Last updated: October 2, 2026
Heylio ("we", "our", "us") is committed to protecting the privacy of businesses and their customers. This Privacy Policy explains how we collect, use, store, and protect personal data in compliance with GDPR.
Data Controller: Heylio
Contact: privacy@support-pilot-ai.com
We share data only with the following service providers (sub-processors), necessary for service operation:
| Provider | Purpose | Data Shared |
|---|---|---|
| Vercel | Application hosting | All requests to the app and API, including the data they carry |
| Convex | Database and file storage | All app data: accounts, settings, tickets, messages, knowledge base, uploaded files |
| Trigger.dev | Background jobs (email sync and processing, knowledge-base processing, reports, data export and erasure) | Data processed by these jobs, in transit |
| GitHub | Daily database backup, kept 90 days in a private repository | A copy of all app data |
| OpenRouter | AI response generation and text embeddings (routes requests to Anthropic Claude and OpenAI embedding models) | Ticket and chat content, customer context, knowledge-base excerpts |
| Anthropic (Claude API) | Backup AI provider when OpenRouter is unavailable | Ticket and chat content, customer context, knowledge-base excerpts |
| OpenAI | Backup provider for text embeddings | Knowledge-base text and search queries |
| Voyage AI | Search result ranking | Customer questions and knowledge-base excerpts |
| TypeSafe | Automated checks on AI drafts and customer intent | Excerpts of customer messages and AI drafts |
| Resend | Transactional and notification emails | Recipient email address and email content |
| PostHog (EU region) | Product analytics and error reporting | Usage events, pseudonymous identifiers, IP address, technical error details |
| ipinfo.io | Country detection for chat widget visitors | Visitor IP address |
| Google Ads | Advertising conversion measurement on our web pages | Page visits and cookie identifiers |
| Stripe | Subscription and credit-pack payments (standalone accounts) | Billing contact, payment details, subscription status |
| Telegram | Optional daily report, when the merchant links a Telegram chat | Telegram chat ID and aggregate ticket counts |
When a business connects one of the following services, data is exchanged with it on the business's behalf:
| Provider | Purpose | Data Shared |
|---|---|---|
| Shopify | Store data, orders and customers; billing for Shopify merchants | Store, order and customer data needed to answer support requests |
| Google (Gmail API, Sign in with Google, Google Docs) | Email synchronization, sign-in, knowledge-base import | Email content, account email address, imported documents |
| Microsoft (Outlook API) | Email synchronization | Email content when Outlook is connected |
| Meta (Instagram and WhatsApp APIs) | Direct message support | DM content, sender username or phone number, conversation history |
| Gorgias, Zendesk, Front | Helpdesk synchronization, when connected | Tickets and messages exchanged with the connected helpdesk |
You have the right to: Access, Rectification, Erasure, Restriction, Portability, and Objection.
To exercise any right, contact: privacy@support-pilot-ai.com