Privacy Policy

Filo Health ("Filo Health," "we," "us," or "our")

Effective date: 24 June 2026  ·  Last updated: 24 June 2026

Website: https://www.filohealth.io  ·  Contact: danablend@gmail.com

Contents

  1. Overview and scope
  2. Our role: controller vs. processor
  3. Data we collect
  4. Platform-specific data handling
  5. WhatsApp and Instagram (Meta)
  6. Google / Gmail Limited Use
  7. Microsoft Graph (Outlook)
  8. IMAP / SMTP email
  9. Telephony, SMS, and AI voice (Telnyx)
  10. Call recording and transcription
  11. How we use data
  12. AI agents and automated processing
  13. How we share data
  14. Data retention
  15. Security
  16. International transfers
  17. GDPR (EEA/UK)
  18. CCPA/CPRA (California)
  19. Data deletion requests
  20. Children's privacy
  21. Cookies and tracking technologies
  22. Changes to this policy
  23. Contact us

1. Overview and scope

Filo Health provides a unified customer-communications platform: a single inbox plus AI agents that businesses ("Customers") use to send, receive, route, and respond to messages and calls across multiple communication channels. Our service connects, on behalf of our Customers, to third-party platforms including WhatsApp and Instagram (Meta Platforms), Gmail (Google), Outlook (Microsoft), generic IMAP/SMTP email servers, and telephony and SMS networks (via Telnyx), including AI voice agents and automated appointment reminders.

This Privacy Policy explains how we access, use, store, share, and retain personal data when you use our website, applications, and services (collectively, the "Service"). It applies to:

2. Our role: controller vs. processor

For most communications data that flows through the Service on behalf of a Customer (messages, emails, call content, contact records, and related metadata), Filo Health acts as a data processor (a "service provider" under U.S. law) that processes data under the instructions of the Customer, who is the data controller. The Customer is responsible for having a lawful basis and the necessary notices and consents in place for the End User data they route through the Service.

For our website, account administration, billing, marketing, and product analytics, Filo Health acts as the data controller. Where we act as a processor, our Data Processing Addendum (DPA) governs that processing in addition to this policy.

3. Data we collect

Account and Customer data

Communications content and metadata (processed on behalf of Customers)

Technical and usage data

4. Platform-specific data handling

The table below summarizes what we access, why, and how long we keep it for each integrated platform. Platform-specific compliance disclosures follow in sections 5 through 10.

PlatformData accessedPurposeRetention
WhatsApp and Instagram (Meta) Messages, attachments, sender profile name and ID, phone number, timestamps Deliver/receive messages in the unified inbox; AI-assisted replies Per Customer config; default 12 months
Gmail (Google) Email messages, headers, attachments, labels, send permission Display, send, and organize email in the unified inbox Per Customer config; revoked on disconnect
Outlook (Microsoft Graph) Email messages, headers, attachments, folders, send permission Display, send, and organize email in the unified inbox Per Customer config; revoked on disconnect
IMAP / SMTP Email messages, headers, attachments, mailbox credentials Fetch and send email for generic mail providers Per Customer config; revoked on disconnect
Telephony and SMS (Telnyx) Call audio, recordings, transcripts, SMS/MMS content, phone numbers, call metadata Inbound/outbound calls and texts, AI voice agents, appointment reminders Per Customer config; default 12 months

5. WhatsApp and Instagram user data (Meta Platforms)

Filo Health integrates with the WhatsApp Business Platform and the Instagram Messaging API provided by Meta Platforms, Inc. ("Meta"). When a Customer connects a WhatsApp Business or Instagram account, we access and process the messages and related data necessary to deliver the messaging features of the Service. Our use of data obtained through Meta platforms complies with applicable Meta Platform Terms, Developer Policies, and the WhatsApp Business Solution Terms.

24-hour messaging window and templates. WhatsApp messaging is subject to Meta's customer-care window and template/opt-in rules. Customers are responsible for obtaining the opt-ins Meta requires before messaging End Users and for complying with Meta's messaging policies.

