Our commitment
to
your privacy
Introduction
This Privacy Policy describes how Alethiom LLC (“Alma,” “we,” “us,” or “our”) collects, uses, discloses, and protects your personal information when you use our website (heyalma.ai), mobile application, and AI-powered phone-based wellness check-in service (collectively, the “Service”).
Alma provides daily AI companion calls to older adults (“Elders”) and shares wellness updates with their designated family caregivers (“Caregivers”). Because a Caregiver may set up the Service on behalf of an Elder, this Privacy Policy applies to both Caregivers and Elders, as well as anyone who visits our website.
By creating an account and affirmatively accepting this Privacy Policy, you agree to the collection and use of information in accordance with it. If you are a Caregiver setting up the Service on behalf of an Elder, you represent that you have legal authority to consent on the Elder's behalf and that you have informed the Elder about the nature of the Service. We may require documentation of legal authority at our discretion.
Information We Collect
Information you provide directly
- Account information — name, preferred name, email, phone number, and login credentials.
- Caregiver information — mailing address, relationship to the Elder, and notification preferences.
- Elder profile information — name, date of birth, language, hearing status, timezone, preferred topics, and AI companion voice preferences.
- Payment information — processed by Stripe; we store a customer identifier and transaction records but not full card numbers.
- Feedback and communications you send when contacting support.
Information generated through the Service
- Conversation transcripts, generated via AssemblyAI. Calls are not audio-recorded; only text transcripts are stored.
- Self-reported health and wellness data — mood, sleep, appetite, pain, medication adherence, and exercise.
- Cognitive assessment data — scores, response times, and performance metrics from optional exercises.
- Biographical and story data, recipes, call metadata, and check-in records.
Information collected automatically
If the Elder has the Alma mobile app installed, we collect step count (via Apple HealthKit or Health Connect) and precise geolocation to confirm safety and trigger Caregiver alerts. We do not currently collect wearable device data, audio recordings, or AI voice models; if that changes we will provide notice and obtain opt-in consent first.
Legal Bases for Processing
We process your personal information under the legal bases permitted by the VCDPA, CCPA/CPRA, and other applicable law. Account, profile, biographical, payment, and call-metadata processing is based on contract performance. Health, wellness, and cognitive assessment data — which is sensitive — is processed on the basis of your explicit opt-in consent. Device and analytics data is processed on the basis of legitimate interest and, for cookies, consent.
How We Use Your Information
We use your personal information to:
- Provide the Service — conduct AI companion calls, generate wellness summaries, deliver notifications, and compile biographies.
- Monitor self-reported health metrics over time and alert Caregivers when concerning patterns are detected.
- Administer cognitive wellness exercises and track trends (this constitutes automated profiling).
- Personalize conversations to the Elder's interests, language, and hearing needs.
- Manage accounts, process payments, and provide customer support.
- Improve the Service using aggregated, de-identified usage data. We do not use identifiable customer data to train third-party AI models.
- Send service-related communications and protect the security of our systems.
Third-Party Service Providers
We use the following third-party services to operate Alma. All are bound by data processing agreements and, where required, Business Associate Agreements:
- Microsoft Azure — cloud hosting and infrastructure.
- OpenAI — AI language model for conversations. OpenAI does not use Alma customer data to train its models under our contractual terms.
- Twilio — telephony services.
- Firebase (Google) — authentication and push notifications.
- AssemblyAI — speech-to-text transcription.
- Stripe — PCI-DSS compliant payment processing.
- Google Analytics — website usage analytics.
Health Data Protections
Alma implements security and privacy safeguards that align with the standards set forth in the Health Insurance Portability and Accountability Act (HIPAA), regardless of whether Alma is a covered entity or business associate. Where Alma contracts with covered entities and receives protected health information on their behalf, we operate as a Business Associate and comply fully with HIPAA.
Administrative, technical & physical safeguards
- Access to health data is restricted to authorized personnel on a need-to-know basis, with audit logs of all access.
- A designated Privacy Officer oversees compliance; workforce training is conducted regularly.
- Data is encrypted in transit (TLS 1.2+) and at rest (AES-256 or equivalent), with role-based access controls and key rotation.
- Infrastructure is hosted on Microsoft Azure, which maintains SOC 2, HIPAA, and ISO 27001 certifications.
