HamiaSign In
ProductsSolutionsPricing
ProductsSolutionsPricingSign In
Legal

Privacy Policy

Last updated: October 2026

Hamia does not sell, rent, or use your business conversations or customer data for advertising.

  • 1. Who We Are
  • 2. What This Policy Covers
  • 3. Information We Collect
  • 4. Business Data and Customer Communications
  • 5. How Hamia Uses Information
  • 6. AI Processing
  • 7. Connected Communication Platforms
  • 8. How We Share Information
  • 9. Third-Party Service Providers
  • 10. Data Ownership and Control
  • 11. Data Isolation
  • 12. Data Retention and Deletion
  • 13. Security
  • 14. International Data Transfers
  • 15. Cookies and Analytics
  • 16. Your Privacy Rights
  • 17. Business Customer Responsibilities
  • 18. AI Discoverability and Visibility Opt-In
  • 19. Children's Privacy
  • 20. Copyright and DMCA
  • 21. Changes to This Policy
  • 22. Contact Us

1. Who We Are

Hamia LLC (Hamia, we, us, or our) is a global technology company building AI-powered products for businesses, creators, and developers, including Hamia Business, Hamia Studio, Hamia Manager, Hamia Education, Hamia API, and Hamia Pay. This policy explains how we collect, use, and protect information across hamia.io and our products.

Hamia LLC, registered at 30 N Gould St Ste N, Sheridan, WY 82801, USA, is the entity you contract with as a Hamia user. A second, real entity, Hamia Ltd, registered in Nigeria, acts as the underlying payment processor for charges routed through Paystack or Flutterwave (typically for users and teachers in Nigeria and other African markets) — see section 9 for how this fits into the real payment flow.

2. What This Policy Covers

This policy covers hamia.io, our product dashboards, and Hamia Business, Hamia Studio, Hamia Manager, Hamia Education, and Hamia API (Hamia Pay is not yet live). It applies to visitors to our site, business owners and staff who use Hamia, teachers and students who use Hamia Education, and the customers who message a business through Hamia on that business's behalf.

3. Information We Collect

We collect information you provide directly to us, including:

  • Account information, such as your name, email address, and sign in details
  • Payment information, processed securely by our payment providers. We do not store full card numbers ourselves
  • Communications you send to us directly, such as through our contact form

We also collect certain information automatically when you visit hamia.io, including your IP address, browser type, device information, and pages visited. Section 4 below covers two further categories in more detail: information a business provides about itself, and information exchanged in that business's customer conversations.

Hamia Education collects additional information specific to that product: a student's phone number (for verification) and date of birth (to apply the right age-based protections, see section 19); a teacher applicant's resume/CV, a short introductory video, a government-issued ID, and payout details, as part of the real verification process described in our product documentation.

4. Business Data and Customer Communications

We treat these as two distinct categories, because they come from different places and belong to the business in different ways.

Business Data

Information the business itself provides to set up and run its AI assistant: its business profile, products, services, pricing, policies, opening hours, assistant name and voice, its knowledge base content, and any payment details it adds so it can receive payments from its own customers.

Customer Communications

When a business connects a channel (see section 7), Hamia processes the messages, attachments, contact information, conversation history, and related data sent through that channel, on the business's behalf. This is the business's own customer data, sent to Hamia so the business can serve its customers. Hamia does not own this data. See section 10, Data Ownership and Control.

5. How Hamia Uses Information

We use the information we collect to:

  • Operate and improve Hamia Agent, Hamia Studio, Hamia Manager, Hamia API, and Hamia Pay
  • Generate AI assistant responses from a business's own knowledge base, on that business's behalf
  • Process payments and manage subscriptions
  • Send account and service related communications
  • Provide a business with analytics and reporting on its own conversations and performance
  • Comply with legal obligations and protect our legal rights

6. AI Processing

Hamia uses a third-party AI model provider to generate a business's assistant responses. When a customer message needs a response, only the information necessary for that specific request is sent to the model provider, such as the relevant part of the business's knowledge base and recent conversation context, not a business's or customer's full account.

Hamia's current AI model provider is Anthropic, using its Claude models. Anthropic's commercial and API terms, which govern how Hamia uses Claude, contractually exclude customer data sent through the API from being used to train Anthropic's models. This is separate from Anthropic's own consumer product, which operates under different terms. If Hamia ever changes AI model providers, we will update this section to reflect the new provider and its terms, rather than treating this as a permanent promise that could become inaccurate later.

Hamia Education's AI Tutor real-time sessions and certain teacher-application checks (a video review and an ID document review) use Google's Gemini models instead, since those specific features need real-time or multi-modal capabilities. Real-time AI Tutor sessions and Live Video/Audio classes are also carried over LiveKit's infrastructure, which processes the underlying audio/video stream to connect participants; it does not use that stream to train any model.

