HeyDr

Privacy Policy

Last updated: September 22, 2026

1. Introduction

Welcome to HeyDr ("we," "our," or "us"). We are committed to protecting your privacy and ensuring the security of the information you share with us. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI Agent services and website (the "Service").

2. Information We Collect

A. Information You Provide to Us: When you register for an account, we may collect business information such as your name, clinic name, email address, phone number, and payment information.

B. Patient Information (PHI): In processing calls and managing appointments on your behalf, we may process Protected Health Information (PHI) provided by the callers. In these instances, we act as a Business Associate under HIPAA frameworks, governed by our Business Associate Agreement (BAA).

C. Automatically Collected Information: We may collect data relating to your usage of our Service, call durations, and technical analytics to improve system performance.

3. How We Use Your Information

  • To provide, operate, and maintain the AI agent and automated booking services.
  • To process and route calls, SMS messages, and calendar data seamlessly.
  • To process your transactions and send related information (e.g., invoices).
  • To monitor and analyze usage patterns and improve the reliability, safety, and performance of the Service.
  • To communicate with you regarding updates, security alerts, and support.

4. Google Workspace API Data & Limited Use

If you connect Google services to HeyDr, we may receive Google Workspace API data, such as Google Calendar data needed to check availability, create or update appointments, and manage scheduling workflows, and Gmail send-only data needed to send clinic-approved email replies.

The use and transfer of raw or derived user data received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

HeyDr does not use Google Workspace API data to develop, improve, or train generalized AI or machine learning models. We use Google Workspace API data only to provide and improve user-facing HeyDr features that you request, maintain security, troubleshoot issues, and comply with applicable law.

A standalone copy of this disclosure is also available at heydr.co/google-limited-use.

5. Third-Party Service Providers

We may share data with service providers needed to operate HeyDr, including Stripe for billing, Google Cloud and Firebase for hosting and authentication, Twilio for telephony, and Google, OpenAI, and ElevenLabs for configured AI or voice features. Processing of protected health information is subject to the applicable service configuration, contractual safeguards, and business associate agreements.

AI processing can include clinic instructions and uploaded knowledge documents, relevant patient messages and conversation history, names and contact details supplied in those conversations, scheduling and appointment details, and audio/transcripts for voice features. Google powers Gemini text and voice features; OpenAI provides configured text fallback and language-model reasoning for ElevenLabs; ElevenLabs processes configured voice calls, speech previews, and voice knowledge documents.

Review the providers, data, and purposes and manage your clinic’s permission in Privacy & AI, also available from Account settings in the mobile app. Declining stops new AI processing without removing access to the manual inbox. Withdrawing permission does not recall processing already underway or delete previously stored data; account deletion is available separately.

6. Data Security & HIPAA Compliance

We implement industry-standard administrative, physical, and technical safeguards designed to protect your data and PHI from unauthorized access, loss, or misuse. However, no data transmission over the Internet or electronic storage system is 100% secure.

7. Data Retention and Deletion

This section describes HeyDr's data-retention practices. We store and retain data only for the periods and purposes described below.

  • Active clinic workspaces: We retain account profiles, clinic configuration, patient conversations, appointments, uploaded media, connected-channel credentials and device registrations while the clinic workspace is active and as needed to provide the Service.
  • Verified deletion requests: We aim to remove the account and its associated data from active systems within 2 business days after verification.
  • Backups and recovery: Encrypted database backups retain the most recent 7 backups, and point-in-time recovery logs are retained for 7 days. Deleted data ages out automatically as those backup cycles complete and is not restored to active systems except for disaster recovery.
  • Limited exceptions: We retain only limited billing, security, fraud-prevention, or regulatory records when required by law, and only for the applicable required period. When retention is no longer required, the records are deleted or de-identified.

A clinic administrator or account holder can request deletion in HeyDr account settings, by emailing gal@heydr.co from the account address, or through our Data Deletion Instructions.

8. Your Rights & Choices

Depending on your jurisdiction, you may have the right to request access to, correction of, or deletion of your personal data. You may update your account settings at any time or contact us directly to exercise these rights.

9. Contact Us

If you have questions or comments about this Privacy Policy or our privacy practices, please contact us at:

Email: gal@heydr.co