Hai Robo — Privacy Policy

Last updated: 18 June 2026  ·  Effective: 18 June 2026

This Privacy Policy explains how KOREIDEA INNOVATIONS PRIVATE LIMITED (“KOREIDEA”, “we”, “us”, or “our”) collects, uses, shares, and protects your information when you use the Hai Robo mobile application and its optional companion software (together, the “App” or “Service”). We are the data fiduciary / data controller for that information. We are committed to data minimisation — most processing happens on your device, and we collect only what we need to provide the Service. We never sell your data or use it for advertising.

By downloading, accessing, or using the App, you acknowledge that you have read and understood this Policy. If you do not agree, please do not use the App.

Contents
  1. Who we are
  2. Information we collect
  3. On-device processing (incl. Health, Contacts, Media, Face recognition)
  4. Device permissions
  5. How and why we use information
  6. AI features, content & reporting
  7. How we share information & service providers
  8. Third-party apps and services you choose to open
  9. International data transfers
  10. Data retention & deletion
  11. Your rights and choices
  12. Security & data-breach notification
  13. Children
  14. Region-specific disclosures (India, EEA/UK, California)
  15. Changes to this Policy
  16. Grievance Officer & contact

1. Who we are

The App is published by KOREIDEA INNOVATIONS PRIVATE LIMITED, a company incorporated in India and based in Visakhapatnam, Andhra Pradesh. For any privacy question, or to exercise your rights, contact our Grievance Officer at admin@koreidea.com (see Section 16).

2. Information we collect

We collect the following categories of information. Where a feature is optional, the related data is collected only if you use that feature or grant the relevant permission.

2.1 Information you provide

CategoryExamplesWhy
Account & identityA unique user ID and, where you allow it, your name and email address, received through Sign in with Apple or Sign in with Google.To create and secure your account and identify you across your devices.
ProfileA display name you optionally set in the App.To personalise replies (e.g. greet you by name).
Voice commands & chatThe text of what you ask (transcribed on your device), and your conversation history with the assistant.To understand your request and generate a reply.
Saved contentSaved places, saved orders, expense entries, ideas/journal entries, and the facts you explicitly ask the assistant to “remember”.To provide the features you asked for and (optionally) sync them across your devices.
Content reportsIf you report an AI response, the report you submit — which may include the flagged prompt and reply plus your description.To investigate and act on objectionable content (see Section 6).

2.2 Information collected automatically

To deliver requests to our backend and keep the Service reliable, limited technical information is processed, such as your device type and operating-system version, the App version, coarse network information, and per-day usage counters used to enforce fair-use limits. We do not embed third-party advertising or cross-app tracking SDKs, and we do not build advertising profiles about you. We do not use the App Tracking Transparency “tracking” permission.

2.3 Information from permissions

Certain features rely on device data accessed only with your permission — see Section 4.

2.4 Data that stays on your device

We do not collect your contacts, your Health data, or your enrolled face data. These are processed on your device for the features you enable and are never uploaded to our servers (see Section 3).

3. On-device processing

We process as much as possible directly on your device, where it never reaches our servers:

3.1 Health data (Apple Health / HealthKit)

If you enable the wellness features, the App reads your step count from Apple Health and writes water-intake entries you log by voice, solely to power in-app activity and hydration reminders. Health data is processed on your device, is never sold, never used for advertising or any form of data-mining, and is never shared with any third party or used for any purpose other than these in-app reminders.

3.2 Contacts

When you ask the App to call or message someone by name, it looks that person up in your contacts on your device to place the call or open the message. Your contacts are not uploaded to our servers.

3.3 Apple Music / media

The App can control playback of your music library (play, pause, skip, shuffle). It does not collect your listening history.

3.4 Face recognition

Face recognition is off by default. If you enable it, faces seen by the camera are converted on your device into an encrypted mathematical summary (AES-GCM, with the key stored in your device Keychain) so the robot can greet enrolled family by name. No photos are saved, nothing is uploaded or synced to iCloud, and you can delete enrolled faces at any time in Settings → Family faces.

4. Device permissions

PermissionHow it is usedLeaves device?
MicrophoneTo hear the wake word and your voice commands.No (wake word on-device; commands become text — see §3).
Speech recognitionTo convert your speech to text.May involve Apple per device settings (see §3).
CameraOn-device face tracking, optional face recognition, and scanning a QR code to pair a Mac.No.
ContactsTo call or message a person you name, looked up on your device.No — contacts are not uploaded.
HealthTo read your step count and log water for in-app activity and hydration reminders.No — stays in Apple Health on your device.
Apple Music / Media libraryTo control playback of your music library.No — no listening history is collected.
Location (when in use)Only when you ask for local weather or to book a ride (to set your pickup point). Checked on demand.Sent only to fulfil that request (weather/ride). Not tracked in background.
Calendar & RemindersTo tell you your next event and to create reminders you ask for.Stays on your device / in your Apple account; we do not copy it to our servers.
Motion & fitnessTo detect when the phone is placed on the dock.No.
NotificationsTo deliver timers, alarms, and reminders you set.Local to your device.
Photos (add only)To save an image the assistant generated, when you tap Save.Saved to your own photo library.
Local networkTo find your paired Mac on the same Wi-Fi for screen-aware help.Stays on your local network.
BluetoothTo connect to the optional Hai Robo robot dock (pan, tilt, lights).Local connection to your own dock only.

You can review or revoke any permission at any time in your device Settings. Revoking a permission disables the related feature but otherwise does not stop you using the App.

