Legal
Privacy Policy
Last updated: July 24, 2026 · Effective date: July 24, 2026
Privacy contact: info@voxovo-ai.com
This policy is written for customers, workspace users, website visitors, and regulators. It is intended to meet common requirements for SaaS platforms, Google OAuth verification, GDPR/UK GDPR, and CCPA/CPRA transparency. It is not legal advice for your outbound dialing or recording obligations—workspace admins remain responsible for lawful use of the product.
1. Introduction
1.1 Purpose of this policy
This Privacy Policy explains how Voxovo AI ("Voxovo", "we", "us", or "our") collects, uses, stores, shares, retains, and deletes personal data when you use our websites, applications, APIs, dashboards, portals, and voice AI services (collectively, the "Services").
1.2 Agreement
By creating an account, signing in with Google, connecting integrations, uploading contacts or knowledge documents, or placing or receiving AI-handled calls, you acknowledge this Privacy Policy. If you do not agree, do not use the Services.
1.3 Roles at a glance
- Voxovo as controller — for our own website visitors, marketing leads, account/billing records, and platform security logs.
- Voxovo as processor — for call content, transcripts, recordings, contact lists, knowledge bases, and CRM/calendar data that customers configure us to process under their instructions.
- Resellers / multi-tenant customers — when a customer processes end-caller data for their own clients, that customer remains controller; we process under their instructions.
2. Who we are & how to contact us
2.1 Operator
The Services are operated by Voxovo AI under the domains voxovo-ai.com, app.voxovo-ai.com, api.voxovo-ai.com, and admin.voxovo-ai.com, including related subdomains used for testing or staging.
2.2 Privacy contact
Privacy inquiries, data subject access requests (DSARs), deletion requests, and regulator correspondence: info@voxovo-ai.com
Subject line recommendation: "Privacy Request" or "DSAR".
2.3 Security & compliance overview
For technical and compliance controls (encryption, residency, SOC 2 path, HIPAA readiness), see our Security page.
3. Scope — who this policy covers
3.1 Covered individuals
- Website visitors and people who use marketing demos or contact forms
- Workspace members (owners, admins, operators) authenticated via Google Sign-In or other supported login methods
- API and SDK consumers using platform API keys (for example keys prefixed
omni_sk_) - Callers and callees who interact with customer-configured AI voice agents
- Workspace members using multi-org membership access
- Individuals whose data appears in uploaded contact lists, knowledge bases, calendars, or spreadsheets connected by a customer
3.2 What this policy does not replace
Customer contracts, Data Processing Agreements (DPAs), Business Associate Agreements (BAAs), and carrier terms may impose additional obligations. Where a signed DPA conflicts with this policy on processor topics, the DPA controls for that customer relationship.
4. Categories of personal data we collect
4.1 Account & workspace data
- Name, email address, profile image (if provided by your identity provider)
- Authentication identifiers (user IDs, workspace/organization IDs), roles, and permissions
- Workspace name, onboarding profile (role, industry, carriers, languages, goals)
- Plan, trial status, credit balances, and credit grant history
- Session tokens and security events (sign-in time, IP approximation, device type)
4.2 Billing & commercial correspondence
- Plan selection, invoices, credit purchase history, and support/sales email threads
- Payment card data is handled by payment processors when self-serve checkout is enabled. We do not store full payment card numbers on Voxovo servers.
4.3 Call content & telephony metadata
- Realtime audio streams processed for speech-to-text (STT), language models (LLM), and text-to-speech (TTS)
- Transcripts, summaries, tool-call arguments/results, latency timelines, and QA scorecards
- Optional call recordings and recording URLs when enabled by the workspace
- Caller/callee phone numbers, carrier, call direction, duration, AMD results, failure reasons, campaign IDs, and contact IDs
4.4 Contacts, campaigns & knowledge
- Contact lists you upload or sync (phone, email, custom fields, DNC/consent flags)
- Campaign configuration, pacing, retry rules, and AMD policies
- Knowledge base documents, extracted text, chunk embeddings, and search logs used for RAG
4.5 Integrations & secrets
- OAuth tokens and refresh tokens for Google and other connected apps (stored encrypted at rest where required)
- API keys for carriers, CRMs, messaging, and BYOK AI providers
- Webhook URLs, SIP credentials, and telephony configuration
4.6 Website analytics & marketing
- Pages visited, referrers, approximate geo (country/region), device and browser type
- Marketing chatbot or voice-demo transcripts when you choose to interact
- Cookie and local-storage identifiers described in Section 14
4.7 Data we do not intentionally collect
We do not require special-category data (e.g. health, biometric templates for identification, precise geolocation) to operate the core product. If such data appears in call audio or uploaded documents because a customer includes it, we process it only as instructed by that customer and subject to applicable agreements (including BAAs where executed).
5. Google Sign-In & Google API services
This section is provided for transparency and to support Google Cloud OAuth verification and the Google API Services User Data Policy, including Limited Use requirements.
