Your customers share data. The AI model does not see it.
Before a conversation reaches the AI model, we take the personal data out and replace it with placeholders. The real details come back in the reply to your customer.
Heyloha masks personal data before a conversation leaves the platform. Names, email addresses, phone numbers, addresses, IBAN and national ID numbers are replaced with placeholders. The AI model sees those codes, not the real values. Data is stored in the EU and conversations are deleted from the AI model after seven days.
What we mask
This happens automatically on your chat channels. There is nothing to configure and no switch to turn it off.
Names and addresses
First and last names, street names, house numbers, postcodes and cities.
Contact details
Email addresses and phone numbers, in both local and international formats.
Financial and official numbers
IBAN and national ID numbers, including a validity check so random digit strings are not masked unnecessarily.
Other identifying data
IP addresses and licence plates.
This covers your chat channels: the chat on your website, WhatsApp, Instagram, LinkedIn and email.
Your agent can only do what you allow
An AI agent that can do anything is a liability. So anything with a consequence is off by default, and we enable per channel only what is safe there.
Closed by default
New capabilities are disabled per channel until they are explicitly cleared. Not the other way around.
Email reads and writes, it does not send
On the email channel your agent prepares a draft. You press send. It cannot take actions there that change anything.
Orders only for the right person
With a Shopify connection, an order is looked up using the verified email address of the sender, not something the AI model filled in itself.
Nothing lingers at the AI model
Your conversations stay yours. They do not linger at the AI model.
Seven days
Conversation data held by the AI model is deleted automatically after seven days without use.
Your archive stays
In your own Heyloha inbox the conversations remain, including the real details.
Stored in the EU
Your data sits on European servers and falls under the GDPR.
Securing your account
Access to your agent is access to your customer contact. That deserves more than a password.
Two-step verification
Secure your account with a code from an authenticator app. You get one-time recovery codes in case you lose your phone.
You decide who has access
Invite colleagues, give them access to the branches they work for, and remove that access again when someone leaves.
Frequently asked questions about privacy
Does OpenAI train on our conversations?
No. Your conversations are not used to train models. On top of that, personal data has already been replaced with placeholders before the conversation leaves the platform.
What if a customer pastes sensitive data into the chat themselves?
That is exactly what this is built for. The masking applies to everything that comes in, not only to what your agent looks up. If someone pastes an address or an IBAN into the conversation, it is replaced before it reaches the AI model.
Where is our data stored?
On servers inside the European Union. Processing falls under the GDPR and we work with a data processing agreement.
Can we decide what the agent is allowed to do?
Yes. Per brand you set what the agent may and may not say, and per channel which capabilities are active. A colleague can always take over manually.
Want to see it for yourself?
Try Heyloha free for 14 days, or book a demo and put your privacy questions to us directly.