Skip to content
VeraDial

Privacy Policy

Last updated: July 15, 2026

VeraDial is operated by VeraDial Inc. In this policy, “VeraDial”, “we”, and “us” refer to VeraDial Inc., the entity responsible for the personal information described below.

1. Information We Collect

Account data: When you create an account, we collect your email address and profile information through Supabase Auth.

Caller profile: If you use AI Calling, we store your display name, website, and caller context that you provide. These are used to identify you on AI calls and voicemail greetings.

Phone numbers: We store information about your purchased phone numbers (including Twilio SID, capabilities, region, and country) and any verified caller IDs you add.

Call records: We maintain call logs including from/to numbers, duration, timestamps, and Twilio call SID for your account history.

Call recordings: When you enable call recording on outbound calls or AI calls, dual-channel audio is recorded by Twilio and stored on their servers. We store a reference to the recording and provide playback through our app.

Call transcripts: When you record a call, the audio is automatically sent to a third-party speech recognition service (Deepgram) for transcription. We store structured transcripts including speaker identification, text, and timestamps alongside the call record.

Call screening data: When call screening is enabled, we store the screening interaction data including the caller's stated identity and intent, a conversation identifier, and timestamp.

Call forwarding: If you configure call forwarding, we store your forwarding phone number and enabled/disabled preference on your profile.

Location data: When you make or receive calls, we may collect your device's GPS coordinates to associate a location with the call record. Location data is used to display your calls on the Call Map feature. Location collection requires your permission and can be disabled through your device's system settings.

SMS content: We store message bodies, sender/recipient numbers, timestamps, and delivery status for messages sent and received through the service. For inbound MMS, we copy any attached media (such as photos) from Twilio into private cloud storage (Supabase Storage) and reference it on the message; the app retrieves it through short-lived signed URLs.

Consent records: We maintain SMS consent status and timestamps to comply with telecommunications regulations.

Voicemail: We store voicemail recordings, transcriptions, duration, and caller information for voicemails left on your VeraDial number. Voicemail audio is recorded by Twilio and transcribed by a third-party speech recognition service (Deepgram).

Voicemail greetings: If you create a custom voicemail greeting, we store the greeting audio file. For AI-generated greetings, we also store the text you write and the voice you select; audio is generated by a third-party AI provider (ElevenLabs or Cartesia, depending on the voice type). For recorded greetings, your uploaded audio is converted to MP3 format on our server. All greeting audio is stored in cloud storage (Supabase Storage).

Voice cloning: If you create a cloned voice, we collect the voice sample you record, your consent acknowledgment, and metadata about the resulting voice model. The raw voice sample is processed server-side and sent to Cartesia to create the clone; VeraDial does not retain the raw sample after successful clone creation. We store the Cartesia voice identifier, clone name, consent record, and generated greeting audio made with that clone until you delete the clone, the greeting, or your account.

AI Call data: When you use AI Call, we store the phone number called, your call goal and notes, call duration, the AI provider used, and the full conversation transcript and summary generated by the AI agent. If you enable recording on an AI call, the recording is stored by Twilio and referenced in your account. Call audio is processed in real-time by the selected AI provider (ElevenLabs, OpenAI, Google, or xAI) and is not stored by VeraDial.

Call translation: When you enable two-way translation on an outbound call, your call audio and the other party's audio are streamed in real-time to OpenAI to generate translated speech. Translation audio is processed in transit to produce the translation and is not stored by VeraDial. We store the translation status of the call (whether translation was used and its outcome) alongside the call record.

Contact memory: If you explicitly turn on Contact Memory in Profile > Contact Memory, we generate a rolling AI summary for each phone number you interact with, using your call transcripts, voicemail transcriptions, AI call transcripts and summaries, and SMS message content from your own account. Summaries, a suggested next-call goal, and the phone number are stored in your account. Summarization is performed by a third-party AI provider (Google Gemini). When Contact Memory is disabled, existing summaries are not read through the feature and new summaries are not generated; existing summaries remain stored unless you delete your account.

Push notification tokens: We store device push tokens to deliver notifications to your device. Tokens are automatically deleted when you sign out or your session expires.

Billing: Purchase and subscription history is managed through RevenueCat and the Apple App Store / Google Play Store. We store your subscription status, billing period, and credit balance. We do not store payment card details directly. On Android, RevenueCat also receives the device's advertising identifier and a Meta-generated anonymous app identifier so subscription events can be attributed to advertising. We do not configure this attribution path to add your email address, phone number, message content, call audio, or transcripts.

Error and crash data: We collect error reports and crash data through Sentry to diagnose and fix issues with the app. This may include device information, OS version, and stack traces. No message content or call audio is included in error reports.

