Privacy Policy
Last updated: June 23, 2026
Who we are
Yomigo AI is a B2B voice-agent platform operated by TachiTech LLC (d/b/a Yomigo AI), a Connecticut limited liability company. Contact us at privacy@yomigo.ai.
What we collect
We collect three categories of data:
- Account data: name, email, profile photo (via Google sign-in), workspace details, billing address.
- Usage data: call metadata (start time, duration, agent, status), transcripts and recordings (when enabled), agent configuration, knowledge-base contents you upload, action endpoints, and integration credentials.
- Telemetry: IP address, user agent, page navigation, and error events necessary to operate and secure the Service.
How we use it
We use this data to provide, secure, bill for, and improve the Service. Specifically: authenticating you, routing calls, generating agent responses, producing analytics, detecting abuse, billing your workspace, and responding to support requests. We do not sell personal data and do not share it for cross-context behavioral advertising.
Sub-processors
Our current sub-processor list, including each vendor's role and Business Associate Agreement status for HIPAA workspaces, is maintained at yomigo.ai/subprocessors. We will notify workspace owners by email at least 14 days before adding a new sub-processor that processes customer or PHI data.
Google Calendar and Google user data
If you choose to connect a Google Calendar to Yomigo, you grant Yomigo access to that calendar through Google's OAuth consent screen. This section explains exactly what we access, how we use it, and how we store it.
- What we access. Using the Google Calendar API scopes you approve, Yomigo creates and manages appointment events on the connected calendar and reads your free/busy availability. We do not read, list, or modify your existing calendar events.
- How we use it. We use this access for one purpose only: to let your Yomigo voice agent quote your real availability to callers and book, reschedule, or cancel appointments on your behalf, so those bookings appear directly on your own calendar. We do not use Google Calendar data for any other feature.
- How we store it. After you approve access, we retain only a single Google OAuth refresh token, kept in an access-restricted datastore that denies all client-side reads and is encrypted at rest; only our server-side functions can read it. Short-lived access tokens are generated as needed and held in memory only. When the agent books an appointment, we mirror the event's basic details (title, time, and a link to the Google event) into your workspace so the appointment is visible in the Yomigo dashboard. We do not store a copy of your broader calendar.
- Sharing, advertising, and AI training. We do not sell Google user data, and we do not share it except as needed to provide the booking feature you requested or as required by law. We do not use Google user data for advertising, and we do not use it to develop, improve, or train generalized or non-personalized artificial intelligence or machine-learning models. Human access to Google user data is prohibited except with your explicit consent for support you request, for security or to comply with law, or where the data has been aggregated and anonymized.
- Disconnecting and deletion. You can revoke Yomigo's access at any time in Settings → Integrations by disconnecting the calendar, which deletes the stored refresh token, and/or at myaccount.google.com/permissions. See our Data Deletion page for details.
Yomigo AI's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Recordings and transcripts
Call recordings and transcripts are stored encrypted at rest. You control whether recordings are made and whether the system plays a recording-consent line at call start. You are responsible for satisfying recording-consent laws in your jurisdictions; we provide the tools but do not enforce compliance for you.
HIPAA
HIPAA Mode is not available yet. Yomigo is not currently offering a Business Associate Agreement, because several sub-processors that carry call audio on our behalf have not yet executed BAAs with us. Current status for every sub-processor is published on our Sub-processors page.
You may not transmit Protected Health Information (PHI) through the Service. This remains true until HIPAA Mode is offered, a BAA is executed between you and Yomigo, and HIPAA Mode is enabled on your workspace. The PHI-handling controls described elsewhere in this policy are implemented, but implemented controls are not a substitute for an executed agreement.
Data retention
Retention is set by data category and workspace mode:
- Account data — life of the account, plus 30 days after deletion to support reversal of accidental deletions.
- Call metadata, transcripts, summaries — default 90 days; HIPAA workspaces default to 7 years per industry standard. Both are workspace-configurable.
- Call recordings — only when recording is explicitly enabled on the workspace. Default retention 90 days. HIPAA workspaces have recordings disabled by default and cannot enable them without support intervention.
- PHI in transcripts — on HIPAA workspaces, Protected Health Information identifiers (SSN, MRN, DOB, phone, email, insurance ID, addresses, and other HIPAA Safe Harbor identifiers) are redacted before transcripts are persisted. The original unredacted text is not stored.
- Security and audit logs — 12 months.
- Daily Firestore backups — 30 days rolling.
You can request immediate deletion of workspace data at any time by emailing privacy@yomigo.ai.
Your rights
Depending on your jurisdiction, you may have rights to access, correct, delete, or export your data; to object to or restrict processing; and to withdraw consent. Email privacy@yomigo.ai to exercise any of these rights. We will respond within 30 days. EU/EEA users may also lodge a complaint with their data protection authority.
International transfers
The Service is operated from the United States. If you are accessing it from outside the US, your data will be transferred to and processed in the US. We rely on Standard Contractual Clauses where applicable.
Security
We use TLS 1.2+ in transit and AES-256 at rest. Access controls are enforced via workspace membership and role-based permissions. We follow industry best practices and are working toward SOC 2 Type II.
Children
The Service is not intended for individuals under 18. We do not knowingly collect data from children.
Changes
We will post material changes to this policy at least 14 days before they take effect and notify workspace owners by email.
Contact
Privacy questions? Email privacy@yomigo.ai.