Privacy Policy
infinityAI ("we", "us", "our") helps businesses build and deploy AI voice agents. This Privacy Policy explains what we collect, how we use it, and the rights you have over your data when you use our website, dashboard, and services (collectively, the "Service").
1. Information we collect
Account information
When you register, we collect your name, email address, organization name (optional), and password (stored as a one-way hash). If you upgrade to a paid plan, our payment processor (Stripe) collects billing details — we never see or store your card number.
Agent configuration
When you build an agent, we store the configuration you provide: agent name, system prompt, knowledge base content (uploaded documents, pasted text, scraped URLs), voice selection, integration credentials, and routing rules.
Call data
For every call placed or received by your agent, we store: caller phone number (redacted in logs older than 30 days), call timestamps, duration, recording URL (if enabled), transcript, AI-generated summary, sentiment score, and outcome (answered, voicemail, no-answer, etc.).
Usage & technical data
We collect standard web analytics: IP address, browser type, pages visited, referrer URL, and session duration. Cookies and local storage are used to maintain your login session and remember preferences. See our Cookie Policy for details.
2. How we use information
- Operate the Service: authenticate you, run your agents, place calls, deliver integrations.
- Improve quality: monitor errors, optimize performance, build aggregated metrics. We never train AI models on your individual call data without explicit opt-in.
- Billing: calculate minute usage, charge subscriptions, handle refunds via Stripe.
- Notifications: send transactional email (welcome, password reset, low-balance alerts, invoices) and — only if you opted in — product updates.
- Security & fraud prevention: detect abuse, enforce rate limits, investigate suspected unauthorized access.
- Legal compliance: respond to lawful requests, enforce our Terms.
3. When we share data
We share data only with the parties needed to operate the Service:
| Provider | Purpose | Data shared |
|---|---|---|
| Vapi | Voice AI infrastructure (call routing, telephony) | Agent prompt, voice config, caller phone, audio stream |
| OpenAI | Knowledge base optimization | Knowledge base text only |
| Groq | Prompt generation | Plain-English use case description |
| Stripe | Payments, subscriptions, auto-recharge | Email, billing address, payment method (held by Stripe, not us) |
| Twilio | Phone number provisioning (optional) | Number selection, area code |
| Your CRM / booking / email tools | Whatever integrations you enable | Only the fields the agent passes during a call |
We never sell your personal data, voice recordings, transcripts, or contacts to advertisers or third parties.
4. Voice & call data
Voice agents process audio in real-time. By default, we store recordings and transcripts in your account so you can review past calls.
- Recordings: stored encrypted at rest. You can disable recording per-agent in your dashboard.
- Transcripts: generated automatically. Used to populate the Inbox, Contacts, and Analytics views you see in the app.
- Caller consent: You are responsible for obtaining caller consent to record and process voice data where required by law (TCPA in the US, GDPR in the EU, CCPA in California, and similar regimes).
- Deletion: Delete a call from the dashboard and the recording + transcript are purged within 7 days.
5. Data retention
We retain account and configuration data while your account is active. After you delete your account, we erase your personal data within 30 days, except where retention is required for legal, tax, or fraud-prevention purposes (typically up to 7 years for billing records).
Aggregated, de-identified metrics may be retained indefinitely for capacity planning and product analytics.
6. Security
We use industry-standard safeguards: TLS 1.2+ for all traffic, AES-256 encryption for data at rest, encrypted credential storage for integration API keys, hashed passwords (bcrypt), and isolated production environments. Access to production systems is limited to engineers who need it and is logged.
No system is perfectly secure. If we discover a breach affecting your data, we will notify you within 72 hours of confirmation as required by applicable law.
7. Your rights
Depending on where you live, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data via your dashboard or by contacting us
- Delete your account and associated data
- Export your data in a machine-readable format (CSV)
- Object to processing for marketing purposes (we don't do this without opt-in)
- Withdraw consent for any processing based on consent
To exercise any of these rights, email [email protected]. We respond within 30 days.
8. International transfers
infinityAI operates from the United States. If you access the Service from the EU, UK, or other regions, your data will be transferred to and processed in the US. We rely on Standard Contractual Clauses and equivalent safeguards for cross-border transfers.
9. Children's privacy
The Service is not intended for anyone under 16. We do not knowingly collect personal data from children. If you believe we have, contact us and we will delete it.
10. Changes to this policy
We may update this policy as the Service evolves. Material changes will be announced by email and via a banner in your dashboard at least 14 days before they take effect. Your continued use of the Service after the effective date constitutes acceptance.
11. Contact us
Questions or requests about this policy:
infinityAI — Privacy Team
[email protected]