Privacy Policy — Callio
Effective date: 2026-06-04 · Last updated: 2026-06-16
This Privacy Policy explains how Wojciech Szymański (Alchemicy AI) ("Callio", "we", "us") collects, uses, and shares information in connection with the Callio AI voice receptionist service, our website, dashboard, and mobile app (the "Service").
Controller / contact: Wojciech Szymański (Alchemicy AI), Poznań, Poland. Email: [email protected].
1. Who our users are
- Business customers ("Customers"): businesses that subscribe to Callio to answer their phone calls.
- Callers ("End Callers"): people who call a Customer's business phone number that Callio answers.
2. Information we collect
From Customers (account): name, business name, business phone number, email, login credentials (hashed), billing details (processed by Stripe — we do not store card numbers), agent configuration, and usage data (minutes, call counts).
From End Callers (during calls): the phone number you call from, the audio recording and transcript of the call, and information you provide during the call (e.g., name, vehicle/appointment details, the reason for your call). We generate an AI summary of the call for the Customer, and we keep a per-caller profile (e.g., name and prior-call facts) so the Customer can recognise returning callers.
Automatically: device/app diagnostics, log data, and (for the website) standard analytics and cookies.
3. Call recording, transcription & AI disclosure
- Calls answered by Callio are recorded and transcribed to book appointments and provide the Customer with a summary. At the start of each call, the AI assistant discloses that the call is recorded and that the caller is speaking with an automated AI assistant. By continuing the call after this disclosure, the caller consents to the recording and transcription.
- We apply an all-party-consent standard to call recording across all U.S. states.
- We do not create or store voiceprints/biometric voice identifiers of callers (see Section 16, Biometric data).
4. How we use information
- Provide the Service: answer calls, book appointments, generate summaries, recognise returning callers, and send the Customer (business owner) an in-app push notification summary.
- Billing, support, security, and fraud prevention.
- Service improvement and analytics for account, website, app, and diagnostic data only — never for End-Caller call content (see the recordings carve-out below).
- Comply with legal obligations.
Recordings carve-out. Call recordings, transcripts, and AI summaries (and the per-caller profiles derived from them) are processed only to provide the Service to the relevant Customer — i.e., to answer the call, book the appointment, summarise it for that Customer, and recognise returning callers for that Customer. We do not use call recordings or transcripts to develop, train, fine-tune, or improve Callio's (or any third party's) AI/ML models or any other product or service, we do not monetise them, we do not sell or share them, and we do not perform cross-customer analytics on call content. Callio acts as a service provider / processor for this content on the Customer's behalf (see our Data Processing Agreement).
Notification policy: We deliver operational notifications (e.g., call summaries) to the Customer (business owner) as in-app push notifications. We do not send SMS or any messages to End Callers. Customers can disable push notifications in their device settings.
5. How we share information
We share information with service providers (subprocessors) strictly to operate the Service:
- Twilio — telephony and phone numbers. · ElevenLabs — AI voice / conversational AI + transcription. · Anthropic (Claude) — call summarization. · Stripe — payments. · Hetzner (Germany, EU) — hosting/infrastructure.
We require these providers to protect information under data-processing terms (subprocessors under our Data Processing Agreement). We do not sell or share personal information (see Section 14). We may disclose information to comply with law or protect rights/safety. For call content, Callio acts as a service provider / processor on the relevant Customer's behalf.
6. Legal bases (GDPR / EEA)
Where GDPR/RODO applies, we process: (a) to perform our contract with Customers; (b) on legitimate interests (operating, securing, and improving the Service, excluding End-Caller call recordings, transcripts, and summaries, which are subject to the carve-out in Section 4; B2B outreach) balanced against your rights; (c) to comply with legal obligations; and (d) on consent where required (e.g., call recording).
7. Your rights
- EEA/UK (GDPR/RODO): access, rectification, erasure, restriction, portability, objection, and the right to lodge a complaint with a supervisory authority (in Poland: Prezes Urzędu Ochrony Danych Osobowych, UODO).
- California (CCPA/CPRA): the rights to know/access, delete, correct, opt out of "sale"/"sharing" (we do not sell or share — see Section 14), and to limit the use of sensitive personal information; plus non-retaliation/non-discrimination for exercising your rights.
- Other U.S. states (VCDPA, CPA, CTDPA, and laws in Oregon, Texas, New Jersey, New Hampshire, Montana, and others): the rights to confirm/access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale, and certain profiling — and the right to appeal a denied request (we will inform you how to appeal if we deny a request).
- Account holders can delete their account and associated data in-app (Settings → Delete account) or by emailing [email protected]. We do not discriminate against you for exercising any of these rights.
How to exercise your rights (verifiable requests). You may submit a request by (1) emailing [email protected], or (2) using the in-app controls (Settings → Delete account / Privacy). To protect your data, we will take reasonable steps to verify your identity (e.g., by matching the account email or phone number, or information you provide) before acting, and we may decline requests we cannot verify. An authorized agent may submit a request on your behalf with proof of authorization. We respond within the timeframes required by applicable law. Because much of the End-Caller data we hold is processed on behalf of a Customer (the business you called), we may refer your request to that Customer (the controller/business) and assist them in fulfilling it.
