Aller au contenu
Hale
Mentions légales

Privacy Policy

Dernière mise à jour le 27 août 2026

Hale helps families across every stage of childhood, and that means we handle some of the most sensitive data there is — including information about newborns and children. We treat that responsibility as the centre of the product, not an afterthought. This policy explains, in plain language, what we collect, why, where it lives, who it is ever shared with, and the control you keep over it. It is written for Canada’s federal privacy law (PIPEDA), Quebec’s Law 25, and Canada’s anti-spam law (CASL).

Ce document est fourni de bonne foi, mais ne constitue pas un avis juridique. Hale devrait le faire réviser par un avocat qualifié avant de s’y fier.

Sur cette page

  1. Who we are
  2. What we collect, and where it comes from
  3. Why we use it, and the consent we rely on
  4. Children's data
  5. Teen privacy (children 13 and older)
  6. AI and automated processing
  7. Who your family’s data is shared with
  8. Sub-processors and cross-border processing
  9. Text messages (SMS)
  10. Data residency, retention, and security
  11. Your rights
  12. Your choices
  13. Other sites and services
  14. Email and electronic messages (CASL)
  15. Changes to this policy
  16. How to reach us

Who we are

Hale is an AI assistant for families that you reach by text message. You (a parent or legal guardian) text the number and tell Hale about your children; there is no account to create, though you may sign in to the web app, and you may optionally connect tools you already use. Hale watches for things that matter, drafts helpful suggestions, and — only with your approval — helps carry them out. Hale is operated by Village Hale Technologies Inc., a company incorporated in Ontario, Canada, which is the organization responsible for your family’s data under PIPEDA; see How to reach us. Our Terms of Service govern your use of Hale; this policy governs your family’s data.

What we collect, and where it comes from

We collect only what we need to run Hale for your family. It reaches us four ways, and the difference matters — most of it you typed, and none of it was bought.

What you give us. The things you tell Hale, in a text or in the web app:

  • Your contact details. The phone number you text from; and, if you sign in to the web app, your name and email address — provided through Google sign-in or the email address and password you register. Plus basic preferences such as language and time zone.
  • Your children’s profiles. Each child’s first name (and last name if you add it), date of birth, and — only if you choose to share them — gender and other optional details such as interests. Hale uses date of birth to derive each child’s stage (newborn, toddler, child, or teenager).
  • Care and activity logs. The day-to-day entries you record — feeds, naps, milestones, and similar notes about your child’s routine.
  • Hale conversations. The questions you ask Hale and its answers.
  • Coarse location only. If you opt in to local discovery, we store a coarse area — your city, province, country, and at most a postal code or forward-sortation area. We never store your precise street address or your child’s location. The full address you may type into the address box is used only to derive that coarse area and is not retained.
  • Village endorsements. When you endorse a local activity, we record that your family endorsed it so we can show an aggregate count (“loved by several families near you”). We never reveal which family endorsed what.

What comes from services you connect. If you connect a tool (such as email, calendar, or a daycare app), we store an encrypted authorization token and the minimum metadata needed to sync, plus the entries that tool records into your family’s timeline. You control which integrations are connected and can disconnect them.

What Hale works out for itself. A structured memory of facts and patterns Hale infers from your family’s activity — for example, a usual nap window or a stated preference — so it can be more helpful over time. Inferred information about your family is your family’s personal information too, and everything in this policy applies to it.

What is collected automatically. Every action Hale takes produces an immutable audit record (see Your rights), and we keep limited technical information such as your IP address and browser type for security and to honour your access requests, plus the coarse product-usage events described under Sub-processors. Visitors to the marketing site also have that visit measured by Google Ads so we can tell whether an advertisement led them there. That measurement does not include family data. We do not buy personal information about your family from data brokers, and we do not collect it from social media or other public sources.

Why we use it, and the consent we rely on

PIPEDA asks an organization to identify its purposes before it collects anything, so here they are — the whole list:

  • Running Hale for your family. Understanding what is happening in your family’s day, answering your questions, drafting suggestions, finding genuinely useful local things to do, preparing an action and — once you approve it — carrying it out, and keeping an accurate record of what Hale did.
  • Keeping your family’s data safe. Recognising you, protecting accounts and the service against abuse, and maintaining the audit record that lets us show you exactly what happened.
  • Making Hale better. Understanding which parts of the product work and which fail, and finding and fixing errors.
  • Meeting our obligations. Complying with the law, responding to lawful requests, enforcing our Terms of Service, and protecting a child or another person from harm.
  • Measuring our advertisements. Understanding whether an ad led a visitor to the marketing site. This is about the advertisement and the visit, not about your family.

