Privacy Policy
Last updated · 2026
Your privacy matters. This policy describes what the platform collects, how it is used, and the choices available to you.
This document is a professionally structured template. Review and adapt it with qualified legal counsel to meet the laws of your jurisdiction before production use.
01Introduction
This Privacy Policy explains how the platform (“the Service”, “we”, “us”) collects, uses, and protects information when you use the application. Because the Service is self-hosted, the operator who deploys it is the data controller for their tenants and end users; this policy describes the default behavior of the software.
02Information we collect
We collect the following categories of information:
- Account data — name, email, password hash, role, and organization/tenant you belong to.
- Contact and lead data — phone numbers, names, emails and any fields you import or that agents capture during calls.
- Call data — recordings, transcripts, summaries, sentiment, lead scores, duration and outcome.
- Configuration — agents, campaigns, flows, provider credentials (stored encrypted) and settings.
- Billing data — plan, credit balance, invoices and payment metadata handled by your chosen gateway.
- Technical data — IP address, browser type, and log/audit records of sensitive actions.
03How we use information
Information is used to operate and improve the Service, including to:
- Place and manage calls, generate transcripts, and score leads.
- Authenticate users and enforce role-based access and tenant isolation.
- Process billing, credits and subscriptions.
- Provide analytics, reporting and audit trails to account administrators.
- Maintain security, prevent abuse and comply with legal obligations.
05Third-party services
To function, the Service connects to providers that you configure with your own credentials, such as:
- Telephony — Twilio, Plivo (to place and receive calls).
- Voice & AI — ElevenLabs, OpenAI (for speech and conversation).
- Payments — the payment gateway(s) you enable.
- Optional integrations — CRMs and webhooks you connect.
Data shared with these providers is governed by their respective privacy policies. You are responsible for choosing providers and obtaining any required consent.
06Data security
The Service applies security measures including encrypted storage of provider credentials, hashed passwords, role-based access control, tenant-level data isolation, and audit logging of sensitive actions. As a self-hosted application, transport security (HTTPS), server hardening, backups and access management are the responsibility of the operator.
07Data retention
Call recordings, transcripts, contacts and related records are retained until deleted by the account or operator, or according to retention rules the operator configures. Deleting a record removes it from the application; operators should also manage backups and any data held by third-party providers.
08Your rights
Depending on your jurisdiction, individuals may have rights to access, correct, export or delete their personal data, and to object to or restrict certain processing. Requests should be directed to the operator of the deployment you interact with, who acts as the data controller.
09Children’s privacy
The Service is intended for business use and is not directed to children. It should not be used to knowingly collect personal information from minors.
10Changes to this policy
This policy may be updated to reflect changes in the software or applicable law. Material changes should be communicated to users by the operator, and the “last updated” date will be revised.
11Contact
For privacy questions about a specific deployment, contact its operator. For questions about the software itself, contact hello@callmineai.com.