Product analytics: We collect anonymized product analytics through PostHog to understand how the app and website are used (screen views, navigation paths, feature engagement, paywall and purchase events, website page views, demo funnel events, and app store click events). Sensitive fields (email, phone numbers, message content, transcripts, recording URLs, raw URLs with query strings, location, goals/notes/prompts) are stripped before analytics events are sent. GeoIP is disabled. On /demo and /demo/live only, we may use masked website session replay through PostHog to diagnose demo-funnel issues; all text and input values are masked, replay respects Do Not Track / Global Privacy Control, and internal traffic is excluded where flagged. Session replay is not used in the mobile app or on non-demo website pages. Analytics are disabled in development builds and screenshot/test builds by default.

Advertising and conversion measurement: On our website (veradial.com) and our web signup and checkout pages (app.veradial.com), we use the Meta (Facebook) Pixel to measure how our advertising performs and to build and optimize ad audiences. The pixel records page views and a registration-completed event when you create an account, together with standard technical data your browser sends (IP address, user-agent, the page URL, and Meta cookie identifiers). In the Android app, the Meta App Events SDK records first launch/app activation and registration completion, and RevenueCat may send subscription lifecycle events (including trial starts, purchases, conversions, and renewals) to Meta for advertising measurement. Android measurement uses the device advertising identifier, a Meta-generated anonymous app identifier, IP address, and standard device/network data. Automatic client-side purchase logging is disabled so RevenueCat is the only source of subscription revenue events. This integration is not used in the iOS app, and we do not configure it to add your email address, phone number, message content, call audio, transcripts, contacts, or goals/notes. You can limit or reset your Android advertising identifier through device privacy settings and control ad personalization through your Meta account settings.

Demo callers (/demo and /demo/live): When you call our public demo line to try the AI receptionist, your phone number may be processed and hashed (salted SHA-256) for demo analytics, fraud prevention, and conversion attribution. Raw caller phone numbers are not stored in our demo database — only the hash is recorded alongside the demo code your call consumed. Operational call routing logs may contain phone metadata for limited retention. This applies only to inbound calls to our demo number — calls to your own VeraDial number(s) are covered by the call sections above.

Demo post-call summary: After a demo call, we generate a short “here's what Vera captured” summary (outcome, caller name, request, timing) so you can see the kind of message the product produces. The call transcript is sent to Google's Gemini API to produce this summary; raw phone numbers and contact digits are automatically removed before the summary is stored, so the demo database keeps only the short summary, never raw caller contact details. The summary is stored briefly on the demo code and is deleted when that code is swept (used demo codes are removed roughly 24 hours after the call). We do not retain the demo call transcript itself.

2. How We Use Your Information

  • Provide calling, messaging, voicemail, and call screening services
  • Forward inbound calls to your configured forwarding number when forwarding is enabled
  • Display your call activity on an interactive map using location data
  • Enforce acceptable use policies and detect abuse
  • Process STOP/HELP opt-out requests (TCPA compliance)
  • Maintain call, message, and voicemail history for your account
  • Transcribe recorded calls for your review
  • Translate outbound call audio in real-time when you enable call translation
  • Generate AI-powered phone calls on your behalf using your instructions
  • Store transcripts and summaries of AI calls for your review
  • Screen inbound calls and report caller identity to you
  • Generate custom voicemail greetings from your text input or recordings
  • Create and manage your verified cloned voice when you choose to use voice cloning
  • Generate per-contact AI summaries across your calls, AI calls, voicemails, and SMS to help you recall prior context and suggest next-call goals
  • Send push notifications for incoming messages, voicemails, missed calls, AI call completions, and low balance alerts
  • Manage your subscription and credit balance
  • Diagnose and fix technical issues using error reports

3. Third-Party Services

We share data with the following third-party services as necessary to provide VeraDial's features. Each service processes only the data required for its specific function. We require service providers that process personal data for VeraDial to protect that data under privacy and security obligations that provide the same or equal protection required by this Privacy Policy.

Twilio: Voice calls, SMS delivery, phone number provisioning, call recording, and voicemail recording. Twilio processes call audio and message content. Twilio Privacy Policy

Supabase: Authentication, database hosting (US-West-2 region), and file storage for voicemail greeting audio. Supabase Privacy Policy

RevenueCat: In-app purchase management and subscription tracking. On Android, RevenueCat also processes advertising identifiers and sends selected subscription lifecycle events to Meta for advertising attribution and measurement. RevenueCat Privacy Policy

ElevenLabs: AI voice processing for AI Call, ElevenLabs-backed Call Screening, and Voicemail Greetings. For AI calls and ElevenLabs screening, call audio and your instructions or screening prompts are processed to generate the AI agent's responses. For voicemail greetings, your greeting text is converted to speech audio. ElevenLabs Privacy Policy

