Skip to main content

Legal

Privacy Policy

Last Updated: May 26, 2026

1. Introduction

This Privacy Policy describes how zoxaAI ("zoxa", "we", "us", "our") collects, uses, stores, and shares your personal information when you use our voice AI platform, including our website, APIs, embedded widgets, and related services (collectively, the "Service"). By using the Service, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

2.1 Account Information

When you create an account, we collect:

  • Email address — used for authentication and account identification
  • Name — used for display and identification
  • Password — stored in encrypted form; we never store your raw password
  • Organization membership — which organization(s) your account belongs to

2.2 Call & Conversation Data

When you or your end-users make voice calls through the Service, we collect:

  • Phone numbers — caller and destination numbers
  • Call audio — bidirectional audio streamed during the call
  • Call recordings — stored securely when recording is enabled
  • Transcripts — full text transcription of the conversation
  • Call metadata — duration, timestamps, status, and end reason
  • AI-generated summaries — when summarization is enabled
  • Context variables — any custom data you pass into the call (e.g., customer name, account ID)
  • Usage and cost information — call usage metrics and per-call cost breakdown

2.3 Campaign Contact Data

When you run outbound call campaigns, we collect contact information from your uploaded files, which may include:

  • Phone numbers and names
  • Any additional fields you include (e.g., account IDs, plan types, custom data)

This data is stored both as the original uploaded file and as structured records in our database.

2.4 Knowledge Base Documents

When you upload documents for AI knowledge retrieval, we collect:

  • Original documents — stored securely in our cloud storage
  • Document metadata — filename, file size, and processing status
  • Extracted text — document content processed for AI-powered search and retrieval

2.5 API Keys

When you generate API keys, we store an encrypted version of the key. The raw key is only shown once at creation and is never stored or retrievable afterwards. We also store creation timestamps and the identity of the user who created the key.

2.6 Embedded Widget Visitor Data

When end-users interact with voice widgets embedded on third-party websites, we collect:

  • IP address and browser information
  • Origin domain of the website hosting the widget
  • A temporary session identifier that expires after 1 hour

2.7 Integration Credentials

When you configure telephony or webhook integrations, we securely store the provider credentials and authentication details you provide in order to operate the Service on your behalf.

2.8 Usage & Analytics Data

We may collect product usage data including:

  • Page views and navigation patterns
  • Feature usage events (e.g., workflow created, call started)
  • Error reports for service improvement

3. How We Use Your Information

We use the information we collect to:

  • Provide and operate the Service — process voice calls, run AI agent pipelines, manage telephony connections
  • Authenticate and secure your account — verify identity, manage sessions, enforce access controls
  • Process and store call data — record, transcribe, and analyze conversations as configured by you
  • Execute campaigns — dial contacts and personalize agent conversations with your provided data
  • Enable knowledge retrieval — index uploaded documents for AI-powered search
  • Deliver webhooks — send call lifecycle events to your configured endpoints
  • Monitor and improve the Service — track errors, measure performance, analyze usage patterns
  • Bill and track usage — calculate costs across AI and telephony services

4. How We Share Your Information

4.1 AI Service Providers

During live calls, audio and text data is transmitted to third-party AI providers for real-time processing:

Service Type Providers Data Shared
Speech-to-Text Deepgram, OpenAI, Cartesia, Sarvam, Speechmatics, AssemblyAI, Gladia, ElevenLabs Call audio
Language Models OpenAI, Google Gemini, Groq, Anthropic, AWS Bedrock, Azure, xAI Conversation text and context
Text-to-Speech ElevenLabs, Deepgram, OpenAI, Cartesia, Sarvam, Camb.ai, Rime Generated response text
Embeddings OpenAI Knowledge base document text

The specific providers used depend on your agent configuration.

4.2 Telephony Providers

Call audio and metadata are shared with the telephony provider you configure, which may include Twilio, Vonage, Telnyx, Vobiz, Cloudonix, or Plivo. Self-hosted options (e.g., Asterisk) keep all audio on your own infrastructure.

4.3 Analytics Services

We use third-party analytics and error-tracking services to monitor and improve the Service. These may receive anonymized usage data, error reports, and performance metrics. You may opt out of analytics through your account settings or by contacting us.

4.4 Webhook Delivery to Your Endpoints

When you configure webhooks on your agents, we send call event data (such as call started, ended, and completed events including call details, transcript, and summary) to your specified endpoint. All webhook deliveries are cryptographically signed for integrity verification.

5. Data Storage & Security

5.1 Where Your Data Is Stored

Your data is stored across the following systems:

  • User accounts, call records, transcripts, and metadata are stored in our database
  • Audio recordings, documents, and campaign files are stored in secure cloud storage
  • Temporary session data is stored in-memory and automatically purged

5.2 Security Measures

We implement the following security measures to protect your data:

  • Password protection — passwords are encrypted and never stored in plain text
  • API key security — keys are encrypted at rest; raw keys are never stored after initial generation
  • Secure sessions — authentication tokens are cryptographically signed with configurable expiry
  • Webhook integrity — all webhook deliveries are digitally signed
  • Transport encryption — all data in transit is protected via HTTPS/TLS
  • Multi-tenant isolation — all data access is scoped to your organization

5.3 Cookies

We use essential cookies for authentication and maintaining your session. These cookies are secure, not accessible to client-side scripts, and expire after 30 days.

6. Data Retention

  • Embedded widget sessions expire automatically after 1 hour.
  • Temporary credentials expire after 24 hours.
  • Application logs are retained for 7 days.
  • Call recordings, transcripts, user data, and other persistent data are retained indefinitely unless you request deletion.

7. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access — Request a copy of the personal data we hold about you.
  • Correction — Request correction of inaccurate personal data.
  • Deletion — Request deletion of your personal data.
  • Data portability — Request a machine-readable copy of your data.
  • Objection — Object to processing of your personal data.
  • Restriction — Request restriction of processing.

To exercise any of these rights, please contact us using the information provided in Section 9.

8. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on our website and updating the "Last Updated" date at the top. Your continued use of the Service after any changes constitutes your acceptance of the revised policy.

9. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us: