Privacy Policy
Effective Date: April 30, 2026
Meet Gabbi (“we,” “our,” or “us”) provides AI-powered communication solutions designed for high-trust, regulated industries. This Privacy Policy explains how we collect, use, store, and protect information, with a focus on data isolation, AI boundaries, and compliance-ready infrastructure.
1. Our Privacy Commitment
Meet Gabbi is built on three core principles:
- Walled-off data environments (no cross-client access)
- No cross-business AI training
- Client ownership of all data
We do not use your data as a shared asset. Your data remains your competitive advantage.
2. Information We Collect
a. Business Information
- Company name, user accounts, and contact details
- Authentication credentials and permissions
b. Customer Interaction Data
- Messages, transcripts, call recordings, and chat interactions processed through the platform
c. Technical & Usage Data
- IP address, browser/device information
- System logs and usage analytics for performance and security
3. How We Use Information
We use data solely to:
- Provide and operate Meet Gabbi services
- Enable AI-driven communication workflows
- Maintain system performance and reliability
- Ensure security, fraud prevention, and compliance
We do not sell data or use it for advertising.
4. Data Sharing
We do not share client data except:
- With authorized service providers required to operate the platform
- When legally required
- With explicit client consent
All subprocessors are contractually bound to confidentiality and data protection obligations.
5. Data Isolation (Walled-Off Architecture)
Meet Gabbi enforces strict data isolation:
- Each client operates in a segregated data environment
- Data is not accessible across clients
- Access is controlled through role-based permissions and auditing
This ensures complete separation of business data.
6. AI Processing and Data Boundaries
Meet Gabbi uses AI to support communication workflows while maintaining strict data boundaries:
- Client data is not used to train shared or global models
- Data is never shared across businesses for AI learning
- Protected health information (PHI) is not transmitted to external LLM providers
- AI outputs are generated within controlled, client-specific contexts
Your data does not improve models for other customers.
7. Data Ownership
Clients retain full ownership of all data processed through Meet Gabbi, including:
- Communications and transcripts
- Recordings and logs
- AI-generated outputs
Meet Gabbi acts solely as a data processor.
8. Security Measures
We implement industry-standard safeguards:
- Encryption in transit and at rest
- Role-based access controls
- Continuous monitoring and logging
- Secure cloud infrastructure
We regularly review and enhance our security posture.
9. Compliance & Certifications
HIPAA (Health Insurance Portability and Accountability Act)
Meet Gabbi is built on HIPAA-eligible infrastructure and partners with key service providers operating under
Business Associate Agreements (BAAs), including:
- Supabase (data storage)
- Twilio (communications: voice and SMS)
Where applicable, Meet Gabbi supports HIPAA-compliant workflows, including:
- Secure storage and transmission of protected health information (PHI)
- Encrypted communications
- Role-based access controls
- Audit logging and monitoring
Protected health information (PHI) is not transmitted to or processed by external large language model
(LLM) providers.
We will enter into Business Associate Agreements (BAAs) with customers where required.
Clients are responsible for configuring their use of the platform in accordance with applicable regulations.
SOC 2 Alignment
Meet Gabbi maintains internal controls aligned with SOC 2 Trust Services Criteria, including:
- Security
- Availability
- Confidentiality
Formal certification status and documentation are available upon request, where applicable.
10. Data Retention
We retain data only as long as necessary to:
- Provide services
- Meet contractual obligations
- Comply with legal requirements
Clients may request deletion of their data, subject to applicable laws.
11. User Rights
Depending on jurisdiction, users may have rights to:
- Access their data
- Correct inaccuracies
- Request deletion
- Restrict or object to processing
Requests may be submitted using the contact information below.
12. Third-Party Providers
We use trusted vendors to support service delivery. These providers:
- Are bound by confidentiality agreements
- Do not use client data for independent purposes
- Maintain appropriate security and compliance standards
Requests may be submitted using the contact information below.
13. Children’s Privacy
Meet Gabbi services are not intended for individuals under the age of 13. We do not knowingly collect data
from children.
14. Updates to This Policy
We may update this Privacy Policy periodically. Changes will be reflected by updating the effective date.
15. Contact Information
For questions regarding this policy or data practices:
Meet Gabbi
hope@meetgabbi.com
3401 Hartzdale Drive
103B PMB 3503
Camp Hill, PA 17011
Meet Gabbi is built for organizations that require trust, control, and data integrity.