Cartesia: Voice cloning and cloned voice text-to-speech for voicemail greetings. When you create a cloned voice, your recorded sample is sent to Cartesia to create the voice model. When you generate a greeting with that clone, your greeting text and selected voice identifier are sent to Cartesia to generate audio. Cartesia Privacy Policy

OpenAI: AI voice processing for AI Call, Call Screening when selected through LiveKit screening, and real-time Call Translation. When OpenAI is selected as the AI provider, call audio and your instructions or screening prompts are processed in real-time by OpenAI's Realtime API to generate the AI agent's responses. When you enable call translation, both parties' call audio is processed in real-time by OpenAI to generate the translated speech. OpenAI Privacy Policy

Google (Gemini): AI processing for AI Call, LiveKit-routed Call Screening when Gemini is selected, Contact Memory, the demo receptionist builder, and the demo post-call summary. For AI calls and screening, call audio and your instructions or screening prompts are processed in real-time by Google's Gemini API to generate the AI agent's responses. For Contact Memory, text from your call transcripts, voicemail transcriptions, AI call summaries, and SMS messages is sent to Google's Gemini API to generate per-contact summaries. For the demo builder, the business details we extract are sent to Gemini to draft your demo receptionist's profile. For the demo post-call summary, the demo call transcript is sent to Gemini to produce a short summary of what the receptionist captured (with raw phone numbers and contact digits removed before storage). Google receives this content only when the corresponding feature is used. Google Privacy Policy

xAI (Grok): AI voice processing for AI Call and, when selected through LiveKit screening, Call Screening. When xAI is selected as the AI provider, call audio and your instructions or screening prompts are processed by xAI's Grok API to generate the AI agent's responses. xAI Privacy Policy

LiveKit: Real-time audio routing and SIP connectivity for AI calls and LiveKit-backed call screening. When LiveKit transport is used, call audio is routed through LiveKit's infrastructure to connect the AI agent with the phone call. LiveKit processes call audio in transit but does not store it. LiveKit Privacy Policy

Google Maps: The Call Map feature uses Google Maps to display your call locations. When you use Call Map, Google receives map tile requests and your viewport region. Google Maps is subject to Google's Privacy Policy.

Deepgram: Speech-to-text transcription for recorded calls and voicemails. When you record a call, or when a caller leaves a voicemail on your VeraDial number, the audio is sent to Deepgram for automatic transcription. Deepgram Privacy Policy

Sentry: Error tracking and crash reporting. We send error reports and diagnostic data to Sentry to identify and fix technical issues. Sentry does not receive message content or call audio. Sentry Privacy Policy

PostHog: Product analytics for the app and website. We send anonymized event data (screen views, feature usage, paywall and purchase events, website page views, demo funnel events, and app store click events) to PostHog to understand how VeraDial is used and improve the product. Sensitive fields are stripped before analytics events are sent; GeoIP is disabled; masked website session replay is limited to /demo and /demo/live and is not used in the mobile app or on non-demo website pages. PostHog does not receive message content, call audio, transcripts, contact details, or unmasked form input values; analytics events strip raw website URLs with query strings. PostHog Privacy Policy

Expo: Push notification delivery. Device push tokens are sent through Expo's push notification service, which routes them to Apple Push Notification service (APNs) or Firebase Cloud Messaging (FCM) for delivery to your device. Expo Privacy Policy

Vercel: Website hosting and analytics. We use Vercel Analytics and Speed Insights to understand website performance. These tools collect anonymous usage data and do not use cookies for tracking. Vercel Privacy Policy

Meta (Facebook): Advertising and conversion measurement on our website, web signup flow, and Android app. We use the Meta Pixel for website page views and registrations; the Android Meta App Events SDK for first launch/app activation and registration completion; and RevenueCat's Meta integration for selected subscription lifecycle events. Meta receives these events with relevant browser or Android advertising identifiers, IP address, and standard device/network data. The integration is not used in the iOS app, and we do not configure it to add your email address, phone number, message content, call audio, transcripts, contacts, or goals/notes. Meta Privacy Policy

Firecrawl: Website content extraction for the demo receptionist builder. When you submit a business URL in the public demo flow to generate an AI receptionist preview, Firecrawl fetches the public web page and returns extracted text and metadata so the demo can be tailored to your business. Firecrawl receives the URL you submit and the page content it extracts. Firecrawl Privacy Policy

Apple / Google: App distribution and payment processing via the App Store and Google Play Store.

4. SMS Consent & Opt-Out

Messages VeraDial sends you directly. When you enter your mobile number on our demo at veradial.com/demo to try a live AI call, you agree to receive texts from VeraDial at that number: a one-time verification code (reply YES to authorize the demo call) and one short summary after the call. This is a double opt-in — you enter your number, then confirm by replying YES. Message frequency is typically one to three texts per demo. Message and data rates may apply. Reply STOP to opt out or HELP for help. Full details are in our SMS Terms & Messaging Policy.

