Privacy Policy
Last updated: July 20, 2026 · Effective: July 20, 2026
RubyVox ("RubyVox," "we," "us," or "our") builds shareable browser-based AI voice agents. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices you have. It applies to rubyvox.com, our subdomains, our web app, and any voice agents built or hosted on our platform (collectively, the "Services").
By using the Services you agree to this Policy. If you do not agree, do not use the Services.
1. Who we are and who this applies to
RubyVox operates the Services from Dallas, Texas, USA. We serve two audiences:
- Builders — account holders who create voice agents.
- Callers — end users who talk with a builder's voice agent, whether in a browser or by phone.
When you are a builder, RubyVox is the controller of your account data. When a caller interacts with a builder's agent, the builder is the controller of the conversation content and RubyVox acts as a processor on the builder's behalf.
2. Information we collect
Account information. Name, email, phone number, password hash, plan tier, and profile settings.
Agent content. Instructions, knowledge sources, voice selection, branding, and configuration you provide.
Conversation data. Audio, transcripts, tool calls, and summaries generated when a caller talks with an agent. Callers may also provide their name, phone number, email, or booking details during a conversation.
Caller memory. If a builder enables persistent memory, we store a hashed device token or phone number so a returning caller can be recognized by that specific agent, along with a small structured memory record.
Telephony metadata. Phone numbers, call start and end times, duration, direction, and status codes for calls placed over our telephony providers.
Payment information. Handled by our payment processor. We do not store full card numbers.
Device and usage. IP address, browser, device type, pages viewed, timestamps, and error logs.
Cookies. Authentication and preference cookies necessary to run the app, plus limited first-party analytics.
3. Voice, telephony, and messaging
Voice conversations are transported to our AI voice provider for real-time speech recognition and speech synthesis. Telephone calls and SMS messages route through Telnyx or Twilio. When a builder enables SMS follow-ups, callers must give explicit consent during the conversation before we send a text. Standard message and data rates may apply. Reply STOP to opt out of any RubyVox-originated SMS thread.
Recorded calls, transcripts, and derived summaries are stored for the builder's review. Builders can delete individual calls or disable recording per agent.
4. How we use information
- Operate, secure, and improve the Services.
- Route voice, telephony, and messaging through our providers.
- Authenticate accounts and enforce usage caps.
- Send transactional email (receipts, security alerts, account notices).
- Provide analytics to builders about their own agents.
- Detect fraud, abuse, and violations of our Terms.
- Comply with legal obligations.
We do not sell personal information. We do not use caller conversation content to train third-party foundation models.
5. Legal bases (EEA / UK)
Where applicable, we process personal data under one or more of: performance of a contract, legitimate interests (operating and improving the Services and preventing abuse), consent (for SMS follow-ups and non-essential cookies), and legal obligation.
6. Sharing and subprocessors
We share data with the vendors we need to run the Services. Current subprocessors:
| Vendor | Purpose | Data |
|---|---|---|
| Supabase | Database, auth, storage | Account, agent, conversation data |
| ElevenLabs | Voice recognition and synthesis | Audio, transcripts |
| Telnyx | Voice and SMS telephony | Phone numbers, call metadata, message bodies |
| Twilio | Backup telephony | Phone numbers, call metadata |
| Simli | Real-time avatar lip-sync | Audio stream |
| Cloudflare | Edge hosting and DDoS protection | IP address, request metadata |
| Cal.com | Optional booking integration | Booking details when the builder enables it |
| Google (Gemini) | AI generation for agent copy | Prompt inputs |
| Payment processor | Billing | Payment metadata |
We may also share information to comply with legal process, to protect rights and safety, or in connection with a merger, acquisition, or asset sale.
7. Data retention
- Account data: for the life of the account, then deleted within 30 days of account closure.
- Conversation transcripts and recordings: retained per the builder's settings; default 180 days.
- Caller memory: rolling 180-day window unless the builder or caller requests earlier deletion.
- Telephony metadata: 24 months for billing and dispute resolution.
- Logs: 90 days.
8. Your rights
Depending on where you live you may have the right to access, correct, delete, or port your personal data, and to object to or restrict certain processing. Builders can exercise most rights directly in the dashboard. Callers should first contact the builder whose agent they spoke with, since the builder controls that conversation data. You can also email us at privacy@rubyvox.com and we will route your request appropriately.
California residents may exercise rights under the CCPA/CPRA. We do not sell or "share" personal information for cross-context behavioral advertising.
9. Security
We use encryption in transit (TLS), encryption at rest for our primary database, role-based access controls, row-level security policies, and signed webhooks. No system is perfectly secure; you use the Services at your own risk. Report vulnerabilities to security@rubyvox.com.
10. International transfers
Our servers and subprocessors are primarily located in the United States. If you access the Services from outside the U.S. you consent to the transfer and processing of your data in the U.S.
11. Children
The Services are not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided data, email privacy@rubyvox.com and we will delete it.
12. Changes to this Policy
We may update this Policy from time to time. Material changes will be announced in the app or by email. The "Last updated" date at the top reflects the current version.
13. Contact
Privacy questions: privacy@rubyvox.com
Security reports: security@rubyvox.com
General: hello@rubyvox.com
Mailing address: Ruby Vox, 6120 Swiss Ave 140333, Dallas, TX 75214