Trust

Security & Trust

Every call your AI agent answers touches your business data and your callers' data. Here's exactly how it's handled.

TLS
Encryption in transit
AES-256
Encryption at rest
Row-level security
Tenant isolation
Never
Data sold to advertisers

Encryption

All traffic between your browser, our servers, and every sub-processor below is encrypted in transit with TLS. Data at rest — business records, call transcripts, account details — is encrypted with AES-256 via Supabase, our database provider.

How your data is isolated from other businesses

Every table that holds business data has row-level security policies enforced by the database itself, not just application code — a business's row can only be read by that business's own authenticated session, regardless of which page or API route is asking. We don't just assume this works: we test it directly against the live database — generating a real session for one business and confirming it genuinely cannot read another business's records — rather than trusting the policy configuration alone.

Who we share data with, and why

To actually answer calls, book appointments, and process payments, we share data with the sub-processors below — never more than the feature requires. We may add more as we add features; when we do, we update this table and the Privacy Policy before that sub-processor starts processing your data.

ProviderPurposeData shared
ElevenLabsAI voice synthesis and conversational AICall audio (streamed in real time), agent configuration, knowledge base content, conversation transcripts
OpenAILanguage model behind your agent's spoken responses, accessed via ElevenLabsConversation content exchanged during the call, your agent's configured instructions
TwilioPhone number provisioning, call routing, and SMSCaller phone numbers, call metadata, SMS message content
RailwayHosts the real-time audio relay between a call and ElevenLabsCall audio, streamed in real time and not stored by this service
GoogleCalendar integration (opt-in)OAuth tokens, calendar availability — never the content of your other existing events
StripePayment processingBilling details, subscription plan — we never see or store raw card numbers
SupabaseDatabase and authenticationAll structured application data
ResendTransactional and notification email deliveryRecipient email address, email content
VercelHosts our web application and APIServer logs, IP addresses, and application data in transit

Full detail on what’s collected and why lives in the Privacy Policy.

Call recording

Your AI agent may record and transcribe calls. Every agent automatically opens each call with a spoken disclosure that it's an AI assistant and that the call may be recorded — this is built into the Service itself and can't be turned off or overridden by your agent's greeting or instructions. Depending on your state or country, you may still be legally required to obtain additional consent beyond this baseline notice — that responsibility is yours, not ours, and we say so plainly rather than burying it.

How long we keep data

  • Call transcripts and summaries — 12 months from the call date, then deleted.
  • Account data — for the life of your subscription plus 60 days, in case you reactivate.
  • Google Calendar tokens — deleted immediately when you disconnect the integration.
  • Billing records — 7 years, as required by financial regulations.
  • Call audio — retained by our AI voice sub-processor under its own retention settings, currently indefinite rather than on a fixed schedule; we're evaluating tightening this to match our 12-month transcript retention.

Full detail, including the public demo widget, lives in the Privacy Policy.

Where we are on formal certification

We don't hold SOC 2 or ISO 27001 certification today, and we'd rather tell you that directly than stay quiet about it. What we do have: encryption in transit and at rest, database-enforced tenant isolation that we test empirically rather than assume, signed webhook verification on every inbound integration, and HTTP security headers (CSP, HSTS, and related) on every page we serve. If a formal certification is a requirement for your business, reach out — we'd rather have that conversation than let a vague claim stand in for it.

Found a security issue?

If you believe you've found a security vulnerability in Voicesse, email security@voicesse.io directly rather than filing a public issue. We'll acknowledge all reports and won't pursue action against good-faith security research.