Hearthby Symphia
Product Platform Pricing Resources
Sign in Book a demo
Product Platform Pricing Resources Sign in
Legal

Privacy Policy

Last updated 30 July 2026 · Applies to hearth.symphia.ai, the Hearth web console and the Hearth iOS app.

On this page

Who we are Our two roles What we collect The Hearth iOS app Microphone & dictation Calls & recordings AI processing How we use it Who we share with Retention Security Your rights If you are a hotel guest Children International transfers Changes Contact us

Who we are

Hearth is an AI guest-experience platform for hotels, operated by Symphia LLC ("Symphia", "we", "us"). Hotels use Hearth to message their guests across SMS, WhatsApp, email, web chat and voice, to run their guest CRM, and to automate parts of the stay.

This policy covers the Hearth marketing site, the Hearth web console and the Hearth iOS app. It does not cover a hotel's own website, its property-management system, or any other service the hotel connects to Hearth.

Our two roles

Which rules apply depends on whose information is involved. Hearth handles two very different categories of data, and we treat them differently.

Whose dataOur roleWhat that means
Hotel staffController We decide how staff account data is handled, because the account relationship is between the hotel's team and us. This policy governs it.
Hotel guestsProcessor Guest information belongs to the hotel. We process it only on that hotel's instructions, under our agreement with them. The hotel's own privacy notice governs why a guest's data was collected in the first place.

Put plainly: a guest's reservation, phone number and message history are the hotel's records, held by us on the hotel's behalf. We do not use them for our own purposes, we do not sell them, and we do not market to a hotel's guests for anyone else.

What we collect

From hotel staff (our users)

  • Name, work email address, work phone number, job title and role.
  • The hotel organisation and properties you have access to.
  • Sign-in records: one-time email codes, session tokens, sign-in time and IP address.
  • Device push tokens, so we can notify you about new guest messages and escalations.
  • Server-side operational logs: request identifiers, timestamps, endpoint, status and IP address, used to keep the service running and to investigate faults.

About hotel guests (on the hotel's behalf)

  • Identity and contact details: name, email address, phone number, and channel handles.
  • Reservation and stay data synced from the hotel's property-management system: confirmation number, arrival and departure dates, room, rate, and stay notes.
  • Message content and metadata across every connected channel.
  • Voice call metadata and, where the hotel has enabled it, call recordings and transcripts.
  • Anything a guest submits through a hotel's digital check-in or mini app — which may include identity-document fields the hotel is legally required to collect.
  • Staff notes, tags and task records attached to the guest.

What we do not collect

  • No advertising or tracking. Hearth contains no advertising SDK, no cross-app tracking, and no data broker integrations. We do not track you or a hotel's guests across other companies' apps or websites.
  • No card numbers. Payment capture is tokenized; card numbers do not touch Hearth's servers.
  • No location tracking. The Hearth app does not request or collect device location.
  • No contacts, photos or health data.

The Hearth iOS app

The iOS app is a staff tool. It is the same console in a native form: you sign in with your work email, and you see the guest conversations, reservations and tasks for the properties your hotel has given you access to.

  • The app collects the staff account data listed above, plus a push token if you allow notifications.
  • Guest information shown in the app is the hotel's data, fetched over an encrypted connection each time; it is displayed to you, not resold or repurposed.
  • The app contains no third-party analytics or advertising SDKs.
  • You can revoke notification and microphone permissions at any time in iOS Settings; the rest of the app continues to work.

Microphone & dictation

The Hearth app asks for microphone access for one reason: dictating a reply. When you tap the microphone button in the message composer, the app records your speech and converts it to text so you can send it as a message.

  • The microphone is active only while you are dictating, and stops the moment you tap the button again or send the message.
  • Speech-to-text is performed by Apple's speech recognition. Depending on your device and language, audio may be processed on-device or sent to Apple for transcription under Apple's privacy policy.
  • Hearth does not store your dictation audio. Only the resulting text reaches our servers, and only if you choose to send the message.
  • We do not use dictation audio to train any model.

Calls & recordings

Hotels can run an AI voice concierge on a phone line, and can review the resulting calls in Hearth. Where a hotel has enabled recording, the recording and its transcript are stored against that hotel's account and are visible to that hotel's staff only.

Recording is the hotel's decision and the hotel's legal responsibility. Consent and notice requirements for recording calls vary by jurisdiction. Hotels using Hearth are responsible for providing the disclosures their local law requires.

AI processing

Hearth uses AI to draft replies, classify what a guest is asking about, route urgent issues to a human, and power the voice concierge. To do that, message content and relevant reservation context are sent to our AI providers.

