Hlla AIالعربية

Privacy Policy

Last updated: 11 September 2026

This Privacy Policy explains what personal data Hlla AI collects, how we use and share it, and the choices you have. It applies to the website at hlla.ai and the Hlla AI iOS and Android apps (together, the "Service").

1. Who We Are and Scope

The Service is operated by Mohammad Dabash for Electronic Marketing, Amman, the Hashemite Kingdom of Jordan ("we", "us"). Mohammad Dabash for Electronic Marketing is the party responsible for the personal data described in this Policy, which is governed by the laws of the Hashemite Kingdom of Jordan. For anything privacy-related, contact us at support@7le.ai.

2. Data We Collect

Ordinary Connected apps and their on-request access described below are separate from Hlla AI Employee. The Employee section of this policy explains its separately authorized history storage and assisted or autonomous background operation; ordinary chat permissions do not activate it.

  • Account data. Your email address, whether you sign in with an emailed one-time code or through Sign in with Apple or Google. When you first set up your profile we also ask for the name you want to be called by and your age; the name is used to address you, the age to apply the minimum-age rules in section 8.
  • Conversations and attachments. The messages you send, the assistant's replies, and the files and photos you attach — including content in Projects (shared files and custom instructions) and your Library.
  • Work mode tasks. When you start a task in Work mode, we store the objective you wrote, any steering notes you add while it is running, and a step-by-step record of what the task did — each step's title, a short summary, and the points it spent. The raw working material behind each step (search results, extracted page text, drafts) is kept on our servers so a task can carry on after an interruption; it is not shown in the app. Files a task produces — Word documents, spreadsheets, CSV and Markdown files, images — are stored in the same private storage as the files you upload, appear in your Library alongside them, and have their text indexed for search in the same way.
  • Voice. When you use voice calls or dictation, your audio is processed to produce a transcription or a spoken reply. We do not retain the raw audio recordings after processing; only the resulting text is stored as part of the conversation.
  • Memory. To personalize replies, the Service extracts facts about you from your messages and stores them as memories. Section 7 describes the controls you have over memory.
  • Imported data. If you use Import Data, conversation histories from official ChatGPT, Claude, or Gemini export files are parsed on your device and stored like your normal conversations. Memories are generated from imported chats only if you choose that option.
  • Usage and telemetry. Usage counters and, for each answer, cost and latency measurements. We use these to run the points system and keep the Service healthy.
  • Billing status. Your plan and subscription status. Payments are processed by PayTabs, our payment service provider; your card details never touch our servers.
  • Issue reports. Reports you submit from settings or by shaking your device, together with a snapshot of your account email so we can follow up, and basic technical details that make the report usable: the platform, the app version, and the interface language.
  • Signing in with Google or Apple. If you sign in with Google we receive three things and nothing else: your email address, your name and your profile picture. The email address IS your account — it is how you sign back in, and where sign-in codes and receipts go; the name and picture are shown in the app so you know which account you are in. Signing in never reaches your Google content. The sign-in request asks for those three things and nothing more, and it uses a completely separate credential from the one Connected apps uses — so signing in cannot read your Gmail, open your Drive, see your Calendar, or reach your Contacts or Photos, and it can never be widened into permission that does. If you want Hlla AI to read any of those — or, later, to act in them — that is a separate and deliberate choice you make under Connected apps below, one app at a time, after a screen that lists exactly what that app can reach — and you can undo it from the same place. Sign in with Apple gives us the same or less — Apple lets you hide your real address behind a private relay, and that works here.
  • Connected apps. If you connect an outside account from Settings — GitHub, Notion, and other apps you choose, which may include Google services such as Gmail, Drive or Calendar — we store the access token that account issues us, encrypted, along with the permissions you granted and the account name so you can tell which one it is. Before you connect anything, its card lists in plain language what it can reach; we ask for nothing beyond that list. We read from a connected account — or, if you have granted write access, act on it — only while answering a request that needs it, never on a schedule and never in the background. The permissions we ask for are read-only unless you separately choose to grant write access; that grant is its own consent screen, its card names exactly what it adds — for Gmail, sending; for Drive, creating files and editing only ones we created or you picked; for Calendar, events — and it never widens on its own. Anything the assistant would send, create or change is shown to you first, and the check that decides whether an action is allowed is made on our servers against the permissions you actually granted — not by the AI. Disconnecting from Settings deletes the token and revokes it with the provider. For Google, Gmail, Drive and Calendar are separate connections here but Google records them as a single authorisation, so revoking it there happens when you disconnect the last of the three — and you can revoke it yourself at any time, independently of us, at myaccount.google.com/permissions. This is entirely optional: nothing is connected unless you connect it. Servers you add yourself. On the paid plans you can also add an MCP server of your own by pasting its address. This one is different from every app above, and the difference is the part worth reading: there is no card listing what it can reach, because nobody here has reviewed it — the tools it offers are whatever its operator chose to offer, and its operator receives whatever the assistant sends that server while answering you. We did not choose that operator and we make no claim about them. Writing is off when you add a server; turning it on is a separate action, per server, behind its own confirmation. Removing it from Settings deletes the row and any token stored with it.
  • Shared answers. When you ask a general, standalone question and we answer it from the web, we may store that question and its answer in a shared cache, so that someone else asking the same thing gets the answer without us paying to generate it again — and gets it instantly. The stored copy carries no account identifier of any kind. This never happens in Temporary Chat, never for a question about you or your files, never when you attach something, never inside a Project, and never when the answer was shaped by what Memory knows about you. You can switch it off entirely under Settings → Data controls → “Improve the model for everyone”; switching it off stops your questions being stored and costs you nothing, because you still receive answers other people's questions produced.
  • Country. Our hosting provider stamps each request with the country it came from, derived from your IP address. We store the two-letter country code on your profile so we can see where the Service is used. We do not store your IP address itself, and we derive nothing more precise than the country.
  • Cookies. Essential authentication and session cookies only. We use no advertising or tracking cookies.

