Privacy Policy
Last updated: August 7, 2026
VeraDial is operated by VeraDial Inc. In this policy, “VeraDial”, “we”, and “us” refer to VeraDial Inc., the entity responsible for the personal information described below.
1. Information We Collect
Account data: When you create an account, we collect your email address and profile information through Supabase Auth.
Caller profile: If you use AI Calling, we store your display name, website, and caller context that you provide. These are used to identify you on AI calls and voicemail greetings.
Phone numbers: We store information about your purchased phone numbers (including Twilio SID, capabilities, region, and country) and any verified caller IDs you add.
Call records: We maintain call logs including from/to numbers, duration, timestamps, and Twilio call SID for your account history.
Call recordings: When you enable call recording on outbound calls or AI calls, dual-channel audio is recorded by Twilio and stored on their servers. We store a reference to the recording and provide playback through our app.
Call transcripts: When you record a call, the audio is automatically sent to a third-party speech recognition service (Deepgram) for transcription. We store structured transcripts including speaker identification, text, and timestamps alongside the call record.
Call screening data: When call screening is enabled, we store the screening interaction data including the caller's stated identity and intent, a conversation identifier, and timestamp.
Call forwarding: If you configure call forwarding, we store your forwarding phone number and enabled/disabled preference on your profile.
Location data: When you make or receive calls, we may collect your device's GPS coordinates to associate a location with the call record. Location data is used to display your calls on the Call Map feature. Location collection requires your permission and can be disabled through your device's system settings.
SMS content: We store message bodies, sender/recipient numbers, timestamps, and delivery status for messages sent and received through the service. For inbound MMS, we copy any attached media (such as photos) from Twilio into private cloud storage (Supabase Storage) and reference it on the message; the app retrieves it through short-lived signed URLs.
Consent records: We maintain SMS consent status and timestamps to comply with telecommunications regulations.
AI SMS receptionist drafts: If you turn on the AI SMS receptionist for one of your lines, the text of inbound messages on that line, recent message history for that conversation, and your line's receptionist identity and instructions are sent to Google's Gemini API to draft a reply. If an inbound message includes photos or other media (MMS), that media is sent to Gemini as part of the request so the draft can take it into account. We store the drafted reply, its status (pending, approved, sent, auto-sent, or discarded), and the timestamps of those decisions alongside the conversation. Each line runs in one of two modes: in approve mode nothing is sent until you review and tap to send, and you may edit the draft first; in auto mode an eligible draft is sent automatically, and a draft is downgraded to pending review when the model asks for a human. When Contact Memory is also enabled, the relevant contact summary may be included as context on the review lane.
Carrier registration and business identity: If you ask to activate US business texting, we collect the business identity and messaging-program information required by mobile carriers and their registration providers. This may include your confirmed legal and display names, business address and country, business type, whether you have a tax or business registration number, website, public Terms, Privacy, and opt-in evidence URLs, messaging use case and description, sample messages, and your attestation that the information is accurate and that you have authority to submit it. We store only the safe metadata needed to show and operate the registration, such as masked identifiers, provider object IDs, statuses, failure categories, timestamps, sender bindings, public evidence URLs, and registration-event history.
For direct carrier registration, raw tax or government identifiers, identity-verification answers, and one-time passcodes may pass through VeraDial's server to Twilio for the requested submission, but VeraDial does not intentionally persist those raw values in its database, logs, analytics, or durable operation records. Twilio may retain the identity information it receives under its own policies and carrier requirements. Toll-free verification may instead collect full identity information directly in Twilio's hosted interface.
Carrier-registration fees: When a carrier-registration fee is offered, we store the displayed product, amount, currency, billing period, purpose, registration revision, authorization status, and RevenueCat transaction identifiers needed to match the purchase to the exact registration action and to handle failure, refund-review, renewal, or dispute states. We do not store payment card details.
Voicemail: We store voicemail recordings, transcriptions, duration, and caller information for voicemails left on your VeraDial number. Voicemail audio is recorded by Twilio and transcribed by a third-party speech recognition service (Deepgram).
Voicemail greetings: If you create a custom voicemail greeting, we store the greeting audio file. For AI-generated greetings, we also store the text you write and the voice you select; audio is generated by a third-party AI provider (ElevenLabs or Cartesia, depending on the voice type). For recorded greetings, your uploaded audio is converted to MP3 format on our server. All greeting audio is stored in cloud storage (Supabase Storage).
Voice cloning: If you create a cloned voice, we collect the voice sample you record, your consent acknowledgment, and metadata about the resulting voice model. The raw voice sample is processed server-side and sent to Cartesia to create the clone; VeraDial does not retain the raw sample after successful clone creation. We store the Cartesia voice identifier, clone name, consent record, and generated greeting audio made with that clone until you delete the clone, the greeting, or your account.
