Hedy AI

Hedy AI Trust Center

Privacy, security, and compliance at Hedy

Hedy provides privacy-first conversation intelligence for professionals. Speech recognition runs locally on your device, and with Local AI Processing, AI analysis can stay on-device too — keeping your transcripts and AI-generated content entirely on your machine.

Private by design: your audio is never uploaded to our servers, and any cloud-based AI analysis processes transcripts transiently — encrypted in transit, with no user-identifying metadata, no retention, and no training. You decide whether anything leaves your machine.

Compliance & Attestations

Independent audits and compliance frameworks.

GDPR Compliant

GDPR Compliant

Valid

European data protection and privacy compliance

SOC 2 Type I

SOC 2 Type I

Valid

Independent SOC 2 Type I examination of our security controls (Trust Services Criteria for Security), issued April 2026. Full report available under NDA.

HIPAA

HIPAA

Valid

Independently assessed against the U.S. HHS HIPAA Audit Program as a Business Associate. Report available under NDA.

Resources & Documentation

Documentation on GDPR, DPA, compliance, and more.

Public

Guidance on Fulfilling Your GDPR Accountability When Using Hedy AI

English – Public guidance for GDPR compliance

Public

Anleitung zur Umsetzung Ihrer DSGVO-Compliance bei Nutzung von Hedy AI

Deutsch – Öffentliche DSGVO-Anleitung

Public

Expert's Confirmation on the Contractual Framework for GDPR Data Processing

English – Public expert confirmation

Public

Data Processing Addendum (full text)

The binding DPA, including the sections its Annexes reference

Public

Transparency Report

Government and law enforcement requests for customer data

Public

Government Data Request Response Policy

How we respond to government requests for customer data

Confidential

SOC 2 Type I Report

Available only under a signed NDA.

Confidential

HIPAA Report on Compliance

Available only under a signed NDA.

Restricted

Transfer Impact Assessment

Restricted

Together.AI DPA

Public

Privacy Policy

Hedy AI Privacy Policy

Restricted

DPA Annex I

Restricted

DPA Annex II

Restricted

DPA Annex III (sub-processors and other recipients)

Security Measures

Comprehensive security controls protecting your data and infrastructure (162 measures).

Privacy & Data Protection

How we protect and handle your data.

On-Device by Default

Speech recognition runs locally on your device. Audio is never uploaded to our servers — transcripts are sent for cloud-based AI analysis only when you choose to, carrying no user-identifying metadata, with no retention and no training.

Local AI Processing (Optional)

For the strictest setup, run AI analysis fully on your device. Transcripts, summaries, notes, and AI-generated content stay on your machine — nothing is sent to the cloud.

No Training on Your Data

We never sell your data, and our AI providers are contractually prohibited from training on your conversations. Your insights stay yours.

End-to-End Security & Control

Data is encrypted in transit and at rest, with EU or US data residency you choose at signup. You can delete your data at any time.

Security Contact

Have questions about our security practices? Email us at security@hedy.ai.

Contact Security Team