HAMO Privacy Policy

Last updated: June 9, 2026

1. Who We Are and Scope

Hamo AI Technology Ltd. (“Hamo AI”, “we”, “us”, “our”) operates an AI-mediated mental wellness platform (the “Service”). This Privacy Policy explains what personal information we collect, how we use it, with whom we share it, and the rights you have under applicable privacy law.

This Policy forms part of our Terms of Service and is incorporated by reference. Capitalized terms not defined here have the meaning given in the Terms.

This Policy is governed by Canadian privacy law, including:

  • the federal Personal Information Protection and Electronic Documents Act (PIPEDA);
  • Ontario’s Personal Health Information Protection Act, 2004 (PHIPA); and
  • other applicable provincial health-privacy statutes.

You own your conversation data. Hamo AI Technology Ltd. holds and processes the personal information you provide on your behalf, for the purposes set out in this Policy — it is not the owner of that information.

2. Information We Collect

2.1 Account Information

  • Email address
  • Display name
  • Date of birth (used solely for age verification)
  • Country / region (for crisis-hotline localization and applicable law)
  • Language preference
  • WhatsApp phone number — collected only if you choose to link the optional WhatsApp channel

2.2 Health-Adjacent Information

  • Your conversations with Avatars (AI therapists)
  • Calibration assessment responses
  • Mood and progress logs you create
  • Personality and Stress Vector State (PSVS) scores derived from your activity

2.3 Authentication and Security

  • Multi-factor authentication codes (transient; expire within minutes)
  • Session tokens
  • Login timestamps and source IP address

2.4 Billing

  • Payment-method tokens issued by our payment processor. We do not store full card numbers.

2.5 Service Telemetry

  • Browser type, operating system, application version
  • Coarse usage patterns (page views, feature interactions)

2.6 What We Do Not Collect

We do not collect MAC addresses, Wi-Fi SSID/BSSID, GPS location, contacts, microphone, or camera data.

3. How We Use Information

We use your information to:

  • provide and operate the Service, including AI-mediated conversations, calibration, and progress tracking;
  • detect and respond to mental-health crises (see §4);
  • match you with — and route alerts to — your assigned licensed therapist;
  • process subscription payments and prevent fraud;
  • authenticate you and protect your account;
  • improve the Service through aggregated, de-identified analysis;
  • comply with legal, tax, and regulatory obligations.

3.1 AI Processing

Conversational responses are generated using large language models from the Google Gemini family. We apply post-generation safety filtering and a Chain-of-Verification check to reduce unsupported claims. AI output may still be incomplete or inappropriate; you should not rely on it as the sole basis for any clinical, medical, legal, financial, or life decision (see Terms §5).

We do not use your conversation content to trainany model — third-party or our own, foundation model or fine-tuned small model — unless you have given separate, explicit, written authorization for that specific use. We say “any model” deliberately: a promise limited to “foundation models” would leave the small models we train ourselves outside it, and that is not the line we hold. We donot sell your data to advertisers.

We do use a limited number of de-identified conversation turns to evaluate our own models — that is, to test whether they score conversations correctly and whether they catch crisis signals reliably. Evaluation is not training: this data is used to measure models, never to build them. See §8.1 for how it is handled and how long we keep it.

4. Crisis Disclosures

Hamo AI implements a documented Crisis Escalation Protocol (full text at hamo.ai/crisis-protocol).

When the platform detects acute self-harm signals — through keyword pre-screening or a zero-temperature Gemini classifier — the following happens:

  1. The next AI response is replaced with a fixed, language-localized safety message (not LLM-generated).
  2. A region-specific crisis hotline card appears in the chat, with one-tap dialling (e.g., 988 in Canada/U.S.; 120 / 010-82951332 in mainland China). This card renders in the web and app clients only — if you are talking to your Avatar over the optional WhatsApp channel, you receive the fixed safety text without a tappable hotline card.
  3. The licensed therapist assigned to your account receives a secure email and dashboard notification containing your name, the crisis type, a short verbatim excerpt of the triggering message, and a timestamp. The excerpt is not anonymized — it is sent, with your name, to the one clinician already responsible for your care.
  4. An immutable audit record is created. After your account is deleted, the record is pseudonymized — your name is replaced with a hash — and retained for the regulatory period required in your jurisdiction. Pseudonymized is not anonymous: we continue to treat these records as personal information.

4.1 Institutional Sponsorship (Tier-2)

If your account is sponsored by an institutional partner (e.g., your employer’s EAP), the partner may receive a notification — but only if you have explicitly opted in, and the notification will contain only the event type and a timestamp, never conversation content. You may revoke this consent at any time at Settings → Privacy. (This Tier-2 capability is committed for delivery in Q2 2026; see the published Crisis Protocol §5 for details.)

4.2 Limits of the Crisis Mechanism

Hamo AI is not an emergency service and cannot place calls on your behalf. In an immediate emergency, dial 911 (Canada/U.S.) or 120 (mainland China).

5. Sharing and Sub-processors

We share your personal information only with:

  • your assigned therapist, in their clinical role;
  • sub-processors that operate the Service on our behalf, under written data-processing agreements;
  • institutional partners, only if you have opted in and only as described in §4.1;
  • law enforcement or regulators, when legally required and only to the minimum extent necessary.