Message dictation: If you use the microphone button to dictate a message (for example in an SMS conversation or the in-app account assistant), the short voice clip is sent from your device to our server and then to a third-party speech recognition service (Deepgram) to convert your speech to text. The clip is processed only to produce the text and is not stored by VeraDial; the app removes the clip from the device's temporary storage after conversion. Only the resulting text appears in your message box, and it is retained only if you send or save the message. Dictation clips are limited to two minutes.
AI Call data: When you use AI Call, we store the phone number called, your call goal and notes, call duration, the AI provider used, and the full conversation transcript and summary generated by the AI agent. If you enable recording on an AI call, the recording is stored by Twilio and referenced in your account. Call audio is processed in real-time by the selected AI provider (ElevenLabs, OpenAI, Google, or xAI) and is not stored by VeraDial.
Call translation: When you enable two-way translation on an outbound call, your call audio and the other party's audio are streamed in real-time to OpenAI to generate translated speech. Translation audio is processed in transit to produce the translation and is not stored by VeraDial. We store the translation status of the call (whether translation was used and its outcome) alongside the call record.
Contact memory: If you explicitly turn on Contact Memory in Profile > Contact Memory, we generate a rolling AI summary for each phone number you interact with, using your call transcripts, voicemail transcriptions, AI call transcripts and summaries, and SMS message content from your own account. Summaries, a suggested next-call goal, and the phone number are stored in your account. Summarization is performed by a third-party AI provider (Google Gemini). When Contact Memory is disabled, existing summaries are not read through the feature and new summaries are not generated; existing summaries remain stored unless you delete your account.
Connected AI assistants: If you choose to connect a compatible AI assistant through VeraDial's read-only connector, the connector can return VeraDial account data needed to answer your request. Depending on the tool you ask the assistant to use, this may include call, AI-call, voicemail, and SMS phone numbers, statuses, durations, timestamps, screening summaries, call and voicemail transcripts, SMS message bodies and attachment media types, phone-line and receptionist settings, subscription and usage information, and contact summaries. Your basic profile (email address and name) may also be processed during the OAuth sign-in and authorization flow. The connector does not return call or voicemail audio, recording URLs, attachment URLs, passwords, authentication tokens, or internal telecom and AI-provider identifiers, and its published tools cannot place calls, send messages, or change your VeraDial account.
In-app account assistant: When you use “Ask Vera a question,” we store your questions, Vera's replies, the detected question category, whether the question was answered, the turn outcome, which fixed account-information tools were used, and — only if you tap them — a thumbs up or down on a reply plus an optional reason you pick from a fixed list. There is no free-text feedback box. Your latest question and a bounded set of your recent questions are sent to Google Gemini only to select a permitted intent, help entry, and at most one read-only account tool. VeraDial runs that selected tool and formats any account facts itself; your phone-line, routing, receptionist, carrier-forwarding, push-registration, subscription, and usage facts are not sent back to Gemini. The assistant does not receive your device contacts, call or voicemail transcripts, SMS bodies, voicemail content, or authentication credentials, and it cannot draft or place outbound calls.
Custom training sources: If you add custom training material so your receptionist can answer questions about your business, we store what you provide and what we derive from it. For an uploaded document, the file is stored in private cloud storage (Supabase Storage) along with its file name, type, and size. For a web address, we store the address and fetch that page's public content through a third-party extraction service (Firecrawl). In both cases, the extracted document or page text is sent to Google's Gemini API, which distills it into a short set of facts a receptionist can use. We store that distilled summary, a label for the source, its processing status, and any failure reason. The distilled summary — not the original file or page — is what gets supplied to your receptionist as caller context during calls. Deleting a training source deletes the stored file and its distilled summary.
Connected automation endpoints: If you connect an automation tool (such as Zapier, Make, or n8n) or register your own webhook endpoint, we store the destination URL, a signing secret used to authenticate our deliveries, which event types you subscribed to, whether you enabled full content, and per-delivery attempt records including status codes and timestamps. When a subscribed event occurs, we deliver it to the endpoint you configured. Events cover completed call screening, received voicemails, AI SMS replies that were sent, and booked appointments, and the delivery includes the caller's phone number and name, the event's summary, and related identifiers and timestamps. Full transcripts and voicemail transcriptions are removed from deliveries unless you explicitly turn on full content for that endpoint. Once data reaches an endpoint you configured, it is handled by that destination and by you, not by VeraDial; see Section 3.
Service emails: We send account and lifecycle email to your account email address through a third-party email provider (Resend) — for example, finishing setup, activation and first-call notices, trial reminders, and win-back messages. We store which of these emails were sent to you and when, your unsubscribe preference, and delivery outcomes reported back by the provider (such as delivered, bounced, or complained) so we can honor unsubscribes and stop mailing addresses that bounce or report our mail as spam. You can unsubscribe from lifecycle email using the link in any such message; this does not stop transactional messages required to operate your account.