5.1 Google Sign-In (authentication)
When you choose "Sign in with Google", we receive:
- Basic profile information (name, email, Google account identifier, profile photo if available)
- An authorization code exchanged server-side for tokens needed to complete login
We use this information solely to create or authenticate your Voxovo workspace session, prevent account takeover, and communicate account-related notices. We do not use Sign-In data for advertising.
5.2 Google Workspace integrations (Sheets, Calendar, Drive file scope)
If you connect Google from Integrations (for example Google Sheets or Google Calendar), we request only the OAuth scopes required for the features you enable. Depending on your selection, that may include:
- Reading and writing spreadsheet data you authorize for lead/logging workflows
- Creating or updating calendar events you authorize for scheduling workflows
- Limited Drive file access only as required to operate the Sheets features you enable
Access tokens and refresh tokens are stored encrypted and associated with your workspace. You can disconnect Google at any time from Integrations; you may also revoke access in your Google Account permissions.
5.3 Google user data — Limited Use commitment
Voxovo's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- Use limitation — Google user data is used only to provide or improve user-facing features that are prominent in the requesting application's user interface (for example logging call outcomes to a Sheet you connect, or booking calendar events you authorize).
- No selling — We do not sell Google user data.
- No advertising — We do not use Google user data for serving advertisements, including retargeting, personalized ads, or ad-measurement.
- No unauthorized human access — Human access to Google user data is limited to cases where you provide consent for support, where it is necessary for security or legal compliance, or where data is aggregated and anonymized for internal operations that cannot identify individuals.
- No training of unrelated AI models — We do not use Google user data to train generalized AI/ML models unrelated to providing your Voxovo features.
5.4 Revoking Google access
- In Voxovo: open Integrations and disconnect Google / Connected Apps.
- In Google: visit myaccount.google.com/permissions and remove Voxovo AI.
- Optionally email info@voxovo-ai.com to request deletion of stored OAuth tokens and related integration config for your workspace.
6. How we use data (purposes)
6.1 Primary purposes
- Provide and operate realtime voice agents, workflows, campaigns, knowledge search, and dashboards
- Authenticate users, enforce workspace isolation, and prevent abuse or fraud
- Measure and improve latency, speech quality, reliability, and product features
- Customer support, onboarding, billing, credit grants, and security investigations
- Comply with law and respond to lawful requests
- Send product, security, and service notices
6.2 What we do not do
- We do not sell personal data.
- We do not use customer call audio or Google user data to train public foundation models.
- We do not use Google user data for advertising.
6.3 BYOK providers
When you bring your own API keys (BYOK) for speech or LLM providers, those providers process relevant content under their own terms and privacy policies. You control which providers are enabled for your workspace.
7. Legal bases (GDPR / UK GDPR)
7.1 Bases we rely on
- Contract — to deliver the Services you requested (account creation, voice calls, integrations you connect).
- Legitimate interests — security, fraud prevention, service reliability, product improvement, and aggregated analytics, balanced against your rights.
- Consent — where required (certain marketing emails, optional cookies, recording disclosures where consent is the lawful basis).
- Legal obligation — tax, accounting, regulatory, or court orders.
7.2 Customer responsibility for outbound & recording laws
Call recording, two-party consent rules, TCPA/Do-Not-Call, quiet hours, and sector-specific rules vary by jurisdiction. Workspace admins are responsible for configuring agents, consent prompts, and campaigns lawfully. Voxovo provides tools; it does not practice law on your behalf.
8. Telephony & bring-your-own carriers
8.1 Numbers and minutes
Phone numbers typically remain on your Twilio, Telnyx, Plivo, Vonage, or SIP trunk account. Carrier minutes and PSTN routing are billed by your provider. Carrier privacy policies also apply to signaling and media that traverses their networks.
8.2 What Voxovo processes
Voxovo processes media streams and related metadata solely to run the AI agent, tools, workflows, and analytics you configure.
9. Recordings, transcripts, retention & deletion
9.1 Optional recording
Call recording is optional and controlled per agent/workspace. When disabled, we still may process ephemeral audio for realtime STT/TTS and may retain transcripts if that feature is enabled for the workspace.
9.2 Typical retention
- Recordings — commonly retained for a workspace-configured period (often about 30 days) unless a longer enterprise retention is agreed.
- Transcripts & call logs — retained according to workspace settings and operational needs (support, billing disputes, quality).
- Account & billing records — retained as required for contract, tax, and accounting.
- Security logs — retained for a limited period for investigation and abuse prevention.
- Backups — may contain residual copies for a limited window before purge.
9.3 Export & deletion
- Operators may export or review transcripts from Call Logs where the feature is available.
- Workspace admins may request export or deletion via privacy settings/APIs or by emailing info@voxovo-ai.com.
- Hard-delete requests are honored subject to legal holds (billing disputes, abuse, security investigations, or statutory retention).
