Built for families & care teams · Private, encrypted, and consent-first
Security & privacy

Security built for the most personal data there is.

A voice and the memories attached to it are deeply personal. We protect them with encryption, strict access controls, clear consent, and HIPAA-aligned safeguards — and we put control in your hands.

Built with HIPAA-aligned safeguards
Encrypted in transit & at rest Consent-first by design We never sell your data Delete your data anytime Role-based access for care teams
How we protect your data

Safeguards at every layer

From the moment a voice is recorded to the day you delete it, your family's data is protected by design.

Encryption

Data is encrypted in transit using [TLS 1.3] and at rest using [AES-256], so recordings and memories are protected on the wire and in storage.

Consent & control

Every voice profile requires explicit, documented consent. You decide whose voice is recorded and can withdraw consent at any time. See our Consent Policy.

Access controls

Data is private to your circle of care. Facility accounts use role-based access so only authorized staff can reach a resident's profile, on a least-privilege basis.

No selling, no public training

We never sell your recordings or memories, and we do not use them to train public or general-purpose AI models. They exist to serve your family — nothing else.

Deletion on your terms

Delete a recording, a voice profile, or your whole account whenever you choose. We delete or de-identify the associated data within [X days].

Monitoring & response

We monitor our systems and follow a defined process to detect, respond to, and notify you of security incidents as required by law. [Summarize your breach-response process.]

What "HIPAA-aligned" means here

Designed with HIPAA principles, described honestly

We build Hamton using safeguards inspired by the HIPAA Security Rule — encryption, access controls, consent, audit-ability, and data minimization. We use the word "aligned" deliberately: it describes our design and intent, not a certification or a regulatory status.

For families

HIPAA generally governs healthcare providers and plans. When you use Hamton directly as a family, your data is still protected by the safeguards on this page and our Privacy Policy.

For care facilities

Facilities subject to HIPAA have specific obligations. If that's you, contact us to discuss your requirements so we can support your compliance needs.

We'd rather under-claim and over-deliver.

Plenty of products slap a "HIPAA compliant" badge on a marketing page. We don't, because a brand built on trust with vulnerable families can't afford to overstate anything. We tell you exactly what we do and let the safeguards speak for themselves.

Encrypted Consent-first Least-privilege access Data minimization Deletable on request
Your data, your call

The controls you keep

Access & export

Request a copy of the data associated with your account at any time by emailing privacy@hamton.example.

Delete & withdraw consent

Delete recordings, profiles, or your account, and withdraw consent for any voice, at any time. See our Consent Policy.

Who we work with

We use vetted service providers (for hosting, speech processing, and payments) under contracts that require them to protect your data and use it only for us. [Maintain a current sub-processor list.]

Report a vulnerability

Found a security issue? We want to hear about it. Email security@hamton.example and we'll respond promptly.

Questions about how we protect your data?

Our team is happy to walk you (or your facility's compliance team) through exactly how Hamton handles voices, memories, and consent.

Talk to us
Start your free voice profile