Privacy Policy
Last updated September 3, 2026
ehllo is a product of EHLLO LTD (“EHLLO LTD”, “we”, “us”), a company registered in England and Wales, Company No. 17434728. EHLLO LTD is the controller of the personal data described here.
ehllo is a relationship workspace: you capture the people you meet, record what mattered, and get help turning that into a follow-up. This policy explains what data we collect, why, and how you stay in control of it — including data we access through optional Google and Microsoft account connections.
Data you give us directly
- Account information — your name, email address, and profile details when you sign up or sign in.
- Contacts and encounters — people you capture, meeting notes, voice recordings you choose to transcribe, and shared meeting summaries.
- Follow-ups — AI-drafted next actions generated from your notes, which you review and approve before anything is sent.
- Events — events you add manually or paste a link for, and your going/not-going status for them.
- Your public card — the profile information you choose to share when someone scans your QR code or visits your public link.
Data from Google and Microsoft (optional)
Connecting a Google or Microsoft account is entirely optional and is separate from signing in to ehllo. If you choose to connect one from Settings, we request only the following, and only for the purposes below:
- Read your calendar (Google Calendar calendar.readonly / Microsoft Calendars.ReadWrite) — we look up which calendars you have and read the title, time, location and attendees of events on them. That is what lets ehllo suggest events worth tracking and, once you confirm a conversation happened during one, link the two together. Reading the list of calendars is what makes meetings on a work or team calendar visible at all; without it only your primary calendar can be seen.
- Create and update events ehllo makes (Google Calendar calendar.events / Microsoft Calendars.ReadWrite) — when you approve a follow-up that needs a meeting, ehllo puts that meeting on your primary calendar, and updates or removes it if you change or cancel the follow-up here. It only ever changes events it created itself; everything already in your calendar is left exactly as it is.
- App-created files (Google Drive drive.file / Microsoft OneDrive app folder) — scoped only to files ehllo itself creates; we cannot see or access any other file in your Drive or OneDrive.
You can disconnect a Google or Microsoft account at any time from Settings → Connected accounts. Disconnecting immediately revokes our access and deletes the stored access/refresh tokens.
How we use your data
- To operate the core product: capturing contacts, recording context, and drafting follow-ups.
- To generate AI summaries, extracted follow-ups and draft messages, and to transcribe recordings you make. See AI processing below for what is sent, to whom, and what we never do with it.
- To detect and suggest calendar events worth tracking, and to put a meeting on your calendar when you approve a follow-up that needs one, if you've connected a calendar.
- To send transactional email (for example, magic-link sign-in) via our email provider.
- To keep the product secure and prevent abuse.
We do not sell your data, and we do not use your private notes or contacts to serve ads.
AI processing
ehllo uses AI to turn what you capture into something useful: a summary of a conversation, the follow-ups it contains, and a draft message. Two kinds of processor are involved, and which one handles your data depends on how ehllo is configured at the time:
- Text (summaries, extracted follow-ups, drafts, and answers from the assistant) — Anthropic (Claude), Google (Gemini) or OpenAI.
- Transcription (audio you record in ehllo) — Groq, Google (Gemini) or OpenAI (Whisper). The audio itself is sent, not just a transcript of it.
What is sent. For a summary, extraction or draft, we send the note or recording that request is about. The assistant is broader: to answer a question about your relationships it is first sent a short index of your workspace — the names of people you have met, the titles and dates of events, whether you were going, a truncated snippet of each summary or note, and the titles of your follow-ups — and then the fuller records for only the items your question concerns. It is never sent your full notes or transcripts to build that index.
Calendar data is included in this, and you can switch it off. If you have connected a Google or Microsoft calendar, the titles and dates of events synced from it can appear in what is sent, because an event title is often the only record of where you met someone. You can stop that without disconnecting anything: in the ehllo app, open Settings → Connected accounts and turn off Use calendar context in AI. With it off, event names and dates are removed from everything sent to an AI provider — enforced on our servers, not just in the app — while your notes, summaries, names and follow-ups are unaffected. It is on by default, because it is what ehllo has always done. Disconnecting the calendar entirely also works, and the rest of ehllo continues either way.
You review everything; AI decides nothing. AI proposes and you dispose. It does not send a message, complete or activate a follow-up, or change a person's details on its own. Nothing drafted for you leaves ehllo until you have read it and chosen to send it.
What we never do. We do not train models on your data. We do not use data obtained from Google APIs — including data obtained through Google Workspace APIs such as Google Calendar — to develop, improve, or train non-personalized AI and/or ML models, and our agreements with the providers above restrict them to processing your data solely to return the result you asked for, not to train their own models. We do not use Google user data for advertising, and we do not sell it or transfer it to data brokers or information resellers. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Data sharing
We share data only with the service providers needed to run ehllo (hosting, database, AI processing, transactional email) under agreements that restrict them to providing that service, and with other ehllo users only to the extent you choose to share it — for example, publishing your card or sending someone a shared meeting summary. We do not share your connected Google or Microsoft data with any third party outside of what's described above.
How we protect your data
We use technical and organizational security measures to protect your data, including the calendar, profile and file data accessed through a connected Google or Microsoft account:
- Encryption in transit. All traffic between your device, ehllo, and the Google and Microsoft APIs is encrypted with TLS (HTTPS). ehllo is not served over unencrypted connections.
- Encryption at rest. Your data is stored in a managed PostgreSQL database (Supabase) with AES-256 disk encryption.
- Extra protection for connected-account credentials. The OAuth access and refresh tokens that let ehllo call Google and Microsoft on your behalf are additionally encrypted at rest in an isolated secrets store and are never exposed through our public API. They can only be decrypted by a server process acting for the account that owns them.
- Per-account isolation. Contact, encounter, calendar and follow-up records are protected by database row-level security, so one account cannot read another account's data.
- Restricted internal access. Access to production systems and data is limited to the ehllo personnel who need it to operate the service, over authenticated connections.
- Least-privilege scopes. ehllo requests only the Google and Microsoft permissions described above; calendar writes and Drive/OneDrive access are limited to events and files ehllo itself creates.
If we become aware of a security incident affecting your data, we will notify affected users and the relevant authorities as required by applicable law.
Retention and deletion
We keep your data for as long as your account is active. You can export or delete individual contacts and encounters at any time from Settings, and you can delete your entire account from Settings at any time.
- Disconnecting a Google or Microsoft account immediately deletes the stored access and refresh tokens for that account, ending ehllo's ability to call that provider. You can also revoke ehllo's access directly from your Google or Microsoft account security settings.
- Deleting your ehllo account removes your contacts, encounters, notes, recordings, follow-ups and connected-account tokens from our production systems within 30 days. Residual copies in encrypted backups age out on our standard backup rotation, after which the data cannot be recovered.
Contact us
The data controller is EHLLO LTD, a company registered in England and Wales, Company No. 17434728. Questions about this policy or your data can be sent to product@ehllo.io.