Legal

Privacy policy

DialRingo runs your phone. That means we handle recordings of your calls, your voicemail, your text messages and conversations your customers have with an AI that answers on your behalf. This page says exactly what we do with all of it.

Last updated 9 August 2026.

The short version. We do not sell your data and we do not use it to train AI models. Calls on numbers with recording switched on are recorded and stored, and recording is on by default when you buy a number. Recorded audio goes to a speech-to-text provider, and the resulting text goes to a second provider that writes the summary. Everything the AI receptionist says and hears is kept. Staff can open your account to help you, and every time they do it is logged with their name.

1. Two kinds of person

Almost every privacy question about DialRingo has two answers, because two different people are involved and we owe them different things.

You, our customer. The business that signed up, and the people on your team who log in. For your data we are the controller: we decided to collect it, we decide what it is for, and this policy is our promise to you about it.

The people who contact you. Your customers, patients, suppliers and anyone else who rings your number, texts it, fills in your booking page or talks to your AI receptionist. They never signed up with us and most of them have never heard of us. For their data we are a processor acting for you: it is your data about your customers, we hold it on your instructions, and you are the controller. If one of them asks us to delete a recording of their call, we will normally pass the request to you, because it is your record and your decision.

That split has a consequence worth stating plainly: the legal duty to tell your customers that they are being recorded, texted or answered by an AI is yours, not ours. We give you the switches and we keep the proof. You decide how you use them. Sections 3, 5 and 6 are the detail.

2. What we collect, and why

We collect what a phone company needs to carry your calls, bill you correctly, keep the network free of fraud, and run the features you switched on. Nothing here exists to build a profile of you.

From you, our customer

WhatWhy we have it
Your name, email address, business name and password To create your account and let you sign in. Passwords are stored as hashes, never as text we can read.
Your phone numbers, their settings, and your team’s logins To route calls to the right place and let the right people answer them.
Billing name, billing email, and the brand, last four digits and expiry of your card To charge you. The full card number is entered on our payment processor’s own form and never reaches our servers - we only ever see the last four digits.
The address you register for 911 Emergency dispatchers need a real street address to send help to. We pass it to our carrier for the emergency database. See the 911 disclosure.
Business registration details for texting and caller ID: legal name, tax ID, address, website, and a description of how you collect consent US carriers will not deliver business texts from an unregistered brand. These go to the carrier and to the industry registry, not to us for our own use.
If you are moving a number to us: your old carrier, your account number and PIN there, the service address on that account, and a signed letter of authorization Your old carrier will not release the number without them. The PIN is encrypted while we hold it, and we pass the package to our carrier to execute the transfer.
Documents you upload to teach the AI receptionist To answer your customers’ questions. These are indexed on our own hardware.
Support conversations and emails you send us To answer you, and to remember what we told you last time.

Automatically, as you use the service

WhatWhy we have it
Call records: the numbers on each call, when it started, how long it lasted, whether it was answered, and where it was routed Billing, carrier disputes, and the call history in your dashboard. Every phone company on earth keeps these.
Call recordings, where recording is switched on So you can listen back. See section 3.
Voicemail audio and its transcript So you can read a voicemail without playing it.
The full text of every text message you send and receive, and any picture attached To show you the conversation, and to answer a carrier if someone complains about a message you sent.
Fax content, if you use fax To deliver and display it. Faxes are stored as PDFs in our file storage.
Technical logs: IP addresses, device and browser details, softphone registrations, and API request records Security, fraud detection, and working out why a call failed.
Usage counts: minutes, messages, AI minutes To bill you and to enforce fair use.

About the people who contact you

This is the data we hold on your behalf. It includes their phone number and caller ID name, the recording and transcript of the call if recording is on, their voicemail, the text of their messages and any picture they sent, anything they typed into your booking page or chat widget, the full conversation they had with your AI receptionist, and any contact record you or your team created for them.

You control where it goes next. If you have pointed a booking page at your own webhook or CRM, we send each enquiry there, with the conversation transcript attached if you asked for it. If you export a list, you have a copy we cannot reach. Once your customers’ data is somewhere you sent it, it is covered by your privacy policy, not this one.

