Privacy Policy
Last updated: 9 October 2026
Hia (“we”, “us”) is software that helps independent health and wellness practitioners run their practice. This policy explains what we collect, why, who helps us process it, how long we keep it, and how to have it deleted. Questions or requests: hey@gethia.com.
Who is responsible for what
Practitioners (the people who sign up for Hia) decide why and how their clients' and prospects' personal data is used. For that data, which includes client contact details, messages, session recordings, transcripts and notes, the practitioner is the one responsible (in the language of India's Digital Personal Data Protection Act, the data fiduciary) and Hia acts as their service provider, processing it on their instructions and for no other purpose. For the practitioner's own account, sign-in and billing details, Hia is responsible.
If you are a client of a practitioner and want to see, correct or delete your data, ask your practitioner first. You can also write to us and we will pass the request on to them or act on it as the law requires.
What we collect
- Practitioner account: name, email, password (stored only as a one-way hash), sign-in with Google details (your Google account email, name and profile identifier), practice name and settings, subscription status.
- Client and prospect data the practitioner adds or receives: names and contact details, enquiries, conversations (including messages that arrive through your Hia web chat, booking page and enquiry form, and through a connected Instagram account or Facebook Page), leads from the practitioner's Facebook and Instagram Lead Ads forms, and comments and replies on the practitioner's own Instagram, Facebook and Threads posts, appointments, forms, invoices and payment status, notes.
- Session data: audio recordings a practitioner uploads or records, the transcripts produced from them, and the notes, summaries and client takeaways prepared from them. These are private to the practice.
- Connected account data: when a practitioner connects an account, Hia receives only what that connection needs (see “Connected accounts” below). Access credentials for connected accounts are stored encrypted.
- Payments metadata: payment link and invoice identifiers, amounts, status and provider reference numbers. We do not receive or store card or bank details; those stay with the payment provider.
- Usage and technical data: basic operational logs (for example errors, request times, which provider call succeeded or failed) and in-product usage figures used to run billing limits and show practitioners how their practice is doing. We do not use third-party advertising or tracking scripts.
- Cookies: only essential ones: your signed-in session, the short-lived state used during Sign in with Google, and referral attribution when you arrive from a referral link.
How we use it
Only to provide the features the practitioner asked for: answering enquiries, booking and reminders, preparing session notes, publishing content they approve, running ads they approve, collecting payments, showing how the practice is doing, keeping the service secure, billing for Hia, and meeting legal obligations. We do not sell personal data, and we do not use it for advertising or to build profiles for third parties.
Connected accounts
A practitioner can connect the accounts listed below. We access an account only after the practitioner connects it, only for the purpose stated, and only with the permissions that purpose needs.
- Instagram (Instagram professional account): read and reply to direct messages people send to the account, publish posts the practitioner approves, read and reply to (or hide) comments on the practitioner's own posts, and read basic profile and post statistics.
- Facebook Page and Messenger (Meta): read and reply to Messenger conversations with the Page, publish Page posts the practitioner approves, read and reply to (or hide) comments on the Page's own posts, read post statistics, and receive leads submitted through the Page's Lead Ads forms (the answers the person chose to submit, the form and the ad they came from).
- Threads (Meta): publish posts the practitioner approves, read and reply to (or hide) replies on the practitioner's own posts, and read post statistics. Threads does not offer direct messages to apps, so Hia does not read any Threads messages.
- Meta Ads: create campaigns (always paused first), launch, pause and change the budget of campaigns the practitioner approves, and read their spend and results. Hia does not upload client lists, create custom or lookalike audiences, target by health condition, or send client or session data to Meta.
- Google Ads: create, pause and resume ad campaigns the practitioner approves and read their results.
- Google Calendar: read when the practitioner is busy (not the content of events) and create, update and cancel the events Hia makes for bookings.
- LinkedIn: publish posts the practitioner approves to their own personal profile. Hia does not read messages or connections.
- Razorpay: using API keys the practitioner pastes in, create payment links on the practitioner's own account, read their status, and issue refunds the practitioner requests. Money goes to the practitioner's account, not to Hia.
Hia only processes private conversations people start with the connected account and comments on the practitioner's own posts. It does not read other accounts' posts or comments, and does not scrape or collect data about people who have not contacted or engaged with the practitioner. Client records, session recordings, transcripts and clinical notes are never sent to Meta.