6. Google and Gmail data: Limited Use disclosure

When a Customer connects a Gmail account, Filo Health requests access to Google user data through Google APIs to display, send, and organize the Customer's email within the unified inbox. We request the minimum OAuth scopes necessary for these features and do not request broader access than the Service needs.

Limited Use disclosure. Filo Health's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

Customers and End Users can revoke our access to Google data at any time by disconnecting the account in the Service or through their Google Account permissions.

7. Microsoft Graph data (Outlook)

When a Customer connects an Outlook or Microsoft 365 account, Filo Health accesses email data through the Microsoft Graph API using delegated permissions granted via Microsoft's OAuth consent flow. We request only the scopes needed to read, send, and organize the Customer's email within the unified inbox.

8. IMAP / SMTP email

For email providers connected via generic IMAP/SMTP, Filo Health uses the mailbox credentials or app-specific passwords supplied by the Customer to fetch and send email. Credentials are encrypted at rest and used only to operate the connection the Customer configured. We access email content and metadata only to provide the inbox features and do not use this data for advertising or model training. Access ends when the Customer disconnects the mailbox or deletes their account.

9. Telephony, SMS, and AI voice (Telnyx)

Filo Health provides voice and messaging features using telecommunications infrastructure from Telnyx LLC ("Telnyx") and, where applicable, downstream carriers. This includes inbound and outbound calls, SMS/MMS texting, AI voice agents that answer or place calls, and automated appointment reminders and notifications.

10. Call recording and transcription: disclosure and consent

Where enabled by a Customer, the Service can record and transcribe phone calls, including calls handled by AI voice agents. Recordings and transcripts are processed to provide the Service (e.g., to operate the AI agent, create call summaries, enable quality review, and maintain records for the Customer).

Consent notice. Recording and transcribing calls is regulated and, in many jurisdictions, requires the consent of one or all parties to the call. The Customer is responsible for providing any required notice and obtaining any required consent before recording or transcribing a call, including playing or displaying a recording disclosure ("This call may be recorded") where required. Filo Health provides configurable disclosure prompts but does not assume the Customer's legal obligation to obtain consent. End Users who do not consent should decline to continue the call.

Recordings and transcripts are encrypted in transit and at rest, access-controlled, and retained per the Customer's configuration and section 14. AI voice agents are disclosed as automated/AI where required by applicable law.

11. How we use data

12. AI agents and automated processing

The Service uses AI models to draft replies, summarize conversations, transcribe calls, and operate conversational text and voice agents. AI processing occurs to deliver features the Customer has enabled. We do not use Customer or End User communications content from connected platforms to train generalized or foundation AI/ML models, and we do not permit our AI subprocessors to use such content to train their general models, except as expressly permitted by the Customer or required for the contracted service. Where Customer-specific model tuning is offered, it is limited to that Customer's environment and governed by the DPA.

13. How we share data

We do not sell personal data. We share data only as follows:

14. Data retention

We retain personal data only as long as necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. Communications content and recordings are retained according to the Customer's configured retention settings (default: 12 months) and are deleted when a channel is disconnected, the account is closed, or a valid deletion request is honored. Aggregated, de-identified data may be retained longer. Backups are purged on a rolling schedule of up to 35 days.

15. Security

We implement technical and organizational measures appropriate to the risk, including encryption in transit (TLS) and at rest, access controls and least-privilege, network protections, logging and monitoring, and regular reviews. No method of transmission or storage is completely secure; we cannot guarantee absolute security. We maintain an incident response process and will notify affected parties of breaches as required by law.

16. International data transfers

We may process and store data in countries other than where you are located, including the United States and the European Economic Area. Where required, we use appropriate safeguards for international transfers, such as the European Commission's Standard Contractual Clauses and, where applicable, the UK International Data Transfer Addendum.