That is all of them. We do not sell your data, we do not use your children’s data for advertising, and Hale shows no advertising.

The consent we rely on. Everything above rests on your consent, and PIPEDA asks that it be meaningful consent — that you understand what you are agreeing to, in language you can actually read, before you agree. So we ask plainly at the start, and separately again for each purpose that deserves its own answer: connecting an integration, sending your context to our AI provider, processing data across borders, letting Hale watch and text you unprompted, sharing a slice of your week with a caregiver you name, letting another assistant read from Hale, being introduced to another household, and unlocking any automated action. We record each consent — what was asked, the words you answered in, the version of this policy, and the time — so the choice is verifiable afterwards, and you can withdraw it at any time (see Your rights and Your choices).

Children's data

Hale is built around children’s information, and we apply heightened protection to it. A child’s data is provided by you, their parent or guardian, and is processed on your authority and for your family’s benefit. Optional and sensitive fields — such as gender — are exactly that: optional, and stored only if you provide them. A child’s information belongs to one family and is never visible to another family.

Hale is for parents and guardians. A child does not have a Hale account and does not text Hale, and we do not knowingly collect information directly from a child — everything Hale knows about your child came from you, or from a tool you chose to connect.

Teen privacy (children 13 and older)

As children grow, their privacy matters more. For a child aged 13 or older, raw content (the actual text of a message or post Hale observes) is redacted from parents by default. Parents see only a category or short summary — enough to stay involved, without reading their teen’s words verbatim.

A parent can ask to see it. Asking reveals nothing on its own: we record what was asked for and the reason given, tell the teen, and open the content only if the teen agrees. Access is limited to the kind of content that was asked for, lasts at most seven days, and can be closed at any time by either of you. Every step — the request, the teen’s answer, the expiry, and any closure — is written to your family’s record.

There is one exception in this policy: a credible risk of harm, where relevant content may be opened without waiting for the teen to agree. Because it skips their agreement it is held to the strictest limits — at most 24 hours, a written reason on the record, and the teen is always told.

Two limits worth stating plainly, because they describe Hale as it is today rather than as we intend it.

First, access is only ever in-app. Even with an open grant, nothing widens what appears in an email, a text message, a calendar feed, a data export, or anything Hale shares with a connected assistant — those always stay redacted.

Second, and more importantly: Hale currently has no way to contact a teen at all. We hold no account and no contact details for them. Since telling the teen is a condition of opening anything, no request can be granted yet — a request is recorded, the notification we owe the teen is recorded as still outstanding, and the default redaction above continues to apply unchanged. The same is true of the safety exception: it is policy, not a button, and it stays unavailable until a teen can actually be told. You can see the pending state and the outstanding notification on any request in Settings. We will not enable either path before a teen can be reached.

AI and automated processing

Hale uses artificial intelligence (Anthropic’s Claude models) to read your family’s context and draft suggestions. To do this, relevant conversation and context data is sent to our AI provider to generate a response.

Hale never acts on its own. The AI only drafts; a parent approves every action before anything happens in the outside world. New accounts begin in an observe-only mode, and any move toward more automation requires your explicit, per-action-type approval. You are always the decision-maker.

Stated the way Quebec’s Law 25 asks us to state it: No decision about your family is made by automated processing alone. Hale produces drafts, suggestions and reminders; a person — you — decides. We do not profile your family for advertising, and we do not use your family’s data to train anyone’s models.

Who your family’s data is shared with

Nothing about your family is shared by default. There are five kinds of recipient, and three of them exist only because you asked for them.

