Privacy Policy
Last updated 26 September 2026
This policy covers the products and services of HiAlly, operated by HiAlly Technologies. We make two kinds of product, and they handle data differently, so this page treats them separately:
- Local products — Billing Books and Assistant — which run on your own computer.
- Connected services — our AI Employees, starting with HiAlly Sales, and the messaging channels a business can connect to them.
It explains what we collect, why, and what you can do about it. It is written plainly on purpose.
The short version: by default, our local products keep your business data on your machine — the only information we hold is what you type when you activate. Connected services work differently by design: when a business connects a messaging channel such as WhatsApp or Telegram, the messages and details needed to run that service are processed by HiAlly’s connected service and by the messaging platform. We do not sell personal data.
Local products and connected services
Local products
Billing Books and Assistant are designed to process your business data locally, on your own computer. Your invoices, ledgers, documents and spreadsheets are not sent to us.
Connected services
An AI Employee talks to a business’s customers on a messaging platform, so it cannot run on one office computer. The messages sent to a connected business, and the information needed to reply and to hand the conversation to the business’s team, are processed by HiAlly’s connected service and by the relevant platform.
Local products
What stays on your computer
By default, local products keep everything they touch on your own machine. For Billing Books that means:
- Every invoice, credit note and receipt
- Your customers and suppliers, and what they owe
- Your items, prices, costs and stock levels
- Your takings, profit figures and reports
- Your GSTIN, shop address and bank details
For Assistant it means your documents and spreadsheets, and the questions you ask about them.
None of this is sent to us. If you turn on backups, the copy goes to a folder you choose — normally your own Google Drive or OneDrive folder — which is your account, not ours.
If you choose to link a locally run HiAlly assistant to a HiAlly online dashboard with a connection key, a record of each conversation it handles — what was said and what it answered — is sent to that dashboard and is treated as connected-service information, described below. Your books themselves are not sent.
What we collect when you activate
When you activate the software, the details you type are sent to us so we can issue your licence:
| What | Why we need it |
|---|---|
| Shop name | It is printed on your licence |
| Your name | So we know who to write to |
| To contact you about your licence and its renewal | |
| Phone / WhatsApp | Support, if you ask for it |
| Country and trade | To understand who uses the software |
| A code for your computer | So your licence works on your machine |
The computer code is a scrambled one-way value. It cannot be turned back into anything about your machine, and it does not identify your hardware, location or network.
What we do with it
- Issue and renew your licence
- Contact you about your licence and its renewal
- Help you if you contact support
- Occasionally tell you about our other products
Where it is kept
On Cloudflare’s servers, which we use to run the licence service. Your details stay for as long as you use the software, and are removed if you ask.
One thing to be aware of. The local products can optionally use an online AI service. In Billing Books it is for typing bills by voice or in plain language, and it is off unless you switch it on and enter a key for a provider you choose. Assistant uses an AI model on your own computer by default, and can instead be set up to use an online one. The software supports Groq, OpenAI and Anthropic. When an online service is used, the words you type or speak for that feature — and, for Assistant, your question and the passages of your documents needed to answer it — are sent to that provider. Your books and files as a whole are never uploaded. With no online service set up, the software sends nothing except your licence check.
Connected services: HiAlly Sales
HiAlly Sales is an AI Employee for customer conversations. It is in development. When a business connects it to a messaging channel, it can:
- greet a customer with the business’s own welcome message and menu;
- recognise which of the business’s own products a customer names, by comparing their words with the product list the business provides;
- recognise an existing customer of the business from the number they message from, where the business has provided its customer list;
- ask the questions the business has set up, and collect the answers as an enquiry with a reference number;
- tell the business’s team about the enquiry, and hand the conversation to a person.
The business decides whether to connect a channel and what information to give HiAlly. The business is responsible for telling its own customers how it handles their messages; we process those messages on the business’s behalf, to provide the service.
How a message flows
For a connected service, a customer’s message travels like this:
| Step | What happens |
|---|---|
| 1. Customer | A customer sends a message to a business on a channel the business has connected — WhatsApp, Telegram, or Instagram when that is enabled. |
| 2. Messaging platform | The platform delivers it: Meta for WhatsApp (and Instagram, when enabled), Telegram for Telegram. |
| 3. HiAlly connected service | HiAlly receives the message and processes it for the business, as described on this page. |
| 4. Business workflow | Depending on what the business has set up, HiAlly records an enquiry, notifies the business’s team, or hands the conversation to a person. |
| 5. Response | Replies go back to the customer through the same platform. |
Meta and Telegram process information on their own platforms under their own terms and privacy policies. HiAlly does not control that processing.
WhatsApp and Meta integrations
- A business may connect its WhatsApp Business account to HiAlly, by giving HiAlly access to its WhatsApp Business phone number through Meta’s WhatsApp Business Platform.
- HiAlly receives, through Meta, the WhatsApp messages sent to that connected number.
- HiAlly processes the content of those messages — such as text, captions and the buttons a customer taps — together with the sender’s WhatsApp number and profile name, to provide the service described above.
- HiAlly processes the identifiers needed to operate the integration, such as the connected phone number ID and message IDs, and keeps the access credential the business provides so that it can reply on the business’s behalf.
- HiAlly sends replies to customers, and notifications to the business’s own team members, through Meta’s APIs — only for a business that has connected and authorised it.
- A business can disconnect its number from its HiAlly settings, which removes the stored connection and credential. It can also remove HiAlly’s access from its Meta business settings. Disconnecting stops new messages; to have past conversations deleted, see Data Deletion.