17. Your rights under the GDPR (EEA/UK)

If you are in the European Economic Area, the United Kingdom, or Switzerland, you have the following rights regarding your personal data, subject to legal limits:

Lawful bases for processing

Where Filo Health is a controller, we rely on the following lawful bases:

Where we act as a processor on behalf of a Customer, please direct GDPR requests to that Customer (the controller); we will assist them as required. To exercise rights for data we control, contact danablend@gmail.com. Filo Health is established in Denmark (an EEA Member State), so a separate EU representative under GDPR Article 27 is not required. UK data subjects may also contact us at the email above.

18. Your rights under the CCPA/CPRA (California)

If you are a California resident, you have the right to:

Categories of personal information we collect

In the preceding 12 months, we have collected the following CCPA/CPRA categories of personal information:

Categories of sources

Business or commercial purposes for which we use personal information

Categories of personal information disclosed for a business purpose

In the preceding 12 months, we have disclosed each of the categories listed above for the business purposes described, to the categories of recipients listed in section 13 (subprocessors/service providers, integrated platforms, the Customer, and, when required, legal/safety recipients).

Sensitive personal information

To the extent communications content (such as account credentials shared in messages, government identifiers, precise location, or health-related information) constitutes sensitive personal information under the CPRA, we use and disclose it only for the purposes permitted by Cal. Civ. Code § 1798.121 and the CCPA regulations (e.g., to provide the Service the Customer requested, to ensure security and integrity, and as otherwise allowed by law). We do not use sensitive personal information to infer characteristics about you.

"Sale," "sharing," and opt-out preference signals

We do not sell or share personal information as those terms are defined under the CCPA/CPRA, and we have not done so in the preceding 12 months. When we process Customer and End User communications data, we act as a service provider and use the data only to perform the Service. We honor recognized browser-based opt-out preference signals, including the Global Privacy Control (GPC), as a valid opt-out request to the extent required by applicable law.

How to exercise your rights

To exercise your rights, contact danablend@gmail.com. You may use an authorized agent, and we will verify requests as required by law. We will respond within the timeframes required by the CCPA/CPRA. We will not discriminate against you for exercising your rights.

19. Data deletion requests

You may request deletion of personal data by emailing danablend@gmail.com, by using the in-product controls, or by following the data-deletion instructions at https://www.filohealth.io/data-deletion. For End User data processed on behalf of a Customer, we will route the request to the relevant Customer and assist them in fulfilling it. Disconnecting a connected platform (WhatsApp, Instagram, Gmail, Outlook, IMAP/SMTP, or a Telnyx number) revokes our access and triggers deletion of the associated data per section 14, except where retention is required by law.

We will acknowledge a valid deletion request promptly and complete deletion within 30 days of receipt (or sooner where required by applicable law), and we will confirm completion. Residual copies in encrypted backups are purged on the rolling schedule described in section 14.

WhatsApp / Instagram (Meta) data deletion. If you contacted a Customer through WhatsApp or Instagram and want the associated data removed from the Service, follow the instructions at https://www.filohealth.io/data-deletion or email danablend@gmail.com. Because the Customer is the controller of those conversations, we will coordinate with them to honor your request.

20. Children's privacy

The Service is intended for businesses and is not directed to children under 16 (or the age defined by local law). We do not knowingly collect personal data from children. If you believe a child has provided us data, contact danablend@gmail.com and we will delete it.

21. Cookies and tracking technologies

We and our service providers use cookies and similar technologies (such as local storage, pixels, and SDKs) on our website and in the Service. We use the following categories:

In the EEA, the United Kingdom, and other jurisdictions that require it, non-essential cookies are set only after you give consent through our cookie banner, and you can change or withdraw consent at any time by reopening the cookie banner from our website footer. You can also control cookies through your browser settings; blocking some categories may affect site functionality. We honor recognized opt-out preference signals where required by applicable law (see section 18).

22. Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version with a new "Last updated" date and, where required, provide additional notice. Continued use of the Service after changes take effect constitutes acceptance.

23. Contact us

Filo Health
Email: danablend@gmail.com
Website: https://www.filohealth.io
Privacy contact: danablend@gmail.com