Skip to content

Draft: under legal review. This document is a working draft and may change before Tuvoz launches.

tuvoz

Legal

Privacy Policy

Version privacy-2026-10-17 · Effective Oct 17, 2026 · Last updated Oct 9, 2026

This Privacy Policy explains how Deepdive AI Labs LLC, a Delaware limited liability company doing business as Tuvoz AI (“Tuvoz”, “we”, “us”) collects, uses and shares personal data. It covers:

  • users: people who create a Tuvoz account and have their AI agent place calls;
  • people we call on a user’s behalf (there is a shorter version for you at Privacy for people we call);
  • visitors to tuvoz.io.

Tuvoz is offered only to adults in the United States. Washington, Nevada and Connecticut residents should also read our Consumer Health Data Privacy Policy.

1. What we collect

From users

Category Examples Source
Account Email, Google account ID, and the name and profile picture on your Google account; your full legal name and first name, the dates you accepted our terms, that you confirmed you’re 18+ and a US resident You and Google sign-in
Phone Your verified mobile number, its carrier line type, the consent you gave for AI calls to it You, Twilio
Your agents Agent name and kind (for example Claude Code), app version, the IP address and browser that requested sign-in, API key metadata (never the full key after it is issued) Your agent, your browser
Calls Numbers you call and why, the brief your agent sends (goal, purpose, facts to share, limits), the request in your own words that started each call, your instructions and answers mid-call, outcomes, approvals You and your agent
People who agreed to AI calls Name, number, relationship and how and when they agreed, as you enter them You
Payments Top-up amounts, tax, your billing name, email and address, payment status, a card fingerprint from Stripe (and card brand and last 4 digits when Stripe sends them), refunds and disputes. We never receive your full card number. Stripe
Technical IP address (kept with records of sign-up, agent sign-ins and use, calls you request, approvals, consents, payments and account changes; for rate limits we also keep a one-way hash of its network prefix), the browser or app that made a request, device and app versions, error reports Your devices
Feedback What you send with the feedback command or in Settings You

From people we call

  • The number called, and whether it’s a business listing, a landline or a mobile (from Twilio and Google Places).
  • Only after they agree to recording: a written transcript of what they say, notes the voice agent saves (such as a confirmation number), and questions they ask that the voice agent passes to the user.
  • Their answer to the recording question (and, if yes, up to 200 characters of it as proof), and any request not to be called again.
  • If they call Tuvoz’s callback number ((628) 386-4393) or the number a call came from: a one-way fingerprint of their number, the time, and whether they pressed 9.
  • We do not keep call audio, and we never build voiceprints or other biometric identifiers.

From site visitors

  • Pages viewed and clicks on a few buttons (PostHog analytics on tuvoz.io only, without session recordings).
  • A referral cookie (tvz_ref) for 30 days if you arrive through a referral link.
  • What you submit in forms on the site (an email for “Notify me”, a phone number you ask us to stop calling, or an abuse report), and a bot check from Cloudflare Turnstile. We keep the number you ask us to stop calling only as a one-way fingerprint on our do-not-call list.

2. How we use it

  • To provide the Service: place and run calls, deliver questions and answers between the call and your agent, call you when your agent can’t answer, show you call history, and settle billing.
  • To keep calls safe and lawful: check numbers against our blocklists and opt-out list, classify numbers (business, landline, mobile), enforce limits and calling hours, detect abuse, monitor the voice agent’s honesty, keep evidence that disclosures and consents happened, and respond to complaints and legal requests.
  • To train and improve AI: see section 3.
  • To run the business: payments, tax, fraud prevention, referral credits, support, product analytics on our website, and improving the Service.
  • To communicate with you about your account, calls, billing and changes to our terms. We don’t send marketing email without your consent.
  • Human review: authorized Tuvoz staff can see call records, transcripts and training records to answer support requests, investigate abuse reports and legal requests, check that the voice agent follows its rules, and check the quality of training data. Their access is logged.

We don’t use calls or account data to show you ads, and we don’t sell personal information, including your contact details. We may license de-identified training records to other AI companies, as section 3 explains. If we ever license data that a state law treats as a “sale” of personal data, we’ll say so here first and offer the opt-out that law gives you.

3. AI training

Calls placed through Tuvoz may be used to train AI, including by other AI companies, which only ever get de-identified records. This section is the binding version of How we use call data.

  • What can be used: a training record holds the brief your agent sent for the call, the transcript starting when the person on the call agreed to recording (only the people who agreed), the outcome and basic call details (kind of number, state, length, which agent placed it).
  • Who uses it: we use training records to train and improve AI, including Tuvoz’s own systems. We may also license training records to other AI companies to train and evaluate their models, but only after we remove names, phone numbers, account and confirmation numbers and other details that identify people, so the records can’t reasonably be linked to anyone. Those companies must agree not to re-identify anyone, not to pass the records on, and to use them only to train and evaluate AI. We never license identifiable personal information, call audio or voice recordings, biometric data, health or financial information, records from Sensitive calls, records from calls with a child, or records to companies controlled by a country the US government treats as a foreign adversary. Before we license records for the first time, we’ll update this section and tell you in the app. Models other than ours may therefore improve from calls placed through Tuvoz.
  • The person on the call is asked first, in the words: “Just so you know, Tuvoz records this call, and it may be used to train AI. Other AI companies may get a transcript with names and numbers removed. Is that okay with you?” A call where they say no is never used.
  • Free plan: training is always on. Paid plan: you can turn training off in Settings; the change applies to calls placed from the moment you change it.
  • Excluded unless you opt in: calls to health, financial and school destinations, and calls whose content involves health, financial accounts, children, precise location or biometrics. The separate Sensitive calls setting (any plan, off by default) includes them. Consumer health data is never sold or shared with other AI companies (see the Consumer Health Data Privacy Policy).
  • Never used: calls where we detect a child, calls to your own phone (test calls and the calls Tuvoz makes to ask you a question mid-call), calls where nobody agreed to recording, and calls that ended for breaking our rules or because of a failure on our side.
  • Deletion: deleting your account deletes your training records, and they are excluded from training runs that start afterwards. Models trained before the deletion are not retrained.
  • We will not widen what we train on, or who may use it, without new consent.