7. Connected Communication Platforms

Hamia is building toward letting a business connect WhatsApp, Instagram, Messenger, Telegram, LINE, Viber, X (Twitter), website chat, and email, with phone and voice calling planned as a further capability. As of this writing, no real, live connection to any of these platforms is available yet: a business's dashboard includes a tool for simulating a customer message so a business can preview how its AI assistant would respond, not a live channel. We will update this section, and tell businesses directly, as each platform becomes genuinely connectable.

Once a channel is live, Hamia acts as a processor for it, a service provider carrying out that business's own communications on its behalf, not as an independent party collecting that data for itself. The underlying platforms (for example Meta for WhatsApp, Instagram, and Messenger, or X for X/Twitter) are covered further in section 9, but the more important point is this processor relationship: the conversation belongs to the business and its customer, and Hamia is the technology carrying it, not a party using it for its own purposes.

Where connecting a platform requires permission to access the business's own email address on that platform, such as X's email permission, Hamia collects that email as part of establishing and maintaining the connection, to identify the connected account and contact the business about it if needed. This is separate from the account email collected at Hamia sign up (see section 3), and, like the rest of a connected platform's access data, it is deleted when the business disconnects that platform (see section 12).

8. How We Share Information

We do not sell your personal information to third parties. We may share information with:

  • Our AI model provider, as described in section 6
  • The messaging and social platform providers behind each channel a business connects, to send and receive messages on that channel
  • Payment processors, to handle billing and subscriptions
  • Legal authorities when required by law or to protect our rights and the safety of our users

9. Third-Party Service Providers

This is the real, current list of every third-party sub-processor that actually touches user data on Hamia, not a general reference to unnamed "third parties":

  • Anthropic — AI model provider for Hamia Business, Studio, Manager, and most of Hamia Education's AI features (see section 6)
  • Google (Gemini) — AI model provider for Hamia Education's AI Tutor real-time sessions and certain application-review checks (see section 6)
  • LiveKit — real-time audio/video infrastructure for Hamia Education's Live Video, Audio, and AI Tutor sessions
  • Stripe — payout processing for Hamia Education teachers outside Africa (Hamia LLC's own integration; teacher bank details are entered directly on Stripe's own hosted page and never touch Hamia's servers)
  • Paystack and Flutterwave — payment processing for subscriptions, course purchases, and African-market teacher payouts, routed through Hamia Ltd (see section 1) for the underlying merchant relationship
  • Twilio — SMS/OTP delivery and voice calling (used today for Hamia Education's phone verification)
  • Resend — transactional email delivery (account verification, receipts, and notices including parental-consent emails, see section 19)
  • Google reCAPTCHA — spam/abuse protection on sign-up, sign-in, and contact forms (see our Cookie Policy)
  • Meta (WhatsApp, Instagram, Messenger), Telegram, LINE, Viber, and X — the messaging and social platforms behind each channel a Hamia Business customer will be able to connect, once live (see section 7)

Each of these providers processes information under its own terms and privacy practices, alongside Hamia's own commitments in this policy.

10. Data Ownership and Control

The business owns its own customer relationships and data. Hamia provides the technology that processes communications on a business's behalf, we do not claim ownership of a business's customer data or conversations. A business controls what goes into its own knowledge base, decides which channels to connect, and can request export or deletion of its data, see section 16, Your Privacy Rights.

11. Data Isolation

Every business's data on Hamia is kept logically separate from every other business's data. This is a platform level requirement, enforced at the data layer and not only in our application code, so one business cannot access another business's information. This is a standing architecture requirement for how Hamia is built, not an optional safeguard added on top.

12. Data Retention and Deletion

Retention depends on the type of information, not one blanket rule:

  • Account information: retained while your account is active. Using Delete Account in Settings removes your core account record immediately, not on a delay, except where we are required by law to retain something for longer (for example, payment records, below)
  • Conversations: retained according to the connected business's own retention settings and policy
  • Business Knowledge Base data (a business's products, pricing, policies, and FAQs): preserved through the 7 day grace period after a subscription lapses, so reactivating is instant, and deleted if the grace period ends without renewal
  • AI-generated responses: retained as part of the conversation they belong to, under the same conversation retention above
  • Connected platform access tokens: retained until the business disconnects that platform, then deleted
  • Payment records: retained as required for accounting, tax, and other legal obligations
  • Security logs and API logs: retained for a defined period, typically up to 12 months, to protect against abuse and support security investigations, then deleted

Deleting your account through Settings is the fastest way to remove your core account data. If you want confirmation that data specific to a particular Hamia product (for example, a Hamia Education teacher application or student record) has also been removed, contact privacy@hamia.io and we will handle it directly.

