Legal
Privacy Policy
Last Updated: May 26, 2026
1. Introduction
This Privacy Policy describes how zoxaAI ("zoxa", "we", "us", "our") collects, uses, stores, and shares your personal information when you use our voice AI platform, including our website, APIs, embedded widgets, and related services (collectively, the "Service"). By using the Service, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Email address — used for authentication and account identification
- Name — used for display and identification
- Password — stored in encrypted form; we never store your raw password
- Organization membership — which organization(s) your account belongs to
2.2 Call & Conversation Data
When you or your end-users make voice calls through the Service, we collect:
- Phone numbers — caller and destination numbers
- Call audio — bidirectional audio streamed during the call
- Call recordings — stored securely when recording is enabled
- Transcripts — full text transcription of the conversation
- Call metadata — duration, timestamps, status, and end reason
- AI-generated summaries — when summarization is enabled
- Context variables — any custom data you pass into the call (e.g., customer name, account ID)
- Usage and cost information — call usage metrics and per-call cost breakdown
2.3 Campaign Contact Data
When you run outbound call campaigns, we collect contact information from your uploaded files, which may include:
- Phone numbers and names
- Any additional fields you include (e.g., account IDs, plan types, custom data)
This data is stored both as the original uploaded file and as structured records in our database.
2.4 Knowledge Base Documents
When you upload documents for AI knowledge retrieval, we collect:
- Original documents — stored securely in our cloud storage
- Document metadata — filename, file size, and processing status
- Extracted text — document content processed for AI-powered search and retrieval
2.5 API Keys
When you generate API keys, we store an encrypted version of the key. The raw key is only shown once at creation and is never stored or retrievable afterwards. We also store creation timestamps and the identity of the user who created the key.
2.6 Embedded Widget Visitor Data
When end-users interact with voice widgets embedded on third-party websites, we collect:
- IP address and browser information
- Origin domain of the website hosting the widget
- A temporary session identifier that expires after 1 hour
2.7 Integration Credentials
When you configure telephony or webhook integrations, we securely store the provider credentials and authentication details you provide in order to operate the Service on your behalf.
2.8 Usage & Analytics Data
We may collect product usage data including:
- Page views and navigation patterns
- Feature usage events (e.g., workflow created, call started)
- Error reports for service improvement
3. How We Use Your Information
We use the information we collect to:
- Provide and operate the Service — process voice calls, run AI agent pipelines, manage telephony connections
- Authenticate and secure your account — verify identity, manage sessions, enforce access controls
- Process and store call data — record, transcribe, and analyze conversations as configured by you
- Execute campaigns — dial contacts and personalize agent conversations with your provided data
- Enable knowledge retrieval — index uploaded documents for AI-powered search
- Deliver webhooks — send call lifecycle events to your configured endpoints
- Monitor and improve the Service — track errors, measure performance, analyze usage patterns
- Bill and track usage — calculate costs across AI and telephony services
4. How We Share Your Information
4.1 AI Service Providers
During live calls, audio and text data is transmitted to third-party AI providers for real-time processing:
| Service Type | Providers | Data Shared |
|---|---|---|
| Speech-to-Text | Deepgram, OpenAI, Cartesia, Sarvam, Speechmatics, AssemblyAI, Gladia, ElevenLabs | Call audio |
| Language Models | OpenAI, Google Gemini, Groq, Anthropic, AWS Bedrock, Azure, xAI | Conversation text and context |
| Text-to-Speech | ElevenLabs, Deepgram, OpenAI, Cartesia, Sarvam, Camb.ai, Rime | Generated response text |
| Embeddings | OpenAI | Knowledge base document text |
The specific providers used depend on your agent configuration.
4.2 Telephony Providers
Call audio and metadata are shared with the telephony provider you configure, which may include Twilio, Vonage, Telnyx, Vobiz, Cloudonix, or Plivo. Self-hosted options (e.g., Asterisk) keep all audio on your own infrastructure.
4.3 Analytics Services
We use third-party analytics and error-tracking services to monitor and improve the Service. These may receive anonymized usage data, error reports, and performance metrics. You may opt out of analytics through your account settings or by contacting us.
4.4 Webhook Delivery to Your Endpoints
When you configure webhooks on your agents, we send call event data (such as call started, ended, and completed events including call details, transcript, and summary) to your specified endpoint. All webhook deliveries are cryptographically signed for integrity verification.
5. Data Storage & Security
5.1 Where Your Data Is Stored
Your data is stored across the following systems:
- User accounts, call records, transcripts, and metadata are stored in our database
- Audio recordings, documents, and campaign files are stored in secure cloud storage
- Temporary session data is stored in-memory and automatically purged
5.2 Security Measures
We implement the following security measures to protect your data:
- Password protection — passwords are encrypted and never stored in plain text
- API key security — keys are encrypted at rest; raw keys are never stored after initial generation
- Secure sessions — authentication tokens are cryptographically signed with configurable expiry
- Webhook integrity — all webhook deliveries are digitally signed
- Transport encryption — all data in transit is protected via HTTPS/TLS
- Multi-tenant isolation — all data access is scoped to your organization
5.3 Cookies
We use essential cookies for authentication and maintaining your session. These cookies are secure, not accessible to client-side scripts, and expire after 30 days.
6. Data Retention
- Embedded widget sessions expire automatically after 1 hour.
- Temporary credentials expire after 24 hours.
- Application logs are retained for 7 days.
- Call recordings, transcripts, user data, and other persistent data are retained indefinitely unless you request deletion.
7. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access — Request a copy of the personal data we hold about you.
- Correction — Request correction of inaccurate personal data.
- Deletion — Request deletion of your personal data.
- Data portability — Request a machine-readable copy of your data.
- Objection — Object to processing of your personal data.
- Restriction — Request restriction of processing.
To exercise any of these rights, please contact us using the information provided in Section 9.
8. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on our website and updating the "Last Updated" date at the top. Your continued use of the Service after any changes constitutes your acceptance of the revised policy.
9. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us:
- Email: [email protected]