// HiroLabz Privacy
Privacy Policy
Last updated: July 19, 2026
Scope
This Privacy Policy explains how Hiro Labz Inc., doing business as HiroLabz ("HiroLabz," "we," "us," or "our"), collects, uses, discloses, retains, and protects personal information when you visit hirolabz.com; communicate with us; join a waitlist; request a consultation; apply for a role; create an account; or use a HiroLabz application, platform, AI feature, API, software product, or service that links to this Policy (collectively, the "Services").
A product-specific privacy notice, customer agreement, Data Processing Addendum, school agreement, Business Associate Agreement, or other notice may supplement this Policy. If a product-specific notice conflicts with this Policy, the product-specific notice controls for that product.
This Policy does not apply to third-party websites, applications, or services that we do not control, even if they are linked to or integrated with a Service.
Our Role: Controller or Processor
When HiroLabz decides why and how personal information is processed, such as for website visitors, prospects, account administration, marketing, product analytics, and direct consumer products, HiroLabz generally acts as a controller or business.
When HiroLabz processes personal data on behalf of a business customer under its instructions, HiroLabz generally acts as a processor or service provider. The business customer is responsible for its notices, lawful basis, instructions, and handling of individual requests. Our Data Processing Addendum governs that processing where applicable.
Personal Information We Collect
| Category | Examples |
|---|---|
| Identity and contact data | Name, username, account identifier, business name, title, email address, telephone number, mailing address, and contact preferences. |
| Account and authentication data | Password hash, passkey information, multi-factor settings, device tokens, login history, session information, and account-recovery data. |
| Commercial and transaction data | Products or services requested or purchased, subscription tier, order history, invoices, payment status, credit or usage balance, trial status, and customer-support history. Payment-card details are generally handled by payment processors rather than stored directly by HiroLabz. |
| Device, internet, and usage data | IP address, browser, device type, operating system, identifiers, pages or screens viewed, clicks, referrer, timestamps, crash logs, diagnostics, feature usage, performance, approximate location derived from IP, and cookie or SDK information. |
| Communications data | Emails, support messages, consultation requests, feedback, survey responses, chat messages, and other correspondence. |
| Customer Content | Prompts, instructions, documents, files, messages, email content, calendar information, tasks, contacts, code, notes, images, audio, call recordings, transcripts, and other data submitted to or processed through a Service. |
| Voice and audio data | Voice commands, call audio, voicemail, transcripts, summaries, call metadata, and speaker-related information where a feature is enabled and lawful consent is obtained. |
| Professional and business data | Employer, job title, business function, industry, business needs, project requirements, purchasing authority, and information associated with B2B relationships. |
| Applicant and workforce data | Resume, work history, education, portfolio, interview notes, compensation expectations, work authorization, references, and related recruitment information. |
| Sensitive personal information | Precise geolocation, government identifiers, financial-account information, health information, biometric information, racial or ethnic origin, religious beliefs, sexual orientation, citizenship or immigration status, contents of certain communications, or other data classified as sensitive by law, but only when a Service requires it and appropriate consent or contractual safeguards are in place. |
| Inferences | Preferences, likely interests, product fit, fraud or security risk, customer-segment information, or other inferences drawn from the information above. |
Sources of Personal Information
- Directly from you, such as through forms, accounts, files, prompts, communications, payments, and product use.
- From your organization, administrator, employer, school, customer, or authorized account owner.
- From connected services and integrations you authorize, such as email, calendar, CRM, storage, communication, telephony, identity, or payment providers.
- Automatically from devices and Services through logs, cookies, SDKs, APIs, and similar technologies.
- From service providers, public sources, event organizers, business partners, referrals, and lawful B2B data sources.
- From third parties who are authorized to provide information to us, including customers that use our Services to communicate with their own contacts or users.
How We Use Personal Information
- Provide, operate, authenticate, personalize, and support the Services;
- Respond to inquiries, consultations, proposals, waitlists, demonstrations, support requests, and customer communications;
- Create and administer accounts, subscriptions, orders, payments, credits, invoices, trials, and renewals;
- Process Customer Content and perform requested AI, automation, communication, integration, and software functions;
- Maintain security, prevent fraud and abuse, enforce access controls, investigate incidents, and protect users, systems, and rights;
- Monitor performance, debug errors, analyze usage, improve reliability, develop features, and conduct quality assurance;
- Send transactional, service, security, product, and administrative communications;
- Send marketing communications where permitted and manage opt-outs and preferences;
- Comply with law, legal process, contractual requirements, tax, accounting, audits, sanctions, export controls, and lawful requests;
- Establish, exercise, or defend legal claims and enforce agreements;
- Conduct recruitment, workforce planning, and vendor or partner management;
- Create deidentified, aggregated, or statistical information for lawful business and product purposes.
