Privacy policy
Last updated 9 September 2026. Draft for review before launch.
What we collect. Account details (name, email), workspace configuration (agent prompts, model choices), call data (audio while a call is in progress, transcripts, per-turn metrics, cost receipts, phone numbers), and billing records. Provider API keys you add are encrypted at rest.
How we use it. To run your agents, print receipts, enforce limits you set, bill usage, and improve reliability. We do not use your call audio or transcripts to train models, and we contractually require the same of providers where the option exists (zero-data-retention settings are exposed in Settings).
Where it goes. Call audio and text are sent to the model providers you select (for example Deepgram, OpenAI, Inworld, Cartesia) in the region you choose, and to your telephony carrier. The full list is on the sub-processors page.
Retention. Transcripts and recordings are kept for the number of days set in your workspace (default 30) and then purged. Zero-retention mode stores neither. Aggregated cost and latency figures are kept for billing.
Your rights. You can export or delete call data through the dashboard or the API (DELETE /api/v1/calls/:id), and request account deletion at [email protected]. EU and UK users have the rights set out in the GDPR, including access, rectification, erasure and portability. California residents have the rights set out in the CCPA/CPRA.
Callers. If you are a person who spoke to a Voiceflint-powered agent, the business that deployed the agent is the controller of that call; contact them first. Voiceflint acts as a processor on their instructions.
Security. Encryption in transit and at rest, per-workspace key encryption, scoped API keys, audit of consent events. Report issues to [email protected].
Contact. [email protected].