We maintain executed Business Associate Agreements with our cloud hosting, transcription, and telephony providers. A current list is available by contacting privacy@heyalma.ai.
Data Security
We implement industry-standard measures to protect your data, including encryption in transit (TLS 1.2+) and at rest (AES-256 or equivalent), Firebase Authentication and OAuth 2.0 login, phone-based one-time password verification, device fingerprinting and compromise detection, encryption key rotation, comprehensive audit logging, and regular backups.
While we strive to protect your information, no method of transmission or storage is 100% secure. We cannot guarantee absolute security but are committed to promptly addressing any security incidents in accordance with our breach notification obligations.
Data Retention
We retain your personal information for as long as your account is active or as needed to provide the Service.
- Active accounts — data is retained for the duration of your subscription and active use.
- Canceled accounts — data is retained for 90 days following cancellation to allow reactivation, then permanently deleted. Financial records required by tax law are retained for 7 years.
- Deletion requests — upon a verified request we delete your personal information within 30 days, including a full cascade deletion of transcripts, health metrics, biography fragments, recipes, and call history.
We may retain de-identified, aggregated data that cannot reasonably identify any individual for analytical purposes indefinitely.
Your Rights
Regardless of your location, you have the right to access, correct, and delete your personal information, to obtain it in a portable format, to withdraw consent where consent is the legal basis for processing, and to opt out of non-essential communications.
Virginia residents (VCDPA)
Virginia residents may additionally opt out of profiling that produces legal or similarly significant effects — including our cognitive wellness trend analysis. To exercise these rights, contact privacy@heyalma.ai; we respond within 45 days. If we decline a request you may appeal with the subject line “VCDPA Appeal,” and we will respond within 60 days.
California residents (CCPA/CPRA)
California residents have the right to know what personal information we collect and why, to delete and correct it, to opt out of sale or sharing (we do neither), to limit the use of sensitive personal information, and to non-discrimination for exercising these rights.
Consent and Authorization for Elders
Because our Service involves a Caregiver setting up an account on behalf of an Elder, we use a multi-layered consent framework. At account creation, the Caregiver must represent that the Elder has been informed about the Service and that the Caregiver has legal authority to enroll them.
During the first AI call, Alma verbally confirms with the Elder that they understand they are speaking with an AI companion service, that they consent to ongoing check-in calls, and that health summaries will be shared with their Caregiver. This verbal consent is logged with a timestamp. The Elder may revoke consent at any time — by telling Alma during a call, calling our support line, or emailing privacy@heyalma.ai— without the Caregiver's involvement, and the Caregiver cannot override that decision.
Sharing of full conversation transcripts with the Caregiver is off by default and requires the Elder's affirmative consent to enable.
Breach Notification
In the event of a data breach involving your unencrypted personal information, we will notify you without unreasonable delay and in no event later than 60 days after discovery, consistent with Virginia's breach notification statute and, where applicable, HIPAA. Notifications describe the incident, the information involved, the steps we are taking, and steps you can take to protect yourself. Where required by law we will also notify the Virginia Attorney General and the U.S. Department of Health and Human Services.
Children's Privacy
Alma is designed for older adults and their adult family caregivers. Our Service is not directed to children under 18, and we do not knowingly collect personal information from children. If we become aware that we have collected such information, we will take steps to delete it within 30 days.
International Users and Data Transfers
Alma's Service is operated from and data is stored in the United States. If you access the Service from outside the United States, your information will be transferred to, stored, and processed in the United States, where data protection laws may differ from those of your country. By using the Service, you consent to this transfer.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. For non-material changes, we will post the updated policy with a revised “Last Updated” date. For material changes — particularly any affecting how we collect, use, or share health data — we will notify you via email and in-app notification at least 30 days before they take effect, and material changes to health data processing will require your affirmative re-consent. If you do not agree, you may cancel and request deletion of your data at any time.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
- Alethiom LLC, 11107 Sunset Hills Rd, Ste 400, Reston, VA 20190
- General inquiries: info@heyalma.ai
- Privacy Officer, HIPAA & breach reports, and VCDPA appeals: privacy@heyalma.ai
We will respond to all privacy-related inquiries within 30 days, or within the timeframes required by applicable law, whichever is shorter.
Last updated February 24, 2026