  • Service providers who run Hale for us. A small, named set — the database, the AI models, hosting, email and text delivery, analytics and observability. Each receives only what that service needs, under contractual safeguards. They are listed one by one in Sub-processors.
  • A caregiver you name. If you invite a grandparent, a nanny or a babysitter, Hale texts them only the slice of your week that the role you chose covers, on the number you gave, and only after they have agreed to be texted. Your authorization is recorded as its own consent, and you can end it.
  • An assistant you connect. If you authorize another AI assistant or tool to read from Hale, it receives only the scopes you selected — and what it reads is re-rendered at the moment of the read to the strictest standard we apply anywhere: a teen’s content removed on their age as of that moment, health and sensitive items generalized, locations dropped. You can revoke the authorization at any time.
  • Another household, in an introduction. Hale can offer to introduce your family to another local family around an activity. Nothing crosses until both households have said yes to that specific introduction, and what crosses is exactly four things: a parent’s first name, an email address, the stage of a child (never a name or a date of birth), and the activity that anchored the match. The introduction is written to your family’s record with those fields named, so you can always see what was disclosed.
  • Where the law requires it. To authorities and in legal process where we are required or permitted to, to protect a child or another person from serious harm, and to our professional advisers — lawyers, accountants, insurers — in the course of their work for us. If Hale is ever acquired, merged, or reorganized, your family’s data may transfer with the business; this policy keeps applying to it, and we will tell you.

Sub-processors and cross-border processing

We rely on a small set of trusted service providers to run Hale. We share with each only what that service needs, under contractual safeguards:

  • Supabase — our primary database. Hosted in Canada (Toronto, ca-central-1). This is where your family’s core data lives.
  • Anthropic — AI processing (the Claude models that draft suggestions). Processed in the United States.
  • Google Maps / Places — address autocomplete and public-venue lookup. Only coarse-area and public-venue queries are sent; your precise home address is never sent.
  • Vercel — application hosting and content delivery, plus Web Analytics and Speed Insights. Operates in the United States and on a global edge network. Vercel Web Analytics is cookieless — it sets no cookies and builds no cross-site profile.
  • PostHog — product analytics, session replay, and error tracking. Event data is coarse and non-identifying (no child data, no message content) — we capture only a few key product steps. Session replay is on so we can understand and fix problems, but every typed value (names, dates of birth, email, address) and all personal data shown on screen — child names and ages, the health and activity timeline, and Hale conversations — is masked before the recording leaves your browser. Error tracking captures unhandled errors (a stack trace, not your data) so we can fix them. Autocapture stays off, and we identify you by an opaque account id, never your name or email. Processed in the United States. On the marketing site, PostHog is configured to write nothing to your device.
  • Google Ads — advertising measurement on the marketing site (villagehale.com) only. Google’s gtag (AW-18412881223) records that a visitor reached a landing page after seeing an advertisement. It may set advertising cookies on that visit. It does not run on the product app, does not receive family data, message content, or children’s information, and Hale still shows no advertising. Processed in the United States.
  • Resend — delivery of transactional and weekly-brief emails (United States).
  • Twilio — delivery of text messages, where you choose to use Hale over SMS. The content of those messages passes through Twilio and is processed in the United States; see Text messages.
  • Langfuse — AI observability, so we can monitor and debug the assistant. A teen’s raw content and contact details (emails, phone numbers, postal codes, and precise addresses) are masked before any data is sent to this service.

To be clear about where data travels: your primary data store is in Canada, while some processing — AI, application hosting, email delivery, observability, and advertising measurement on the marketing site — happens in the United States. We ask for your consent to cross-border processing, and we put appropriate contractual safeguards in place with these providers. Because some processing occurs outside Quebec and Canada, that data may be accessible to authorities in those jurisdictions under their laws.

Text messages (SMS)

If you use Hale by text message, that conversation travels over the ordinary mobile network, and you should know exactly what that means. Text messages are not end-to-end encrypted. Every message passes through your mobile carrier and through our messaging provider, Twilio, which processes it in the United States, and anyone holding the phone can read the thread. That is how SMS works everywhere; we cannot change it, so we tell you plainly and we write to it.

Because the channel is open, the strictest limits we apply anywhere apply to what we put into a text message:

  • a health or appointment reminder names the task, never the condition — “Max’s appointment Thursday at 4”, never what it is for;
  • for a child aged 13 or older, nothing they wrote goes out over text — only a category or a short summary, as described in Teen privacy;
  • anything recorded as sensitive is generalized before it is sent — the time survives, the subject does not;
  • messages are short by design, one idea each, so there is less in transit to begin with.