Our lawful basis, if you are asking under GDPR

  • Performance of a contract for everything needed to run the service you bought: accounts, routing, recordings, messages, billing.
  • Legal obligation for call records, 911 address registration, texting consent records and financial records.
  • Legitimate interests for security, fraud and abuse prevention, and improving reliability. Our interest is keeping a phone network working and not letting it be used for fraud, and we have weighed that against the intrusion, which is low.
  • Consent where we ask for it directly, such as marketing email you can unsubscribe from at any time.

3. Call recording

Call recording is a setting on each individual phone number, not on your account as a whole. You can turn it off for one number and leave it on for another, under that number’s settings.

Recording is on by default when you buy a number, and we do not play an announcement to the person on the other end. Nothing is spoken to your caller and there is no beep. If your callers need to be told, telling them is your job.

Recording law is not the same everywhere. Some US states let one party to a call consent on everyone’s behalf; others require every party to consent, and recording without that consent can be a crime as well as a civil claim. Which rule applies can depend on where your caller is, not only on where you are. We are not able to work that out for you and this policy is not legal advice.

What we do: give you a per-number switch, record only when it is on, store the audio, and let you download or delete a recording. What you do: decide whether you are allowed to record, and disclose it to your callers if you are required to. If you are not certain, turn recording off for that number and ask a lawyer.

Separately, an owner or admin on your account can listen to a call while it is happening, speak privately to their own team member, or join the call. This is meant for training. The person on the other end is not told, and the same consent law applies to it.

4. Transcription and call summaries

When a call is recorded, and when someone leaves a voicemail, we can turn the audio into text so you can read it. Doing that means the audio leaves our servers.

  1. The audio goes to our speech-to-text provider, which returns the transcript. It receives the recording itself, which means it receives whatever was said on the call.
  2. The transcript text then goes to our AI summarisation provider, which writes the summary, the sentiment reading and the follow-up list you see in the dashboard. It receives the words, not the audio.

Both are contracted to process the data for us and for nothing else, and neither is permitted to train on it.

Your controls:

  • Turn call recording off for a number and there is no audio, so nothing is transcribed.
  • Delete the transcript of an individual call from that call’s record. Doing so also marks the call so it is never sent for transcription again. It does not delete the recording itself, which you delete separately.

Voicemail transcription is a paid add-on and is off unless you buy it. When it is on, the voicemail audio goes to our speech-to-text provider and comes back as text - it is not sent on for summarisation, because a voicemail does not need a summary. The transcript is also included in the notification email we send you, so bear that in mind if your email goes somewhere shared.

5. The AI receptionist

SMART Voice answers your phone, your website chat and your website call button in your business’s name. The person on the other end is talking to software.

What is kept from every AI conversation: the recording and transcript of the conversation, a written summary, the caller’s number, how long it lasted, what the agent did during it, and anything the caller gave it - a name, a callback number, an appointment time, an order. It is kept so you can see what happened on a call you did not take, and so the agent can act on it. It is not used to train anyone’s model.

Where it runs. The agent itself runs on hardware we own and operate, on our own network, and so does the recording and transcript of every conversation it has. So does the voice it speaks with, and the search index built from the documents you upload - those are indexed on our own machines and the index never leaves the building.

What does leave is the conversation itself. Turning your caller’s speech into text, and working out what to say back, is done by our speech-to-text and AI provider. The summary you read afterwards is written by our AI summarisation provider. Those are the same two providers as in section 4, and the same caveats apply.

Disclosure to your callers. For calls the agent places, there is a setting that makes it say up front that it is an automated system, in wording you write. It is off unless you turn it on. For calls the agent answers, there is no such setting today. Several states and a growing number of federal rules require an AI caller to identify itself. Deciding what your agent says, and whether it satisfies the law where you operate, is yours.

Video meetings are a separate feature and are not recorded. The video and audio pass through our own server. Chat messages typed during a meeting are stored.

6. Texting, consent and opt-outs

We store the full text of every message sent and received on your numbers, and we keep two more kinds of record that exist purely as evidence.

Consent records

When someone agrees to receive texts from you, we write down more than “yes”. We store how they agreed (a form, your register, a keyword they texted, a verbal yes on a recorded call), when they agreed, whether they agreed to service messages or marketing or both, and the exact wording that was on screen in front of them at that moment, copied word for word rather than pointing at whatever your form says today.

