Privacy Policy
Last Updated: August 2026
HeyMyra Inc. ("Myra," "we," "us," or "our") operates the Myra platform - an all-in-one CRM, communications and automation product that includes voice calling, SMS/MMS, email, calendars, forms, pipelines, e-signatures, payments, AI assistants and whitelabel tooling. This Privacy Policy explains what data we collect, how we use it, who we share it with, and the rights you have.
Myra is offered both directly and through partners who resell Myra to their own clients. Where a business or its client controls a workspace, Myra acts as a data processor and the business/client is the data controller for content they upload or transmit through the platform.
1. Information We Collect
Account & profile data
- Name, email address, phone number, password hash, profile photo.
- Business / workspace membership, roles and permissions.
- Multi-factor authentication (MFA) enrolment status and recovery data.
- Billing details processed via Stripe (we do not store card numbers).
Contact & CRM data
Data you or your team import or capture about your own leads and clients, including names, phone numbers, email addresses, tags, notes, pipeline stage, custom fields, tasks, calendar events, forms responses, and files.
Communications data
- Voice calls: call metadata (from, to, duration, direction, timestamps), and - where enabled - call recordings and AI-generated transcripts, summaries and action items.
- Voicemail: audio recordings and AI transcripts/summaries.
- SMS/MMS: message content, media attachments, delivery status, opt-in/opt-out state, keyword replies.
- Email: sent and received message content, subject lines, attachments, opens/clicks (where tracking is enabled), and unsubscribe status.
- WhatsApp & social channels: message content and metadata for channels the workspace connects.
Payments data
When a workspace collects payments through Myra, Stripe processes the transaction. We store transaction metadata (amount, currency, status, invoice/receipt IDs, customer reference) but do not store full card numbers or CVV - those are handled directly by Stripe under PCI-DSS.
AI & usage data
Prompts, generated outputs, credit usage per workspace, feature-toggle state, and product analytics used to operate, secure and improve the service.
Meta / Instagram end-user data
Where a workspace connects a Facebook Page or Instagram Professional account, we process direct message content, comments, story replies, mentions and basic public profile metadata via the Meta Graph API. Media received via Meta is streamed from Meta's CDNs in line with the Meta Platform Terms and is not permanently rehosted by us.
Technical data
IP address, device and browser information, log data, cookies and similar identifiers - see our Cookie Policy.
Availability, device & sign-in data (platform users)
To route calls to people who can actually answer them, and to help workspace administrators see why a call did not ring, we record operational data about the people who use the platform itself - business and client staff, not their contacts.
- Availability: while the app is open, your browser sends a heartbeat roughly every 30 seconds recording that the app is open, whether the calling connection is registered, and the time of that signal.
- Device & browser: the browser user-agent string of the devices you sign in from, and whether the browser is currently blocking call audio.
- Call-routing health: for each call routed to you, whether your app was reachable, and counts of consecutive unreachable attempts.
- Notification setup: push-notification subscriptions for each device (an endpoint identifier issued by your browser's push service, the device type, and whether delivery succeeded or failed), your browser's notification-permission state, and whether the app is installed to your home screen.
- Sign-in & credentials: the time you last signed in, whether you have set a password, and when you last set or changed it. We never store your password itself - only a one-way hash held by our authentication provider.
Who can see this. These indicators are shown to administrators of the workspaces you belong to, and to other members of those workspaces, on the team management screen. They exist so a business can tell whether its team is set up to receive calls. They are not used to measure individual productivity, and we do not record the content of your screen, your keystrokes, or your location.
If you use Myra as an employee or contractor of a business, that business is the controller of this data and is responsible for telling you how it uses it.
2. Google User Data
Where you connect a Google account to Myra, we access the Google user data listed below. We request the narrowest permissions that allow each feature to work. We never sell Google user data and never use it for advertising.
- Google Calendar - view and edit events (calendar.events): used to create, update and cancel the appointments you book through Myra, so a booking made in Myra appears on your Google Calendar and cancelling it in Myra removes it.
- Google Calendar - read-only (calendar.readonly): used to read your existing calendar events so Myra can show your real availability and avoid double-booking you. Events from the connected calendar are copied into your Myra workspace so they appear alongside your bookings.
- Gmail - read-only (gmail.readonly): used to show your email conversations in Myra's unified inbox alongside calls and messages for the same contact. Message content retrieved this way is stored in your workspace so the conversation history remains available in the inbox.
- Gmail - send (gmail.send): used to send email that you compose in Myra, from your own address.
- Email address (userinfo.email): used only to show which Google account is connected and to reconnect it if the connection expires.
Limited Use. Myra's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer Google user data to third parties except as needed to provide the features you have connected, to comply with applicable law, or as part of a merger or acquisition. We do not use Google user data to train generalised artificial intelligence models. We do not allow humans to read it, except with your explicit permission, for security purposes such as investigating abuse, to comply with applicable law, or where the data has been aggregated and anonymised.
