Legal
Privacy Policy
Last updated: July 19, 2026 · Contact: info@voxovo-ai.com
This Privacy Policy describes how Voxovo AI ("Voxovo", "we", "us", or "our") collects, uses, stores, shares, and deletes personal data when you use our websites (including voxovo-ai.com), web applications, APIs, dashboards, client portals, and voice AI services (collectively, the "Services").
By creating an account, connecting a carrier, or placing or receiving AI-handled calls, you acknowledge this policy. If you do not agree, do not use the Services.
1. Who we are & how to contact us
Voxovo AI operates a production voice-agent platform at voxovo-ai.com, app.voxovo-ai.com, api.voxovo-ai.com, admin.voxovo-ai.com, and user.voxovo-ai.com (agency client portal). Privacy inquiries, DSARs, and deletion requests: info@voxovo-ai.com. Agencies remain controllers for their end-customer caller data when they resell Voxovo; we act as a processor for that content under their instructions.
2. Scope
This policy covers:
- Website visitors and marketing chat / demo voice interactions
- Workspace members (owners, admins, operators) authenticated via Clerk
- API / SDK consumers using
omni_sk_keys - Callers and callees who interact with customer-configured AI agents
- Agency clients using white-label portals
3. Categories of personal data we collect
3.1 Account & workspace data
- Name, email, authentication identifiers (Clerk user/org IDs), role, workspace name
- Onboarding profile (role, industry, carriers, languages, goals) when you complete welcome flows
- Plan, trial status, credit balances, and credit grant history
3.2 Billing & commercial correspondence
- Plan selection, invoices/credit requests, email threads with support or sales
- Payment card data is processed by payment processors when self-serve checkout is enabled — we do not store full card numbers on Voxovo servers
3.3 Call content & telephony metadata
- Realtime audio streams processed for STT / LLM / TTS
- Transcripts, tool-call arguments/results, latency timelines, QA scorecards
- Optional recordings and recording URLs when enabled by the workspace
- Caller/callee numbers, carrier, duration, AMD results, failure reasons, campaign/contact IDs
3.4 Contacts, campaigns & knowledge
- Contact lists you upload or sync (phone, email, custom fields, DNC/consent flags)
- Campaign configuration, pacing, retry and AMD policies
- Knowledge base documents and embeddings used for RAG mid-call
3.5 Integrations & secrets
- OAuth tokens and API keys for carriers, CRM, calendars, sheets, messaging (stored encrypted where required)
- Webhook URLs and SIP / BYOK configuration
3.6 Website analytics & marketing
- Pages visited, referrers, rough geo (country/region), device type
- Marketing chatbot / voice demo transcripts when you opt to interact
4. How we use data (purposes)
- Provide and operate realtime voice agents, workflows, campaigns, and dashboards
- Authenticate users, enforce workspace and agency-client isolation, prevent abuse and fraud
- Measure and improve latency, speech quality, Presence Buffer, and reliability
- Customer support, billing, credit grants, and security investigations
- Comply with law and respond to lawful requests
- Send product and security notices
We do not sell personal data. We do not use customer call audio to train public foundation models. BYOK providers process audio under their own terms when you select them.
5. Legal bases (GDPR / UK GDPR)
- Contract — to deliver the Services you signed up for
- Legitimate interests — security, fraud prevention, product improvement, aggregated analytics (balanced against your rights)
- Consent — where required (e.g. certain marketing emails, recording laws, cookie banners where applicable)
- Legal obligation — tax, regulatory, or court orders
Call recording and outbound dialing may require additional consent or quiet-hour compliance in your jurisdiction — workspace admins are responsible for configuring agents lawfully.
6. Telephony & BYO carriers
Phone numbers remain on your Twilio, Telnyx, Plivo, Vonage, or SIP trunk account. Carrier minutes and PSTN routing are billed by your provider. Voxovo processes media and transcripts solely to run the AI agent and tooling you configure. Carrier privacy policies also apply to signaling and media that traverses their networks.
7. Recordings, transcripts, retention & deletion
- Recording is optional per agent/workspace and may be disabled
- Default retention is configurable (commonly 30 days for recordings; transcripts may follow workspace policy)
- Operators can re-transcribe, redact common PII patterns, and export transcripts from Call Logs for support workflows
- Workspace admins may request export or deletion via privacy APIs / settings. Hard-delete requests are honored subject to legal retention (billing disputes, abuse, security logs)
- Backups may retain residual copies for a limited period before purge
8. Sharing & subprocessors
We share data only as needed to run the Services:
- Clerk — authentication
- Hosting — cloud/VPS providers hosting app, API, databases, Redis, object storage
- Speech & AI — Deepgram, AssemblyAI, Gladia, OpenAI, Cartesia, ElevenLabs, Groq, Google Gemini, and others you enable via BYOK
- Telephony — your chosen carrier APIs
- Email / support — when you contact us or when Email AI assists mailbox triage (admin controlled)
- Professional advisors / law enforcement — when legally required
We require processors to protect data under contractual terms appropriate to the processing.
9. International transfers & residency
Default processing region is the United States unless otherwise agreed in writing. Enterprise customers may request residency options. Cross-border transfers use appropriate safeguards (e.g. SCCs where required).
10. Security measures
- TLS in transit; encrypted storage for secrets where required
- Workspace isolation and agency client scoping (
X-Client-Workspace-Id) - Admin APIs protected by separate admin keys
- Audit logging for sensitive admin actions
- Role-based access for workspace operators
See our Security page for SOC 2 path and HIPAA/BAA readiness notes. No method of transmission or storage is 100% secure.
11. Your rights (GDPR, CCPA/CPRA & similar)
Depending on your region, you may have rights to:
- Access, correct, delete, or export personal data
- Restrict or object to certain processing
- Withdraw consent where processing is consent-based
- Appeal automated decisions where applicable (voice agents act under customer prompts — customers control agent behavior)
- Opt out of “sale”/“sharing” as defined by CCPA — we do not sell personal information
Email info@voxovo-ai.com with the subject “Privacy Request”. We may verify identity before fulfilling. Agencies must route end-user caller requests through their own process when they are the controller.
12. Children
Voxovo is a B2B product and is not directed to children under 16. We do not knowingly collect data from children.
13. Cookies & similar technologies
We use essential cookies/storage for authentication (Clerk), security, and load balancing. Analytics cookies may be used on marketing pages. You can control cookies via browser settings; disabling essential cookies may break login.
14. Changes to this policy
We may update this policy as the product evolves (for example after major platform releases). Material changes will update the “Last updated” date and, where appropriate, in-product notice. Continued use after the effective date constitutes acceptance of the revised policy.
15. Contact
Privacy: info@voxovo-ai.com
Website: https://voxovo-ai.com
Security overview: /security