5. How and why we use information

We rely on your consent (which you give when you sign in and when you grant a permission) and, where applicable, on our legitimate interest in operating, securing, and improving the Service and on compliance with legal obligations. We do not sell your personal data, we do not use your data for advertising, and we do not use your conversations to train AI models.

6. AI features, content & reporting

The assistant’s replies, search answers, translations, and generated images are produced using artificial intelligence (see providers in Section 7). When you ask a question, the recognised text of your request — and, for screen-aware help, a screenshot you explicitly request, or an image you ask the App to generate from — is sent through our backend to the AI provider to generate a response.

Your AI requests are not stored on our servers. The request text and any image you ask about are forwarded to the AI provider, the reply is returned to you, and nothing is retained on our servers afterwards. AI requests are not used to build an advertising profile or to train models.

AI can make mistakes. Responses and generated images may be inaccurate, incomplete, or unexpected, and should not be relied on for medical, legal, financial, or other critical decisions.

Content moderation and reporting. We apply content-safety filtering to reduce objectionable output. If you encounter a response that is offensive, unsafe, or otherwise inappropriate, you can report it from Settings → AI safety & reporting or by tapping the flag shown on a reply. A report may include the flagged prompt and reply and basic app/device details so we can locate and review it. We review reports and take appropriate action, typically within 24 hours.

7. How we share information & service providers

We share information only with the service providers (sub-processors) needed to run the App, under agreements that require them to protect it and use it only for our purposes:

ProviderRoleData involved
AppleSign in with Apple; on-device speech recognition; WeatherKit; iCloud sync of your saved data.Account identifier; speech (per device settings); coarse location for weather; your saved data in your iCloud.
GoogleSign in with Google; Gemini AI (replies, search, translation, images — via our backend); Maps Places (address lookup).Account identifier; the text of your request and (for screen help) a requested screenshot; address queries.
SupabaseAuthentication, our AI proxy, optional cloud sync, and storage of account data.Account data; your request text in transit; your saved data if cloud sync is on.
wttr.inFallback weather source used only if Apple WeatherKit is temporarily unavailable.Approximate location or place name to return weather.

AI provider keys are held only on our backend and are never shipped inside the App. We do not sell your data and do not share it for advertising. We may also disclose information if required by law, to protect our rights or users’ safety, or in connection with a merger, acquisition, or asset transfer (in which case we will notify you and this Policy will continue to apply).

8. Third-party apps and services you choose to open

Some features (for example, booking a ride or reordering food or groceries) work by opening a third party’s app or website that you have chosen, so you can complete the action there. We do not process or receive your payment details, and once you leave the App your activity is governed by that third party’s own privacy policy and terms. We encourage you to review them. Features that fetch public information (such as news, encyclopedia summaries, or stock quotes) send only your query to the relevant public source to return a result.

9. International data transfers

We are based in India. Some of our service providers (such as Google and Supabase) may process and store data on servers outside your country, including outside India. Where data is transferred across borders, we rely on appropriate safeguards and, where required, your consent. By using the App you consent to such transfers as described in this Policy.

10. Data retention & deletion

We keep personal data only for as long as your account is active or as needed to provide the Service, resolve disputes, maintain safety and security, and meet legal obligations. Specifically:

A nightly automated job enforces the 30-day windows above.

11. Your rights and choices

Subject to applicable law, you have the right to:

To exercise a right that isn’t self-service in the App, email admin@koreidea.com. We may need to verify your identity before acting and will respond within the timeframe required by law.

12. Security & data-breach notification

We use reasonable technical and organisational measures to protect your data, including encryption in transit (TLS), access controls, and provider-side encryption at rest. On-device sensitive data (such as face summaries and your session token) is stored in the iOS Keychain. No method of transmission or storage is completely secure, but if a personal-data breach likely to cause harm occurs, we will notify affected users and the relevant authority as required by applicable law.

13. Children

The App is intended for users 18 years and older and is not directed to children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us data, contact us and we will delete it.

14. Region-specific disclosures

India (Digital Personal Data Protection Act, 2023)

We act as the data fiduciary. We process personal data on the basis of your consent for specified purposes, provide the rights described above, and have appointed a Grievance Officer (Section 16). You may approach the Data Protection Board of India if your grievance is not resolved.

EEA / United Kingdom (GDPR)

Where GDPR applies, our legal bases are consent, performance of a contract (providing the Service you request), our legitimate interests (security, abuse prevention, reliability), and legal obligation. You have the rights of access, rectification, erasure, restriction, objection, and portability, and the right to lodge a complaint with your local supervisory authority.

California (CCPA/CPRA)

We do not sell or “share” (as defined for cross-context behavioural advertising) your personal information, and we do not use it for targeted advertising. California residents have the rights to know, delete, correct, and to non-discrimination for exercising these rights.

15. Changes to this Policy

We may update this Policy from time to time. When we do, we will revise the “Last updated” date above and, for material changes, provide a more prominent notice as appropriate. Your continued use of the App after an update means you accept the revised Policy.

16. Grievance Officer & contact

In accordance with the Digital Personal Data Protection Act, 2023 and applicable rules:

Grievance Officer: Surendra Bharath Palle
Email: admin@koreidea.com
Company: KOREIDEA INNOVATIONS PRIVATE LIMITED
Visakhapatnam, Andhra Pradesh, India

We aim to acknowledge grievances promptly and resolve them within the period required by law.