LEGAL
Privacy Policy
Effective date: August 26, 2026
This policy explains what information Vocarium handles, why we handle it, who we share it with, and what you can do about it. It covers two different groups of people: the businesses that use Vocarium, and the people who speak with the AI phone agents those businesses run.
1. Who we are
Vocarium is operated by Elabry Inc., a corporation organised under the laws of the State of Delaware, United States, doing business as Vocarium. In this policy, “Vocarium”, “we”, “us” and “our” mean Elabry Inc.
You can reach us about anything in this policy at contact@vocarium.co.
This policy applies to the Vocarium website, the dashboard, the API, and the phone calls handled by agents built on the platform. It works alongside our Terms of Use.
2. Who this policy is about
Vocarium sits between two groups of people, and we handle their information differently.
Business customers. These are the companies and individuals who open a Vocarium account, configure AI phone agents, and pay for the service. We decide how their account, billing and usage information is handled, so for that information we are the responsible party.
Callers. These are the people who call, or are called by, an AI agent that a business customer has configured. We handle caller information on behalf of that business customer. The business decides why the call happens, what the agent asks, and what is done with the result. We process that information according to the business’s instructions and in order to run the service.
If you spoke with an AI agent and want to know why you were called or what was kept, contacting the business you were dealing with is usually the fastest route. If you cannot identify or reach them, write to us and we will help.
3. Information we collect from business customers
Account information
Your name, email address, and a cryptographic hash of your password. We never store passwords in a readable form and cannot recover them. If you sign in with a third-party identity provider, we receive the basic profile information that provider releases to us.
Business profiles
The details you enter about your business or businesses: company name, industry, hours, services, locations and similar operational facts. Agents use this to answer callers accurately.
Billing information
Payments are processed by Stripe. Card numbers are entered directly with Stripe and are held by Stripe; Vocarium never receives or stores full card numbers. What we hold is the record of what happened: the amounts you added to your balance, your current balance, payment status, and a reference that lets us match a payment to your account.
Usage records
A ledger of what the account consumed: call minutes, phone numbers rented, messages sent, and AI usage, with the charge applied to each. This is how billing is calculated and how the usage reporting in your dashboard is produced.
Knowledge base content
Documents you upload or write so that your agents know how to answer questions, along with content gathered from a company website when you ask the platform to research one. This is your material and you control it.
Integration credentials
Tokens, keys and secrets for the calendars, email accounts, automation platforms and endpoints you connect. These are stored encrypted and are used only to operate the connection you set up.
Technical information
Basic information generated when you use the dashboard or API, such as IP address, browser type, timestamps, and error and performance logs. We use it to keep the service running, to investigate faults, and to detect abuse.
4. Information we handle about callers
When an AI agent takes or places a call, the platform handles the following on behalf of the business customer whose agent it is:
- the caller’s phone number, the number dialled, and the time and duration of the call;
- the audio of the call. Calls may be recorded, depending on how the business has configured its agent;
- a text transcript produced from that audio, which contains whatever was said on the call;
- the outcome of the call, such as an appointment booked, a message sent, or a request passed to the business.
Because a transcript records a real conversation, it can contain any personal information a caller chooses to share, including names, addresses, contact details and the reason for the call.
Returning callers
So that an agent can recognise someone who has called before, the platform can keep a short record about a caller against their phone number: their name, any preferences they expressed, and a summary of what they asked about or arranged previously. The purpose is to make the next call better, so a returning caller does not have to start over.
This record is held separately for each business customer. It is never shared between businesses, and one business’s agents cannot see what a caller said to another business’s agents.
5. Calls are handled by AI
We want to be plain about this. Calls on the Vocarium platform are answered and conducted by artificial intelligence, not by a person. During a call, the audio is streamed to a speech recognition service that converts it to text, that text is sent to a language model that decides what to say next, and the reply is turned back into speech by a voice synthesis service.
This processing is how the service works; there is no version of it that does not send call audio and text to those providers. The providers we use are named in section 8.
Where the law requires a caller to be told they are speaking with an automated system, it is the business operating the agent that is responsible for making that disclosure. The platform provides the means to do so.
6. Caller verification codes
A business customer can turn on caller verification for sensitive requests. When it is enabled and a caller provides an email address, the platform sends a one-time numeric code to that address, and the caller reads the code back to the agent to confirm their identity.
These codes are short-lived and expire quickly. We do not store the code itself: we store only a salted hash of it, which is enough to check a code the caller reads back but cannot be reversed to recover the code. The email address is used to deliver the code and to identify the caller for the business.
7. How we use information
We use the information described above to:
- operate the service, connect calls, and keep agents attached to phone numbers;
- understand what a caller said and generate the agent’s reply using the relevant business’s knowledge base;
- carry out the in-call actions a business has configured, such as checking availability, booking an appointment, sending an email or message, or calling the business’s own systems;
- recognise returning callers and give them continuity from one call to the next, on behalf of the business they are calling;
- measure usage, draw it down against the prepaid balance, and produce billing records;
- show call history, transcripts, recordings and reporting in the dashboard;
- provide support and respond to messages you send us;
- detect, investigate and prevent fraud, abuse and misuse of the platform;
- keep the service reliable, secure and fast;
- meet our legal, accounting and tax obligations.
We do not sell personal information, and we do not share it with advertising networks or use it to build marketing profiles.
8. Service providers we rely on
Running a phone agent takes specialised infrastructure, so parts of the service are delivered by other companies acting on our instructions. Each is bound by a contract that limits it to processing data for the purpose of delivering the service to us. The providers we currently use are:
- Telnyx — telephony and carrier services. Telnyx carries the calls and provides the phone numbers, so it handles call audio and phone numbers.
