Hiya
hiya.comHiya is a consumer-facing caller-identification and spam/scam-blocking service delivered through Samsung device integration and a website. The supplied consumer Terms of Service grant Hiya a broad, perpetual, irrevocable, sublicensable license over user-submitted content, cap liability at USD $100, and impose mandatory arbitration and class-action waivers on U.S. users. The privacy policy discloses collection of contact information, IP addresses, location and usage data, and sharing with service providers and (with consent) advertisers, but is largely silent on AI/ML model training, deletion timelines, and formal security certifications — notable gaps for a product marketed as AI-native deepfake detection. The documents are also fragmented and internally inconsistent across jurisdictions (differing arbitration forums, license terms, and effective dates), creating cross-document tension.
AI Transparency Facts
Independent analysis by TermsWatchdog · © 2026 TermsWatchdog
Input Data Ownership
The U.S. Terms do not claim ownership of user content but require you to grant Hiya an extremely broad, perpetual, irrevocable, worldwide license to use, modify, distribute and archive it. The Italian version explicitly states Hiya does not own user content and grants a more limited, terminable license, showing the posture varies by jurisdiction.
Output Data Ownership
The Terms define all service materials, including 'Hiya Data' (the caller-identification information the user obtains), as proprietary to Hiya, and grant the user only a limited personal-use license with heavy restrictions on reuse. The user does not own the outputs and may not store, aggregate, republish or resell them.
Training Data Usage
The product is marketed as AI-native (real-time deepfake detection learning from billions of calls), yet the supplied consumer policies never state whether user inputs, call data or content are used to train or improve models. The broad license to 'modify' and 'create derivative works' plus feedback usage rights could enable model improvement, but there is no explicit training disclosure, opt-out, or carve-out — silence on a core capability.
Data Retention & Deletion
The consumer documents provide no explicit retention schedule and no deletion SLA. The privacy policy commits to deleting data from children under the minimum age, but for general users the only deletion mechanism is a vague instruction that the user must use unspecified 'tools we make available' to remove their own content. There are no defined retention periods or audit-log obligations.
Third-Party Data Sharing
The privacy policy discloses sharing with affiliates, named service providers (Zendesk, HubSpot), successors in a merger, and — only with user consent — third parties for their own marketing. Sharing is disclosed and partly consent-gated, but the marketing-cookie language allows third parties to track users across sites for behavioral advertising, which broadens the exposure beyond what the core caller-ID service strictly requires.
Opt-Out Rights
The privacy policy provides opt-out mechanisms for cookies and behavioral tracking, references browser-signal handling, and points U.S. state residents to additional rights. However, marketing sharing to third parties is consent-based rather than opt-out, and the referenced 'Choices About How We Use and Disclose Your Information' section is not fully reproduced, leaving the mechanisms partly undefined.
Compliance & Certifications
As a consumer-general tool, Hiya is assessed against the universal baseline plus COPPA (minors). The documents reference GDPR extensively and acknowledge multiple U.S. state privacy laws (effectively CCPA/CPRA, VCDPA, CPA and others), and impose child-age gating consistent with COPPA-style concerns, but no framework is certified or third-party attested. No SOC 2, ISO 27001/42001, NIST CSF or EU AI Act references appear. Frameworks are claimed/acknowledged, not certified.
Model Explainability & Auditability
Despite marketing the product as AI-driven with real-time deepfake detection, the supplied policies provide no transparency into model behavior, no explainability commitments, and no enterprise auditing rights. The documents are entirely silent on how automated caller scoring or scam detection decisions are made or challenged.
Security Practices & Breach History
The privacy policy states a general commitment to protecting information but discloses no specific security controls — no mention of encryption at rest/in transit, access controls, penetration testing, or incident response in the accessible text. A trust center URL exists but was inaccessible. No breach history is disclosed, and no dedicated security page content was available.
Enterprise vs. Consumer Risk Delta
The consumer Terms explicitly state they apply only to non-commercial personal use and that any business/commercial use requires a separate Commercial Use Agreement. That referenced enterprise MSA was not supplied, so the differences in data handling between tiers cannot be verified — the consumer policy simply defers commercial terms elsewhere.
Human Review of User Inputs
Hiya reserves the right — though it disclaims any obligation — to review or monitor user content to operate the service, ensure compliance, or comply with legal requirements. This means staff may access user prompts/content at Hiya's discretion, but the right is framed as discretionary rather than routine.
Regulatory & Litigation Exposure
The Terms disclose that Hiya may cooperate with law enforcement to prosecute users who violate the agreement, and the privacy policy notes disclosure to comply with legal obligations. The Terms also impose mandatory arbitration and class-action waivers (U.S. version), a one-year claim-filing limit, and a USD $100 liability cap — all materially limiting user legal recourse.
PII & SPI Data Inventory
Hiya collects a significant amount of PII: name, email, phone number, mailing address, IP address, location, device ID, and usage/browsing patterns. Given the nature of caller-ID, contact/phone data is central. The policy discloses these categories with purpose statements, but the collection of location and device identifiers plus third-party behavioral tracking pushes this into moderate risk; no explicit SPI categories are described.
Policy–Product Currency
The product is explicitly AI-native — marketing touts real-time deepfake detection and AI learning from billions of calls — yet the supplied policies never mention AI/ML processing, model training, or third-party model providers. The governing documents are also badly out of sync: the U.S. Samsung Terms are dated April 26th, 2019, the Italian version November 15, 2023, the Korean version January 1, 2025, and the website privacy policy February 26, 2024. The stale 2019 core terms plus complete silence on the AI capabilities the product ships justify RED.
Cross-Document Consistency
Multiple documents were supplied and they materially contradict each other. The U.S. Terms grant a perpetual, irrevocable license while the Italian version says Hiya does not own content and that the license terminates on account closure. The U.S. Terms mandate JAMS arbitration in the user's U.S. county under Washington law, whereas the Korean version mandates SIAC arbitration seated in Singapore, and the Italian version disclaims mandatory arbitration in favor of the user's home-country courts. These are material, decision-changing conflicts.
You've read all 15 risk ratings for Hiya. Create a free account to see the exact policy wording behind each rating.