Bot protection: Our public demo builder and web signup pages use Cloudflare Turnstile to distinguish real visitors from automated abuse. When you complete the check, the challenge token and your IP address are sent to Cloudflare for verification. We store only the verification outcome, not the token.
Network and device information (fraud prevention): When you sign in and use VeraDial, our servers record the IP address your requests come from, together with your app's user-agent string and, where the app provides one, a random per-install device identifier (not a hardware or advertising identifier). We keep the times each address or identifier was first and last seen on your account. This information is used only to protect the service — detecting fraud, trial abuse, and coordinated misuse by recognizing when multiple accounts operate from the same network or device — and to respond to carrier, provider, and lawful requests. It is not used for advertising or profiling and is not sold. If you delete your account, these records are detached from the account — the link to your account is removed — and the network and device observations themselves are kept for fraud and abuse prevention and deleted no later than 90 days after the account is deleted. See “Fraud-prevention records that outlast deletion” in Section 5.
Google Calendar booking: If you connect Google Calendar, VeraDial creates a separate “VeraDial Bookings” calendar in your Google account and stores an encrypted Google refresh token, the Google account email address and account identifier you connected, and the identifier of that Bookings calendar. Calendar identifiers are assigned by Google and can resemble email addresses. To find open times, VeraDial requests only free/busy time ranges, and only from your main Google calendar and that Bookings calendar — events on your other Google calendars are not consulted and do not block a booking. VeraDial cannot read event titles, descriptions, attendees, or contents from any calendar it did not create, and it cannot modify your other calendars. The candidate appointment times Vera offers are processed by the AI provider handling that call so they can be spoken to the caller; your event contents are never accessible to VeraDial and are never sent. When Vera confirms an appointment, we write the event to the Bookings calendar and store the appointment time, timezone, caller name, callback number, and stated reason in your account. Calendar data is not sold, is not shared with advertisers, and is not used to train AI models. Disconnecting revokes VeraDial's access and stops new bookings; it leaves the Bookings calendar and your existing appointment records in place. Deleting your account revokes access and removes VeraDial's calendar records.
Push notification tokens: We store device push tokens to deliver notifications to your device. Tokens are automatically deleted when you sign out or your session expires.
Billing: Purchase and subscription history is managed through RevenueCat and the Apple App Store / Google Play Store. We store your subscription status, billing period, and credit balance. We do not store payment card details directly. On Android, RevenueCat also receives the device's advertising identifier and a Meta-generated anonymous app identifier so subscription events can be attributed to advertising. On iOS, RevenueCat receives an Apple AdServices attribution token and the Apple Search Ads campaign details Apple returns for it, so subscription events can be attributed to advertising; see “Apple Search Ads attribution (iOS)” below. We do not configure either attribution path to add your email address, phone number, message content, call audio, or transcripts.
Error and crash data: We collect error reports and crash data through Sentry to diagnose and fix issues with the app. This may include device information, OS version, and stack traces. No message content or call audio is included in error reports.
Product analytics: We collect anonymized product analytics through PostHog to understand how the app and website are used (screen views, navigation paths, feature engagement, paywall and purchase events, website page views, demo funnel events, and app store click events). Sensitive fields (email, phone numbers, message content, transcripts, recording URLs, raw URLs with query strings, location, goals/notes/prompts) are stripped before analytics events are sent. GeoIP is disabled. On /demo and /demo/live only, we may use masked website session replay through PostHog to diagnose demo-funnel issues; all text and input values are masked, replay respects Do Not Track / Global Privacy Control, and internal traffic is excluded where flagged. Session replay is not used in the mobile app or on non-demo website pages. Analytics are disabled in development builds and screenshot/test builds by default.
Google Analytics measurement: On our websites (veradial.com and veradial.ca), we use Google Analytics 4 to measure site traffic and marketing performance, including page views, demo funnel events, and app store click events, together with standard browser and device data. Google Analytics estimates approximate location (such as country, region, and city) from your IP address during collection; Google Analytics 4 does not log or store the IP address itself. In the Android app, Google Analytics for Firebase automatically assigns an app-instance identifier and collects app lifecycle, session, engagement, Android advertising identifier, masked-IP-derived approximate location, and standard app/device data. It may also automatically observe Google Play purchase and subscription events. VeraDial sends two additional Android events: signup method (email, Google, or Apple) and activation mode (direct use or call forwarding). We use this information for analytics and Google Ads conversion measurement. Personalized-ad signals and automatic screen reporting are disabled by default. We do not set a Firebase Analytics user ID or send Google Analytics your name, email address, phone number, Supabase user ID, contacts, messages, calls, audio, transcripts, recordings, business profile, website, goals, notes, or prompts. This mobile measurement is not used in the iOS app.
