Privacy Policy
This policy explains what data is collected by this website and by hiify, the AI agent platform operated at hiify.ai, and what is done with it. Section 3 covers data obtained from Google accounts — Calendar, Drive and Sheets — and is the section relevant to Google OAuth.
Effective date: 22 August 2026
1. Who is responsible
hiify, operated at hiify.ai, is the data controller for this website and for the hiify product. Contact for any privacy question or request: support@hiify.ai.
2. This website
The public marketing pages describe the product. Creating an account is optional. If you only read these pages we may still collect device and log data needed to operate the site.
- Essential cookies for authentication, session security and preferences when you sign in.
- Device and log data such as IP address, user-agent and pages viewed, used for security and reliability.
- If you email support, we keep that correspondence so we can reply.
3. hiify and Google user data
hiify can connect to a Google account so that an AI agent can check availability and book appointments, and so that it can read or write rows in a Google Sheet you choose. Each connection is optional and is initiated by a workspace admin. If a connection is never made, hiify never receives that Google data.
3.1 What is requested, and why
| Scope | Why it is needed |
|---|---|
| https://www.googleapis.com/auth/userinfo.email | To identify which Google account was connected to the hiify workspace. We receive the email address associated with that account and use it only to label the connection. |
| https://www.googleapis.com/auth/calendar | To read free/busy information so the agent offers only genuinely open slots, and to create, reschedule and cancel the appointments the agent agrees with a caller. Offline access is requested so a booking made during a call still succeeds if you are not present. |
| https://www.googleapis.com/auth/drive.readonly | To list existing Google Sheets files in the connected account so a workspace admin can pick which spreadsheet an agent step should use. This scope is used only to list Sheet files (name and file id). hiify does not download file bytes, does not read non-Sheet Drive files, and does not create, move or delete files in Drive. |
| https://www.googleapis.com/auth/spreadsheets | To read the header row of the tab the admin selected, and to append, find, update or clear data rows on that tab during a live conversation, using only the column mapping they configured. hiify does not create new spreadsheets or columns, and does not read or write tabs or cells the admin did not select. |
3.2 What is stored
- OAuth tokens. The access token and refresh token, encrypted before they are written to the database. Tokens are decrypted only inside server-side code and are never sent to the browser.
- Appointment records. The booking the agent made — time, duration, and the attendee's name, email address and phone number where they gave them — so that the appointment can be shown, rescheduled or cancelled.
- Free/busy results. Read at the moment a caller asks about availability and used to compute the slots offered. Calendar event contents are not copied into hiify beyond the appointments it created itself.
- Sheet configuration. The connected Google account email, the spreadsheet file id and name, the selected tab, and the column mapping a workspace admin saved on an agent step. Sheet cell contents are not copied into hiify as a dataset. Values collected from a caller (for example name, email or phone) may appear in the conversation record and are written to the mapped columns at the time of the call.
3.3 Limited use
hiify's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In plain terms, Google user data is never:
- used for advertising, or sold or transferred for advertising purposes;
- used to train, fine-tune or improve any generalised artificial intelligence or machine-learning model;
- sold to anyone, or shared with data brokers or information resellers;
- read by a human, except with your explicit consent for a support request you raised, where it is necessary for security or to comply with the law, or where the data has been aggregated and anonymised.
3.4 How to disconnect and delete
You can disconnect Google from hiify at any time in Apps → Google Calendar or Apps → Google Sheets. Disconnecting revokes the tokens with Google and deletes the stored credentials. You can also revoke access directly at myaccount.google.com/permissions.
To delete your hiify account and everything associated with it, email support@hiify.ai and it will be erased within 30 days, except where a record must be retained by law.
4. Other data hiify processes
- Account data — name, email address, organisation and authentication identifiers, to run your account.
- Knowledge base content — the documents and pages you upload for your agent to search.
- Conversations — chat transcripts, call recordings and transcripts where consent was recorded, along with the tools the agent used, so you can review what your agent did.
- Operational logs — request identifiers, IP address, user agent and audit entries. Secrets and personal data are masked before anything is written to a log.
- Optional Microsoft Excel connection — if a workspace admin connects OneDrive or Microsoft 365, hiify stores encrypted OAuth tokens and the workbook, worksheet and column mapping they selected, then reads or writes only those mapped rows during a conversation.
5. Sub-processors
hiify passes data to these services only as far as delivering the product requires:
- Model providers — to generate replies.
- Speech providers — speech synthesis and recognition for voice agents.
- Google — calendar availability and booking, and listing or updating the Google Sheet a workspace admin selected, as described above.
- Hosting, database and object storage providers — to run the service.
- Stripe — payment processing, where billing is enabled.
- Microsoft — listing or updating the Excel workbook a workspace admin selected, when that connection is enabled.
- Telephony providers you bring yourself (for example Twilio).
Your data is never sold, and it is not shared for any purpose beyond operating the service.
6. Security
- Credentials and OAuth tokens encrypted at rest, with transport encryption in transit.
- Authenticated requests, role-based access, and tenant isolation.
- Secrets and personal data redacted from logs.
No system is perfectly secure, but if a breach affects your data you will be told promptly and told what to do about it.
7. Your rights
You may request access to your data, correction, deletion, a portable copy, or restriction of processing, and you may object to processing. Email support@hiify.ai and we will respond within 30 days. If you are in the EEA or UK you also have the right to complain to your data protection authority.
8. Children
Neither this website nor hiify is directed at children under 16, and neither knowingly collects their data. If you believe a child has provided data, contact us and it will be deleted.
9. Changes
This policy may be updated. The date at the top always reflects the current version, and any material change affecting how Google user data is handled will be notified to affected account holders by email before it takes effect.
Also see our Terms of Service.