Skip to content
Legal

Privacy policy

What we collect, who else touches it, how long we keep it and how to have it deleted. Last updated 10 September 2026.

Draft — legal review pending. This is a working draft written to describe what the service actually does today. It has not been reviewed by counsel.

callintel is operated by [operating entity — legal name to be inserted], a company registered in India. We are the controller for your account details and a processor for the call data you connect. The short version: we do not sell your data, we do not use it to train models, and you can have all of it deleted by asking.

1. What we hold

About you

  • Name, email address and a hashed password (argon2id). We never see the password itself.
  • Workspace membership and role, plan, credit balance and a ledger of what was spent on what.
  • Session records: an opaque token, when it was created and from which IP address.

About your calls

  • Call records from the sources you connect: caller and target numbers, time, duration, agent, and any revenue field your source provides.
  • The recordings themselves, converted to FLAC and stored in our object storage so we can play them back to you.
  • Transcripts, split by speaker, with timings.
  • The answers extracted from each call, the findings built from them, and any questions you ask and their answers.
  • Credentials for your sources — a Ringba token, a Google OAuth grant — encrypted at rest.

Callers are not our customers and we have no relationship with them. You are responsible for being allowed to record and process their calls (see the terms, section 3).

2. Why we hold it

  • To run the service: sync, transcribe, analyse, display, and play back.
  • To bill you and to tell you when credits are low.
  • To keep the service secure: login lockout, session checks, abuse detection.
  • To email you about your account. We do not send marketing email.

We do not sell personal data, we do not share it with advertisers, and we do not use your recordings, transcripts or findings to train machine-learning models — ours or anyone else's.

3. Who else processes it

These are the only third parties that receive your data, and what each one receives:

ProviderUsed forWhat it receives
AssemblyAITranscription (Standard tier)Audio of a call; returns the transcript
DeepgramTranscription (Precise tier)Audio of a call; returns the transcript
OpenRouterAnalysis — the questions, discovery and askTranscript text; returns structured answers
StripeCard paymentsBilling email, plan, card handled by Stripe
BrevoTransactional emailYour email address and the message
HetznerHosting and storageEverything above, at rest, in the EU

Transcription and analysis providers receive a call only for the time it takes to process it, and we opt out of provider-side retention and training wherever the provider offers the setting. Which transcription provider handles a workspace depends on the tier you choose in settings.

4. How long we keep it

  • Call records, recordings, transcripts and findings: for as long as your workspace exists, so that the evidence behind every finding stays playable.
  • Public share links you create expire on the date you set (30 days by default) and can be revoked at any time before that.
  • Sessions: until you sign out or they expire.
  • The credit ledger: for the life of the account, because it is the record of what you were charged.
  • After an account is closed: everything is deleted within 30 days, except billing records we must keep under Indian tax law.

5. Deletion and your rights

Deletion is on request: email us from the address on the account and say what you want removed — a call, a source and everything synced from it, a workspace, or the whole account. Deleting a call removes its recording, transcript and findings. Deleting the account removes everything in section 1. We confirm by email when it is done, within 30 days. Self-serve deletion inside the product is planned; until it ships, email is the way.

You can also ask us for a copy of what we hold about you, ask us to correct it, or object to a use of it. We answer within 30 days. Under India's Digital Personal Data Protection Act, and under the GDPR if you are in the EU or UK, you may also complain to your data-protection authority.

6. Cookies

We set two cookies, both first-party: a session cookie so you stay signed in, and a theme cookie that remembers light or dark. There are no analytics or advertising cookies on this site or in the product.

7. Security

  • Everything travels over HTTPS.
  • Passwords are hashed with argon2id; sessions are opaque random tokens in httpOnly cookies; mutating requests carry a CSRF token.
  • Source credentials are encrypted at rest. Every database query is scoped to a workspace by a single, tested chokepoint.
  • If we discover a breach that affects you, we will tell you without undue delay and say what was involved.

8. Contact

Privacy questions and deletion requests: email the address shown in your workspace settings, from the email on your account. We update this page in place and change the date at the top when we do.