That last part is the whole point. Forms get reworded. If a carrier or a regulator asks you to prove that a specific person agreed, the only answer worth anything is what that person actually read on that day. Consent records are never edited and never overwritten - a later change of mind is a new record, so the timeline stays intact.

Do-not-contact records

When someone opts out, we keep a record of that too: their number, how they opted out, and when. We have to keep it, because the record is the mechanism - it is what makes the system refuse to text or call that number again. Deleting it would let the messages start again. Opting out is treated as final and it wins over any consent on file.

7. Who else touches your data

We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not let anyone use it to train an AI model. We do use other companies to run parts of the service. Each one only receives what its job needs.

WhoWhat they receive
Telephone carrier Your phone numbers, the numbers on every call and message, routing and delivery data, and the address and business details you submit for 911, caller-ID name and texting registration. They are the licensed carrier your numbers actually live on.
Speech-to-text and AI provider
Transcription, and the AI receptionist’s answers
Audio of recorded calls and voicemails, and the live conversation your AI receptionist is having with a caller.
AI summarisation provider
Summaries
Transcript text from calls, for the summary, sentiment and follow-up list. If you use POS, also the aggregated sales figures behind the plain-English insights - totals and trends, not customer records.
Cloud file storage provider Call recordings, voicemail audio, fax PDFs and files you upload. Stored encrypted; they do not look inside them.
Data centre operator
Server hosting
The physical machines our software runs on, which means everything, at rest. They are a landlord, not a processor of your calls.
Payment processor Your name, email, billing address and card details, entered on their own form. They tell us the brand, last four digits and expiry so we can show you which card is on file.
Fax provider Fax numbers and the content of the fax, and only if your fax number is set up to route through them. Fax can also run on our own equipment over the carrier trunk, in which case the document does not leave our systems at all.
Google and Microsoft
Sending email as you
If you connect your Google Workspace or Microsoft 365 mailbox so the AI agent can send email in your name, the messages it sends go out through them. See below for what we can and cannot do with that connection.
Apple and Google
Mobile push
A device token and the contents of the notification - typically a caller’s number or “new voicemail” - so your phone can ring when the app is closed. Only if you use the mobile app.

What runs on our own hardware

This is unusual enough to be worth spelling out. The following are not somebody else’s cloud service. They are software we run on machines we control, and the data in them does not leave our network:

  • The phone switch that connects your calls.
  • The AI receptionist itself, and the voice it speaks with.
  • The search index built from documents you upload to teach it.
  • The database and the login system.
  • Video meetings.
  • The mail server that sends your voicemail notifications and receipts.

We also use ordinary business tools that see limited personal data as a side effect - our support chat and our own accounting - and we require confidentiality from all of them.

Connecting your mailbox

If you let the AI agent send email in your name, we ask Google or Microsoft for permission to send, and nothing else. We do not request read access to your mailbox, and the code refuses to store a broader permission even if the provider offers one. We cannot read your email.

There are two exceptions worth knowing about. If you connect a mailbox using an app password over SMTP instead of the Google or Microsoft sign-in, that password gives full mailbox access - all we can tell you is that we only use it to send. And if you set up an inbound address so the agent can act on incoming mail, that mail is forwarded to a mailbox we run, and we do store those messages, including their text.

Every mailbox credential is encrypted with a key unique to your account. Access tokens are held in memory and never written down.

Things we deliberately do not do

Worth stating, because several of them are what people assume a product like this must be doing:

  • Video meetings are not recorded. The feature to record them is not built and not deployed. Text chat typed during a meeting is stored.
  • Watch stores no camera footage. If you use our camera product, we store the site address, the camera settings, and a description of each event. We do not store images or clips, and no footage is sent to any AI provider.
  • No card number reaches us, ever. Not for your subscription, and not for POS. POS card processing is not switched on; cash is the only method that works today.
  • Nothing you send us is used to train an AI model, by us or by any provider we use.

8. Where your data is stored

DialRingo is a US business serving US customers, but our servers and our file storage are physically in Germany. Your recordings, messages and account data are stored in the European Union.

Our AI providers are the exception, because processing has to happen where they run rather than where we do: audio is processed by our speech-to-text provider, and transcript text goes to our AI summarisation provider. If you would rather none of that happened at all, turn off call recording so there is nothing to transcribe, and read section 5 before switching on the AI receptionist.

