Privacy Policy
The short version: we keep what we need to connect your call and bill you for it, we record audio only if you switch recording on, and we never sell anything about you.
1. The distinction that matters
There are two very different kinds of information here and we treat them differently.
- Call metadata is the record that a call happened: the number dialled, when, for how long, what it cost, whether it connected. We keep this for every call, because we cannot bill you or investigate a fault without it.
- Call content is what was actually said. We do not record or listen to your calls unless you switch recording on.
2. What we collect
Account information. Your email address. There are no passwords here: you sign in with Google, or with a link sent to your email. If you sign in with Google we receive your name, email address and profile picture, and nothing else. If we need to verify you, the information you give us for that.
Payment information. Handled by our payment processor. We receive a confirmation, the amount, and the last four digits and brand of the card. We never see or store your full card number.
Call metadata. For every call: the number dialled, the country and band it resolved to, start and end time, duration, price, which carrier carried it, and whether it connected, reached voicemail or a menu. We also record the keypad tones you send during a call, which is how we learn which menu path reaches a human at a given organisation.
Recordings and transcripts, only if you turn recording on. Where you enable it, the audio is transcribed and summarised, and the audio file is then deleted. The transcript and summary stay on your account until you delete them.
Technical information. IP address, browser and device type, and connection quality measurements from your calls. We use these to route calls, to diagnose bad audio, and to detect fraud.
3. Why we collect it, and our legal basis
- To connect your calls and bill you. Necessary to perform our contract with you.
- To prevent fraud and protect the network. Our legitimate interest, and in places a legal obligation. Toll fraud on a prepaid calling service is common and expensive, and it is checked against exactly this data.
- To keep required records. Tax, accounting and telecommunications rules require us to retain certain call and payment records.
- To improve reliability and coverage. Our legitimate interest. Aggregated, de-identified outcome data tells us which routes are dropping calls and which numbers reach a person.
- To record and transcribe calls. Only on your consent, given by switching recording on, and withdrawable at any time.
4. Recording is your responsibility too
Whether a call may lawfully be recorded depends on where you are and where the other person is. Some places require every party to agree. Recording is off by default, and if you turn it on it is on you to have whatever consent the law requires. Tell the other person.
5. Who we share it with
We do not sell your personal information, and we do not share it for advertising. We share only what is needed, with:
- Telnyx and Twilio, our telecommunications carriers. Whichever one carries a given call receives the number you are calling and the call audio, because a call cannot be connected without a carrier. We choose between them per call on measured line quality.
- Stripe, for payments and refunds. Your card details go to Stripe directly and we never see or store them.
- Supabase, which holds your account, your balance and your call records.
- Railway, which runs the application itself.
- Sentry, for error monitoring. Phone numbers are stripped out before anything is sent, including from URLs and request bodies.
- PostHog, for product analytics. It receives the country you called and what it cost, never the number itself and never anything said on the call.
- Telegram, which delivers feedback you send us. It receives your message, the email address you give us for a reply, and the page you were on. Never the number you were calling.
- DeepInfra, which would transcribe call recordings. Recording is switched off across the service and cannot currently be turned on, so nothing is sent to them today. If that changes it will be opt-in, per the section above.
- Authorities, where we are legally required to. We resist requests that are overbroad and, where we are allowed to, we tell you.
Every provider above processes data on our instructions and under contract.
Processor locations to be confirmed once the operating entity is registered.
6. How long we keep it
- Call metadata and billing records: for as long as tax and telecoms record-keeping rules require, then deleted.
- Recording audio: deleted once transcribed.
- Transcripts and summaries: until you delete them or close your account.
- Account data: deleted on request, except records we must keep by law.
Specific retention periods to be inserted once the operating jurisdiction is fixed.
7. Your rights
Depending on where you live, you can ask us for a copy of your data, to correct it, to delete it, to restrict or object to how we use it, and to receive it in a portable form. You can withdraw consent to recording at any time without affecting recordings already made. You can complain to your local data protection authority.
Ask at [email protected]. We reply within 30 days.
8. Security
Call audio is encrypted in transit. Access to call records is limited to the people who need it to run the service and is logged. No system is perfectly secure, and we will tell you and the relevant regulator if a breach affects you.
9. International transfers
Connecting an international call necessarily involves sending the number you dialled to carriers in other countries. Our own infrastructure may also process data outside your country. Transfer mechanism and safeguards to be inserted.
10. Children
Airlophone is not for under 18s and we do not knowingly collect their information. Tell us if you think we have.
11. Changes
We will post any update here and, where a change materially affects you, tell you before it takes effect.