Advertising and conversion measurement: On our websites (veradial.com and veradial.ca) and our web signup and checkout pages (app.veradial.com), we use the Meta (Facebook) Pixel to measure how our advertising performs and to build and optimize ad audiences. The pixel records page views and a registration-completed event when you create an account, together with standard technical data your browser sends (IP address, user-agent, the page URL, and Meta cookie identifiers). In the Android app, the Meta App Events SDK records first launch/app activation and registration completion, and RevenueCat may send subscription lifecycle events (including trial starts, purchases, conversions, and renewals) to Meta for advertising measurement. Android measurement uses the device advertising identifier, a Meta-generated anonymous app identifier, IP address, and standard device/network data. Automatic client-side purchase logging is disabled so RevenueCat is the only source of subscription revenue events. This integration is not used in the iOS app, and we do not configure it to add your email address, phone number, message content, call audio, transcripts, contacts, or goals/notes. You can limit or reset your Android advertising identifier through device privacy settings and control ad personalization through your Meta account settings.
Apple Search Ads attribution (iOS): If you install or redownload VeraDial after tapping an Apple Search Ads advertisement in the App Store, Apple's AdServices framework provides the app with a short-lived attribution token once purchases are set up. VeraDial passes that token to RevenueCat, which exchanges it with Apple for standard attribution details — whether the install was ad-attributed, and the campaign, ad group, keyword, ad, conversion type, claim type, and country or region Apple reports — so we can measure which advertising leads to trials and paid subscriptions. This uses Apple's Standard attribution data, which does not require the App Tracking Transparency prompt: VeraDial does not ask for tracking permission, does not collect the Advertising Identifier (IDFA) for this purpose, and does not link the Meta advertising SDK into the iOS app. This path does not add your email address, phone number, contacts, message content, call audio, transcripts, or goals/notes. You can limit Apple's ad personalization and attribution in iOS Settings under Privacy & Security.
Demo callers (/demo and /demo/live): When you call our public demo line to try the AI receptionist, your phone number may be processed and hashed (salted SHA-256) for demo analytics, fraud prevention, and conversion attribution. Raw caller phone numbers are not stored in our demo database — only the hash is recorded alongside the demo code your call consumed. Operational call routing logs may contain phone metadata for limited retention. This applies only to inbound calls to our demo number — calls to your own VeraDial number(s) are covered by the call sections above.
Demo post-call summary: After a demo call, we generate a short “here's what Vera captured” summary (outcome, caller name, request, timing) so you can see the kind of message the product produces. The call transcript is sent to Google's Gemini API to produce this summary; raw phone numbers and contact digits are automatically removed before the summary is stored, so the demo database keeps only the short summary, never raw caller contact details. The summary is stored briefly on the demo code and is deleted when that code is swept (used demo codes are removed roughly 24 hours after the call). We do not retain the demo call transcript itself.
2. How We Use Your Information
- Provide calling, messaging, voicemail, and call screening services
- Forward inbound calls to your configured forwarding number when forwarding is enabled
- Display your call activity on an interactive map using location data
- Enforce acceptable use policies and detect abuse
- Process STOP/HELP opt-out requests (TCPA compliance)
- Submit and administer business identity, Brand, Campaign, toll-free verification, and sender-association requests when you ask us to activate carrier-regulated messaging
- Maintain call, message, and voicemail history for your account
- Transcribe recorded calls for your review
- Translate outbound call audio in real-time when you enable call translation
- Generate AI-powered phone calls on your behalf using your instructions
- Store transcripts and summaries of AI calls for your review
- Screen inbound calls and report caller identity to you
- Draft replies to inbound SMS on lines where you enable the AI SMS receptionist, for your approval or automatic sending
- Distill the training material you provide into facts your receptionist can use to answer callers
- Deliver receptionist events to automation endpoints and webhooks you connect
- Send account and lifecycle email, honor unsubscribes, and stop mailing addresses that bounce or report spam
- Protect our public demo and signup pages from automated abuse
- Generate custom voicemail greetings from your text input or recordings
- Create and manage your verified cloned voice when you choose to use voice cloning
- Generate per-contact AI summaries across your calls, AI calls, voicemails, and SMS to help you recall prior context and suggest next-call goals
- Provide read-only access to the VeraDial data you request through an AI assistant that you explicitly connect and authorize
- Answer questions about your VeraDial account, explain setup, and prepare outbound call drafts for your review in the app
- Send push notifications for incoming messages, voicemails, missed calls, AI call completions, and low balance alerts
- Manage your subscription and credit balance
- Diagnose and fix technical issues using error reports
- Measure website and Android acquisition performance without changing Supabase authentication or sending account identity to Google Analytics
3. Third-Party Services
We share data with the following third-party services as necessary to provide VeraDial's features. Each service processes only the data required for its specific function. We require service providers that process personal data for VeraDial to protect that data under privacy and security obligations that provide the same or equal protection required by this Privacy Policy.