AI, Model Providers, and Training
When you use AI-enabled features, we may send prompts, instructions, relevant context, and necessary Customer Content to HiroLabz systems or approved model and infrastructure providers to generate Outputs and complete requested actions. We seek to limit information to what is reasonably necessary for the function.
Unless you expressly opt in or a signed agreement clearly says otherwise, HiroLabz does not use Customer Content to train generalized AI models. We may use deidentified or aggregated telemetry, evaluations, safety signals, error reports, and performance data to test, secure, and improve the Services.
Some features may involve human review for support, abuse investigation, quality assurance, safety evaluation, or where you request review. Access is limited to authorized personnel and providers with a need to know and appropriate obligations.
Where required, product-specific notices will disclose whether personal information is used to train or fine-tune a model, whether processing occurs on-device or in the cloud, which categories of providers are involved, and available controls.
Calls, Messages, Recordings, and Transcripts
If you enable a feature that records, screens, places, receives, transcribes, summarizes, or analyzes calls or messages, we may process phone numbers, call routing information, timestamps, duration, audio, transcripts, summaries, messages, consent records, and opt-out information.
HiroLabz may provide technical notices or controls, but the person or organization using the feature is responsible for ensuring that communications are lawful and that required consent and disclosures are provided. We may retain records of consent, opt-outs, suppression, call disposition, and compliance checks where necessary to operate the feature and demonstrate compliance.
Cookies, SDKs, Analytics, and Similar Technologies
We and our service providers may use cookies, pixels, local storage, SDKs, log files, and similar technologies to operate the Services, remember preferences, secure sessions, measure performance, understand usage, and, if enabled, support advertising or campaign measurement.
| Category | Purpose | Control |
|---|---|---|
| Strictly necessary | Authentication, security, load balancing, session management, fraud prevention, and core functionality. | Required for the Service and generally cannot be disabled through the preference center. |
| Functional | Remember settings, language, preferences, and enhanced features. | Can be controlled where the preference center supports it. |
| Analytics | Measure visits, product use, errors, performance, and content effectiveness. | Consent or opt-out is provided where required. |
| Advertising / campaign measurement | Measure campaigns, limit repetition, attribute conversions, or support targeted advertising if used. | Disabled until consent where required; opt-out through Your Privacy Choices. |
You can manage non-essential technologies through the cookie-preference tool where available. Browser settings may also limit cookies, but disabling them may affect functionality. Where required by law, we honor valid universal opt-out preference signals, including Global Privacy Control, for sale, sharing, or targeted-advertising opt-outs.
How We Disclose Personal Information
We may disclose personal information to the following categories of recipients for the purposes described in this Policy:
- Service providers and processors that host data, provide cloud infrastructure, AI models, analytics, security, identity, customer support, communications, telephony, email, payments, accounting, project management, or other operational services;
- Connected third-party services and integrations you choose to use;
- Your organization, account administrator, authorized users, or business customer, where your use is associated with that organization;
- Business partners, resellers, implementation partners, or referral partners when necessary for a requested relationship and subject to appropriate terms;
- Professional advisers, auditors, insurers, banks, investors, and financing sources under appropriate confidentiality obligations;
- Law enforcement, regulators, courts, government authorities, or other parties when required by law or reasonably necessary to protect rights, safety, security, and the integrity of the Services;
- A buyer, investor, lender, successor, or other participant in a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar transaction, subject to appropriate confidentiality and legal requirements;
- Other recipients at your direction or with your consent.
We may disclose deidentified or aggregated information that cannot reasonably be used to identify you, subject to applicable law.
Sale, Sharing, and Targeted Advertising
HiroLabz does not sell personal information for monetary consideration. Depending on the technologies configured on the website or in a product, disclosures of identifiers, device information, and internet activity to analytics or advertising partners may be considered a "sale," "sharing," or processing for "targeted advertising" under some state privacy laws, even when no money changes hands.
Where applicable, you may opt out through the "Your Privacy Choices" link, the cookie preference center, a valid universal opt-out preference signal, or by contacting privacy@hirolabz.com. HiroLabz does not knowingly sell or share personal information of children under 16 for targeted advertising.