Where personal data covered by UK or EU law moves outside those areas, we rely on the European Commission’s standard contractual clauses, with the UK addendum where the UK GDPR applies.

9. How long we keep things

Here is the honest picture, which is that some of this is automatic and some of it is not.

Deleted automatically

  • Voicemail you delete sits in the Deleted tab for 30 days so you can restore it, then the message and its audio are permanently removed.
  • Calling lists you upload for an outbound campaign are deleted after 90 days by default. You can set anything from 1 to 365 days, or delete the list immediately. The campaign and its totals survive; the phone numbers do not.
  • Softphone connection logs are kept for 90 days, and the samples behind them for 30.
  • Operational alerts and delivery logs are kept between 30 and 180 days depending on the type.

Kept until you delete it

Call records, call recordings, transcripts, voicemail you have not deleted, text messages, faxes, contacts, chat and AI conversations, booking-page enquiries and POS customer records are kept for as long as your account is open. There is no automatic expiry on these today. You can delete individual items from the dashboard whenever you like, and you can ask us to delete a category - see section 12.

Kept on purpose, even after you leave

Closing your account does not erase everything, and we would rather say so than imply otherwise. We keep the following for seven years: call records, texting consent and registration records, the account audit log, invoices and payment records, and 911 address registrations. Each of these is either a billing record, a regulatory record, or the evidence that answers a complaint about you.

We also permanently keep the log of any occasion a member of our staff opened your account (section 10). The database itself refuses to let us edit or delete that log, which is the point of it.

Closing your account

You can request closure from Settings in the dashboard. Your subscription stops renewing immediately, and then service stays fully live for 30 days. You can cancel the closure from the same screen at any point in that window.

After the 30 days a person on our team removes the account. That step is deliberately done by hand rather than by a scheduled job, because releasing or porting a phone number is carrier work and getting it wrong takes a business’s phone off the air. What is removed: call recordings and voicemail audio, transcripts and AI summaries, contacts and message threads, your AI agent’s configuration and knowledge, and all logins, softphone credentials and API keys. What is kept is the seven-year list above.

10. Who at DialRingo can see your account

Our support staff can open your account and see what you see, so they can fix something without asking you to describe it down the phone. We do not notify you when this happens.

What we do instead is make it impossible to do quietly:

  • Access is time-limited. A support session expires after 60 minutes and has to be re-established.
  • Every session is recorded with the staff member’s email address, the reason they gave, and their IP address.
  • Every change they make while inside your account is stamped with their name, not yours, so your own activity history shows who really did it.
  • The log is append-only and hash-chained. The database has had permission to update or delete those rows revoked, so nobody at DialRingo can rewrite or erase it - including whoever might want to.

You can ask us for the record of every time your account was opened by staff, and we will give it to you.

11. How we protect it

  • Traffic between you and us is encrypted in transit, and files in our storage are encrypted at rest.
  • Links to a recording or voicemail are signed and expire after about a minute, so a copied URL is useless almost immediately. Nothing in our file storage is publicly readable.
  • Softphone passwords, port-out PINs, camera credentials and connected mail credentials are encrypted with separate keys, so a leak of one does not open the others.
  • Where we keep a visitor’s IP address at all - website chat, the call button, booking pages, meeting waiting rooms - we store a salted hash of it rather than the address. It is enough to tell two visitors apart and not enough to identify one.
  • Your data is separated by account at the database level, not by our code remembering to filter.
  • Access to production systems is limited to staff who need it and is logged.
  • Payment card numbers never reach our servers.

No system is perfect, and we are not going to claim otherwise. If we discover a breach affecting your data we will tell you and any regulator we are required to tell, without unnecessary delay.

12. Your rights, and how to use them

Whoever you are and wherever you live, you can email privacy@dialringo.com and ask us to do the things below. We will not charge you, we will not make you create an account to ask, and we will not treat you worse for asking. We do have to check you are who you say you are before handing over anyone’s data, which for a customer usually means asking from the email address on the account.

  • Know what we hold about you and why.
  • Get a copy, in a format you can take elsewhere.
  • Correct anything that is wrong.
  • Delete it, subject to the records in section 9 that we are required to keep.
  • Opt out of marketing email, at any time, using the link in it.

