Privacy Policy
This Privacy Policy describes how Louneh (“Louneh,” “we,” “us”) collects, uses, and shares personal information when you use our AI receptionist services, our website, and any related products (collectively, the “Services”).
1. Who we are
Louneh is a Delaware corporation that provides AI-powered phone answering, scheduling, and customer-communication services to small businesses (our “Customers”). When we provide those services on behalf of our Customers — for example, by answering calls placed to their published phone number — we typically act as a service provider or business associate, not as the data controller of the call content itself.
This policy covers personal information we collect in our own right (for example, when you sign up for an account or visit this website). For personal information our Customers entrust to us to operate the Services on their behalf, our Customers’ own privacy policies and our contracts with them govern.
2. What we collect
Information you give us directly
- Early beta interest: your email address and consent to receive beta-access updates. Joining the list does not create an account or guarantee an invitation.
- Account information: name, email, business name, phone number, role.
- Billing information: handled by our payment processor (Stripe). We never store full card numbers on our systems.
- Communications: messages you send to support, sales, or partnerships.
Information we collect when you use the Services
- Usage metadata: pages viewed, features used, session duration.
- Device and connection metadata: IP address, browser, operating system, timestamps.
- Optional marketing analytics: when enabled and accepted, PostHog receives approved public-page events, campaign categories, a random session identifier, and verified inquiry or beta-interest conversions. Beta conversions use a random registration receipt identifier; email addresses are excluded. Analytics preferences lets you decline or withdraw consent. We honor Do Not Track and Global Privacy Control.
- Analytics preferences are stored locally; the optional analytics identifier lasts for the browser tab session. Form contents, patient activity, session recordings, raw URLs, and raw error messages are excluded from PostHog. Operational logs contain approved service, status, timing, and error-category fields.
Information from your callers (when we act on your behalf)
- Call audio recordings (subject to applicable two-party-consent disclosures).
- Call transcripts and AI-generated summaries.
- Caller phone number, voicemail content, SMS content, deposit payment metadata.
- For Customers in healthcare: protected health information (PHI), governed by a separate Business Associate Agreement.
3. Why we collect it
- To provide, operate, and improve the Services.
- To bill you and collect payments owed.
- To send transactional notices about your account, security, or service changes.
- To detect, investigate, and prevent fraud, abuse, and security incidents.
- To comply with legal obligations and respond to lawful requests.
- With your consent, to send you marketing communications. You can opt out at any time.
We do not sell personal information. We do not train any public foundation model on your data or your callers’ data.
5. Retention
We retain personal information only as long as needed for the purposes described in this policy or as required by law. Defaults for Customer-controlled data:
- Call audio: 30 days, configurable down.
- Transcripts and AI summaries: 90 days, configurable down.
- Appointment records: lifetime of the Customer account, or as set by the Customer.
- Billing records: 7 years (tax and accounting obligations).
- Audit logs: 7 years (HIPAA and security obligations).
You can request deletion of your account data at any time; see “Your rights” below.
6. PHI and HIPAA
For Customers who use the Services to handle protected health information (PHI), we execute a Business Associate Agreement (BAA) that governs the use, disclosure, and safeguarding of PHI under the HIPAA Privacy and Security Rules. The current template BAA is published at /baa.
Where this Privacy Policy and the BAA differ for PHI, the BAA controls.
7. Your rights
Depending on your jurisdiction, you may have rights to access, correct, delete, port, or restrict our processing of your personal information, and to object to certain processing. To exercise any of these rights, email privacy@louneh.ai from the email address on your account. We respond within 30 days.
If we act as a service provider for a Customer who controls the data, we will route your request to that Customer and assist them in responding.
8. Children
The Services are not directed to children under 13, and we do not knowingly collect personal information from children. If you believe a child has provided personal information to us, contact privacy@louneh.ai and we will delete it.
9. Security
We use commercially reasonable administrative, technical, and physical safeguards to protect personal information. Our current posture — encryption, access controls, audit logging, breach notification, sub-processor program — is detailed on our Security page. No system is perfectly secure; if we discover a breach of personal information, we will notify affected Customers and, where required, regulators.
10. International transfers
We currently operate primarily in the United States. If you access the Services from outside the U.S., your information may be transferred to and processed in the U.S., which may have different data-protection laws than your country.
11. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be announced to Customers in writing at least 30 days before they take effect. The “Last updated” date above is authoritative.
12. Contact us
Questions about this policy or our handling of personal information: privacy@louneh.ai. For security disclosures, use security@louneh.ai.