Data Retention
We retain personal information only as long as reasonably necessary for the purposes described in this Policy, to provide the Services, comply with law and contracts, resolve disputes, enforce rights, maintain security, and meet legitimate business needs. Retention varies by product, account status, sensitivity, contractual requirements, and legal obligations.
| Data Type | Typical Retention Approach |
|---|---|
| Account and profile data | For the account term and a reasonable period afterward for recovery, fraud prevention, legal compliance, and dispute handling. |
| Customer Content | According to the product settings, customer instructions, subscription terms, and applicable agreement; deletion or export may be available before or after termination. |
| Billing and transaction records | As required for tax, accounting, audit, chargeback, anti-fraud, and legal obligations. |
| Security and access logs | For a period appropriate to security monitoring, incident investigation, abuse prevention, and contractual requirements. |
| Support and business communications | For the duration of the relationship and a reasonable period afterward to maintain history and resolve issues. |
| Marketing data | Until you unsubscribe, the purpose ends, or retention is no longer justified; suppression records may be retained to honor opt-outs. |
| Call recordings and transcripts | According to product settings, consent, customer instructions, and legal requirements; customers may configure shorter periods where supported. |
| Applicant data | For the hiring process and a reasonable period for future roles, legal compliance, and defense of claims, subject to local law. |
We may retain information longer if required by law, legal hold, security investigation, dispute, or written agreement. When retention ends, we delete, anonymize, or securely dispose of information using methods appropriate to the data and system.
Security
HiroLabz uses reasonable administrative, technical, and organizational safeguards designed to protect personal information based on the nature of the Service and sensitivity of the data. Measures may include access controls, authentication, encryption, tenant isolation, logging, monitoring, secure development practices, provider review, backups, and incident-response procedures where appropriate.
No security method is perfect. You are responsible for securing your devices, credentials, connected accounts, configurations, and user permissions. If you believe your account or information has been compromised, contact security@hirolabz.com promptly.
Your Choices
- Account settings: review or update certain profile, security, integration, and communication preferences.
- Marketing email: use the unsubscribe link or contact us. We may continue sending transactional, security, or service messages.
- Cookies: use the cookie preference center and browser controls.
- Connected services: disconnect integrations through account or provider settings, recognizing that previously imported information may remain until deleted under applicable settings or requests.
- Mobile permissions: manage contacts, microphone, notifications, calendar, camera, location, and other permissions through device settings.
- Call and message opt-outs: follow the instructions in the communication or contact the relevant sender. Customers using HiroLabz outreach tools must maintain their own suppression lists.
- Privacy requests: submit through https://hirolabz.com/privacy-request or email privacy@hirolabz.com.
US State Privacy Rights
Depending on where you live and whether a state law applies to HiroLabz or a particular processing activity, you may have the right to:
- confirm whether we process your personal information and access it;
- obtain a portable copy of certain personal information;
- correct inaccurate personal information;
- delete personal information, subject to legal exceptions;
- opt out of sale, sharing, targeted advertising, or certain profiling;
- limit certain uses or disclosures of sensitive personal information;
- withdraw consent where processing is based on consent;
- appeal a decision on a privacy request;
- receive non-discriminatory treatment for exercising privacy rights.
To exercise a right, submit a request at https://hirolabz.com/privacy-request or email privacy@hirolabz.com. Describe the right you wish to exercise and provide enough information for us to locate the relevant records. We will verify requests using information reasonably related to the request and sensitivity of the data. We may ask for additional information, decline or limit a request where permitted, or retain information where an exception applies.
Authorized agents may submit requests where applicable, but we may require proof of authority and may verify the consumer directly. If we deny a request, residents of states that provide an appeal right may appeal by replying to our decision or emailing privacy@hirolabz.com with the subject "Privacy Appeal." We will respond within the timeframe required by applicable law and provide information about contacting the relevant regulator where required.
