Back to home

Privacy Policy

How Callany handles account data, call records, recordings, transcripts, summaries, billing data, and provider processing.

Last updated: 2026-08-02

1. Data Controller and Contact

Callany is an individual operator based in China and is the data controller for this Service. For privacy requests, support, billing, refunds, cancellation, or security concerns, contact support@callany.app. Callany has not appointed a data protection officer.

This Privacy Policy explains how Callany collects, uses, stores, and shares information when users configure AI phone assistants, place calls, buy credits or subscriptions, and review call results.

2. Information We Collect

We collect information needed to operate and secure the Service:

  1. Account and support information — name, email address, authentication records, settings, roles, and the contents of support requests.
  2. Payment information — orders, subscriptions, credit grants and consumption, invoices, and payment-processor references. Waffo Pancake processes payment-card data; Callany does not store full card numbers.
  3. Call setup data — assistant prompts, first messages, language, voice or model settings, maximum duration, runtime variables, destination country and phone number, contact name, and scheduled time.
  4. Call records and artifacts — platform call IDs, status, duration, pricing snapshots, credit reservations and final charges, recordings, transcripts, summaries, analysis, and reconciliation events.
  5. Provider and security evidence — redacted provider request, response, and webhook records needed for debugging, reconciliation, fraud prevention, and auditability.
  6. Device and usage data — browser, device, IP-derived logs, security events, feature use, and diagnostics.

3. How We Use Information

We use personal information to provide and maintain the Service; authenticate users and protect accounts; create, schedule, route, and reconcile calls; reserve and finalize credits; provide support; prevent fraud, abuse, and security incidents; and comply with legal obligations. Where data-protection laws require a legal basis, we rely on performance of a contract, our legitimate interests in operating and securing the Service, legal obligations, or your consent where required.

We may aggregate or de-identify information for product analysis and service improvement. We do not use your Service input to train AI models without your explicit consent.

4. Cookies and Analytics

We use strictly necessary cookies and similar technologies to operate authentication, sessions, security, and language preferences. Disabling those technologies may prevent the Service from functioning.

If configured for the Service, Google Analytics or Plausible may collect usage information to help us understand and improve the Service. Their processing is governed by their own policies: Google Privacy Policy and Plausible Data Policy. We do not use marketing cookies or sell personal information. You can control non-essential cookies through your browser settings where available.

5. Sharing and Disclosure

We do not sell personal information. We share information only as needed to operate the Service or where required by law:

  • With service providers that operate hosting, databases, storage, email, analytics, customer support, and voice calling, subject to contractual or legal confidentiality obligations.
  • With Waffo Pancake, our PCI-DSS-compliant payment processor, to process purchases, subscriptions, refunds, and fraud checks. Payment-card data is processed by Waffo Pancake and does not pass through Callany’s servers.
  • With voice and AI providers to place calls, process call audio, generate transcripts or summaries, return call events, and prevent abuse.
  • With authorities or other parties when required by law, legal process, or to protect users, call recipients, Callany, or the public from fraud, abuse, security threats, or unlawful activity.
  • In a business transfer, with notice where required by law and subject to this Policy or equivalent protections.

6. Call Recipients, Recordings, and International Processing

Users decide who to call, what number to dial, what assistant profile to use, and what runtime variables to provide. Users are responsible for having a lawful basis to call each recipient, honoring do-not-call and opt-out obligations, and providing any notice or obtaining any consent required for automated calls, AI-generated speech, recording, transcription, or analysis.

Recordings and derived text artifacts may contain personal information from both the user and call recipient. Recordings are archived in private platform storage and served only through authenticated platform download routes. We do not expose upstream recording URLs or private storage keys to end users.

Calls may involve recipients in different countries, and providers may process data outside your or a recipient’s location. We make those transfers only as permitted by applicable law and use appropriate contractual, technical, or organizational safeguards where required.

7. Security

We use safeguards appropriate to the Service, including HTTPS or TLS in transit where supported, access controls, private storage for recordings, authenticated download routes, secret handling, and audit-oriented logs. No internet service can be perfectly secure. If a security incident affects your rights, we will assess it and notify affected people and authorities as required by applicable law.

8. Retention

We retain personal information for the following periods, then delete or anonymize it unless longer retention is required or permitted for legal obligations, accounting, fraud prevention, disputes, security, or auditability:

| Data type | Retention period | End-of-period handling | | -------------------------------------------------------------------------------------- | --------------------------------------------------------------------------- | ------------------------------------------------------------- | | Account, profile, and contact information | While the account is active, then 90 days after an account-deletion request | Delete or anonymize | | Call setup data, call records, recordings, transcripts, summaries, and analysis | While the account is active, then 90 days after an account-deletion request | Delete or anonymize unless a specific record must be retained | | Payment records, credit-ledger entries, invoices, and provider reconciliation evidence | 5 years after the relevant transaction | Delete or archive where retention remains necessary | | Support requests | 2 years after closure | Securely delete or anonymize | | Security and access logs | 12 months after collection | Securely delete or anonymize |

9. Your Rights

Depending on applicable law, you may have rights to know about, access, correct, delete, restrict processing of, object to certain processing of, or receive a portable copy of your personal information, and to withdraw consent. To exercise a right, email support@callany.app from your account email address. We will respond within 30 calendar days, unless law permits or requires a different period. You may also complain to the relevant data-protection authority where applicable.

10. Children

The Service is not directed to anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact support@callany.app so we can investigate and delete it where appropriate.

11. Changes and Contact

We may update this Policy as the product, providers, laws, or operating practices change. For a material change, we will give at least 15 days’ notice through the Service or the email address associated with your account and update the date at the top of this page. Continued use after the effective date means acceptance of the revised Policy.

For privacy requests, support, billing, refunds, cancellation, or security concerns, contact support@callany.app.