10. Sharing & subprocessors
10.1 When we share
We share personal data only as needed to operate the Services, comply with law, or with your instructions (for example sending data to a CRM webhook you configure).
10.2 Categories of recipients
- Hosting & infrastructure — cloud/VPS providers hosting application servers, databases, Redis, object storage, and backups.
- Identity — Google (for Sign-In and optional Workspace APIs you connect).
- Speech & AI providers — for example Deepgram, Cartesia, ElevenLabs, Groq, OpenAI, Google Gemini, and others you enable (including via BYOK).
- Telephony carriers — your chosen carrier APIs.
- Email / support tooling — when you contact us or when mailbox assistance is enabled by admins.
- Payment processors — when self-serve billing is enabled.
- Professional advisors & authorities — auditors, counsel, or law enforcement when legally required.
10.3 Contractual protections
We require processors to protect data under contractual terms appropriate to the processing. A current subprocessor list may be provided to enterprise customers on request.
11. International transfers & data residency
11.1 Default region
Default processing region is the United States unless otherwise agreed in writing. Enterprise customers may request residency options.
11.2 Safeguards
Where personal data is transferred internationally, we use appropriate safeguards such as Standard Contractual Clauses (SCCs) or equivalent mechanisms where required by law.
12. Security measures
12.1 Technical & organizational measures
- TLS encryption in transit; encrypted storage for secrets and OAuth tokens where required
- Workspace isolation and membership scoping
- Admin APIs protected by separate admin credentials
- Audit logging for sensitive administrative actions
- Role-based access for workspace operators
- Signed webhooks where enabled
12.2 Incident response
We investigate suspected security incidents affecting personal data and, where legally required, notify affected customers and/or regulators without undue delay. No method of transmission or storage is 100% secure. See also /security.
13. Your privacy rights
13.1 GDPR / UK GDPR (EEA, UK, and similar)
Depending on your location, you may have the right to:
- Access personal data we hold about you
- Correct inaccurate data
- Delete data (erasure), subject to legal exceptions
- Export data in a portable format
- Restrict or object to certain processing
- Withdraw consent where processing is consent-based
- Lodge a complaint with your local supervisory authority
13.2 CCPA / CPRA (California)
- Right to know / access, delete, and correct personal information, subject to exceptions
- Right to opt out of “sale” or “sharing” as defined by California law — we do not sell personal information, and we do not share it for cross-context behavioral advertising
- Right to non-discrimination for exercising privacy rights
13.3 How to exercise rights
Email info@voxovo-ai.com with subject "Privacy Request". We may need to verify your identity before fulfilling a request. We aim to respond within 30 days (or sooner where law requires).
13.4 End-caller requests
If you are a caller who spoke with a customer's AI agent, please contact that business first—they are typically the controller. Customers must route end-user requests through their own process when they are the controller; we will assist that customer as processor.
13.5 Automated decision-making
Voice agents act under prompts, tools, and workflows configured by customers. Customers control agent behavior. If you believe an automated outcome materially affects you, contact the business that operated the agent, or contact us if Voxovo is the direct controller for the relevant data.
14. Cookies & similar technologies
14.1 Essential
We use essential cookies and local storage for authentication/session continuity, CSRF and security protections, and load balancing. Disabling these may break login and core app features.
14.2 Analytics & preferences
Marketing pages may use analytics or preference cookies to understand traffic and improve content. Where required by law, we will request consent before non-essential cookies.
14.3 Controls
You can control cookies through your browser settings. Do Not Track signals are not uniformly standardized; we treat privacy choices made through our product settings and consent tools as controlling where available.
15. Children
Voxovo is a B2B platform and is not directed to children under 16 (or the higher age required in your jurisdiction). We do not knowingly collect personal data from children. If you believe a child has provided us data, contact info@voxovo-ai.com and we will take appropriate steps to delete it.
16. Artificial intelligence processing
16.1 Realtime inference
Voice calls use automated speech recognition, language models, and speech synthesis to generate responses in realtime. Outputs may be imperfect; customers should review critical workflows and provide human escalation paths where appropriate.
16.2 Training
We do not use your call audio or Google user data to train public foundation models. We may use aggregated, de-identified metrics (for example latency histograms) to improve platform reliability.
16.3 Knowledge grounding
Documents you upload to Knowledge are chunked and searched to ground agent answers. You are responsible for having rights to upload that content and for not uploading unlawful data.
17. Changes to this policy
We may update this Privacy Policy as the product, law, or subprocessors evolve. Material changes will update the "Last updated" date at the top of this page and, where appropriate, we will provide in-product or email notice. Continued use of the Services after the effective date constitutes acceptance of the revised policy, except where additional consent is required by law.
18. Contact
Privacy & DSAR: info@voxovo-ai.com
Website: https://voxovo-ai.com
This policy URL: https://voxovo-ai.com/privacy
Security overview: https://voxovo-ai.com/security
For Google Cloud Console / OAuth verification, use the privacy policy URL above exactly.