Your parent's conversations with Rose belong to your family — not to Hello Rose, and not to any AI model being trained somewhere in the background. You can see what Rose remembers, delete any single fact, export the full record whenever you want, and delete everything entirely, including the copies held by the voice technology provider that powers the calls. None of it is ever used to train AI models. That's the plain-language version of our data commitments, and the rest of this piece explains what actually stands behind it.
Data promises are cheap to write and easy to break quietly. We'd rather explain the actual mechanics — what you can do, what we've built ahead of regulation requiring it, and why an aging parent's daily conversations deserve more caution than most consumer data, not less.
What "your family owns it" actually means
Ownership, in practice, means three concrete things you can do, not just a sentence in a privacy policy. First, you can see what Rose remembers about your parent at any time — the rolling story of their days and the specific facts that have come up, like a garden doing well this year or a knee that's been bothering them. Second, you can delete any single fact without touching the rest of that memory, so a health worry that turned out to be nothing doesn't have to sit in the record forever, and you're never forced into an all-or-nothing choice between keeping everything and wiping it all out. Third, you can export the entire record in a standard format whenever you want a copy for your own files, and you can delete everything entirely, whenever you choose — not just from Hello Rose's own systems, but including the copies held by the underlying voice technology provider. When you delete, it's actually gone, not archived somewhere quietly out of view.
That last point is worth sitting with. "We deleted it" means different things depending on who says it. A company can wipe its own front-end record while a third-party vendor behind the scenes keeps a copy untouched. Ownership that doesn't reach the subprocessors isn't really ownership — it's a partial promise dressed up as a complete one.
Never used to train AI models
Your parent's conversations, memories, and recordings are never used to train AI models — not Hello Rose's own systems, and not any underlying voice or language technology we rely on. What gets said on a call stays a private record for your family, not raw material for improving someone else's model.
We're explicit about this because it isn't the default everywhere, and it's exactly the kind of thing that's easy to permit quietly in a long terms-of-service document nobody reads closely. A daily companion service is, almost by design, collecting an unusually intimate window into someone's life — health mentions, family names, routines, worries. That's a meaningfully different category of data than browsing history or shopping preferences, and we think it should be treated that way, not folded into the same training pipelines as everything else a company collects.
When your family deletes a memory, it's gone, including the copy the voice provider was holding.
The unglamorous groundwork: a DPIA and real data processing agreements
None of this happens by accident, and none of it happens for free. Before our UK launch, we carried out a Data Protection Impact Assessment — a formal risk analysis that UK GDPR requires for processing likely to pose a high risk to people's rights, which the ICO's own guidance explicitly flags for novel technology, including AI, combined with certain other risk factors. A DPIA isn't a marketing document — it's a structured exercise in identifying what could go wrong with a given kind of data processing and designing the mitigations before you launch, not after something goes wrong.
We also put formal data processing agreements in place with our subprocessors — including the voice technology provider that powers the calls — spelling out exactly what they can and can't do with the data, and confirming that full deletion actually reaches their systems too, not just ours. That's the part of "your family owns it" that has to be true at the infrastructure level for the promise to mean anything at the product level.
None of this shows up on a landing page in a way that's exciting to read. Data processing agreements are contracts, not press releases; they bind a vendor to specific obligations rather than describe good intentions. The value of both a DPIA and those agreements is almost entirely invisible when everything goes right — which is exactly why so few companies bother with them before they're legally forced to.
Why this is a US commitment too, not just a UK one
We're describing the DPIA and subprocessor agreements in the context of our UK launch because UK GDPR is where the specific legal requirement for a DPIA comes from. But the underlying commitments — never training on conversation data, full export and delete reaching every subprocessor, one-click deletion of individual facts — aren't scoped to one country's regulation. They describe how we handle a US parent's data as much as a UK parent's, because the reason for doing this was never "a regulator requires it here." It was that an aging parent's daily conversations deserve this level of care regardless of which side of the Atlantic they're recorded on.
Why we did this before anyone made us
Neither the US nor the UK currently has a single, comprehensive AI-specific privacy law that would have forced our hand on all of this. We did it anyway, ahead of launch, because of who's actually on the other end of these calls. Older adults are disproportionate targets of scams and privacy exploitation — the FBI's Internet Crime Complaint Center reported $4.885 billion in elder fraud losses in 2024, and that figure is widely understood to undercount the real total, since older victims are less likely to report fraud out of embarrassment or uncertainty about how. A population already this exposed to exploitation is exactly the wrong population to hand vague, unenforceable data promises to.
Doing the DPIA and the data processing agreements before launch, rather than reactively after a regulator or a journalist asked hard questions, was a deliberate choice about what order to do things in. It's slower, and it's less glamorous than shipping features. We think it's the right order anyway when the data in question is a detailed, ongoing record of an elderly parent's health, routines, and relationships.
What you can actually do, today
Concretely, this is what a family using Hello Rose can do right now: open the memory view and see exactly what Rose has retained about your parent; delete any single fact that's outdated, wrong, or just not something you want stored, without affecting anything else; export the full set of recordings and transcripts in one click, whenever you want a copy; and delete everything, permanently, including the subprocessor copies, whenever you decide you're done. None of that requires an email to support or a delay while someone manually processes a request.
That's the standard we think any company holding recordings of a parent's private conversations should be held to, and it's covered in more detail — alongside how Rose decides what to remember in the first place and how we think about safety more broadly — on our safety page. Read it, and ask the same questions of anyone else you're considering trusting with your parent's daily conversations.
Hello Rose is a companionship service, not a medical or emergency service. This article describes our data practices and is not legal advice on data protection law in any jurisdiction.