Telegram
- A business may connect a Telegram bot it has created, by giving HiAlly the bot’s token.
- HiAlly receives the messages sent to that bot and processes their content, the sender’s Telegram user ID and display name, the chat ID, and — if the sender chooses to share it — their phone number, to provide the same service.
- If the business adds its bot to a Telegram group, HiAlly may process messages in that group to provide the features the business has enabled — for example, recording work reports from the business’s own team.
- Replies and notifications are sent through Telegram’s Bot API. A business can disconnect its bot from its HiAlly settings.
Instagram (when enabled)
When enabled, HiAlly may integrate with Instagram Professional accounts to receive and respond to messages through Meta’s APIs. This integration is not available yet. If a business connects an Instagram Professional account, HiAlly would process the account’s identifiers and the messages sent to it, for the same purposes and in the same way as described for WhatsApp. We will update this policy before it becomes available.
Information we may process
Not every category applies to everyone — it depends on which services a business enables. HiAlly may collect or process:
| Category | Examples |
|---|---|
| Account and sign-in information | The name and email of each person who signs in, and their sign-in sessions. Passwords are stored only as a salted hash. |
| Business information | Company name, industry, welcome message, menu, questions, product categories and delivery areas the business sets up. |
| Product and customer lists | Item and customer lists a business uploads — for example item names, rates, stock, customer names, phone numbers and balances — or information read from a business system it connects. |
| Customer contact information | The phone number or messaging name a customer writes from, and the names and phone numbers in a customer list a business uploads. |
| Customer messages and conversation history | The messages a business’s customers send, the replies sent to them, and when. |
| Messaging identifiers | WhatsApp numbers and profile names; Telegram user IDs, display names and chat IDs; connected phone number IDs and message IDs; Instagram account identifiers when that integration is enabled. |
| Enquiry information | The product understood, the answers to the business’s questions, reference numbers and status. |
| Human handoff information | Which team member took a conversation or an enquiry, and when. |
| Team reports | Free-text work reports sent by a business’s own team members, and the records made from them. |
| Integration settings and credentials | Access tokens and bot tokens a business provides, and the address and key of a business system it connects. |
| Usage records | Counts of the messages and actions handled, used to show the business its activity and to account for paid services. |
| Technical information | Server logs, which can include IP addresses, the addresses requested, and times. |
| Contact information | Whatever you include when you email us. |
| Licence information | For local products, as described above. |
How we use it
- To provide the services a business has enabled: receiving messages, replying, collecting enquiries, and notifying and handing over to its team
- To show the business its conversations, enquiries and activity on its dashboard
- To keep the services secure and working, and to investigate problems
- To provide support
- To count use of paid services
We do not sell personal data, we do not pass it to advertisers or data brokers, and we do not use customer conversations to train AI models.
AI processing
Certain HiAlly products and features may use AI or automated processing. The specific processing depends on the product and on the features the business enables. Not every message is sent to an AI model.
HiAlly Sales does not currently use an AI model to write its replies to customers. Its replies are built from fixed wording and the information the business has set up, and it recognises products by comparing the customer’s words with the business’s own product list.
Some other HiAlly features do use AI models:
- In the connected service, free-text work reports sent by a business’s own team members can be read by an AI model, currently provided by Groq, to turn them into records. Where the result is unclear, the team member is asked to confirm.
- In the local products, typing or speaking a bill in plain language uses the AI provider the user chooses, as described above.
AI output can be wrong. We design these features to check what a model produces and to ask a person when it is unsure, rather than guess. A business remains responsible for the accuracy of the information it gives HiAlly.
We may introduce further AI capabilities in the future, including AI-assisted replies. We will update this policy before they are used.
Service providers and third parties
- Meta — WhatsApp messages are sent and received through Meta’s WhatsApp Business Platform, and Instagram messages will be when that integration is enabled. Meta processes this information under its own terms and privacy policy; HiAlly does not control Meta’s processing.
- Telegram — for businesses that connect a Telegram bot, under Telegram’s own terms.
- Cloudflare — hosts this website and our licence service, and carries connections to our connected service.
- Groq — the AI model provider for reading team members’ free-text reports, when that feature is used.
- Zoho — hosts our email, so it receives what you send us.
- GitHub — serves the Windows installer when you download it.
We may also disclose information where the law requires it.
How long we keep it
We do not set a fixed retention period. Data may be retained for as long as necessary to provide the service, support the business’s operations, comply with applicable obligations and maintain security, or until a valid deletion request is processed. For example, conversation history and enquiries stay available to the business on its dashboard until deletion is requested. Sign-in sessions expire after 30 days. Licence details for local products are kept for as long as you use the software, and removed if you ask.
Security
How we protect this information is described on our Security & Data Protection page.
Your choices
You can ask us at any time to:
- Tell you what we hold about you
- Correct anything that is wrong
- Delete your details
- Stop emailing you
A business can also disconnect any channel it has connected, at any time.
If you are a customer of a business that uses HiAlly, the business is usually the best first contact, because it decides how your messages are used. You can also contact us directly and we will help, working with the business where needed.
Email hello@hially.in. Deleting your licence details does not stop the local software working — your books are yours and stay on your computer.
Deleting your data
How to ask us to delete data — including what happens to connected WhatsApp, Telegram and Instagram data — is explained on our Data Deletion page.
Children
This is business software and is not intended for anyone under 18.
Changes
If this changes in a way that matters, we will say so on this page and put the new date at the top.
Contact
HiAlly Technologies — hello@hially.in · Contact page