HAIL.SOAll legal docs

Privacy Policy

Last updated: 2026-07-07

1. Who we are

Hail is a hosted developer platform, operated by Hail HQ ("we," "us"), reachable at hi@hail.so.

Hail lets Developers (our direct customers — the organizations and individuals who hold a Hail account) trigger outbound calls, SMS/text messages, and email programmatically via our API, MCP server, and CLI, to people they choose to contact (Recipients).

This Privacy Policy explains how we handle personal data for two different groups of people, because our legal role is different for each:

  • Developers. When you create a Hail account, we are the controller of your account, billing, and usage data. Section 3 covers you.
  • Recipients. When a Developer uses Hail to call or email someone, we process that person's data on the Developer's behalf, as a processor (GDPR Art. 28). The Developer decides who to contact, why, and with what content — we are not in a direct relationship with, and do not control the purposes for which, Recipient data is processed. Section 4 covers Recipients.

If you are a Recipient with questions about a specific call or email you received, the Developer who initiated it is normally the right first point of contact, since they control the purpose of the contact. Section 7 explains how to reach us directly as well.

Scope note. This Policy covers Hail's hosted cloud product only. Hail is also available under an AGPLv3 self-hosted license. If you interact with a self-hosted Hail instance, that deployment is operated independently by the party running it. Hail HQ is not a controller or processor of, has no visibility into, and has no liability for data processed by self-hosted instances — this Policy does not apply to them.

2. What Hail does (so this Policy makes sense)

Developers use Hail to trigger:

  • Voice calls, placed by Hail's own AI voice agent. Numbers are provisioned through Hail's own Twilio account (Hail does not support Developers bringing their own Twilio account).
  • SMS/text messages, sent via Hail's own Twilio account.
  • Email, sent via AWS SES for all Developer-triggered product email.

Call audio is not recorded or stored. Voice interactions are converted to a text transcript in real time (using speech-to-text and large language model providers listed in Section 5); the audio itself is not retained by Hail. This is our current practice and reflects the product as built today; if that ever changes, we will update this Policy and notify Developers with notice before any change takes effect.

Email content (the raw message) is stored for delivery and audit purposes.

3. Developers: data we collect and why

3.1 What we collect

CategoryExamples
Account dataName, email address, organization name, password/auth credentials
Billing dataBilling contact, payment method (tokenized by Stripe — Hail does not store raw card numbers)
Usage dataAPI calls, calls/emails triggered, volumes, configuration, logs
Support dataMessages, attachments, and metadata from support requests
Technical dataIP address, device/browser information, authentication tokens

3.2 Why we process it (lawful basis)

For Developers, our processing is based primarily on performance of a contract (our Terms of Use / order form with you) — we need this data to create your account, operate the service, and bill you. We also rely on:

  • Legitimate interests — to secure the platform, prevent fraud/abuse, and improve the product.
  • Legal obligation — e.g., retaining billing records as required by tax law.
  • Consent — for optional communications (e.g., marketing emails), where required.

3.3 Sharing

We share Developer data with the sub-processors listed in Section 5 as needed to run the service (e.g., Stripe for billing, Supabase for our database, Vercel for hosting), and as required by law.

3.4 SMS account notifications

If you opt in — via an unchecked checkbox at sign-up — we send SMS account notifications (billing, security, and service alerts) to the mobile number you provide. Consent is optional and not a condition of using Hail. Message frequency varies; message and data rates may apply. Reply STOP to opt out, HELP for help.

Mobile phone numbers and SMS opt-in consent collected for account notifications are not shared with or sold to any third party or affiliate for their marketing or promotional purposes. They are disclosed only to our SMS delivery sub-processor (Twilio, Section 5) as necessary to send the messages, and as required by law.