13. Security

We take reasonable technical and organisational measures to protect your information, including encrypting stored platform access tokens, hashing API keys, keeping each business's data isolated from every other business's, and enforcing role based access controls so only authorised people can reach a given business's data. However, no method of transmission over the internet is completely secure, and we cannot guarantee absolute security.

14. International Data Transfers

Hamia operates globally, and the providers described in this policy may process information in countries other than your own. Where this happens, we apply appropriate safeguards consistent with applicable data protection laws in the regions where Hamia operates, including standard contractual protections where required.

15. Cookies and Analytics

See our full Cookie Policy for the real, current list of every cookie this site sets and why. In short: a small number of strictly necessary cookies keep you signed in and protect the site from abuse; we do not currently use any analytics or advertising cookies. EU/UK visitors see a real opt-in consent banner; US visitors see a Do Not Sell or Share My Personal Information control instead, consistent with the CCPA. You can change your choice at any time using the control shown on the page.

16. Your Privacy Rights

Depending on applicable law in your region, including the GDPR for users in the EU and the CCPA for users in California, along with other applicable data protection laws in the regions where Hamia operates, you may have the right to:

  • Access the personal information we hold about you
  • Correct inaccurate or incomplete information
  • Request deletion of your personal information
  • Object to or restrict how we process your information
  • Request a portable copy of your data
  • Withdraw consent where processing is based on consent

To exercise any of these rights, contact us at privacy@hamia.io.

17. Business Customer Responsibilities

A business controls who on its own team can access its Hamia account and its customer data, through role based access: owner, admin, agent manager, developer, support, or viewer. Granting a staff member or an agency access to a business's account does not change Hamia's role as a processor described throughout this policy, the business remains responsible for who it grants access to, and for meeting its own obligations to its customers.

18. AI Discoverability and Visibility Opt-In

Separately from the AI processing described in section 6, a business may choose to opt into AI Discoverability, so customers can find it when they ask search engines or AI assistants like ChatGPT or Gemini for recommendations. Opting in means specific business information, such as its name, category, general offerings, and general location, becomes deliberately public and indexable by search engines and AI crawlers.

This is a materially different kind of exposure than the internal AI processing Hamia otherwise carries out on a business's behalf, so it is always its own clear, separate choice, never folded into general processing consent.

19. Children's Privacy

Hamia Business, Hamia Studio, Hamia Manager, Hamia API, and Hamia Pay are not directed at children, and we do not knowingly collect personal information from children through them.

Hamia Education is different: it genuinely involves students who may be minors, so this section states our real, current policy plainly, consistent with the U.S. Children's Online Privacy Protection Act (COPPA) and Article 8 of the GDPR.

  • Under 13, anywhere: we do not permit self-service account creation, and we do not collect a birthdate confirming this from a visitor at all — if the birthdate a visitor enters computes to under 13, it is discarded on your own device before it is ever sent to us, and no account is created.
  • Ages 13–15, EU/UK/EEA visitors: account creation requires a real parent or guardian to confirm consent by email before the account becomes active, consistent with GDPR Article 8. (We apply this to every EU/UK/EEA country uniformly, using the EU's own default age of 16, rather than each country's own, sometimes lower, locally-set threshold — a deliberate, disclosed simplification that is never less protective than what any single member state requires.)
  • Anyone under 18, everywhere: Live Video classes specifically are not available, regardless of the general age threshold above, given the real safety consideration of a live video session between an adult teacher and a student. AI Tutor and Audio classes remain available under the rules above.

If you believe a child has provided us with personal information outside of this real, built process, please contact us at privacy@hamia.io so we can address it.

20. Copyright and DMCA

If you believe content uploaded by a Hamia Education teacher or student infringes your copyright, see our full Copyright / DMCA Policy for how to file a notice and how the review and removal process works.

21. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email or by displaying a notice on hamia.io. Your continued use of Hamia after any changes means you accept the updated policy.

22. Contact Us

If you have any questions about this Privacy Policy or how we handle your data, please contact us at privacy@hamia.io, or write to us at our registered address.

Hamia

Hamia is a technology company building the products behind modern business, education, payments, and commerce.

ProductsHamia BusinessHamia EducationHamia CreateHamia PayHamia API
SolutionsSolutionsPricing
Terms and PoliciesPrivacy PolicyTerms of ServiceUsage PolicyDo Not Sell or Share My Info
CompanyAboutHamia NewsSecurity and Compliance
Help and SupportStatusSupport CenterContact

© 2026 Hamia LLC. All rights reserved.