gmail messages and the ability to draft and send email on your behalf (to create and send meeting follow-ups), and read-only access to your Google Drive files (to reference documents inside the app). You choose which of these to connect, connect them one feature at a time, and can disconnect them at any moment from your settings.
Heidi's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we use Google user data only to provide and improve the user-facing features described above; we do not sell Google user data; we do not use it for advertising; and we do not use it, or transfer it, to develop, improve, or train generalized or foundation artificial-intelligence or machine-learning models. Humans do not read your Google data except with your explicit consent, where necessary for security purposes (such as investigating abuse), to comply with applicable law, or on data that has been aggregated and de-identified.
We request the narrowest Google permissions needed for each feature, and ask for additional access only when you activate the corresponding feature. If we ever intend to use Google user data for a materially different purpose, we will ask for your consent first.
10. Recording and participant consent
Heidi is a recording product, and recording carries legal responsibilities. Laws on recording meetings, calls, and conversations differ by country, state, and region, some require that all participants be notified, and some require the explicit consent of everyone present.
As the Heidi user who initiates a recording, you are responsible for knowing and complying with the laws that apply to you and your participants, and for providing any notice and obtaining any consent those laws require before recording, transcribing, or analyzing a meeting. Heidi provides tools and indicators to help, but the obligation to notify participants and obtain their consent rests with you.
By using Heidi to record or analyze a meeting, you confirm that you have the necessary rights and permissions to do so. If a participant does not consent, you should not record that meeting with Heidi.
11. International data transfers
Heidi is hosted in Europe, and we design our processing to keep personal data within the European region wherever possible. This EU-first approach is a deliberate part of how we build the product.
Some of our sub-processors may process limited data outside the European Economic Area. Where any transfer of personal data outside the EEA occurs, we put appropriate safeguards in place, such as the European Commission's Standard Contractual Clauses or reliance on an adequacy decision, so that your data continues to receive a level of protection consistent with the GDPR.
If you would like more information about the safeguards applied to a specific transfer, you can contact us using the details at the end of this policy.
12. Data retention and deletion
We keep your account data for as long as your account is active and you continue to use Heidi. This allows us to provide the service and preserve your meetings, transcripts, summaries, and settings.
If you cancel your account, we retain your data for approximately 30 days after cancellation and then delete it, except where a longer period is required to comply with legal obligations, resolve disputes, or enforce our agreements. This short window gives you the opportunity to reactivate or recover information before it is removed.
You remain in control throughout: you can export your data or delete specific meetings and content at any time from within the app, and you can request deletion of your account and associated personal data as described in the next section.
13. Security
We take the protection of your data seriously and apply technical and organizational measures designed to safeguard it. Personal data and meeting content are encrypted in transit and at rest, access is restricted on a need-to-know basis, and we monitor our systems to detect and respond to potential threats.
Our meeting-recording infrastructure is SOC 2, HIPAA and ISO 27001 certified. Heidi is EU-hosted and GDPR-oriented, and we are also pursuing our own SOC 2 and HIPAA readiness; those efforts are in progress and Heidi is not itself SOC 2 or HIPAA certified yet. We will update this policy and our security materials as our compliance program matures.
No method of transmission or storage is completely secure, so while we work hard to protect your information, we cannot guarantee absolute security. If we become aware of a personal data breach that affects you, we will notify you and the relevant authorities as required by applicable law.
14. Your rights and choices
Subject to applicable law, and in particular the GDPR, you have rights over your personal data. These include the right to access the data we hold about you, to have inaccurate data corrected (rectification), to have your data erased, to receive your data in a portable format, to restrict or object to certain processing, and to withdraw consent where processing is based on consent.
You can exercise many of these rights directly in the app, for example, by updating your profile, exporting your data, or deleting meetings and your account. For other requests, contact us at info@hi-heidi.ai and we will respond within the timeframes required by law. We may need to verify your identity before acting on a request.
If Heidi processes your data as a processor on behalf of a business customer, we will direct or forward your request to that customer, who acts as the controller. You also have the right to lodge a complaint with your local data protection authority.
15. Children, changes, and how to contact us
Heidi is not intended for children. The service is meant for adults in a professional context, and we do not knowingly collect personal data from anyone under the age of 18, or under 16 where that is the applicable age of consent. If you believe a minor has provided us personal data, please contact us so we can remove it.
We may update this Privacy Policy from time to time to reflect changes in our service, technology, sub-processors, or legal requirements. When we make material changes, we will update the "last updated" note and, where appropriate, notify you through the app or by email. Your continued use of Heidi after an update means you accept the revised policy.
If you have questions about this policy or how we handle your data, contact us at info@hi-heidi.ai. The data controller responsible for your personal data is ID Digital Lab, 17 Rue de Rosheim, 67000 Strasbourg, France. Any questions of governing law or jurisdiction relating to this policy are governed by French law, and the courts of Strasbourg, France have exclusive jurisdiction.
Questions about this document? See the contact page, a real human reads every message.