Back to home

Privacy Policy

Effective Date: December 11, 2025

Last Updated: December 11, 2025

This Privacy Policy describes how Voxinity AI ("we", "us", or "our") collects, uses, discloses, and safeguards information when you use our AI voice and chat agent platform (the "Service"). By using the Service, you agree to the practices described in this Policy.

1. Information We Collect

We collect information you provide directly to us, information collected automatically through your use of the Service, and information from third-party integrations you authorize.

a. Account & Profile Information

Name, email address, phone number, business name, billing address, and password (stored as a salted, one-way hash).

b. Customer & Contact Data

When you connect a CRM or import contacts, we process the contact records you provide, including names, phone numbers, email addresses, custom fields, and tags. You are the controller of this data; we act as a processor on your behalf.

c. Voice, Call & Conversation Data

We record, transcribe, and store voice calls, SMS messages, chat widget conversations, and related metadata (timestamps, call duration, outcome, sentiment) to deliver, improve, and audit the Service. Call recordings may be retained for up to 90 days unless you configure a different retention period or request earlier deletion.

d. Payment Information

Payment card details are collected and processed by our PCI-DSS compliant payment processor (Stripe). We do not store full card numbers on our systems.

e. Technical & Usage Data

IP address, browser type, device identifiers, referring URLs, pages viewed, feature usage, and diagnostic logs.

2. How We Use Information

  • To provide, operate, maintain, and improve the Service.
  • To process voice calls, SMS, and chat conversations through connected AI models and telephony providers.
  • To sync activity (calls, recordings, transcripts, contact updates, notes, tags) back to CRMs you have authorized.
  • To bill, invoice, and process payments.
  • To send service-related notifications, security alerts, and administrative messages.
  • To detect, investigate, and prevent fraud, abuse, and security incidents.
  • To comply with legal obligations and enforce our Terms.

We do not sell personal information, and we do not use customer voice or conversation content to train third-party foundation models without your explicit consent.

3. How We Share Information

We share information only with the categories of recipients described below, and only as required to deliver the Service:

  • Sub-Processors & Service Providers: We engage trusted third parties to host infrastructure, send emails, process payments, deliver telephony, run speech-to-text and text-to-speech, and provide large language model inference. These vendors are contractually bound to use information only to perform services for us.
  • CRM Integrations: When you authorize a CRM connection (e.g., via OAuth), we send and receive data with that CRM strictly under your direction.
  • Legal & Safety: When required by law, subpoena, court order, or to protect the rights, property, or safety of Voxinity AI, our users, or others.
  • Business Transfers: In the event of a merger, acquisition, financing, or sale of assets, information may transfer subject to this Policy.

4. Sub-Processors

We rely on the following categories of sub-processors. By using the Service, you authorize their use:

VendorPurposeData Handled
TwilioTelephony, SMS, call routingPhone numbers, call audio, SMS content
ElevenLabsText-to-speech voice synthesisOutbound text to be voiced
OpenAI / Anthropic / GoogleLarge language model inferenceConversation messages, system prompts
StripePayment processingBilling details, payment methods
CRM Platforms (via OAuth)Contact sync, calendar, opportunitiesContacts, notes, calls, appointments
Cloud InfrastructureHosting & storageAll Service data at rest

5. CRM Data Usage (LeadConnector)

When you connect a LeadConnector sub-account or agency to Voxinity AI through the LeadConnector Marketplace OAuth flow, we read from and write to a clearly scoped set of resources in your LeadConnector account to operate the Service on your behalf. The table below lists every category of data we touch, what we do with it, and how long we retain it.

