Privacy Policy

Last updated: March 2026

1. Data Controller

Call0 Inc. ("Call0", "we", "us") is the data controller responsible for the processing of personal data as described in this privacy policy.

Call0 Inc.
447 Broadway, 2nd Floor Suite #3389
New York, NY 10013, United States

For privacy-related questions, contact us via our contact page.

2. Data We Collect

Account Data: Email address, name, company name (optional), authentication provider (email OTP or Google OAuth).

Usage Data: Call logs, call duration, transcriptions, agent configurations, booking data, credit balance and transaction history.

Payment Data: Processed exclusively by Stripe Inc. We do not store credit card numbers, bank account details, or other payment credentials on our servers.

Technical Data: IP address, browser type, device information, referring URLs, collected for security, fraud prevention, and service improvement.

Call Data: Phone numbers of callers (hashed via SHA-256 in customer profiles), call recordings (if enabled), AI-generated transcripts, summaries, and sentiment analysis.

Channel Data: WhatsApp messages (phone number, message content, timestamps) and email messages (email address, subject, body, timestamps) processed through configured integrations.

3. How We Use Your Data

We process your data for the following purposes:

  • - Service delivery: Providing AI voice agent functionality, call handling, transcription, and analytics
  • - Account management: Authentication, billing, credit management, and customer support
  • - Service improvement: Analyzing usage patterns to improve platform performance and features
  • - Security: Fraud prevention, abuse detection, and protecting our infrastructure
  • - Legal compliance: Tax records, regulatory obligations, and responding to legal requests
  • - Communications: Service-related notifications (account, billing, security alerts). Marketing communications only with your explicit consent

4. AI Call Processing

AI Disclosure: Every incoming call begins with an automated notice that the caller is speaking with an AI voice agent and the call may be recorded. By continuing the call, the caller consents to processing. They can hang up at any time to decline.

Data processed during calls:

  • - Caller phone number (pseudonymized via SHA-256 hash in customer profiles)
  • - Real-time speech-to-text transcription (Deepgram / AssemblyAI)
  • - AI-generated responses (Anthropic Claude / OpenAI)
  • - Text-to-speech synthesis (ElevenLabs / Cartesia)
  • - Sentiment analysis of the conversation
  • - AI-generated call summary and extracted information
  • - Bookings and orders created during the call

Retention: Call transcripts and recordings are retained for 90 days. Customer memory profiles are retained as long as the business account is active and fully deleted upon account deletion.

5. Third-Party Services

We use the following third-party services to provide the platform:

ProviderPurposeLocation
Supabase Inc.Database & AuthenticationUSA
Stripe Inc.Payment ProcessingUSA
Twilio Inc.Telephony & SMSUSA
Anthropic PBCAI Language Model (Claude)USA
OpenAI Inc.AI Language Model (GPT)USA
Deepgram Inc.Speech-to-TextUSA
AssemblyAI Inc.Speech-to-TextUSA
ElevenLabs Inc.Text-to-SpeechUSA
Cartesia Inc.Text-to-SpeechUSA
Vercel Inc.Hosting & CDNUSA

For EU/EEA data subjects, transfers to US-based providers are covered by Standard Contractual Clauses (SCCs) per Art. 46(2)(c) GDPR.

6. Data Retention

Account data: Retained as long as your account is active.

Call data: Transcripts and recordings retained for 90 days, unless you delete them earlier.

Booking data: Retained as long as your account is active.

Payment records: Retained for the legally required period (typically 7 years for tax purposes).

Account deletion: All personal data is deleted within 30 days of account deletion, except where legal retention requirements apply.

7. Cookies

We use only essential cookies required for the functioning of our service:

  • - Authentication cookies (Supabase Auth): Session management, login state
  • - Language preference: Your selected interface language
  • - Cookie consent: Your cookie preference (stored in localStorage)

We do not use tracking, analytics, or advertising cookies. See our Cookie Policy for more details.

8. Your Rights (GDPR — EU/EEA Residents)

If you are located in the European Economic Area, you have the following rights under the GDPR:

  • - Right of Access (Art. 15): Request a copy of your personal data
  • - Right to Rectification (Art. 16): Correct inaccurate data
  • - Right to Erasure (Art. 17): Request deletion of your data
  • - Right to Restrict Processing (Art. 18): Limit how we use your data
  • - Right to Data Portability (Art. 20): Receive your data in a machine-readable format
  • - Right to Object (Art. 21): Object to processing based on legitimate interest
  • - Right to Withdraw Consent (Art. 7(3)): Withdraw consent at any time

Legal basis for processing: Contract fulfillment (Art. 6(1)(b)), legitimate interest (Art. 6(1)(f)), consent (Art. 6(1)(a)), and legal obligation (Art. 6(1)(c)).

You also have the right to lodge a complaint with your local data protection authority.

For business customers: Call0 acts as a data processor for caller data. See our Data Processing Agreement for details.

9. Your Rights (CCPA — California Residents)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA):

  • - Right to Know: Request what personal information we collect, use, and disclose
  • - Right to Delete: Request deletion of your personal information
  • - Right to Opt-Out: Opt out of the sale or sharing of personal information
  • - Right to Non-Discrimination: We will not discriminate against you for exercising your rights

We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising.

To exercise your CCPA rights, contact us via our contact page. We will respond within 45 days.

10. Data Security

We implement appropriate technical and organizational measures to protect your data:

  • - TLS 1.3 encryption for all data in transit
  • - AES-256 encryption for data at rest
  • - Row Level Security (RLS) for database access control
  • - Pseudonymization of caller phone numbers (SHA-256)
  • - Automated backups with point-in-time recovery
  • - DDoS protection via Vercel/Cloudflare

11. Children's Privacy

Call0 is not directed at children under 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected data from a child, please contact us and we will promptly delete it.

12. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of significant changes via email or through the platform. Continued use of the service after changes constitutes acceptance.

13. Contact

For privacy-related questions or to exercise your rights:

Call0 Inc.
447 Broadway, 2nd Floor Suite #3389
New York, NY 10013, United States

Or via our contact page.