California Privacy Notice
This section supplements the Policy for California residents if the California Consumer Privacy Act, as amended, applies to HiroLabz or the relevant processing. In the preceding 12 months, we may have collected the categories below, depending on the Services used.
| CCPA Category | Examples / Purpose | Disclosed For Business Purpose |
|---|---|---|
| Identifiers | Name, account ID, email, phone, IP address, device identifiers; used for accounts, support, security, communications, and service delivery. | Cloud, identity, support, communications, analytics, and security providers. |
| California customer-record information | Contact, billing, payment status, and business relationship information; used for transactions and account management. | Payment, accounting, support, and professional-service providers. |
| Commercial information | Purchases, subscriptions, trials, product interest, and usage; used for fulfillment, billing, support, and improvement. | Payment, analytics, CRM, and customer-success providers. |
| Internet or network activity | Browsing, usage, logs, clicks, diagnostics, and interactions; used for security, analytics, and improvement. | Hosting, security, analytics, and support providers. |
| Geolocation | Approximate location from IP; precise location only when a feature requires it and permission is enabled. | Infrastructure, security, maps, or location-service providers as needed. |
| Audio, electronic, and visual information | Call audio, transcripts, messages, support recordings, and uploaded media; used to provide enabled features and support. | Telephony, communications, AI, storage, and support providers. |
| Professional or employment information | Employer, role, project needs, resume, and experience; used for B2B relationships and recruiting. | CRM, recruiting, communication, and professional advisers. |
| Education information | Education history for applicants or student-related data in product-specific services. | Recruiting or authorized education-service providers, as applicable. |
| Inferences | Product fit, preferences, risk, or engagement; used for personalization, security, and sales operations. | Analytics, CRM, and service providers. |
| Sensitive personal information | Account credentials, precise geolocation, contents of communications, health, financial, or biometric-related data only where applicable. | Only to providers necessary for the requested Service and subject to appropriate restrictions. |
We collect these categories from the sources and use them for the purposes described in Sections 4 and 5. We do not sell personal information for money. If analytics or advertising disclosures are considered sale or sharing under California law, California residents may opt out through Your Privacy Choices or a valid Global Privacy Control signal. California residents may also request access, deletion, correction, and limitation of certain sensitive personal information and may not be discriminated against for exercising rights.
Biometric and Device Authentication
If a Service allows sign-in using fingerprint, face, or other biometric authentication provided by your device, the biometric template is generally stored and processed by the device operating system or platform provider. HiroLabz typically receives only a confirmation that authentication succeeded and does not receive the raw fingerprint, face scan, or biometric template.
If HiroLabz later offers a feature that directly collects or derives biometric identifiers or biometric information, we will provide a product-specific notice and obtain consent where required before collection.
Health, Financial, Education, and Other Regulated Data
The general Services are not automatically designed or contracted to satisfy sector-specific requirements such as HIPAA, the Gramm-Leach-Bliley Act, FERPA, or payment-card security obligations. Do not submit protected health information, nonpublic financial information, student education records, government-classified information, or other regulated data unless the specific Service and a signed agreement expressly authorize it and required safeguards and addenda are in place.
If HiroLabz acts as a HIPAA business associate, the parties must sign a Business Associate Agreement before protected health information is processed. If a non-HIPAA health application is subject to the FTC Health Breach Notification Rule or a state consumer-health law, a product-specific health privacy notice and incident process may be required.
Children and Minors
The general website and Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13 without verifiable parental consent or another lawful authorization. If you believe a child has provided personal information improperly, contact privacy@hirolabz.com.
A product intended for schools, families, or minors must use product-specific terms and privacy notices and implement age screening, parental or school authorization, data minimization, retention limits, security safeguards, and other requirements that apply to the use case. We do not knowingly sell or share minors' personal information for targeted advertising.
International Data Transfers
HiroLabz is based in the United States and may process information in the United States and other countries where our personnel and service providers operate. Those countries may have different privacy laws. Where required, we use contractual, technical, or organizational measures intended to protect transferred information.
Any representation that HiroLabz participates in a specific transfer framework, such as the EU-US Data Privacy Framework, will be made only if the company has formally certified and remains listed as an active participant.
Business Transfers and Corporate Events
We may disclose or transfer personal information in connection with an actual or proposed merger, acquisition, financing, restructuring, bankruptcy, sale of assets, or similar corporate transaction. We will use appropriate safeguards and provide notice where required by law.
Changes to This Policy
We may update this Policy as laws, products, vendors, and data practices change. We will post the updated Policy and revise the "Last Updated" date. If changes are material, we will provide additional notice where required, such as by email, in-product notice, or a prominent website notice.
Contact and Privacy Requests
Hiro Labz Inc. (doing business as HiroLabz) | Austin, Texas, United States
Privacy: privacy@hirolabz.com | Security: security@hirolabz.com | General: hello@hirolabz.com
Request forms: https://hirolabz.com/privacy-request | https://hirolabz.com/privacy-choices