If you are in California

Under the CCPA as amended by the CPRA you have the rights above, plus the right to know the categories of personal information we collect, the categories of source, the business purpose, and the categories of third party we disclose to - all of which are in sections 2 and 7. You may also limit the use of sensitive personal information, and you may appoint an authorized agent to ask on your behalf.

We do not sell personal information and we do not share it for cross-context behavioral advertising, as those terms are defined in the CCPA, and we have not done so in the previous twelve months. That includes personal information of anyone under 16. Because we do not sell or share, there is no “Do Not Sell or Share My Personal Information” link on this site; if that changes, this policy changes with it and the link appears.

The contents of your calls, messages and voicemail are sensitive personal information under California law. We use it only to provide the service you asked for and for the purposes listed here, which are the permitted ones - never to infer characteristics about you.

Similar rights exist in Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana and a growing list of other states, including a right to appeal if we refuse a request. Use the same email address and tell us which state you are in. If we turn you down and you disagree, reply and say so; we will look again, and you can complain to your state attorney general.

If you are in the UK or the EU

You have the rights above and, in addition, the right to restrict processing, to object to processing carried out on the basis of legitimate interests, and to data portability. Where we rely on consent, you can withdraw it at any time without affecting what we did before you withdrew it. You can complain to your national data protection authority.

We do not make decisions about you by automated means alone that produce legal or similarly significant effects.

13. If you called or texted a DialRingo customer

You have probably reached this page because a business you contacted uses us for their phone, and you want to know what happened to that call.

Here is the honest answer. The recording, the transcript, the message and the conversation with the AI belong to that business, not to us. We store them on their behalf. So the fastest route is almost always to ask them directly - they can delete it themselves, immediately, from their dashboard.

If you cannot reach them, or you would rather not, email privacy@dialringo.com with the number you called or texted from and roughly when. We will identify the business and pass your request to them, and we will help them carry it out. Where the law makes us act on your request directly, we will.

To stop being contacted is faster and is something we do ourselves. Reply STOP to any text and you are removed at once and cannot be texted again from that business until you reply START. Telling the AI receptionist to stop calling you also works, and it stops the texts too. We keep a record of your opt-out, and we keep it precisely so it keeps working - see section 6.

We are a phone company, so we get asked. We disclose customer data to law enforcement or in litigation only where we are legally required to - a valid subpoena, court order, warrant or equivalent legal process - and we will disclose only what the request actually covers.

Where the request concerns a customer’s account and the law allows us to tell them, we will tell them, so they have the chance to object. Sometimes the order forbids that, and then we cannot.

15. Children

DialRingo is a product for businesses. It is not directed at children and we do not knowingly collect personal information from anyone under 16. If a child calls or texts a business that uses DialRingo, we will hold whatever that call or message contained, in the same way as any other call. If you believe we hold a child’s personal information and it should not be there, email privacy@dialringo.com and we will remove it.

16. This website

dialringo.com sets no advertising or analytics cookies. There is no Google Analytics tag, no advertising pixel and no cookie banner, because there is nothing to consent to. Our web server keeps ordinary request logs containing IP addresses, for security and to know the site is up.

The support chat bubble in the corner runs on infrastructure we operate ourselves. It stores what you type plus a browser identifier, so your conversation survives a page reload. It is not an advertising or analytics tool and it does not follow you to other sites.

If you sign up, the dashboard uses browser storage to keep you signed in. That is required for the product to work and is not tracking.

If you use our booking pages or website widgets on your own site: you can connect your own Google Analytics, Google Ads or Meta pixel, and you can add your own script. When you do, those vendors become your vendors and receive visitor data under your privacy policy, not ours. Turning them on is your decision and disclosing them is your responsibility.

17. Changes to this policy

When we change something material - a new provider that receives your call content, a new category of data, a shorter or longer retention period - we will update the date at the top of this page and email the account owner before it takes effect. Small corrections we will simply make.

18. Contact us

DialRingo is a service of Intelligent Solutions LLC, a Kentucky limited liability company.

Privacy questions, and any request under section 12: privacy@dialringo.com.
Everything else: support@dialringo.com.

By post:

You are also welcome to raise anything in this policy with us before you complain to a regulator. We would rather fix it.