Large language models. Tuvoz uses personal data you provide, and transcripts of people who agreed on the call, to train AI models, including large language models. Tuvoz doesn’t sell personal data to train large language models; it licenses only de-identified records, as described above.

4. Who we share data with

Recipient What they get Why
Google (Gemini API, paid tier) Call audio as it happens, transcripts, the brief The voice on the call, transcription and reading the outcome. On the paid tier Google doesn’t train on our data; it keeps limited logs for abuse monitoring (up to 55 days) and a short-lived session cache.
Twilio Phone numbers, call audio as it happens, your number for verification Placing calls, number checks, phone verification
Google Places The number being called Checking whether it’s a listed business
Supabase Account and call records Database and sign-in
Stripe Payment and billing details Payments, tax, refunds and fraud checks
Fly.io and Vercel Data in transit and in processing Hosting our servers, website and dashboard
Sentry Error reports with phone numbers, transcripts and keys removed Fixing bugs
Cloudflare Form submissions’ bot-check signals Spam protection
PostHog Website page views and clicks Site analytics
Your agent’s provider (for example Anthropic, OpenAI or Meta) What your agent reads about your calls Your agent works on your behalf; their policies apply
Other AI companies De-identified training records only (section 3), if we license them Training and evaluating AI models, under a contract that forbids re-identification and onward transfer
Authorities and carriers What the law requires, or what is needed to trace an abusive call Legal process, carrier traceback, protecting people
A buyer of our business The data covered by this policy A merger or acquisition, under this policy’s commitments

Service providers process data for us under contract and only for the purposes above.

5. How long we keep it

Data Kept
What people we call said: transcripts, notes, questions, summaries 30 days after the call
What the voice agent said, and instructions sent mid-call 5 years after the call, as proof of what was disclosed, unless you delete your account
Call records without content (time, status, consent answer, cost) For the life of your account
Training records Until you delete your account
Evidence of disclosures, consents and opt-outs (stored as fingerprints, not words), audit logs 5 years
Records of each call request: your request in your own words, which agent sent it, when, and from which IP address and device 5 years after the call, as evidence that you asked for it, including after you delete your account
Records of what you accepted and agreed to (terms, consents and settings, with the time, IP address and device) Indefinitely, including after you close your account
Payment and ledger records At least 7 years
Payment-provider event records (including billing name and address) 400 days
Feedback, and people you added as having agreed to AI calls (including ones you removed) Until you delete your account
“Notify me” emails Until you ask us to remove yours
Abuse reports Indefinitely, as a record of the report and what we did about it
Numbers that asked not to be called, banned accounts, free-minute records Indefinitely
Requests made with the “stop calls” form (fingerprints of the number and of the network address) 2 days, for rate limits
Sign-up, verification and security logs, and records of calls to our numbers (a fingerprint of the caller’s number, the time, whether they pressed 9) 400 days
Website analytics Up to 1 year

Data covered by a legal hold is kept until the hold ends.

6. Security

Each user’s data is isolated in our database by row-level security. Money, consents, opt-outs and evidence can only be written through controlled database functions. Data is encrypted in transit and at rest by our providers. API keys are stored as one-way hashes. We log identifiers, not phone numbers or call content. No system is perfectly secure; if a breach affects you, we’ll tell you as the law requires.

7. Your rights and choices

  • Access and portability: ask for a copy of your personal data.
  • Correction: ask us to correct inaccurate data. Your legal name is locked after sign-up; email support to change it.
  • Deletion: delete your account in Settings, or ask us. Deletion covers your calls’ content, training records and phone numbers; we keep billing records, and the evidence and consent records listed in section 5, for the periods shown there.
  • Training: paid plans can turn training off for new calls; any plan can opt in to or out of Sensitive calls.
  • Opting out of sale, sharing or targeted advertising: we don’t sell personal information or use your data for targeted advertising. Where a state law gives you the right to opt out of the sale or sharing of personal data, or of its use to train AI, email privacy@tuvoz.io and we’ll honor it as that law requires.
  • People we call can ask us to delete what they said; see Privacy for people we call.
  • Appeals: if we decline a request, you can appeal by replying to our answer. If you’re not satisfied, you can contact your state attorney general.

Email privacy@tuvoz.io from your account email to make a request. We may need to confirm it’s you, for example by a code sent to your verified phone. We answer within 45 days, and we won’t treat you differently for using your rights.

8. Children

Tuvoz is for adults only. We don’t knowingly collect data from children. If the voice agent detects that it’s talking with a child, it stops keeping what they say, deletes what they already said, and the call is never used for training. If you believe a child has an account, email privacy@tuvoz.io.

9. US only

We provide the Service only in the United States, store data in the United States, and don’t offer the Service to people outside it.

10. Changes

Each version of this policy has a version string (this one is privacy-2026-10-17) and a date. We’ll tell you about material changes by email or in the app before they take effect. We won’t apply a change that widens how your data is used for training to calls placed before you agree to it.

11. Contact

Deepdive AI Labs LLC, a Delaware limited liability company doing business as Tuvoz AI. Email privacy@tuvoz.io.