Trust & safety
How We Protect Health Data
We apply HIPAA-aligned security standards to all health information collected during check-ins, including mood, sleep, and medication adherence data. Protections include TLS 1.2+ encryption in transit and AES-256 at rest, role-based access controls, comprehensive audit logging of all data access, and hosting on Microsoft Azure's SOC 2- and HIPAA-certified infrastructure. A designated Privacy Officer oversees compliance and can be reached at privacy@heyalma.ai.
Our Data Practices
We collect only what we need: account details, self-reported health data, text-only conversation transcripts (no audio recordings), cognitive assessment scores, biographical stories, call metadata, and payment information processed by Stripe. We explicitly do not:
- Sell personal or health data.
- Share private conversations with advertisers.
- Use health information for targeted marketing.
- Store full credit card numbers.
- Allow OpenAI to train its models on customer conversations under our contractual agreement.
Who Can See Your Loved One's Data
Only the designated Caregiver receives call summaries and health updates through the app and notifications. Full conversation transcripts are not shared with the Caregiver by default — sharing requires a privacy setting that is off by default and demands the Elder's explicit consent. Authorized Alma personnel access data only on a need-to-know basis for service operation, technical support, and safety reviews, and all access is logged and audited.
Data Deletion
You can request deletion of all personal data at any time, with permanent removal occurring within 30 days of a verified request. Deletion covers conversation transcripts, health metrics, cognitive assessments, biographical stories, recipes, and call history. We may retain de-identified aggregate data for service improvement and financial records required by tax law for 7 years; all other personal information is permanently removed.
Consent & Authorization
The Caregiver must confirm the Elder understands they will receive AI-powered calls and consents to transcription and wellness data sharing. The Caregiver must also represent they have legal authority to enroll the Elder — through direct consent, power of attorney, legal guardianship, or healthcare proxy — with documentation potentially requested. During the first call, Alma verbally verifies the Elder's understanding and consent with timestamp logging; if the Elder does not consent, the call ends and the Caregiver is notified.
Either party may withdraw consent at any time without the other's permission. Elders can revoke by telling Alma “stop calling me,” calling the support line, or emailing privacy@heyalma.ai. When an Elder revokes consent, calls stop immediately and the Caregiver is notified but cannot override the decision.
Elder Safety
If an Elder discloses, or the AI detects, indicators of abuse, neglect, self-harm, or exploitation, the AI responds with empathy and encourages contacting trusted people or emergency services. Alma may flag calls for internal review, notify the Caregiver of welfare concerns (unless the Caregiver is the suspected source of harm), and report suspected abuse to authorities as permitted or required by law. Alma does not undertake a duty to monitor for or detect elder abuse, and caregivers retain primary responsibility for safety.
Alma Is Not a Medical Service
Alma does not diagnose, treat, or cure medical conditions, and all health metrics are self-reported and not clinically validated. Cognitive wellness exercises are for wellness tracking only and are not diagnostic tools. The Service cannot substitute for professional medical advice, in-home care, or emergency response systems — always call 911 in an emergency. Alma can help families notice changes by alerting caregivers to significant mood or routine shifts, but those alerts are generated automatically by AI analysis and should not be treated as clinical assessments.
AI Transparency
Alma's calls are conducted by AI — not humans — designed to sound warm and natural, with conversations flowing through speech-to-text transcription, OpenAI's language model, and text-to-speech conversion. The system maintains conversation memory in a secure database to provide personalized responses, and AI-generated health alerts and cognitive trend scores are computed algorithmically. Under our current contractual terms with OpenAI, Alma customer conversations are not used to train OpenAI's models. We acknowledge AI has limitations, including occasional misunderstandings and missed patterns.
What Happens If There's a Security Incident
In the event of a data breach, we will notify affected individuals without unreasonable delay and in no event later than 60 days after discovery, describing what occurred, which information was involved, the remedial steps taken, and protective measures you can take. Notifications go to the account email address, and where required by law we will also notify the Virginia Attorney General and the U.S. Department of Health and Human Services. We maintain a security incident log and conduct post-incident reviews to prevent recurrence.
Your Privacy Rights
All users can request copies of their data, correct inaccuracies, request deletion, export data in a portable format, and withdraw consent at any time. Virginia residents under the VCDPA can additionally opt out of profiling used for significant decisions — including cognitive wellness analysis and health alerting — and appeal denied requests within 60 days. California residents under the CCPA/CPRA can know what information is collected and its sources, direct limits on sensitive data use, and avoid discrimination for exercising privacy rights. All requests should go to privacy@heyalma.ai.
Our Policies
Alma's complete practices are detailed in three governing documents: the Privacy Policy (data collection, use, and rights), the Terms of Service (use agreement, billing, and liability), and the Cookie Policy (website tracking). In the event of any conflict between this Trust & Safety page and the Privacy Policy or Terms of Service, the Privacy Policy and Terms of Service govern.
Questions or Concerns?
- General questions: info@heyalma.ai
- Privacy matters, HIPAA, and breach reports: privacy@heyalma.ai
- Alethiom LLC, 11107 Sunset Hills Rd, Ste 400, Reston, VA 20190
Last updated February 24, 2026