- Deepgram — speech-to-text. Deepgram receives call audio and returns the transcript.
- Anthropic — language model. Anthropic receives the conversation text and the relevant knowledge base content, and generates the agent’s replies.
- Cartesia — speech synthesis. Cartesia turns the agent’s reply text into the voice the caller hears.
- Stripe — payment processing. Stripe handles card details and processes payments for balance top-ups.
- Microsoft Azure — database hosting. Account, call and configuration data is stored in Azure.
- Zoom Video Communications, Inc. — video meetings, used only where a business customer connects their own Zoom account so their agent can book meetings. For those customers we store the connection’s OAuth tokens, encrypted, together with the basic profile details Zoom returns — name, email address and default time zone — and we create, change and cancel meetings on that account on the customer’s behalf. Disconnecting the integration revokes the tokens with Zoom and deletes them.
Email sent by the platform, including verification codes and agent-sent messages, may be delivered through a business customer’s own email provider when that customer connects one. In that case the message passes through the provider the customer chose, on the customer’s account.
We may add or replace providers as the platform develops. A replacement is held to the same contractual standard before customer or caller data reaches it, and this section is updated when the list changes.
Separately from these providers, we may disclose information where we are legally required to, where it is necessary to enforce our Terms of Use or protect the rights and safety of people or the platform, or to a successor entity in a merger, acquisition or sale of assets.
9. Google Calendar data and Google API Limited Use
A business customer can connect their own Google Calendar so that an agent can check when the business is free and put a booking in the diary. Where that connection exists, we receive information from Google APIs, and how we may use it is limited.
Vocarium’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
What we read, and what we do not
The platform accesses only what booking requires:
- the list of calendars on the connected account, so the customer can choose which one their agent books into and so we can read that calendar’s time zone;
- free/busy time blocks on the chosen calendar — when it is occupied and when it is open, not what the occupied time is for;
- the events the platform itself creates, so it can change or cancel them later.
We do not read event titles, descriptions, attendees, or events created by other applications.
How the data is used
Google user data is never used to develop, improve or train generalised artificial intelligence or machine learning models. The AI agent never receives raw calendar contents: it is given a derived summary of availability — the open slots it may offer a caller — and nothing else.
We do not sell Google user data, and we do not transfer it to third parties except as needed to provide the calendar feature itself, for security purposes, or to comply with applicable law. Disconnecting the integration in the dashboard revokes and deletes the stored tokens.
10. How long we keep information
We keep information for as long as it is needed to provide the service, and for as long afterwards as the law requires us to. In practice that means:
- account and business profile information is kept while the account is open, and removed after it closes except where we are required to keep it;
- call recordings, transcripts, call history and returning-caller records are kept while they are useful to the business customer, and are deleted when that customer deletes them or closes the account;
- knowledge base documents and integration credentials are kept until you remove them or close the account;
- billing and usage records are kept for as long as accounting and tax law requires, which is typically several years, even after an account closes;
- verification codes expire within minutes and the stored hash is discarded shortly afterwards;
- security and error logs are kept for a limited period appropriate to investigating incidents.
Business customers control their agents’ data. You can delete call records and knowledge documents from the dashboard, and you can request deletion of anything else by writing to contact@vocarium.co. Deletion takes effect in our active systems promptly, and routine backups take a further short period to cycle out.
11. Security
Data is encrypted in transit. Integration credentials and other secrets are encrypted at rest. Passwords are stored only as salted hashes and cannot be read back by us or by anyone else with access to the database.
Each account is isolated at the data layer, so one account’s calls, transcripts, knowledge base and credentials are not visible to another. Access to production systems is limited to the people who need it to operate and support the platform.
No system is perfectly secure and we cannot guarantee that information will never be accessed improperly. Please use a strong, unique password, do not share logins, remove access for people who no longer need it, and avoid putting sensitive identifiers into knowledge documents or agent instructions.
13. Your choices and rights
Depending on where you live, you may have rights under applicable data protection law to ask for a copy of the personal information held about you, to have it corrected, to have it deleted, or to object to or restrict certain uses of it.
Business customers can do much of this directly in the product: account details can be edited, call records and transcripts can be viewed and deleted, and knowledge documents can be added, changed or removed. For anything the dashboard does not cover, write to contact@vocarium.co.
If you are a caller rather than a business customer, the business whose agent you spoke with controls that information, and we handle it on their behalf. We may therefore refer your request to that business, or ask them how they want it handled. If you write to us with the phone number and the approximate date and time of the call, we will route the request and assist. We may need to verify your identity before acting, and we may decline requests that are unfounded, excessive, or that would reveal someone else’s personal information.
14. Where information is processed
Vocarium is operated from the United States, and the providers listed in section 8 operate across several countries. Information handled by the platform, including call audio and transcripts, may therefore be processed outside the country where you or your callers are located.
Where information moves between countries, we rely on the transfer arrangements in our contracts with those providers, together with the security measures described in section 11.
15. Children
Vocarium is a business service. It is not directed to children, and we do not knowingly collect personal information from anyone under 16.
Business customers should not configure agents aimed at children under 16 without a valid legal basis and whatever parental consent their jurisdiction requires. If you believe a child’s information has reached the platform without that basis, tell us and we will help remove it.
16. Changes to this policy
We update this policy when the service changes, when the way we handle information changes, or when the law requires it. The effective date at the top of the page shows when the current version took effect.
If a change is material, we will give notice before it takes effect, by email to the address on the account or by a notice in the dashboard. Continuing to use the service after a change takes effect means you accept the updated policy.
17. How to contact us
For privacy questions, data requests, or anything else in this policy, write to contact@vocarium.co, addressed to Elabry Inc.