4. Recipients: data we process on a Developer's behalf

4.1 What we process

When a Developer triggers a call or email through Hail, we process, as applicable to the channel used:

CategoryExamples
Contact informationRecipient phone number or email address, and any name supplied by the Developer
Call contentReal-time audio, transcribed to text transcript only (see Section 2 — audio is not recorded or stored)
SMS/text contentThe message body sent
Email contentThe email message sent, including subject and body
Call/message metadataTimestamps, duration, delivery/status events

4.2 Why this data is processed (lawful basis)

Hail is a processor with respect to Recipient data, not a controller. The Developer determines the purpose and legal basis for contacting a Recipient — typically the Developer's own legitimate interest in reaching the Recipient, or consent the Developer has obtained directly from the Recipient. Hail requires every Developer to warrant that they have a lawful basis and any necessary consent to contact each Recipient, under applicable law (including GDPR, ePrivacy/PECR, TCPA, and CAN-SPAM as relevant). Hail does not independently verify a Developer's basis for contacting a given Recipient before a call or email is sent.

If you are a Recipient and believe a Developer contacted you unlawfully or without your consent, please contact the Developer directly, or contact us using Section 7 and we will assist as the facts and our role allow.

4.3 Sharing

Recipient data is shared only with the sub-processors necessary to deliver the specific call, SMS, or email (Section 5) — for example, Twilio and LiveKit for voice delivery, Twilio for SMS delivery, Deepgram for transcription, and AWS SES for email delivery. We do not sell Recipient data, and we do not use Recipient data to build profiles for our own advertising purposes.

5. Sub-processors

We use a number of sub-processors to provide the Hail service — for example, cloud infrastructure and storage, billing, telephony carriage, voice-agent speech and language processing, and product analytics. The full, current list (name, role, and data categories processed) is published at /legal/subprocessors and is incorporated into this Policy by reference; we keep that page current rather than duplicating it here.

6. International data transfers

Hail and its sub-processors may process data outside your country, including in the United States. Where personal data originating in the EEA, UK, or Switzerland is transferred to a country without an adequacy decision, we rely on appropriate safeguards, including the EU Standard Contractual Clauses (SCCs) and, where a sub-processor participates, the EU-US Data Privacy Framework (DPF). Developers may contact us via Section 7 to request further information about the safeguards applicable to a specific transfer.

7. Data subject access requests and contact

To exercise a data subject right — access, correction, deletion, portability, or objection — or to ask a question about this Policy, contact:

hi@hail.so

We will verify your identity before acting on a request and respond within the timeframe required by applicable law (generally one month under GDPR). If you are a Recipient, we may need to confirm the request with the Developer who initiated contact, since the Developer controls the purpose of processing and may hold the underlying records.

8. Data retention

We retain call transcripts, SMS/text message content, and stored email content for the duration of the Developer's account, plus 12 months after account closure. After that period, this data is deleted or de-identified in accordance with our internal retention policy.

Other data categories (e.g., billing records) may be retained for longer where required by law (such as tax and accounting obligations).

9. Children's data

Hail is not directed at children, and our service may not be used to knowingly place calls or send emails to, or otherwise collect personal data from, children (under 16 in the EEA/UK, or the applicable age of consent in your jurisdiction, or under 13 in the US). Developers are responsible for ensuring they do not use Hail to contact children. If we become aware that we have processed a child's personal data in violation of this section, we will take steps to delete it.

10. Security

We use technical and organizational measures appropriate to the risk, including encryption in transit, access controls, and vendor security review of our sub-processors. No system is completely secure, and we cannot guarantee absolute security of any data transmitted to or stored by Hail.

11. California residents (CCPA/CPRA)

If you are a California resident, you have the right to:

  • Know what personal information we collect, use, and disclose about you, and the categories of sources, purposes, and third parties involved.
  • Delete personal information we hold about you, subject to certain exceptions (e.g., data we must keep for legal compliance).
  • Correct inaccurate personal information.
  • Opt out of "sale" or "sharing" of personal information. Hail does not sell or share personal information as those terms are defined under the CCPA/CPRA, and we have not done so in the preceding 12 months.
  • Non-discrimination for exercising any of these rights.

To exercise any of these rights, contact us using Section 7. We will verify your request before responding.

12. Cookies and analytics

Our website uses cookies and similar technologies, including for product analytics via PostHog, which are active by default. You can opt out at any time via the cookie banner or the preferences described in our Cookie Policy.

13. Changes to this Policy

We may update this Policy from time to time. If we make material changes, we will provide notice (for example, by posting a notice on our site or notifying Developers directly) before the changes take effect.

14. Contact

Hail HQ Contact: hi@hail.so