How HelloRemind Keeps Your Family's Data Safe and Private

How we handle privacy and security. What we collect, how we protect it, and why you can trust us with sensitive information.

By HelloRemind Team

When you trust a service with information about your loved one’s medications, health routines, and daily activities, you deserve complete transparency about how that data is protected.

At HelloRemind, privacy and security shape how every part of the service is built. Here’s exactly how we keep your family’s information safe.

What Information We Collect

Here’s everything we collect and why:

Information You Provide

Account Information:

Recipient Information:

Why we need this: To deliver reminders to the right person at the right time and to communicate with you about your account.

Information We Automatically Collect

Service Usage Data:

Technical Information:

Why we need this: To ensure reminders are delivered reliably, troubleshoot problems, and improve our service.

What We DON’T Collect

We deliberately avoid collecting:

We follow the principle of data minimization: if we don’t need it, we don’t collect it.

How We Protect Your Data

Encryption, and exactly where it applies

Data in Transit: Everything sent between your device and our servers, and between our servers and the providers that deliver your reminders, is encrypted with TLS 1.2 or newer.

Data at Rest: Phone numbers are encrypted in our database. Audio, the data exports you request, and our daily backups are held in storage that encrypts every object with AES-256, and each backup is also encrypted to a key our servers do not hold.

What is not encrypted at rest: reminder titles and messages, and recipient names, are stored readable so the service can schedule, search and speak them. They are protected by account isolation, limits on what our staff can see, and an audit trail of every staff view. Our security page keeps the full, current list.

Layered Safeguards

We protect your family’s information with:

Secure Infrastructure

Cloud Hosting: We run on established cloud providers with:

Access Controls:

Payment Security

We use Stripe, a PCI DSS Level 1 certified payment processor (the highest security standard).

What this means:

How We Use Your Data

We use your information only for purposes that directly benefit you:

Primary Uses

  1. Deliver reminder calls: Schedule and execute reminder calls to your loved one
  2. Send notifications: Alert you when reminders are delivered or missed
  3. Customer support: Help you troubleshoot issues or answer questions
  4. Billing: Process payments and send receipts
  5. Service improvements: Analyze usage patterns to improve reliability and features

What We DON’T Do

We NEVER:

Your Privacy Rights

You have complete control over your data:

Access and Portability

Deletion

When you delete your account:

Communication Preferences

Data Retention

We keep your data only as long as necessary:

Third-Party Services

We work with carefully vetted third parties:

Who We Share Data With

Telephony providers: To deliver reminder calls (secure, encrypted connections) Payment processor: Stripe, for billing (PCI DSS compliant) Cloud infrastructure: Established hosting providers Analytics: Privacy-focused analytics (Cloudflare Web Analytics: no cookies, no personal data tracking)

What We Require

All third parties must:

Incident Response

Despite our best efforts, no system is 100% secure. If a data breach occurs:

Our Commitment

  1. Immediate investigation: Identify scope and impact
  2. Contain the breach: Stop unauthorized access immediately
  3. Notify affected users: Alert you promptly about what happened
  4. Provide guidance: Explain what happened and what you should do
  5. Prevent recurrence: Implement fixes to prevent similar breaches
  6. Transparency report: Publish details about what happened and how we responded

Privacy by Design

Security and privacy are embedded in our development process:

Compliance and Standards

HelloRemind complies with:

HelloRemind isn’t a healthcare provider, so HIPAA doesn’t apply to us directly, and we are not a business associate: we don’t sign Business Associate Agreements, and our terms don’t allow hospitals, home health agencies or other covered entities to put patient information into HelloRemind. But because families use it for medication schedules and daily routines, we design our data handling to follow HIPAA’s security safeguards anyway.

Transparency and Accountability

We believe in being open about our privacy practices:

Questions or Concerns?

If you have questions about privacy or security:

We take every question seriously and typically respond within 24 hours.

In short

We treat your family’s information the way we’d want our own family’s data treated.

When you choose HelloRemind, you’re choosing a service that:

Your loved one’s safety and your peace of mind shouldn’t come at the cost of privacy. With HelloRemind, you don’t have to choose.

Try HelloRemind free for 14 days and see how secure, private reminder calls work for your family.


More questions about privacy? Contact our team or read our detailed Privacy Policy.