Your phone number is encrypted where we store it and matched through a keyed hash, so we can recognise your family without keeping a readable list of numbers. Your consent to receive messages is recorded in the words you used to give it, and you can end it at any time: reply STOP to any message and we stop, immediately, until you ask us to start again. Standard message and data rates from your carrier apply.

If you would rather not use text at all, you do not have to — email and the web app are always available instead, and you can tell us at privacy@villagehale.com.

Data residency, retention, and security

Residency. Your family’s primary data is stored in Canada (Toronto). See Sub-processors for the processing that occurs elsewhere.

Retention. We keep your family’s data for as long as your account is active and as needed to provide Hale. When you delete your account or ask us to erase your data, we delete it, except where we must retain certain records (such as audit logs) to meet legal obligations. Removing a child removes that child’s identifying data; some family history is retained in de-identified form. In deciding how long to keep anything, we weigh how sensitive it is, what we still genuinely need it for, the harm that holding it could cause, and any legal requirement to keep it.

Security. Access to your data is isolated per family at the database level (row-level security), data is encrypted in transit, and integration tokens are encrypted before they are stored. We log every action Hale takes so it can always be reviewed. No system is completely secure and we will not pretend otherwise; if a breach ever creates a real risk of significant harm to your family, we will report it to the Office of the Privacy Commissioner of Canada — and, where Law 25 applies, to the Commission d’accès à l’information du Québec — and tell you, as those laws require.

Your rights

Under PIPEDA and Quebec’s Law 25, you have the right to:

  • Access the personal information we hold about your family. Because every action Hale takes is recorded in an immutable audit log, we can show you what happened and when.
  • Correct information that is inaccurate or incomplete.
  • Delete your data and close your account.
  • Withdraw consent at any time, including consent to AI processing, cross-border processing, a specific integration, or any automated action.
  • Port your data — receive a copy in a structured, commonly used format.
  • Complain. If you are not satisfied with how we handle your data, you may contact the Office of the Privacy Commissioner of Canada, or, in Quebec, the Commission d’accès à l’information du Québec.

To exercise any of these rights, contact us at the address in How to reach us.

Your choices

Those are the rights the law gives you. These are the switches in the product, and none of them requires writing to us:

  • Stop the texts. Reply STOP to any message and the messages stop, immediately, until you ask us to start again.
  • Stop the email. Every non-essential email carries a working unsubscribe link; see Email and electronic messages.
  • Stop the introductions. Text NO INTROS and Hale will not look for a match for your family or raise it again.
  • Disconnect a tool. Any integration you connected can be disconnected, and any assistant you authorized to read from Hale can have that authorization revoked.
  • Skip the address. Coarse location is opt-in — local discovery is the only thing that needs it, and Hale works without it.
  • Decline to tell us something. Optional fields are optional. Some of Hale gets less useful without them, and none of Hale stops working.
  • Advertising cookies on the marketing site. villagehale.com loads Google Ads so we can measure landing-page visits. It may set advertising cookies on that visit. Blocking third-party scripts in your browser stops that measurement and does not affect Hale over text. The product app does not load this tag.

Other sites and services

Hale points you at things other people run — a city’s registration page, a program, a venue. Those sites are not ours and this policy does not cover them; what they collect when you arrive is governed by their own privacy practices, which are worth reading before you register. The same is true of any tool you connect to Hale.

Email and electronic messages (CASL)

We send you email that is necessary to run your account — such as security notices and the weekly brief and other updates you ask Hale to prepare. If we ever send commercial electronic messages, we do so only with your consent, we identify ourselves, and every such message includes a clear, working way to unsubscribe. You can opt out of non-essential messages at any time without affecting your account.

Changes to this policy

We may update this policy as Hale evolves. When we make a material change, we will update the date at the top and, where appropriate, ask for your renewed consent. The version you agreed to is recorded with your consent.

How to reach us

Our Privacy Officer — the person in charge of personal information under Quebec’s Law 25 — is Anzhe Dong, Founder. For any privacy question, or to exercise your rights, contact us at privacy@villagehale.com.


Voir aussi notre Terms of Service.