Twilio: Voice calls, SMS delivery, phone number provisioning, call recording, voicemail recording, toll-free verification, and A2P 10DLC business identity, Brand, Campaign, and sender registration. Twilio processes call audio and message content and, when you request carrier registration, the business identity, messaging use case, public consent evidence, and verification information required for that registration. Twilio Privacy Policy
Supabase: Authentication, database hosting (US-West-2 region), and file storage for voicemail greeting audio. Supabase Privacy Policy
RevenueCat: In-app and web purchase management, subscription tracking, and any one-time or recurring carrier-registration fee offered by VeraDial. RevenueCat returns transaction identifiers and purchase metadata that VeraDial uses to authorize only the matching registration action. On Android, RevenueCat also processes advertising identifiers and sends selected subscription lifecycle events to Meta for advertising attribution and measurement. On iOS, RevenueCat processes the Apple AdServices attribution token and exchanges it with Apple for the standard Apple Search Ads campaign details described in Section 1, so ad-attributed installs can be measured against subscription outcomes. RevenueCat Privacy Policy
ElevenLabs: AI voice processing for AI Call, ElevenLabs-backed Call Screening, and Voicemail Greetings. For AI calls and ElevenLabs screening, call audio and your instructions or screening prompts are processed to generate the AI agent's responses. For voicemail greetings, your greeting text is converted to speech audio. ElevenLabs Privacy Policy
Cartesia: Voice cloning and cloned voice text-to-speech for voicemail greetings. When you create a cloned voice, your recorded sample is sent to Cartesia to create the voice model. When you generate a greeting with that clone, your greeting text and selected voice identifier are sent to Cartesia to generate audio. Cartesia Privacy Policy
OpenAI: AI voice processing for AI Call, Call Screening when selected through LiveKit screening, and real-time Call Translation. When OpenAI is selected as the AI provider, call audio and your instructions or screening prompts are processed in real-time by OpenAI's Realtime API to generate the AI agent's responses. When you enable call translation, both parties' call audio is processed in real-time by OpenAI to generate the translated speech. OpenAI Privacy Policy
Connected AI assistant providers (including OpenAI/ChatGPT and Anthropic/Claude): When you explicitly connect and authorize an AI assistant, VeraDial sends only the account data returned by the read-only tool you ask that assistant to use. The assistant provider receives that data over an encrypted connection and may retain or use it under its own privacy policy, retention settings, and account controls. Disconnecting VeraDial in the assistant stops that assistant from making future connector requests, but it may not delete data the provider already retained; use the provider's controls for those copies. OpenAI Privacy Policy · Anthropic Privacy Policy
Google (Gemini): AI processing for AI Call, LiveKit-routed Call Screening when Gemini is selected, Contact Memory, the AI SMS receptionist, custom training sources, the in-app account assistant, the demo receptionist builder, and the demo post-call summary. For the AI SMS receptionist, the inbound message text, recent conversation history, any attached MMS media, and your line's receptionist instructions are sent to Gemini to draft a reply. For custom training sources, the text extracted from the document or web page you provide is sent to Gemini to produce the distilled summary. For AI calls and screening, call audio and your instructions or screening prompts are processed in real-time by Google's Gemini API to generate the AI agent's responses. For Contact Memory, text from your call transcripts, voicemail transcriptions, AI call summaries, and SMS messages is sent to Google's Gemini API to generate per-contact summaries. When you use the in-app account assistant, your latest question and a bounded set of your recent questions are sent to Gemini only to select a permitted intent, help entry, and at most one read-only account tool. Account facts returned by that tool are formatted inside VeraDial and are not sent to Gemini; this assistant does not create proposed call drafts. For the demo builder, the business details we extract are sent to Gemini to draft your demo receptionist's profile. For the demo post-call summary, the demo call transcript is sent to Gemini to produce a short summary of what the receptionist captured (with raw phone numbers and contact digits removed before storage). Google receives this content only when the corresponding feature is used. Google Privacy Policy
xAI (Grok): AI voice processing for AI Call and, when selected through LiveKit screening, Call Screening. When xAI is selected as the AI provider, call audio and your instructions or screening prompts are processed by xAI's Grok API to generate the AI agent's responses. xAI Privacy Policy
LiveKit: Real-time audio routing and SIP connectivity for AI calls and LiveKit-backed call screening. When LiveKit transport is used, call audio is routed through LiveKit's infrastructure to connect the AI agent with the phone call. LiveKit processes call audio in transit but does not store it. LiveKit Privacy Policy
Google Calendar: Appointment booking during call screening, if you choose to connect it. VeraDial requests free/busy time ranges from your main Google calendar and from the separate “VeraDial Bookings” calendar it creates in your Google account, and creates and manages events only on that Bookings calendar. The authorization VeraDial requests does not permit reading event titles, descriptions, or attendees on your other calendars, or modifying those calendars. You can revoke access at any time from within VeraDial or from your Google Account security settings. Google Privacy Policy
Google Maps: The Call Map feature uses Google Maps to display your call locations. When you use Call Map, Google receives map tile requests and your viewport region. Google Maps is subject to Google's Privacy Policy.
