Rexa.ai
Rexa.ai

Legal

Voice API Platform — Privacy Policy

DRAFT — v0.1 (P0-M6.9). Compliance Counsel produces the final version before Phase 6.

Effective Date: (to be set at launch)


This Privacy Policy describes how we collect, use, share, and protect personal information in connection with the Voice API Platform ("Service"). It applies to:

  • Visitors to our marketing website
  • Customers (companies using the Service), their authorized users,

and their employees

  • End users of Customer applications, whose personal information

may be processed by the Service while Customer uses it (call participants, dashboard viewers, call recipients)

Customer is the "Controller" of the personal information its Authorized Users and End Users share with the Service. We act as a "Processor" (or equivalent local-law term) of that personal information on Customer's behalf.

1. What we collect

(a) Account information. Name, email, password (hashed), profile picture, organization name, billing address, tax identifiers, and similar business-contact information from Customer sign-up and billing flows.

(b) Authentication information. OAuth identifiers from Google, GitHub, and similar providers when Customer's Authorized Users sign in via those providers. We receive only the scopes we request (typically `email`, `profile`).

(c) Call content (processed on behalf of Customer). Phone numbers dialed, call audio, call recordings (when enabled), call transcriptions, call metadata (duration, direction, status codes), session identifiers, caller IDs, and related telecom records.

(d) Voice-clone data. Audio samples Customer uploads for voice cloning, consent certifications, and the cloned voice model output. Consent records are retained for seven (7) years or the period required by law, whichever is longer.

(e) Usage information. API request logs (method, path, status, request ID, hashed API-key prefix, timestamp), dashboard interaction logs, and telemetry we collect to operate and improve the Service.

(f) Payment information. Billing contact and payment-method metadata received from Stripe. We do NOT store full card numbers or bank-account numbers; those live with Stripe.

(g) Device and browsing information. IP address, browser type, device type, referrer, and similar data collected via server logs and our dashboard's session cookies.

2. How we use it

We use the information described above to:

(a) provide, operate, maintain, and improve the Service; (b) authenticate Authorized Users and protect the Service from abuse; (c) bill Customer and process payments; (d) respond to Customer support requests; (e) comply with our legal obligations, including TCPA, DNC, CCPA, GDPR, and similar laws; (f) detect, prevent, and investigate fraud, security incidents, abuse, or violations of our Acceptable Use policy; (g) send transactional emails (sign-in links, invitations, billing receipts, service announcements); and (h) send marketing emails — only with your opt-in and with an unsubscribe link in every message.

We do not sell personal information. We do not use Customer call content, recordings, transcripts, or voice-clone data to train general-purpose models. See §6.

3. How we share it

We share information with:

(a) Sub-processors. Service providers that help us run the Service. See `sub-processors.md` for the current list. (b) Telecom carriers (only to the extent necessary to route a call Customer initiates or receives). (c) Payment processor (Stripe). (d) Professional advisors (lawyers, accountants, auditors) under appropriate confidentiality obligations. (e) Acquirers in connection with a merger, acquisition, or sale of all or substantially all our assets — subject to appropriate confidentiality. (f) Law enforcement and regulators when required by law, legal process, or to protect rights, property, or safety.

4. Your rights

Depending on where you live, you may have rights including:

  • Access: request a copy of the personal information we hold.
  • Correction: request that we fix inaccurate information.
  • Deletion: request that we delete your information, subject to

our retention obligations under law and our contracts.

  • Portability: receive a machine-readable copy of your information.
  • Objection / restriction: object to or restrict certain

processing activities.

  • Opt-out of sale: we do not sell personal information; the opt-out

is therefore moot, but we honor it as a matter of policy.

  • Withdrawal of consent: where processing is based on consent, you

may withdraw it without affecting the lawfulness of prior processing.

End Users of Customer applications should direct requests to the Customer, which is the Controller. We will assist Customer in responding.

To exercise your rights, contact `privacy@<ourdomain>.com`. We respond within thirty (30) days (or the period required by applicable law, whichever is shorter).

5. Retention

We retain personal information for as long as needed to provide the Service plus a reasonable tail for legal, tax, fraud-prevention, and contract-enforcement purposes.

Default retention windows (overridable per Customer agreement):

| Category | Default retention | | ------------------------- | ------------------------------------------------------------------------------ | | Account information | Life of the account + 7 years | | Call recordings | 90 days (configurable per tenant; 0-day setting available) | | Call transcripts | 90 days | | Call metadata (CDRs) | 2 years | | Voice-clone audio + model | Life of the consent + 1 year, or until the cloned individual withdraws consent | | API request logs | 30 days (reduced to 7 days in P5-M1) | | Billing records | 7 years (tax statute of limitations) |

6. How we use Customer content

We do not:

  • use Customer call content, recordings, transcripts, or voice-clone

data to train general-purpose models;

  • disclose Customer content to anyone other than the sub-processors

and other recipients listed in §3;

  • retain Customer content beyond the windows in §5 except when

required by law.

We do use Customer content, on an aggregated and de-identified basis, to operate the Service, detect abuse, and improve reliability and security.

7. International transfers

The Service is hosted in the United States. If you access it from outside the US, your information will be transferred to and processed in the US. For transfers from the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (SCCs) as updated, together with supplementary measures where appropriate. A copy of the SCCs covering transfers to us is available upon request.

8. Security

We maintain administrative, physical, and technical safeguards designed to protect personal information. These include:

  • encryption in transit (TLS 1.2+) for all public endpoints;
  • encryption at rest for databases, object storage, and backups;
  • role-based access control on internal systems;
  • multi-factor authentication for employee accounts;
  • quarterly access reviews;
  • security training for all employees;
  • a documented incident-response process, including notification

obligations under applicable law.

No method of transmission or storage is 100% secure. In the event of a security incident affecting your personal information we will notify you as required by applicable law.

9. Children

The Service is not directed at children under 16, and we do not knowingly collect personal information from children.

10. Cookies

The dashboard uses cookies for session authentication (NextAuth). The cookie is `HttpOnly`, `SameSite=Lax`, and set to `Secure` in production. We do not use third-party analytics cookies on the dashboard. The marketing site may use a small set of analytics or advertising cookies described in the cookie banner shown on first visit.

11. Changes to this Policy

We may update this Policy from time to time. Material changes will be notified via email to the primary account contact at least thirty (30) days before they take effect.

12. Contact

Questions about this Policy: `privacy@<ourdomain>.com`.

Data protection officer (designated for EEA / UK inquiries): see `privacy@<ourdomain>.com`. A dedicated DPO address goes live before the first EEA design partner signs.

Back to home
© 2026 Rexa.ai · Voice AI platform
© 2026 Rexa.ai · Voice AI platform