Temporary Chat conversations are not saved and never touch memory.

3. How We Use Your Data

  • To provide answers: chat with third-party AI models, web search with cited sources, image generation, Deep Research reports, voice calls and dictation, and processing of your attachments.
  • To run Work mode tasks: a task works through its steps on its own and keeps going after you close the app, calling AI models and searching the web at each step without you present.
  • To personalize replies through Memory, subject to the controls in section 7.
  • To operate and enforce plan limits, including the daily points allowance.
  • To send transactional email, such as sign-in codes and service or billing notices.
  • To debug problems and improve the Service, using telemetry and the issue reports you submit.

We do not use your conversations or content to train AI models. We do not sell personal data, and the Service shows no third-party advertising.

4. Sharing and Processors

Hlla AI's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

We share data only with the service providers needed to run the Service:

  • AI model providers — OpenAI, Anthropic, Google, DeepSeek, Groq, Moonshot AI, Alibaba Cloud, and DeepInfra. The conversation content needed to answer (text, attachments, and audio for transcription) is sent to the provider serving that reply, depending on the model you choose or automatic routing. We never send your email address or account identifiers to AI providers. Data from a connected Google account never reaches a provider whose terms permit training on submitted content. Google's Limited Use requirement forbids using data obtained from its APIs to train generalised AI models, and DeepSeek's public terms reserve that right — so anything read from your Gmail, Drive or Calendar is served only by providers that make no such claim. This is enforced in two places, not promised in one: a barred model is never given the Google tools at all, so nothing is read on its turn; and a conversation that has ever carried Google content is marked, permanently, so the background summaries and memory extraction that run over it later are barred too. Along with the content needed to answer, we send what Memory holds about you, which can include the name you asked to be called by; disabling Memory, or using Temporary Chat, stops that. A Work mode task uses the same providers, but sends to them repeatedly: at each step it sends your objective and the output of the earlier steps, unattended.
  • YouTube links you paste (Google) — if your message contains a YouTube link, we hand that link to Google's Gemini model and Google fetches and watches the video itself. We never download the video, and it never passes through our servers. Two things follow from that, and you should know both: the request reaches Google as a request for that specific video, and what the model can tell you about it is limited to what is publicly available at that link — a private, deleted, or region-blocked video simply fails. Videos are only read this way on the Pro and Max plans, and only when you paste a link yourself.
  • Video clips you attach (Google) — a clip you upload is different from a link, and the difference is worth stating plainly: its bytes DO pass through our servers and are stored with your other attachments, and we send those bytes to Google's Gemini model to be read. A clip is read only on the turn you attach it — it is not re-sent with later questions in the same conversation — and clips are limited to 60 seconds. Like every other attachment, you can delete it, and deleting it removes the stored file.
  • Cohere — embeddings and reranking for search and retrieval.
  • Serper and Firecrawl — web search and web page extraction. A Work mode task runs these itself, several times over the course of one task.
  • Supabase — database, authentication, and file storage.
  • Vercel — hosting (EU, Frankfurt region).
  • Cloudflare — DNS.
  • Resend — transactional email.
  • Apple Push Notification service (APNs) — iOS push notifications.