LeadConnector ResourceReadWriteRetention
ContactsLookup by phone / email, fetch custom fields and tags for call context.Create new contacts, update name/phone/email, append notes, add or remove tags, write structured call summaries to custom fields.Mirror retained 13 months
Conversations & MessagesRead inbound SMS / chat history to maintain conversational context.Send outbound SMS replies, post-call summaries, and follow-up messages via your LeadConnector number.13 months
Calendars & AppointmentsRead calendar IDs and free / busy windows when the AI offers slots.Create, reschedule, or cancel appointments only when a caller confirms.For the life of the connection
OpportunitiesRead opportunity stage to brief the AI during calls.Move opportunities between stages when a workflow asks for it.For the life of the connection
Custom Fields & Custom ValuesDiscover schema so the AI knows which fields exist.Populate fields with call outcome, summary, transcript URL, last-call timestamp.For the life of the connection
TagsList available tags.Apply tags such as "AI-Called", "Booked", "No-Answer".For the life of the connection
WorkflowsList active workflows so customers can target them.Trigger a specific workflow on demand from a Voxinity action.For the life of the connection
Locations & UsersRead location metadata and assigned users for display in our dashboard.None.For the life of the connection
FormsList form submissions so the AI can reference them.None.For the life of the connection
OAuth TokensStored encrypted at rest, refreshed automatically before expiry.Refresh tokens are rotated by the LeadConnector OAuth server.Deleted on uninstall or disconnect

We do not sell, rent, or transfer LeadConnector data to third parties, and we do not use the content of LeadConnector conversations, contacts, or calls to train any third-party machine-learning model. Conversation content is sent to large language model providers (OpenAI / Anthropic / Google) only to generate the live response and is excluded from their training programs under our zero-data-retention enterprise agreements.

When you uninstall the Voxinity app from a LeadConnector sub-account, our LeadConnector Marketplace webhook handler revokes the stored OAuth tokens, halts every background sync loop for that sub-account, and flips the integration card in Voxinity to "Disconnected" within seconds. You can independently delete a workspace and all of its CRM-derived data at any time by emailing support@voxinity.ai.

6. Data Retention

We retain personal information for as long as your account is active or as needed to provide the Service. Default retention windows:

  • Account & billing records: duration of account + 7 years.
  • Call recordings: up to 90 days (configurable per workspace).
  • Transcripts & conversation logs: up to 13 months.
  • Diagnostic logs: up to 30 days.

You may request deletion of your account and associated data at any time by emailing support@voxinity.ai. We will action verified deletion requests within 30 days, subject to legal retention obligations.

7. Security

We implement administrative, technical, and physical safeguards designed to protect the information we process. These include encryption in transit (TLS 1.2+), encryption at rest, role-based access controls, least-privilege provisioning, audit logging, and periodic security reviews. No method of transmission or storage is 100% secure; we cannot guarantee absolute security.

8. Your Rights

Depending on your jurisdiction, you may have the right to access, correct, port, restrict, or delete personal information we hold about you, and to object to or withdraw consent for certain processing. To exercise these rights, contact us at support@voxinity.ai. We will respond within the timeframe required by applicable law.

California Residents (CCPA/CPRA): You have the right to know what personal information we collect, the right to delete it, the right to correct inaccurate information, the right to opt out of sale or sharing (we do neither), and the right not to be discriminated against for exercising your rights.

EU/UK Residents (GDPR/UK GDPR): We process personal data on the legal bases of contract performance, legitimate interests, consent, and legal obligation. You may lodge a complaint with your local data protection authority.

10. Children's Privacy

The Service is not directed to individuals under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.

11. International Data Transfers

We may process and store information in the United States and other countries that may have different data protection laws than your country of residence. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses.

12. Cookies & Tracking

We use strictly necessary cookies for authentication and session management, and limited analytics cookies to understand how the Service is used. You may control cookies through your browser settings. Disabling necessary cookies may impair Service functionality.

13. Changes to This Policy

We may update this Policy from time to time. Material changes will be communicated by email or via an in-product notice at least 30 days before they take effect. Continued use of the Service after the effective date constitutes acceptance of the updated Policy.

14. Contact Us

For privacy questions, requests, or complaints, contact our Privacy team at support@voxinity.ai.

Legal Disclaimer

This document is provided for general informational purposes and does not constitute legal advice. Voxinity AI recommends that you consult qualified legal counsel to confirm that this Policy meets the regulatory requirements applicable to your business and the jurisdictions in which you operate.