Back to home

Privacy Policy

Last updated: May 7, 2026

Call AI is committed to protecting the privacy of users and call recipients served via the Platform. This document explains what data we collect, how it is stored, and the rights of data subjects.

1. Data We Collect

From the Customer (account owner)

  • Email, name, phone number, company details (incl. tax ID)
  • Payment details — held by the payment processor (Stripe / Cardcom), not by us
  • Signup IP, billing country, card BIN country (for VAT residency detection)
  • Customer-created content: prompts, knowledge base, contact lists

From Call Recipients

  • Phone number (and name/address if uploaded by the Customer)
  • Recordings + call transcripts (with automatic PII redaction)
  • Telephony metadata (duration, quality, hangup cause)
  • Opt-in / opt-out status

2. How We Use the Data

  • Service operation — placing calls, routing audio through STT/TTS, issuing invoices
  • Quality control — sampled human review (anonymized) to improve the model
  • Model training — only with explicit Customer opt-in via Settings
  • Legal compliance — call logs retained for audit and legal defense

We do not sell data to third parties. We do not use call transcripts for marketing. We do not show one customer's data to another.

3. Sub-processors

To operate the Service, we share data with the following sub-processors, all of whom are bound by a DPA (Data Processing Agreement) and obligated to protect data:

ProviderRoleRegion
Anthropic / OpenAI / Google GeminiLLMUS, EU
ElevenLabs / CartesiaTTSUS
DeepgramSTTUS
Telnyx / TwilioTelephonyGlobal
Cloudflare R2Recording storageGlobal
Stripe / CardcomPayment processingUS / IL
ResendTransactional emailUS
Meta WhatsAppWhatsApp messagingGlobal
SentryError monitoringUS, EU

This list is updated as our infrastructure changes. The current list is always available via [email protected].

4. Retention & Deletion

  • Recordings — 90 days by default (cron auto-purge); configurable per plan.
  • Transcripts — stored alongside recordings; deleted with them.
  • Audit logs — 365 days (statutory).
  • Invoices — 7 years (Israeli Tax Authority requirement).
  • Contact data — until the Customer requests deletion, and no more than 3 years after the last call.

5. Security

  • Encryption at rest — AES-256
  • Encryption in transit — TLS 1.3
  • Optional TOTP 2FA for all users, mandatory for OWNER role
  • Immutable audit logs with timestamp signing
  • API keys hashed (SHA-256) in DB
  • HMAC-SHA256 signatures on every outgoing webhook
  • Rate limiting + per-API-key IP allowlist
  • Sentry error monitoring with PII redaction

6. Your Rights (GDPR + Israeli Privacy Act)

You may at any time:

  • Access — full data download in JSON via account settings
  • Rectify — update details via your user profile
  • Erase — Settings → Account → Delete Account (removed within 30 days, except statutorily retained data)
  • Port — JSON export (Data Portability)
  • Object to marketing — Settings → Email Preferences
  • Lodge a complaint with the Israeli Database Registrar or your relevant EU DPA

Requests are handled within 30 business days at [email protected].

7. Call Recording

Calls placed via the Platform are recorded for quality control. At the start of each call (inbound or outbound), the agent provides a recording disclosure: "This call is being recorded for service improvement." A recipient who wishes not to be recorded may say so — the agent will end the call and notify the Customer.

The account owner may disable recording for all of their agents via Settings → Privacy. This is at the owner's risk (in the event of chargeback or dispute, no recording will be available as evidence).

8. Cookies

We use only essential session cookies. There is no marketing tracking, no Google Analytics, and no Facebook Pixel inside the authenticated app.

9. International Transfers

Some of our sub-processors are located outside Israel / the EU (e.g., the United States). Such transfers rely on the EU Commission's Standard Contractual Clauses (SCCs), or the EU-U.S. Data Privacy Framework (DPF) where applicable. For Israeli data subjects, transfers comply with the Israeli Privacy Protection Regulations (Transfer of Data Abroad), 2001.

10. Children

The Service is not directed at children under 16. We do not knowingly collect information from children. If we learn we have inadvertently collected data from a child, we will delete it.

11. Law-Enforcement Requests & Court Orders

Call AI receives requests from law-enforcement authorities (police, prosecutors, tax authorities). Our policy:

  • Validity check: we disclose information only on a valid court order or formal lawful demand from a competent authority in the relevant jurisdiction.
  • Customer notice: we attempt to notify the account holder before disclosing — unless a gag order applies, the account itself is the subject of the criminal investigation, or there is legal urgency.
  • Minimum scope: we disclose only what the order explicitly requires, nothing more.
  • Transparency: we will publish an annual transparency report (request counts, no identifying details) once volumes warrant it.
  • Channel: [email protected]

12. Changes

Material changes will be communicated by email at least 14 days in advance. Minor changes (wording, contact details) are updated without notice but will be marked in the "Last updated" line.

13. Contact

מדיניות פרטיות · Privacy Policy · Call AI | Call AI