  • Providers process this content to return a response to us. Under our agreements, they do not use it to train their models.
  • Complaints, billing disputes and safety issues are always routed to a human rather than answered autonomously, and the AI's confidence gates what it may send on its own.
  • A hotel can turn AI replies off per conversation or per property at any time.

How we use information

  • To provide the service: deliver messages, sync reservations, run journeys, raise tasks and escalations, and show analytics to the hotel.
  • To authenticate you and keep accounts secure.
  • To send you operational notifications about your own work — new guest messages, escalations, assigned tasks.
  • To keep the platform reliable: monitoring, debugging, capacity and abuse prevention.
  • To meet legal obligations and enforce our terms.

We do not sell personal information, and we do not share it for cross-context behavioural advertising.

Who we share with

We share data only with service providers who help us run Hearth, each under contract and only for that purpose:

ProviderPurpose
Amazon Web ServicesHosting, storage and database infrastructure (United States).
SymphiaOur own AI, messaging and voice engine.
TwilioSMS, WhatsApp and voice delivery.
Anthropic, OpenAILanguage models used for drafting, classification and voice.
ApplePush notification delivery, and speech recognition for dictation.
Email delivery providersTransactional email — sign-in codes and notifications.
The hotel's own systemsProperty-management systems (such as Mews) and booking channels the hotel connects.

We may also disclose information where legally required, or in connection with a merger or acquisition — in which case this policy continues to apply to the transferred data.

Retention

  • Guest data is retained for as long as the hotel's account is active, or until the hotel deletes it. Hotels control retention for their own records.
  • Staff accounts are retained while the account is active. Deactivating a staff member revokes access immediately.
  • Sign-in codes expire in ten minutes and are purged.
  • Operational logs are retained on a rolling short-term basis for troubleshooting.
  • On termination, a hotel may export its data; we then delete or anonymise it within a reasonable period, except where law requires us to keep it.

Security

  • TLS in transit and encryption at rest.
  • Passwordless sign-in with hashed, expiring, single-use, attempt-capped codes.
  • Strict tenant isolation — a hotel's data is scoped to its own organisation and properties on every request.
  • Role-based access (owner, manager, agent) plus per-property access, with an audit trail of who changed what, across staff and AI alike.
  • Tokenized payment capture, so card numbers never reach our servers.

No system is perfectly secure. If we become aware of a breach affecting personal data we will notify affected hotels without undue delay, as our agreements and applicable law require.

Your rights

Depending on where you live, you may have the right to access, correct, delete, port or restrict the use of your personal information, to object to certain processing, and to withdraw consent. You also have the right not to be discriminated against for exercising these rights.

If you are a member of hotel staff, contact us using the details below and we will respond within the time your law allows.

Deleting your staff account

You can ask your hotel's Hearth owner or manager to deactivate your account, which revokes access immediately, or write to us and we will action it. See Support for the full account-deletion request path.

If you are a hotel guest

The hotel you stayed with — not Symphia — decides what guest information is collected and why. Please contact the hotel first: they can amend or delete your record directly in Hearth, and they are the party whose privacy notice governs it. If you contact us instead, we will pass the request to the relevant hotel and support them in fulfilling it, but we cannot act on their records on our own initiative.

To stop receiving messages, reply STOP to any SMS or WhatsApp message. Opt-outs are recorded per channel and enforced immediately across automated journeys, campaigns and AI replies.

Children

Hearth is a business tool for hotel staff and is not directed to children. We do not knowingly collect personal information from children under 16. If you believe a child's information has reached us, contact us and we will delete it.

International transfers

Hearth is operated from the United States and our infrastructure is hosted there. If you or a hotel's guests are located elsewhere, information will be transferred to and processed in the United States. Where required, we rely on appropriate safeguards such as the European Commission's standard contractual clauses.

Changes to this policy

We will update this page when our practices change and revise the date at the top. If a change is material we will also notify hotel account owners by email. Continued use of Hearth after an update means you accept the revised policy.

Contact us

Symphia LLC, operator of Hearth.

Privacy questions, data requests and account deletion: support@symphia.ai

General enquiries: hello@hearth.hotel

Hearthby Symphia

The AI guest-experience platform for hotels that care about how it feels to stay with them.

Product

  • Guest messaging
  • AI concierge & voice
  • Journeys
  • Mini apps
  • Upsells & reviews
  • Marketing suite

Platform

  • PMS connections
  • Channels
  • Security & data
  • The Symphia engine

Company

  • Pricing
  • Resources
  • Book a demo
  • Support
  • hello@hearth.hotel
© 2026 Hearth. All rights reserved. Privacy Terms Security