  • Firebase Cloud Messaging (Google) — Android push notifications.
  • An MCP server you added yourself — if you add your own server under Connected apps, its operator becomes a recipient of your data. What reaches them is what the assistant sends that server in order to use one of its tools while answering you, together with whatever your sign-in with that server carries. Unlike everyone else on this list, we did not choose them, we have no agreement with them, and we have not reviewed what their tools do. You chose them, and removing the server from Settings ends it.
  • PayTabs — payment processing. Card details go directly to PayTabs and never reach our servers.
  • Google Fonts — the website loads its typefaces from Google's font servers, so opening any page on hlla.ai — including this one — makes your browser request those files from Google, which receives your IP address and browser details as part of that request. The apps do not do this: they carry their fonts inside the app.

5. International Transfers

Our providers process data in the United States and the European Union. Some models — DeepSeek, Kimi (Moonshot AI), and Qwen (Alibaba Cloud) — are operated by companies whose infrastructure may be located in other jurisdictions, including China. If you choose one of those models, the conversation content needed to answer is sent to that provider and processed there.

6. Retention

The Connected apps retention description below applies to ordinary on-request chat connections. Employee can separately store the authorized history and business records described in the Employee section, with its own deletion controls and minimum economic/security evidence.

  • We keep your data while your account is active.
  • For documents attached to a chat, the file bytes are deleted after roughly 30 days, while the extracted text remains available for search and retrieval. Uploaded images are kept. Files added to a Project are exempt: they stay as long as the Project does, because they are a visible list you manage yourself.
  • Files a Work mode task produced are kept under exactly the same rule as the files you upload: a generated document's own bytes are removed after roughly 30 days — after that the file can no longer be opened, while its extracted text stays searchable — and generated images are kept.
  • A Work mode task's record — the objective, your steering notes, and the step log — is kept while your account is active. It is deleted when you delete the conversation the task belongs to, and in every case when you delete your account. We do not otherwise expire it.
  • Content read from a connected app — including Gmail, Drive and Calendar — is fetched to answer the request that needed it, and no separate copy of your mailbox, drive or calendar is kept. What persists is only what ended up in the conversation itself, under that conversation's own rule: kept while your account is active, gone when you delete the conversation or the account. Disconnecting deletes the stored token; Connected apps in section 2 says what that revokes and how to revoke it yourself.
  • Raw voice audio is not retained after processing.
  • A shared-cache entry expires on its own — within five minutes for anything time-sensitive, within 72 hours otherwise — and is deleted about a week after that. Because it holds no account identifier, deleting your account does not reach it; the entry simply expires. Switch the setting off and nothing further is stored.
  • Deleting your account from the app (section 7) takes effect at once: conversations, files, memories, projects, Work mode task records and the files those tasks produced, generated images, and any connected-app tokens are erased. If instead you email us to request deletion, we complete it within 30 days. Either way, your email address is kept on a permanent block list so that it can never be used to register again, and invoices and billing records are retained as required by law — an invoice keeps the email and plan as they stood when it was issued.
  • We may keep aggregated statistics that no longer identify you.