Business messaging. SMS consent on VeraDial is consumer-initiated. When you call or text a VeraDial business number to reach that business, you consent to receive SMS replies and follow-up messages from that business, at the number you used, about that conversation. VeraDial sends no bulk, automated, promotional, or marketing messages and never messages anyone who has not first contacted the account holder. Message frequency varies. Message and data rates may apply. Full details are in our SMS Terms & Messaging Policy.

  • Recipients can text STOP to opt out of messages from any VeraDial number at any time; opt-out is enforced automatically.
  • We honor HELP requests with support contact information.
  • Opt-out records are maintained per sender/recipient pair.
  • Consent status is checked before every outbound message.
  • We do not sell your phone number, message content, or consent, and we do not share them with third parties or affiliates for marketing or promotional purposes.

5. Push Notifications

VeraDial sends push notifications for incoming messages, new voicemails, missed calls, AI call completions, and low credit balance alerts.

For your privacy, notifications display only the sender or caller number — no message content, voicemail transcriptions, or AI summaries appear on your lock screen.

You can disable notifications at any time through your device's system settings. Push tokens are stored on our server and are automatically deleted when you sign out or your session expires.

6. Data Retention

  • Call logs and SMS history: Retained for the lifetime of your account.
  • Call recordings: Retained on Twilio's servers for the lifetime of your account.
  • Call transcripts: Retained alongside call records for the lifetime of your account.
  • Call screening data: Retained with call logs for the lifetime of your account.
  • Location data: GPS coordinates are stored with call records for the lifetime of your account.
  • Voicemail recordings: Retained for the lifetime of your account.
  • Voicemail greetings: Retained until you delete them or your account is deleted.
  • Voice clones: Retained until you delete the cloned voice or your account is deleted. Deleting a cloned voice removes VeraDial's reference to the provider voice model and deletes generated greetings made with that clone. Raw enrollment samples are not retained after successful clone creation.
  • Call forwarding settings: Retained until you change them or your account is deleted.
  • Opt-out records: Retained indefinitely as required for TCPA compliance.
  • AI Call transcripts: Transcripts and summaries are retained for the lifetime of your account. Call goals and notes are stored with each AI call record.
  • Contact memory summaries: Per-contact summaries are retained for the lifetime of your account unless you delete your account. If you disable Contact Memory, existing summaries are no longer read through the feature or updated.
  • Push tokens: Deleted when you sign out, your session expires, or your device is no longer registered.
  • Released/swapped numbers: Records retained with “swapped” or “released” status.
  • Error reports: Retained by Sentry per their data retention policies.
  • Account deletion: Use the in-app deletion flow in VeraDial or visit veradial.com/delete-account for deletion instructions and retention details.

7. Data Security

We use industry-standard measures to protect your data, including encryption in transit (TLS/HTTPS), authenticated API access, and secure credential storage. Authentication tokens are validated using public-key cryptography (ES256 via JWKS).

While we take reasonable steps to protect your information, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.

8. Data Processing & International Transfers

Your data is stored and processed in the United States (US-West-2 region, Oregon). If you are located outside the United States, your data will be transferred to and processed in the United States. By using VeraDial, you consent to this transfer.

Our third-party service providers may process data in their own data centers, which may be located in different regions. See Section 3 for details on each provider.

9. Abuse Prevention & Account Suspension

We monitor for patterns consistent with harassment, fraud, or illegal use. Accounts may be suspended or terminated for policy violations. Abuse cases are logged and retained.

10. Children's Privacy

VeraDial is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us at support@veradial.com and we will promptly delete it.

11. Your Rights

California residents (CCPA): You have the right to know what data we collect, request deletion, and opt out of the sale or sharing of personal information for cross-context behavioral advertising. We do not sell your personal data. Our use of Meta for audience optimization may be considered sharing under California law; you can limit it through your browser/device and Meta ad settings or contact us to exercise your rights.

Canadian residents (PIPEDA): You have the right to access your personal information held by VeraDial, challenge its accuracy, and withdraw consent for its collection, use, or disclosure. We collect and use personal information only for purposes that a reasonable person would consider appropriate.

EU/EEA residents (GDPR): You have the right to access, rectify, erase, and port your data.

To exercise your rights, email support@veradial.com.

12. Emergency Services

VeraDial is NOT a replacement for traditional phone service. 911 and emergency calling is not supported. Do not rely on VeraDial for emergency communications.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we make changes, we will update the “Last updated” date at the top of this page. For material changes, we will notify you through the app or by email. Your continued use of VeraDial after changes are posted constitutes your acceptance of the updated policy.

14. Contact

For privacy inquiries, contact us at support@veradial.com.