5.1 Current Sub-processors

Sub-processorPurposeRegion
Google LLCGemini conversational AI processingUnited States
Amazon Web ServicesHosting, database (DynamoDB), encryption (KMS), email delivery (SES)Canada (ca-central-1) and United States
Stripe Inc.Payment processingCanada / United States
Meta Platforms, Inc.WhatsApp Business Platform — message delivery for the optional WhatsApp channel (message content and WhatsApp phone number, only if you link WhatsApp)United States

We do not sell, rent, or trade your personal information.

6. Cross-Border Data Transfers

Some of our sub-processors process personal information outside Canada, primarily in the United States. We rely on Standard Contractual Clauses and equivalent safeguards required by PIPEDA’s accountability principle. Where feasible, mental- health data for Canadian users is stored in Canadian AWS regions.

7. Your Privacy Rights

Under PIPEDA, PHIPA, and applicable provincial law, you have the following rights:

RightWhat it meansWhen we respond
AccessRequest a copy of the personal information we hold about youWithin 30 days, free of charge
CorrectRequest corrections to inaccurate or incomplete informationPromptly, with confirmation
DeleteRequest deletion of your account and associated dataWithin 7 business days for active deletion; up to 90 days for irrevocable deletion of replicated backups
ExportReceive a machine-readable export of your conversation historyWithin 14 days
Withdraw consentStop further processing for analytics, marketing, or institutional notificationEffective immediately for future events

Submit requests to privacy@hamo.ai. We will not retaliate against you for exercising any right under this Policy.

7.1 Complaint Channels

If you are not satisfied with our response, you may lodge a complaint with:

  • the Office of the Privacy Commissioner of Canada priv.gc.ca
  • the Information and Privacy Commissioner of Ontario ipc.on.ca
  • the equivalent privacy regulator in your province or country of residence.

8. Data Retention

Data typeRetention period
Account profileWhile account is active
Conversation historyWhile account is active; deleted within 90 days of account deletion
Calibration and PSVS dataWhile account is active; deleted within 90 days of account deletion
Crisis-event metadataAnonymized at account deletion; retained for the period required by applicable law (typically 7 years)
Audit logs (MFA verification, access, mutation events)7 years
Billing records7 years (Canadian tax law)

8.1 Evaluation Data

To measure whether our models score conversations correctly and catch crisis signals reliably, we maintain a fixed evaluation set built from a limited number of de-identified conversation turns. Three things about it are worth stating plainly:

  • It is pseudonymized, not anonymized, and we would rather describe the gap than round it off. The salt used to hash identifiers is a fixed, hard-coded string, so the mapping is reproducible by anyone holding the script — not only by us. Full timestamps are retained. Conversation text is preserved verbatim. And the redaction patterns cover mainland-China formats only: in our own testing, Hong Kong 8-digit numbers, North-American +1 numbers, personal names, WeChat IDs and street addresses all passed through unredacted — while our users are in Hong Kong and Canada. We are closing those gaps before the next export. Until then and after, we continue to treat this data as personal information, and the rights described in §7 continue to apply to it.
  • It is never used to train models — only to test them.
  • It is frozen. Every generation of a model has to be measured against the same test, so turns already included are not automatically removed when an account is deleted. Your conversation history in the live Service is still deleted as described in the table above. These evaluation files are never shared, published, or distributed outside the company. If you want your turns removed from this set, contact us using the details in §12.

9. Security

  • Data is encrypted in transit using TLS 1.2 or higher.
  • Data is encrypted at rest using AWS KMS Customer-Managed Keys (CMKs), with annual key rotation.
  • We enforce email-based multi-factor authentication on all logins (PHIPA 6.1.4 compliant).
  • Access is enforced by JWT role checks: only the therapist assigned to a client can view that client’s conversations and crisis alerts.
  • We maintain a documented PHIPA self-assessment and conduct regular security reviews.
  • No security control is perfect. Help us by keeping your password and email account secure.

10. Children and Minors

You must be at least 16 years of age to use the Service in Canada or the United States, or 18 years of age in jurisdictions where the contractual age of majority is higher. Users under 18 should use the Service only with the involvement of a parent or guardian.

We do not knowingly collect personal information from individuals under 16. If we become aware that we have collected such information, we will delete it without undue delay. If you believe a minor has registered, please contact privacy@hamo.ai.

11. Changes to This Policy

We may update this Policy from time to time. Material changes will be notified by email and via in-app banner at least 30 days before they take effect. Continued use of the Service after the effective date constitutes acceptance of the revised Policy.

12. How to Contact Us

Hamo AI Technology Ltd.
108 College St, Schwartz Reisman Campus, SUITE W640
Toronto ON M5G 0C6
Canada

13. Governing Law

This Policy is governed by the laws of the Province of Ontario, Canada, and the federal laws of Canada that apply. Disputes follow the process described in our Terms of Service §13.

Copyright© 2026 Hamo AI Technology Ltd. · Incorporated in Ontario, Canada.