7. Your Rights and Controls

  • Memory controls. View, edit, or delete individual memories, or disable memory entirely, from within the app.
  • Temporary Chat. Use it when you want a conversation that is not saved and never touches memory.
  • Improve the model for everyone. On by default, under Settings → Data controls. It governs only whether YOUR answers are contributed to the shared cache described in section 2 — never whether you benefit from it.
  • Conversation deletion. Delete individual conversations from the app at any time.
  • Copies of your conversations. You can copy conversations from the app; for data access requests, email us.
  • Access, correction, deletion, and objection. To exercise these rights, email support@7le.ai.
  • Account deletion. You can permanently delete your account from the app (Settings → Data controls → Delete account, confirmed by typing DELETE FOREVER) — immediate and irreversible, and the email address goes on a permanent block list so it can never register again — or email support@7le.ai from your account email, in which case deletion is completed within 30 days, as described in section 6.

8. Children

The minimum age to use the Service is 13. Paid subscriptions require being at least 18 or having a guardian's consent. If you believe a child under 13 is using the Service, contact us at support@7le.ai.

9. Security

We protect your data with encryption in transit, access controls, and private storage for uploaded files. No online service can guarantee absolute security, but we work to protect your data with measures appropriate to the risk.

10. Changes to This Policy

We may update this Policy from time to time. For material changes, we will give reasonable notice by email or in the app before they take effect. The date at the top shows when this Policy was last revised.

11. Contact

Mohammad Dabash for Electronic Marketing, Amman, the Hashemite Kingdom of Jordan. Email: support@7le.ai.

Hlla AI Employee: business messages and background operation

Employee is a separate, optional business feature for active Max accounts, available only where enabled and configured. Connecting an ordinary app for a chat does not activate Employee or give it access to that connection. You explicitly connect the supported Telegram, Instagram professional or Messenger Page account, choose any history to import, review the business guide, and choose assisted or autonomous operation before activation. Platform permissions can limit the history we can retrieve; we show actual coverage, not a promise to read every past message.

With your authorization, we store the connected account identity and permissions, selected message history and documents, incoming customer messages, business knowledge, customer-scoped context, drafts, actions and their status. Relevant content is processed by the AI providers configured and approved for Employee: a setup model for the history and owner interview, then Hlla Auto for runtime work. We minimize and redact content before these requests, but messages may themselves contain personal information. Do not import data you are not authorized to process. Employee business content is not contributed to the shared answer cache or used by Hlla to train models.

Your approved business facts and permitted customer context can be used to answer that customer. Private business notes are kept separate from customer-visible knowledge, and customer context is scoped to the connected account and conversation; a similar name on another channel is not permission to combine people. Approved external tools receive only the data needed for that permitted operation. Model providers, connected messaging platforms and approved tool operators process the relevant data under their respective terms; Employee does not receive unrestricted access to every connected app.

Once activated, Employee runs on our servers and can continue while your devices are offline. Assisted mode prepares drafts for your approval. Autonomous mode may send replies and use permitted tools under the operating policy you approved without asking before every routine reply. Actions requiring concrete approval remain blocked until you approve them. Human requests, missing knowledge, uncertain outcomes and budget or connection problems can stop automated work and appear as needs-attention items in Hlla; this is not a promise of immediate human response or a separate push-notification service.

Employee credentials are stored separately from business memory using encrypted envelopes protected by a managed key-management service in the configured live environment. Hlla's authorized execution service can decrypt them to contact the intended service; this is private storage, not end-to-end encryption. Models are not given plaintext credentials or a tool that retrieves them. Use the dedicated secure form, not a business chat, to add or replace a credential. A local simulator is not evidence that a hosted key-management service has been configured.

You can pause, take over a conversation, disconnect, inspect or export Employee data, and delete the employee from its settings. These controls remain available after Max access ends. Disconnecting blocks new work for that connection and removes local credentials; provider-side revocation is attempted where supported, and an unresolved remote result is shown honestly. Disconnecting alone does not delete message history. Deleting the employee removes its stored content and derived memory and disables its connections, while retaining only the minimum economic and security evidence needed for usage, unresolved operations and audit. Deletion is not a refund and cannot recall messages already sent. A send whose result is unknown is not automatically repeated or treated as failed. We do not promise instantaneous removal from third-party services or backups; their applicable retention and deletion processes also apply. Privacy or customer-data requests can be sent to support@7le.ai.