Meta platform data (Instagram, Facebook, Messenger, Threads, Lead Ads, Meta Ads)
This section applies when a practitioner connects Instagram, a Facebook Page, Threads or Meta Ads to Hia. Hia is an independent product. It is not made, endorsed or approved by Meta, and Meta's own terms and policies also apply to the accounts a practitioner connects.
What we process
- Identifiers and names for the connected Meta user, Facebook Page, Instagram professional account, Threads profile and ad account.
- Messages people send to the practitioner's Instagram account or Facebook Page through Instagram and Messenger, and the replies the practitioner sends back, with the sender's Meta-scoped ID and the name or handle Meta provides.
- Public comments and replies on the practitioner's own posts (Instagram, Facebook Page, Threads).
- Posts the practitioner publishes through Hia, and their engagement and insight figures (for example reach, likes, replies).
- Lead Ads form submissions for the connected Page: the answers the person chose to submit, the form and the ad they came from.
- Ad account details (name, currency), campaigns Hia creates for the practitioner, and their spend and performance figures.
- Connection details: which permissions were granted, when the connection was made, and its status. The access tokens themselves are stored encrypted (see “How we protect it”).
Why, and how it is used
The practitioner chooses to connect each account, and each one separately. Hia then uses the data only for what that connection is for: publishing content the practitioner approves, managing engagement (answering comments and replies), bringing enquiries from Instagram and Messenger into Reception and Inbox, importing Lead Ads leads, running ad workflows the practitioner approves, and showing analytics. Hia does not use Meta data for any other purpose.
Where it is stored and who processes it
Meta data is stored in Hia's database on Google Cloud in Mumbai (asia-south1) and is visible only to the practice that connected the account. AI processing of message text happens in two situations: when a practitioner asks Hia to read or draft a reply to a message, and when Hia's reception assistant is switched on for new enquiries (Settings → Hia → Answering new enquiries), in which case the text of a new enquiry that arrives by Instagram or Messenger, together with the earlier messages in that same conversation, is sent to Hia's AI processors listed under “Who processes data for us” (Sarvam AI and Google Vertex AI) so Hia can draft a reply. By default Hia only drafts: the practitioner reads the suggestion and presses Send. Hia sends a reply to a new enquirer by itself only if the practitioner has turned on “Let Hia answer new enquiries” for Instagram and Messenger (Settings → Hia → Communication, off by default) and chose automatic mode. Replies to clients are never composed by AI over Instagram or Messenger, and AI-composed replies to prospects are checked by fixed rules before sending. Comments are sorted into categories by fixed keyword rules, without an AI model. Meta data is not shared with anyone else.
What Hia does not do
- Hia does not sell Meta data or share it with data brokers.
- Hia does not build advertising profiles of people, and does not use Meta data for advertising of its own.
- Hia does not train AI models on private clinical data or on the content of Meta conversations.
- Hia does not target ads by health condition, and does not upload client lists or create custom or lookalike audiences from client data.
- Hia does not send clinical records, session notes, transcripts or client notes through Meta. Sensitive conversations with clients are continued securely inside Hia, and Hia blocks health details and private links from being sent over Instagram and Messenger.
- Hia does not read other accounts' posts or comments, and does not read messages that were not sent to the connected account or Page. Threads has no direct messages for apps, so Hia reads none.
Retention
Messages, comments and leads stay in the practice while the practitioner keeps them. Meta webhook notifications Hia has already processed are deleted from our processing queue after 30 days. Disconnecting an account or removing Hia in Meta deletes the stored tokens and subscriptions immediately. When a person removes Hia in their Meta settings, Hia also cancels that account's scheduled posts, redacts the text of Meta direct messages, and deletes comments and Lead Ads answers received through the connection; Meta-origin contacts who were only enquiries are anonymised. Records the practitioner created in Hia itself (appointments, invoices, payments, sessions and clinical records) are kept for the practice. Details are on the data deletion page.
How to disconnect, and how to ask for deletion
- In Hia: Integrations, Meta, then Disconnect on the account.