Google Analytics / Firebase: Website traffic and marketing measurement for veradial.com and veradial.ca, plus Android app acquisition and activation measurement. Google processes website page views and events, Android app-instance and advertising identifiers, lifecycle/session/engagement data, standard browser/app/device data, masked-IP-derived approximate location, and possible Google Play purchase/subscription events. VeraDial also sends signup method and activation mode from Android. We do not configure a Firebase Analytics user ID or send account identity, contact, message, call, audio, transcript, recording, business-profile, website, goal, note, or prompt data. Google Analytics for Firebase is not linked into the iOS app. Google Privacy Policy
Deepgram: Speech-to-text transcription for recorded calls, voicemails, and message dictation. When you record a call, when a caller leaves a voicemail on your VeraDial number, or when you use the in-app microphone button to dictate a message, the audio is sent to Deepgram for automatic transcription. Dictation clips are processed to produce the text and are not stored by VeraDial. Deepgram Privacy Policy
Sentry: Error tracking and crash reporting. We send error reports and diagnostic data to Sentry to identify and fix technical issues. Sentry does not receive message content or call audio. Sentry Privacy Policy
PostHog: Product analytics for the app and website. We send anonymized event data (screen views, feature usage, paywall and purchase events, website page views, demo funnel events, and app store click events) to PostHog to understand how VeraDial is used and improve the product. Sensitive fields are stripped before analytics events are sent; GeoIP is disabled; masked website session replay is limited to /demo and /demo/live and is not used in the mobile app or on non-demo website pages. PostHog does not receive message content, call audio, transcripts, contact details, or unmasked form input values; analytics events strip raw website URLs with query strings. PostHog Privacy Policy
Expo: Push notification delivery. Device push tokens are sent through Expo's push notification service, which routes them to Apple Push Notification service (APNs) or Firebase Cloud Messaging (FCM) for delivery to your device. Expo Privacy Policy
Vercel: Website hosting and analytics. We use Vercel Analytics and Speed Insights to understand website performance. These tools collect anonymous usage data and do not use cookies for tracking. Vercel Privacy Policy
Meta (Facebook): Advertising and conversion measurement on our website, web signup flow, and Android app. We use the Meta Pixel for website page views and registrations; the Android Meta App Events SDK for first launch/app activation and registration completion; and RevenueCat's Meta integration for selected subscription lifecycle events. Meta receives these events with relevant browser or Android advertising identifiers, IP address, and standard device/network data. The integration is not used in the iOS app, and we do not configure it to add your email address, phone number, message content, call audio, transcripts, contacts, or goals/notes. Meta Privacy Policy
Firecrawl: Website content extraction for the demo receptionist builder and for custom training sources you add by web address. Firecrawl fetches the public web page and returns extracted text and metadata, so the demo can be tailored to your business or the page can be distilled into receptionist facts. Firecrawl receives the URL you submit and the page content it extracts. Firecrawl Privacy Policy
Resend: Delivery of account and lifecycle email. Resend receives your account email address, the message content we send you, and returns delivery outcomes (such as delivered, bounced, or complained) that we use to honor unsubscribes and stop mailing bad addresses. Resend Privacy Policy
Cloudflare: Bot protection on our public demo builder and web signup pages through Cloudflare Turnstile. Cloudflare receives the challenge token and your IP address to verify the request is not automated. Cloudflare Privacy Policy
Automation endpoints you connect (such as Zapier, Make, or n8n): If you connect an automation tool or register your own webhook endpoint, VeraDial delivers the receptionist events you subscribed to — including the caller's number and name, event summaries, and, only if you turn on full content for that endpoint, transcripts and voicemail transcriptions. These destinations are chosen and controlled by you, not by VeraDial: once an event is delivered, the receiving service handles that data under its own terms and privacy policy and under any onward automations you build. Removing the endpoint in VeraDial stops future deliveries but does not delete data the destination already received. Zapier Privacy Policy
Apple / Google: App distribution and payment processing via the App Store and Google Play Store. If you install VeraDial from an Apple Search Ads advertisement, Apple additionally provides standard ad attribution details for that install through its AdServices framework, which we receive through RevenueCat. Apple Privacy Policy · Google Privacy Policy
4. SMS Consent & Opt-Out
Messages VeraDial sends you directly. When you enter your mobile number on our demo at veradial.com/demo to try a live AI call, you agree to receive texts from VeraDial at that number: a one-time verification code (reply YES to authorize the demo call) and one short summary after the call. This is a double opt-in — you enter your number, then confirm by replying YES. Message frequency is typically one to three texts per demo. Message and data rates may apply. Reply STOP to opt out or HELP for help. Full details are in our SMS Terms & Messaging Policy.
