Privacy Policy
Conversa · Last updated 4 August 2026
Conversa provides an AI voice agent that makes outbound business calls on behalf of our customers. This policy explains what personal information we handle, why, and what you can ask us to do about it.
If we called you
You are probably here because you received a call from an AI agent and want to know who is behind it. The short version:
- A Conversa customer — a business — supplied your phone number and instructed us to call you. They decide who gets called; we operate the system.
- Our agent will never claim to be human. Ask it directly and it will tell you it is an AI. That rule is not configurable.
- We keep a written transcript of the call. We do not record audio unless the calling business has explicitly enabled recording, in which case you are told at the start of the call.
- You can ask to be removed. Email legal@getconversa.ai with the phone number that was called and we will add it to our do-not-call list and pass the request to the business that called you.
1. Two groups of people
We handle personal information about two distinct groups, and the rules differ for each.
Customers are the businesses and individuals who hold a Conversa account. For their data we are the controller.
Call recipients are the people our customers ask us to call. For their data our customer is the controller and we act as a processor on that customer's instructions. This matters: we do not choose who gets called, and we do not build or sell calling lists.
2. What we collect
From customers
- Account details — name, work email, organization name.
- Authentication data. Passwords are handled by our authentication provider and are never visible to us.
- Calendar connection tokens, if you connect Google or Microsoft Calendar so the agent can book meetings. These are encrypted at rest with a key our database never sees.
- Usage and billing records.
About call recipients, on our customer's instruction
- Phone number, and where the customer supplies it, name and company.
- The consent record — where the customer obtained permission to call and when. Our import process requires this; a list without it cannot be dialled.
- A written transcript of the conversation.
- Call metadata — time, duration, outcome, and whether a meeting was booked.
- Meeting details, if a meeting is booked: name, email address and chosen time.
- Audio recordings only where the customer has enabled them. See section 4.
3. AI disclosure
Our agent may never deny being an AI, claim to be human, or dodge the question. This holds in every configuration and is enforced in the agent's instructions and in our automated tests.
By default the agent volunteers that it is an AI early in the conversation. A customer may configure it instead to disclose on request — meaning it does not raise the subject unprompted but confirms plainly the moment it is asked. Disclosure itself cannot be switched off.
4. Call recordings are off by default
Conversa ships with audio recording disabled. Written transcripts, which carry materially less risk, deliver nearly all the operational value.
Recording is available only as a deliberate opt-in by a customer, and when it is enabled the agent discloses recording at the start of the call. Recording consent is a separate legal obligation from AI disclosure — several U.S. states require the consent of all parties, and Illinois treats voiceprints as biometric identifiers. Customers who enable recording are responsible for their own compliance.
5. How long we keep things
| Data | Retention | Why |
|---|---|---|
| Call metadata | Indefinitely | Aggregate analytics and service improvement. Contains no conversation content. |
| Transcripts | 12–24 months, configurable per customer | Quality review and dispute resolution. |
| Audio recordings | Per customer setting; off by default | Deleted from storage as well as from our database. |
| Consent records | 5 years | Evidence that a call was permitted. Retained even after a deletion request — see below. |
| Customer account data | Life of the account, then 90 days | Billing and legal records. |
6. Your rights
Depending on where you live you may have the right to access, correct, delete, or port your personal information, to object to processing, and to be free from discrimination for exercising these rights. We do not sell personal information and we do not share it for cross-context behavioural advertising.
Email legal@getconversa.ai to make a request. If you were a call recipient, include the phone number that was called so we can find the right record.
One deliberate exception: when we action a deletion request we remove call history and contact details, but we keep the consent record. That record is the evidence that the call was permitted in the first place, and deleting it would destroy the proof that protects both you and us. It contains only the source and date of the permission.
If you are a call recipient, we will also pass your request to the customer who initiated the call, since they control that data.
7. Who else processes your data
We use a small number of subprocessors. Each is contractually bound to handle data only as we instruct.
| Provider | Purpose |
|---|---|
| Vapi | Real-time voice orchestration |
| Twilio | Telephony — placing and carrying calls |
| Anthropic | The language model behind the agent's conversation |
| Supabase | Database and authentication |
| Calendar booking, and our own business email | |
| Microsoft | Calendar booking, where a customer connects Outlook |
| Resend | Sending booking confirmations and calendar invitations |
| Render | Application and API hosting |
8. Security
- Every record is scoped to a single organization, enforced in the database itself rather than only in application code.
- Calendar refresh tokens are encrypted with AES-256-GCM. The encryption key is held outside the database.
- Data is encrypted in transit.
- Access to production data is limited to personnel who need it.
No system is perfectly secure, and we do not claim otherwise.
9. Children
Conversa is a business tool and is not directed to anyone under 18. We do not knowingly collect information from children. Our customers' calling lists are business contacts.
10. International transfers
We operate from the United States and our subprocessors may process data there. If you are outside the U.S., your information will be transferred to and processed in the U.S.
11. Changes
If we make a material change we will update the date at the top of this page and, for customers, give notice by email before it takes effect.
12. Contact
Conversa
legal@getconversa.ai
