Privacy Policy
Last updated 22 August 2026
Vistrow Voice ("we", "us", "Vistrow") builds AI voice agents that businesses use to answer and place phone calls. This policy explains what we collect, why, and the choices you have - whether you're a business running Vistrow Voice or someone who spoke with an AI agent powered by it.
1. Who this policy covers
If you run a business on Vistrow Voice ("Customer"), this covers your account, workspace, and team data.
If you called, or were called by, a Vistrow Voice-powered AI agent ("Caller"): calls may be recorded for quality, training, and record-keeping purposes, and this section covers that call recording, transcript, and any details the agent captured during that call. Our Customers, not Vistrow Voice, decide when and why to call you - for questions about a specific call, contact that business directly. We act as their data processor for this data, and as a controller only for the platform-level data described below.
2. What we collect
Account data - name, email, phone, password hash (or OAuth identity if you sign in with Google, GitHub, or Slack), workspace/company name, and role.
Call data - audio, live transcripts, call metadata (duration, timestamps, channel), and any structured fields your AI agent is configured to extract (e.g. name, budget, appointment time).
Connected-integration data - if you connect Google Calendar, Slack, WhatsApp, or a CRM webhook, we store the minimum needed to operate that connection (an OAuth token, a webhook URL) and the data your agent sends through it (e.g. a calendar event, a lead notification).
Usage data - pages visited in the dashboard, API requests, and error logs, used to keep the product working and secure.
Payment data - online checkout is not enabled during public testing, so the platform does not collect or store card numbers.
3. How we use Google user data
When you connect Google Calendar, Vistrow Voice requests the calendar.events scope solely to let your AI agent check real appointment availability and create calendar events on your behalf during a call - and for nothing else. We do not read, analyze, or share the content of your calendar beyond what's needed for that booking function.
Vistrow Voice's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You can revoke Vistrow Voice's access to your Google Calendar at any time from the Integrations page in your dashboard, or directly from your Google Account permissions. Revoking access stops future bookings; it does not delete events already created.
4. Why we process this data
- To operate the service - answering calls, running your AI agents, showing your dashboard.
- To improve reliability - debugging, monitoring, and analytics on how the platform is used.
- To communicate - service emails (password resets, invites, billing), and, if you opt in, product updates.
- To comply with law - tax records, responding to lawful requests, and enforcing our Terms.
We do not sell personal data, and we do not use call recordings or transcripts to train third-party AI models beyond what's needed to generate that call's own response.
5. Who we share data with
We share data only with service providers who process it on our behalf, under contract, to run the platform:
- Speech & language models - OpenAI, Google Cloud/Google AI, Sarvam AI, and ElevenLabs, used for conversation intelligence, speech recognition, and voice generation according to the agent configuration.
- Call infrastructure - LiveKit (real-time voice transport) and EnableX (telephony/SIP).
- Hosting & database - Railway (application servers, Postgres database, hosted in the United States) and Vercel (web app).
- Call recording storage - Backblaze B2 (audio recordings, hosted in the United States).
- Email delivery - Resend, to send account and notification emails.
- Integrations you connect - Google Calendar, Slack, WhatsApp providers, or a CRM you configure - only the data needed for that specific integration to work, and only while it's connected.
Each of these processes data under its own privacy commitments; we choose providers that meet industry-standard security practices.
6. Where your data is stored & international transfers
Vistrow Voice is built and operated for Indian businesses, but some of the service providers listed in Section 5 store or process data on servers located in the United States - currently our application database and hosting (Railway) and call recording storage (Backblaze B2). This means account data, call transcripts, and call recordings may be transferred to, and stored in, the United States as part of running the service.
The Digital Personal Data Protection Act, 2023 (DPDP Act) permits this kind of transfer unless the destination country is specifically restricted by the Indian government, which the United States currently is not. We require every processor we use to handle data under a contract committing them to appropriate security and confidentiality obligations, consistent with the protections this policy describes, regardless of where they're located.
We may add or change hosting providers or regions over time; this section will be updated to reflect where data is actually stored, and material changes will be notified per Section 12.
7. Data retention & deletion
Call recordings and transcripts are kept until a Customer configures a retention period in their Compliance settings (default: indefinite, but a Customer can set an automatic purge window in days). Account data is kept for as long as the account is active, plus a reasonable period after closure for legal and accounting purposes.
To request deletion of your data - as a Customer closing your account, or as a Caller asking about a specific call - email vistrowai@gmail.com. We'll act on Customer-account deletion requests within 30 days; Caller requests about a specific business's calls are forwarded to that business, since they control that data.
8. Your rights
Depending on where you're located, you may have the right to access, correct, export, or delete your personal data, and to object to certain processing. Indian residents have these rights under the Digital Personal Data Protection Act, 2023; residents of other regions may have equivalent rights under local law (e.g. GDPR). To exercise any of these, contact us at vistrowai@gmail.com.
9. Cookies & similar technologies
We use a single essential, httpOnly session cookie to keep you signed in - no third-party advertising or tracking cookies. Disabling this cookie will sign you out.
10. Security
Passwords are hashed, not stored in plain text. Session tokens are signed and httpOnly. Data in transit is encrypted (HTTPS/TLS). No system is perfectly secure, but we take reasonable, industry-standard measures to protect your data and will notify affected Customers of any breach as required by law.
11. Children's privacy
Vistrow Voice is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18.
12. Changes to this policy
We'll update the date at the top of this page when we make changes, and for material changes we'll notify active Customers by email.
13. Contact us
Vistrow Voice (operated by Vistrow Technologies). Questions or requests about this policy: vistrowai@gmail.com. See also our Terms of Service.