Business messaging. SMS consent on VeraDial is consumer-initiated. When you call or text a VeraDial business number to reach that business, you consent to receive SMS replies and follow-up messages from that business, at the number you used, about that conversation. VeraDial sends no bulk, automated, promotional, or marketing messages and never messages anyone who has not first contacted the account holder. Message frequency varies. Message and data rates may apply. Full details are in our SMS Terms & Messaging Policy.
- Recipients can text STOP to opt out of messages from any VeraDial number at any time; opt-out is enforced automatically.
- We honor HELP requests with support contact information.
- Opt-out records are maintained per sender/recipient pair.
- Consent status is checked before every outbound message.
- We do not sell your phone number, message content, or consent, and we do not share them with third parties or affiliates for marketing or promotional purposes.
5. Push Notifications
VeraDial sends push notifications for incoming messages, new voicemails, missed calls, AI call completions, and low credit balance alerts.
For your privacy, notifications display only the sender or caller number — no message content, voicemail transcriptions, or AI summaries appear on your lock screen.
You can disable notifications at any time through your device's system settings. Push tokens are stored on our server and are automatically deleted when you sign out or your session expires.
6. Data Retention
- Call logs and SMS history: Retained for the lifetime of your account.
- Call recordings: Retained on Twilio's servers for the lifetime of your account.
- Call transcripts: Retained alongside call records for the lifetime of your account.
- Call screening data: Retained with call logs for the lifetime of your account.
- Location data: GPS coordinates are stored with call records for the lifetime of your account.
- Voicemail recordings: Retained for the lifetime of your account.
- Voicemail greetings: Retained until you delete them or your account is deleted.
- Voice clones: Retained until you delete the cloned voice or your account is deleted. Deleting a cloned voice removes VeraDial's reference to the provider voice model and deletes generated greetings made with that clone. Raw enrollment samples are not retained after successful clone creation.
- Call forwarding settings: Retained until you change them or your account is deleted.
- Opt-out records: Retained indefinitely as required for TCPA compliance.
- Carrier-registration records: Safe business metadata, public evidence URLs, provider identifiers and statuses, fee-authorization records, sender bindings, and audit events are retained while the registration or account is active and as reasonably required afterward for carrier compliance, billing disputes, fraud prevention, and audit. On account deletion, VeraDial attempts to detach senders and retire Campaign and dedicated Messaging Service resources where the provider supports it before releasing the number. Twilio may retain approved business identity, Customer Profile, Trust Product, or Brand records that its APIs or policies do not permit VeraDial to delete; VeraDial retains a limited audit record of that provider-retention disposition rather than claiming the provider deleted it. Raw tax/government identifiers and one-time passcodes are not intentionally retained by VeraDial after submission.
- AI Call transcripts: Transcripts and summaries are retained for the lifetime of your account. Call goals and notes are stored with each AI call record.
- Contact memory summaries: Per-contact summaries are retained for the lifetime of your account unless you delete your account. If you disable Contact Memory, existing summaries are no longer read through the feature or updated.
- AI SMS receptionist drafts: Drafted replies and their approval status are retained with the SMS conversation for the lifetime of your account. Turning the AI SMS receptionist off stops new drafts from being generated; messages you already sent remain in your message history.
- Custom training sources: Uploaded files, stored web addresses, and distilled summaries are retained until you delete the source or your account. Deleting a source removes the stored file and its distilled summary, and the receptionist stops using it.
- Connected automation endpoints: Endpoint configuration, signing secrets, subscribed event types, and delivery attempt records are retained until you remove the endpoint or delete your account. Data already delivered to an endpoint is retained by that destination under its own policies, not by VeraDial.
- Service email records: Records of which lifecycle emails were sent to you, your unsubscribe preference, and delivery outcomes are retained for the lifetime of your account. Unsubscribe and suppression records may be retained after account deletion where needed to keep honoring an opt-out.
- Connected AI assistants: VeraDial does not create a separate retained copy of account data merely because the connector returns it. Your existing VeraDial records follow the retention periods above. An assistant provider may retain copies under its own policy and account settings; disconnecting VeraDial prevents future connector access but does not by itself delete copies already retained by that provider.
