Effective August 13, 2026

Privacy Notice

What we collect

We may process your sign-in identity, verified callback phone, exact approved company access, subscription status and allowance, call status events, provider identifiers, menu decisions, timing, cost, and final receipt. Unsupported route requests retain privacy-safe company, department and demand details; never put tracking, order, account, password, OTP, security-answer, payment or other personal data in them. Preparation details are limited to reviewed fields and have explicit retention periods.

What we do not want

Do not provide passwords, PINs, one-time codes, security answers, payment-card details, Social Security numbers, or unnecessary account credentials. Card details go directly to Stripe and are not collected by Caller AI. The product blocks known sensitive categories where possible.

Audio and transcripts

Consumer calls are not recorded by default. Temporary automated-menu diagnostics may be enabled only for an exact controlled test under the displayed retention policy. Human free conversation is not retained as routine product data.

Why we use data

We use it to authenticate users, prevent abuse, aggregate requested-route demand, manage subscriptions and allowances, verify callback reachability, operate requested calls, detect a representative, establish the conference, produce history, investigate failures, enforce quotas, and reconcile provider costs.

Service providers

Supabase supports authentication and storage, Twilio supports verification and telephony, OpenAI supports reviewed real-time menu navigation, Stripe supports hosted billing, Vercel hosts the web application, and Railway hosts the voice gateway. Each receives only the data needed for its role.

Control and deletion

You can change a callback number when no call is active. A number used for phone sign-in must be replaced before it can be removed. You can manage billing in Stripe and request account deletion from Profile. Some security, billing, provider, or audit records may be retained where necessary to prevent abuse, settle transactions, or meet legal obligations.

Security

Sensitive stored fields are encrypted, provider webhooks are signed, browser access is restricted by row-level policies, and real calling remains fail-closed behind user, billing, route, quota, budget, and kill-switch gates.