Trust
Every call your AI agent answers touches your business data and your callers' data. Here's exactly how it's handled.
All traffic between your browser, our servers, and every sub-processor below is encrypted in transit with TLS. Data at rest — business records, call transcripts, account details — is encrypted with AES-256 via Supabase, our database provider.
Every table that holds business data has row-level security policies enforced by the database itself, not just application code — a business's row can only be read by that business's own authenticated session, regardless of which page or API route is asking. We don't just assume this works: we test it directly against the live database — generating a real session for one business and confirming it genuinely cannot read another business's records — rather than trusting the policy configuration alone.
To actually answer calls, book appointments, and process payments, we share data with the sub-processors below — never more than the feature requires. We may add more as we add features; when we do, we update this table and the Privacy Policy before that sub-processor starts processing your data.
| Provider | Purpose | Data shared |
|---|---|---|
| ElevenLabs | AI voice synthesis and conversational AI | Call audio (streamed in real time), agent configuration, knowledge base content, conversation transcripts |
| OpenAI | Language model behind your agent's spoken responses, accessed via ElevenLabs | Conversation content exchanged during the call, your agent's configured instructions |
| Twilio | Phone number provisioning, call routing, and SMS | Caller phone numbers, call metadata, SMS message content |
| Railway | Hosts the real-time audio relay between a call and ElevenLabs | Call audio, streamed in real time and not stored by this service |
| Calendar integration (opt-in) | OAuth tokens, calendar availability — never the content of your other existing events | |
| Stripe | Payment processing | Billing details, subscription plan — we never see or store raw card numbers |
| Supabase | Database and authentication | All structured application data |
| Resend | Transactional and notification email delivery | Recipient email address, email content |
| Vercel | Hosts our web application and API | Server logs, IP addresses, and application data in transit |
Full detail on what’s collected and why lives in the Privacy Policy.
Your AI agent may record and transcribe calls. Every agent automatically opens each call with a spoken disclosure that it's an AI assistant and that the call may be recorded — this is built into the Service itself and can't be turned off or overridden by your agent's greeting or instructions. Depending on your state or country, you may still be legally required to obtain additional consent beyond this baseline notice — that responsibility is yours, not ours, and we say so plainly rather than burying it.
Full detail, including the public demo widget, lives in the Privacy Policy.
We don't hold SOC 2 or ISO 27001 certification today, and we'd rather tell you that directly than stay quiet about it. What we do have: encryption in transit and at rest, database-enforced tenant isolation that we test empirically rather than assume, signed webhook verification on every inbound integration, and HTTP security headers (CSP, HSTS, and related) on every page we serve. If a formal certification is a requirement for your business, reach out — we'd rather have that conversation than let a vague claim stand in for it.
If you believe you've found a security vulnerability in Voicesse, email security@voicesse.io directly rather than filing a public issue. We'll acknowledge all reports and won't pursue action against good-faith security research.