Privacy Policy
Last updated 2026-07-14. This page is written to reflect the system's actual current behavior — not aspirations.
This policy is short because the honest answer is short: we hold the minimum needed to run your voice agent, we fence it per tenant at the database layer, we scrub it from logs, and we hard-delete it when you leave. Here is exactly what that means.
01Scope, and the two hats we wear
For your account data (login identity, workspace settings, billing status), we are the data controller. For the data you load into the Service about your leads and customers — names, phone numbers, stated problems, appointments, call outcomes — we are your processor: we handle it only on your instructions, to operate the Service for you. Your leads should look to your privacy notice for how your business uses their information; this page explains what our platform does underneath.
02What we collect
- Account data — your email and authentication identity via Firebase Authentication; workspace settings; admin roles (MFA-gated).
- Lead data you submit — names, phone numbers, and stated pain points from your forms and campaigns, plus appointment records.
- Call data — call metadata and transcripts of AI calls; recordings only where you have enabled them (off by default).
- Billing signals — plan, payment status, and Stripe references. Never card numbers (see Section 3).
- Operational logs — security and reliability logs that are redacted before they leave the process: emails, phone numbers, card-number patterns, and credentials are scrubbed automatically.
03What we deliberately never hold
- Payment card numbers. Stripe Elements tokenizes card data inside Stripe's own iframes in your browser; raw card numbers never reach our frontend state, our backend, or our logs.
- Voice-collected health information. Our agents are instructed to refuse it, and collecting it by voice is prohibited by our Terms.
- Advertising profiles. We do not sell personal information, we do not share it for cross-context behavioral advertising, and we run no ad trackers on the product.
04How we use data
To place and answer calls, book appointments, show you transcripts and intent signals, bill you, send transactional and lifecycle email, keep the Service secure (including forensic records of attempted cross-tenant access), and comply with law. Alert emails to administrators are built zero-PII by design: they carry an opaque incident token and a dashboard link, never names, numbers, or tracebacks.
05Subprocessors — the exact list
We use a small, named set of providers, each for one job:
- Vapi — voice call orchestration, configured for zero data retention on the AI processing path.
- Google Cloud — hosting, PostgreSQL database, object storage, and logging (logs pre-redacted as above).
- Firebase Authentication — sign-in identity and session security.
- Stripe — payments and card tokenization.
- Resend — transactional and lifecycle email delivery.
We will update this list before adding a provider that touches personal data.
06How your data is protected
- Per-tenant row-level security enforced by the database engine (FORCE RLS with write-side checks) — isolation is a property of the schema, not a promise in application code.
- Encryption: AES-256 at rest, TLS 1.3 in transit.
- Outbound call metadata carries an HMAC tenant signature so a shared webhook secret alone cannot impersonate a workspace.
- An outbound response filter wipes any payload that crosses tenant boundaries, terminates the session, and writes an immutable forensic record.
- Administrative access requires multi-factor authentication.
- PII is scrubbed from application logs before they leave the process.
07Call recording
Recording is off by default. Where a customer enables it, calls disclose it, and the customer remains responsible for recording-consent law in every jurisdiction they call — including all-party-consent states such as Florida. Transcripts used for your dashboard are processed under the zero-retention configuration described above.
08Retention and deletion
We keep your data while your account is open. Closing your account triggers a cascading hard delete across every tenant table and stored asset, completing within 30 days. Encrypted backups age out automatically on the snapshot retention schedule. Forensic security records of attempted abuse may be retained where the law allows, because they document conduct — not your business data.
09Your rights
Depending on where you live — including under the GDPR, the CCPA/CPRA, and the Florida Digital Bill of Rights — you may have the right to access, correct, delete, or export personal information, and to not be discriminated against for exercising those rights. Write to legal@growthagentsystem.com and we will respond within the legally required window. If you are a lead who received a call from a business using our platform, we will route your request to that business and assist them in honoring it.
10Children, changes, and contact
The Service is for businesses and is not directed to anyone under 18; we do not knowingly collect children's data. We will post changes to this policy here and announce material changes; the "last updated" date always tells you the current version. Questions, requests, or concerns: legal@growthagentsystem.com.