- In-app account assistant: VeraDial stores questions, replies, question categories, answer status, turn outcomes, and fixed tool names. Starting a new conversation deletes handled and system-error turns from the cleared conversation; unsupported questions, Vera's bounded decline replies, and any question and reply you marked with a thumbs down are kept so the problem can be reviewed and fixed, and are then deleted automatically 90 days after the question was asked. A thumbs up keeps no extra text — only the rating itself. Ratings are deleted with the reply they belong to. That deletion runs on a schedule and does not depend on you returning to the assistant. Once nothing is left from a cleared conversation, the conversation record itself is removed. The assistant does not read or store contacts, authentication data, call or voicemail transcripts, voicemail content, or SMS bodies through this feature.
- Google Calendar connection and bookings: The encrypted refresh token, connected Google account identifiers, and the identifier of the VeraDial Bookings calendar are retained until you disconnect Google Calendar or delete your account. Appointment records are retained for the lifetime of your account, including after you disconnect. Events already written to your “VeraDial Bookings” calendar remain in your Google account until you delete them there.
- Push tokens: Deleted when you sign out, your session expires, or your device is no longer registered.
- Released/swapped numbers: Records retained with “swapped” or “released” status.
- Error reports: Retained by Sentry per their data retention policies.
- Fraud-prevention records that outlast deletion: A small set of narrow records is kept after an account is deleted, because deleting an account would otherwise erase the evidence of abuse committed with it and reset the limits that abuse prevention depends on. Each record is detached from the deleted account — the link to the account is removed, but the listed data itself is kept, so these records are pseudonymized rather than fully anonymous: the phone-claim record (a keyed hash of the verified phone number, its last four digits, and line type — never the number itself), the receptionist-identity screening record (a hash of the screened identity and the screening verdict — no identity text), abuse case records (the case type, the description of the detected behaviour, any phone number the case concerns, and whether it was resolved), and refused-attempt records — the policy decisions that blocked a message or call before it was sent (for messages: hashed destination and content fingerprints, counts, and the refusal reason, never message text or raw numbers; for calls: the phone number dialed, the caller ID attempted, and the refusal reason — these call records do contain the raw phone numbers involved in the refused attempt), and network and device observations (the IP addresses, user-agent strings, and per-install device identifiers described in Section 1, with the times each was first and last seen). Refused-attempt records are deleted no later than 12 months after the attempt was made, whether or not the account still exists; records of messages and calls that were allowed are deleted with the account. Network and device observations are deleted no later than 90 days after the account is deleted. These records are used only for abuse prevention and for responding to carrier, provider, and lawful requests.
- Account deletion: Use the in-app deletion flow in VeraDial or visit veradial.com/delete-account for deletion instructions and retention details.
7. Data Security
We use industry-standard measures to protect your data, including encryption in transit (TLS/HTTPS), authenticated API access, and secure credential storage. Authentication tokens are validated using public-key cryptography (ES256 via JWKS).
While we take reasonable steps to protect your information, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.
8. Data Processing & International Transfers
Your data is stored and processed in the United States (US-West-2 region, Oregon). If you are located outside the United States, your data will be transferred to and processed in the United States. By using VeraDial, you consent to this transfer.
Our third-party service providers may process data in their own data centers, which may be located in different regions. See Section 3 for details on each provider.
9. Abuse Prevention & Account Suspension
We monitor for patterns consistent with harassment, fraud, or illegal use. For accounts flagged for suspected abuse, monitoring may include automated review of call transcripts, voicemail transcriptions, AI-call conversation records, and message content associated with the flagged account, together with the network and device signals described in Section 1. Automated review is used to surface suspected abuse for human review; accounts may be suspended or terminated for policy violations. Abuse cases are logged and retained.
10. Children's Privacy
VeraDial is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us at support@veradial.com and we will promptly delete it.
11. Your Rights
California residents (CCPA): You have the right to know what data we collect, request deletion, and opt out of the sale or sharing of personal information for cross-context behavioral advertising. We do not sell your personal data. Our use of Meta for audience optimization may be considered sharing under California law; you can limit it through your browser/device and Meta ad settings or contact us to exercise your rights.
Canadian residents (PIPEDA): You have the right to access your personal information held by VeraDial, challenge its accuracy, and withdraw consent for its collection, use, or disclosure. We collect and use personal information only for purposes that a reasonable person would consider appropriate.
EU/EEA residents (GDPR): You have the right to access, rectify, erase, and port your data.
To exercise your rights, email support@veradial.com.
12. Emergency Services
VeraDial is NOT a replacement for traditional phone service. 911 and emergency calling is not supported. Do not rely on VeraDial for emergency communications.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we make changes, we will update the “Last updated” date at the top of this page. For material changes, we will notify you through the app or by email. Your continued use of VeraDial after changes are posted constitutes your acceptance of the updated policy.
14. Contact
For privacy inquiries, contact us at support@veradial.com.