- In Meta: remove Hia from your Facebook or Instagram settings (Apps and Websites) or Threads settings. Meta tells Hia and the removal above runs automatically; you get a confirmation code you can check at /data-deletion/status.
- To request deletion of data held about you, see data deletion, or write to hey@gethia.com.
Google user data
Hia's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- Sign in with Google uses your name, email address and profile identifier to create and recognise your Hia account.
- Google Calendar data is used only to provide the user-facing features described above, inside Hia, for the practitioner who connected it.
- We do not use Google user data for advertising, and we do not sell or transfer it, except as needed to provide the feature, to comply with law, or as part of a merger or sale with notice to you.
- No person at Hia reads your Google data unless you ask us to, it is needed to investigate abuse or a security issue, or the law requires.
- Hia also sends its own emails (verification, password reset, notifications) through the Gmail API from a Hia-owned mailbox; this does not involve any practitioner's Google data.
Who processes data for us
- Google Cloud (Mumbai, India region, asia-south1): hosts the Hia application, database and file storage.
- Sarvam AI: speech-to-text for session recordings, and language-model processing for drafts, summaries and Ask Hia.
- Google Vertex AI (Gemini, Mumbai region): fast language-model replies in Ask Hia and similar short drafting tasks.
- Dodo Payments: collects and processes payment for Hia subscriptions.
- Google (Gmail API): delivers Hia's own transactional emails.
- The providers a practitioner connects (Meta, Google, LinkedIn, Razorpay, OpenAI), only to do what the practitioner asked. Those providers have their own policies.
These providers process data on our behalf or on the practitioner's instructions and may not use it for their own purposes under our arrangements with them. Some, such as Meta or Sarvam, may process data outside India as part of their own services. If we add or change a processor we will update this page.
AI processing and approvals
To draft replies, summaries and plans, relevant content is sent to the AI processors above. Hia does not permit your data to be used to train general-purpose models. Anything that would be sent to a client, published, or spend money on ads on the practitioner's behalf is shown to the practitioner for approval unless they have chosen automatic mode for that kind of action. Session transcripts are treated as private, untrusted text and cannot trigger actions on their own.
How we protect it
- Each practice's data is separated from every other practice's in our database, by application checks on every query and, for the AI assistant, a database-level row security policy as a second layer.
- Access credentials for connected accounts are encrypted at rest with AES-256-GCM, tied to the practice and connection they belong to, decrypted only for the moment a request to the provider is made, and never shown in the app, logged, or given to the AI model.
- Passwords are stored as one-way hashes. Connections use encrypted channels (HTTPS).
- Incoming provider notifications are verified before they are acted on.
- No security system is perfect and Hia does not hold formal certifications such as ISO 27001 or SOC 2 at this time. If a breach affects your data we will tell the affected practitioners and, where the law requires, the authorities.
Retention and deletion
- Disconnecting an account: a practitioner can disconnect any connected account in Integrations at any time. Hia stops using it, asks the provider to revoke access where the provider supports that, and deletes the stored credentials immediately. Messages and records already received stay in the practice until deleted (for Meta accounts, see “Meta platform data” above).
- Records: practice records stay while the account is active, or until the practitioner deletes them.
- Deleting a practice: email hey@gethia.com from your account email (see data deletion). We delete the practice and its data within 30 days. Copies in encrypted database backups age out on a rolling schedule of about 14 days after that. We may keep a minimum of billing and tax records where the law requires.
- Removing Hia from Meta: if you remove Hia in your Facebook, Instagram or Threads settings, Meta notifies us and we disconnect the account, delete its stored credentials and remove the Meta data described above automatically. You get a confirmation code you can look up on the status page.
- Hia's own logs are kept for a limited period for security and debugging.
Your rights
You can ask to access, correct, export or delete your data and to withdraw consent by writing to hey@gethia.com. You may also nominate someone to exercise these rights for you. If you are in India and are not satisfied, our grievance contact is the same address; we aim to respond within 30 days. You may also approach the Data Protection Board of India once it is operational.
Children
Hia is for practitioners and is not directed at children. Practitioners are responsible for obtaining any guardian consent needed for clients who are minors.
Changes
We will post updates here with a new date and, for material changes, tell practitioners in the app or by email.
See also: Terms of Service · Security · Data deletion · Contact