Disconnecting. You can disconnect a Google account at any time from Settings. Disconnecting revokes Myra's access token with Google and deletes the calendar events that were synced from that account. You can also review and revoke access directly at Google.
3. How We Use Information
- Provide, operate, secure and improve the platform and its features.
- Route, deliver and log calls, SMS, email, WhatsApp and social messages between workspaces and their contacts.
- Route calls to team members whose app is open and able to receive them, and diagnose why a call did not connect.
- Generate AI transcripts, summaries, drafts, task triage and other automations you enable.
- Process payments and wallet top-ups, including Stripe auto-recharge for telephony and AI credit balances.
- Send transactional messages (security alerts, MFA codes, billing notifications, service updates).
- Detect and prevent fraud, abuse, spam and violations of our Terms of Service.
- Comply with legal, tax, accounting and carrier/A2P 10DLC obligations.
We do not use your contacts' data, message content, call recordings or CRM records to train general-purpose AI models.
4. Call Recording & Consent
Call recording and AI transcription are workspace-configurable. Where enabled, the workspace is responsible for providing any legally required disclosure or consent (including two-party consent in applicable US states, and equivalent laws elsewhere). Myra provides tooling - including recording announcements and per-number toggles - but the workspace is the controller and must operate the feature lawfully.
5. SMS, A2P 10DLC & TCPA
US SMS traffic sent through Myra runs over registered A2P 10DLC campaigns. Workspaces must complete A2P registration, keep a valid opt-in mechanism, honour STOP / UNSUBSCRIBE / HELP keywords (Myra handles these automatically), and comply with the TCPA and CAN-SPAM Act, including quiet-hours rules and sender identification. Myra retains message content, delivery receipts and opt-out state to demonstrate compliance.
Phone-number / SMS consent data is never shared with third parties or affiliates for their own marketing. This applies to all opt-in and consent records regardless of category.
6. Data Sharing & Subprocessors
We do not sell your personal information. We share data only with vetted subprocessors that need it to run the service, under contractual confidentiality and data-protection obligations. Key subprocessors include:
- Cloud infrastructure & database - application hosting, storage and backups.
- Telephony providers - voice, SMS/MMS delivery and phone-number provisioning.
- Stripe - payment processing, invoicing, wallet top-ups and tax calculation.
- Email delivery providers - for transactional and workspace-sent email.
- AI model providers - for transcription, summarisation, drafting and assistant features.
- Meta Platforms - where Facebook / Instagram / WhatsApp channels are connected.
- Analytics & error monitoring - to operate and secure the service.
We may also disclose data where required by law, to enforce our Terms, or to protect the rights, safety and property of Myra, our users or the public.
7. Data Retention
- Account & workspace data: retained while the account is active, plus up to 30 days after closure for backup/recovery.
- Calls, recordings, transcripts, SMS, email: retained while the workspace is active or until deleted by the workspace.
- Billing & transaction records: retained for up to 7 years to meet tax and accounting requirements.
- Meta / Instagram end-user data: retained until the workspace or the end-user requests deletion.
- Availability, device & notification records: held as current status and overwritten each time they refresh, rather than kept as a running history. A snapshot of which team members were available is retained with each call's routing log for as long as that call record is kept.
- Aggregated, anonymised analytics: may be retained indefinitely for service improvement.
On verified deletion requests we remove personal data within 30 days, except where retention is required by law.
8. Your Rights
Depending on your jurisdiction (including GDPR in the EEA/UK and CCPA/CPRA in California) you may have the right to access, correct, delete, port or restrict processing of your personal data, and to object to certain uses. To exercise these rights contact us at contact@heymyra.ai. End-users who interacted with a Myra-powered workspace can also use our Data Deletion Page.
9. Security
We use encryption in transit, access controls, row-level security in our database, audit logging, signed webhooks, MFA for accounts, and least-privilege service credentials. No system is 100% secure - report suspected vulnerabilities to contact@heymyra.ai.
10. International Transfers
Myra is operated from the United States. If you access the service from outside the US, your information may be transferred to and processed in the US and other countries where our subprocessors operate. We rely on appropriate safeguards (such as Standard Contractual Clauses) for transfers of personal data out of the EEA / UK.
11. Children's Privacy
Myra is not intended for children under 13 (or 16 in the EEA). We do not knowingly collect personal information from children. If you believe a child has provided us data, contact contact@heymyra.ai and we will delete it.
12. Changes to this Policy
We may update this Policy from time to time. Material changes will be notified in-app or by email. Continued use of the platform after an update constitutes acceptance of the revised Policy.
13. Contact
HeyMyra Inc. (a Delaware corporation)
Email: contact@heymyra.ai
