Privacy Policy
Last updated: September 2026
1. Introduction
HelloRemind ("we," "us," or "our") provides automated reminder call services to help caregivers ensure their loved ones receive important medication and appointment reminders.
This Privacy Policy describes how we collect, use, and protect your personal information when you use our reminder service. We are committed to protecting your privacy and will never sell, trade, or share your personal information with third parties for marketing purposes.
2. Information We Collect
Account Information
- Your name and email address
- Your phone number for account notifications
- Payment information processed securely through Stripe
- Account preferences and settings
Reminder Recipient Information
- Recipient's name and phone number
- Reminder schedules and messages you create
- Reminder delivery preferences and settings
- Call and text message response history and delivery status
- Escalation preferences and contact methods
Audio Content
- Voice recordings you upload for personalized reminders
- Text-to-speech audio files generated from your reminder messages
- Audio files are securely stored on Cloudflare R2
Technical Information
- IP addresses and device information for security
- Browser type and usage analytics
- System logs for service reliability
- Authentication data through WorkOS
3. How We Use Your Information
We use your information solely to provide our reminder service:
- Making automated reminder calls and sending text messages to your designated recipients
- Sending escalation notifications via SMS or phone calls when reminders are missed
- Sending you notifications about call and text message delivery status
- Processing your subscription payments
- Providing customer support and technical assistance
- Ensuring service security and preventing unauthorized access
- Improving our service quality and reliability
- Maintaining audit logs for service operation
We Never Share Your Personal Information: We do not sell, trade, rent, or share your email address, phone number, or any personal information with third parties for marketing or any other commercial purposes.
4. Third-Party Services We Use
To provide our reminder service, we rely on the following third-party providers. Each receives only what it needs to perform its function:
- Twilio: Makes phone calls and sends text messages on our behalf
- ElevenLabs: Converts text to speech for personalized reminder messages
- Cloudflare R2: Stores audio files, exports, and backups, encrypted at rest
- Postmark: Delivers account and notification emails, which can include a recipient’s name and a reminder title
- DigitalOcean: Hosts our application and database
- Stripe: Processes payments securely (we never see your full payment details)
- Cloudflare: Serves and protects our websites (DNS, security, and content delivery)
- Fathom Analytics: Cookieless, aggregate page analytics on this marketing site only — no cookies, no persistent identifiers, and no cross-site tracking. Because it sets no cookies, no cookie banner is required. Read Fathom’s privacy policy. We honor the Do Not Track (DNT) and Global Privacy Control (GPC) browser signals; when either is enabled, analytics are disabled.
We share only the minimum information each service needs, and we do not authorize any of them to use your data for their own purposes.
5. Data Protection and Security
We protect your information with these measures:
- Everything is encrypted in transit, including when we hand a reminder to the providers that deliver it
- Phone numbers are encrypted at rest in our database. Audio recordings, data exports, and database backups are encrypted at rest in our object storage
- Two-factor authentication is available on every account, and is required for administrator access and for sensitive account changes
- Staff access to your information is recorded in an audit trail
- Automated daily checks for unusual access patterns
- Staff access is tiered — support staff see your account with personal details masked
- Automated daily backups
What is not encrypted at rest: reminder titles and messages, and recipient names, are stored in readable form in our database so the service can schedule, search, and speak them. We state this plainly because a blanket claim to the contrary would not be true. Our Security and HIPAA posture page sets out the full picture.
6. When We Share Information
We do not sell, trade, or rent your personal information to anyone. We only share information in these limited circumstances:
- With the third-party services listed above, only as needed to provide our service
- When required by law, court order, or government request
- To prevent fraud or protect the safety of our users
- If our business is sold, your information may transfer to the new owner (you'll be notified)
Mobile numbers and SMS consent are treated separately and more strictly. We do not sell, rent, or share mobile phone numbers or text-messaging consent with third parties for their own marketing, and we do not share them with other companies or affiliates for that purpose under any circumstances. A mobile number is disclosed only to the telecommunications provider that delivers the message on our behalf, which is what makes delivery possible. Mobile numbers are encrypted at rest, and we keep a timestamped record of each consent and opt-out. See our Messaging Policy for how that consent is collected.
7. Data Retention
We keep your information only as long as needed:
- Account information: Until you delete your account
- Reminder and call records: For 2 years after your last activity
- Audio files: Until you delete them or close your account
- Payment records: As required by law (typically 7 years)
- Security logs: 2 years for fraud prevention
When you delete your account, we will permanently delete your personal information within 30 days, except what we're legally required to keep.
8. Your Rights and Control
You have full control over your information:
- View and update your account information anytime
- Delete reminder recipients and their data
- Download a copy of your data
- Delete your account and all associated data
- Opt out of marketing emails (service emails will continue for active reminders)
To exercise any of these rights, contact us at hi[at]helloremind[dot]me or use the account settings in your dashboard.
9. Cookies and Tracking
We only use essential cookies needed for the service to work properly:
- Login sessions and security
- Remembering your preferences
- Preventing fraud and abuse
We don't use advertising cookies or track you across other websites.
10. Children's Privacy
Our service is intended for adult caregivers managing reminders for their loved ones. We don't knowingly collect information from children under 13. If you're under 13, please have a parent or guardian create and manage the account.
11. Data Breaches
If a security breach occurs that could affect your personal information, we will:
- Notify you by email within 72 hours of discovery
- Explain what happened and what information was involved
- Tell you what we're doing to fix the problem
- Provide steps you can take to protect yourself
12. Changes to This Policy
We may update this Privacy Policy occasionally. If we make significant changes that affect how we use your information, we'll email you at least 30 days before the changes take effect.
You can always find the current version on our website with the last updated date at the top.
13. Contact Us
Questions about this Privacy Policy? Want to update or delete your information? We're here to help.