8. Data retention
We retain End-Caller call recordings, transcripts, summaries, and per-caller profiles for up to 12 months (or a shorter period the Customer configures, or longer where required by law), after which they are deleted or anonymised. Account data is retained while the account is active and for a reasonable period afterward for legal/accounting needs.
9. International transfers
We are based in Poland (EU); our providers may process data in the United States and elsewhere. Where required, transfers rely on appropriate safeguards (e.g., Standard Contractual Clauses).
10. Security
We use industry-standard measures (encryption in transit, hashed passwords, access controls, JWT-based auth, tenant isolation). No method is 100% secure.
11. Children
The Service is for businesses and is not directed to children under 16. We do not knowingly collect their data.
12. Google API Services & Google Calendar integration
Callio offers an optional integration with Google Calendar so your AI receptionist can check availability and create, update, or cancel appointment events on calendars you own. If you connect Google Calendar:
- What we access: with your explicit OAuth consent, we access events on calendars you own (scope:
calendar.events.owned) solely to read availability for booking and to create, update, or cancel appointment events made through Callio.
- Limited Use: Callio's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of information received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
- No advertising, no AI training: we do not use Google Calendar data for advertising, and we do not use any Google user data to develop, improve, or train generalized or foundation artificial-intelligence and/or machine-learning models. Calendar data is processed per customer, in isolation, only to deliver the booking feature you enabled.
- No human access: humans do not read your calendar data except with your explicit permission (e.g., a support request), where required for security or legal compliance, or where the data is aggregated and anonymised.
- Retention & revocation: Google OAuth tokens are stored encrypted and deleted when you disconnect the integration or delete your account. You can revoke Callio's access at any time in the app or at myaccount.google.com/permissions.
13. California Notice at Collection
This section is the Notice at Collection required by the CCPA. At or before the point of collection, we collect the following categories of personal information for the purposes described in Sections 2–4:
- Identifiers (e.g., name, business name, email, phone number; caller phone number) — to create and manage accounts and to answer, route, and document calls.
- Customer records / commercial information (e.g., billing metadata, subscription/usage data) — for billing and account management. Card numbers are handled by Stripe; we do not store them.
- Audio / electronic information (call recordings and transcripts, AI summaries) — to provide the receptionist and scheduling Service to the relevant Customer (see the recordings carve-out in Section 4).
- Internet/network and device information (diagnostics, log data, website analytics/cookies) — for security, support, and app/website improvement.
- Inferences (e.g., per-caller profile facts to recognise returning callers) — to provide the Service to the relevant Customer.
- Sensitive personal information: we do not intentionally collect sensitive PI; a caller may volunteer sensitive details in free-form conversation, which we process only to provide the Service and never to infer characteristics. We do not create voiceprints or voice biometric identifiers (Section 16).
Sale/share: we do not sell or share any category of personal information (Section 14). Retention: see Section 8 (call data up to 12 months, or a shorter Customer-configured period; account data while active plus a reasonable period). For full details, read this entire Policy.
14. Do Not Sell or Share / Limit the Use of My Sensitive Personal Information
- We do not sell or share your personal information, and we have not sold or shared personal information (including call recordings, transcripts, and caller data) in the preceding 12 months — as "sell" and "share" (cross-context behavioral advertising) are defined under the CCPA. Because we maintain this genuine no-sale / no-share posture, no opt-out is necessary for a sale or share to stop; there is nothing to opt out of. If this ever changes, we will update this Policy and provide a "Do Not Sell or Share My Personal Information" link and mechanism beforehand.
- Limit the Use of My Sensitive Personal Information. We do not use or disclose sensitive personal information for purposes beyond those permitted by the CCPA (i.e., we use it only to provide the Service and for related, permitted operational purposes). We therefore are not required to offer a "Limit the Use of My Sensitive Personal Information" choice; nonetheless, you may ask us to limit such use by emailing [email protected], and we will honor verifiable requests within the time required by law.
- Honoring opt-out preference signals / Global Privacy Control (GPC). We recognize the Global Privacy Control (GPC) and similar opt-out preference signals as a valid request to opt out of the sale or sharing of personal information. Because we do not sell or share personal information, no additional action is required to honor these signals; if our practices ever change, we will treat a GPC signal as a valid opt-out.
15. Privacy-policy updates & contact for requests
We review and update this Policy at least every 12 months and whenever our practices change materially. For any privacy question or to exercise a right, contact [email protected] (see Sections 7 and 18).
16. Biometric data (no voiceprints)
- Callio does not collect, capture, generate, or store voiceprints or any voice biometric identifiers, and does not use voice to identify, verify, or authenticate any individual. We do not create or store a biometric template from any caller's voice, and we do not enroll callers in any voice-recognition or voice-authentication system.
- Why transcription/diarization is not biometric: speech-to-text transcription and speaker-turn diarization (labelling "caller" vs "assistant" for transcript readability) do not measure, derive, compare, or store the unique geometry of a person's voice, and are not used to identify a specific speaker. Under biometric-privacy laws such as Illinois BIPA and Texas CUBI, a "voiceprint" is a template measured/analysed for the purpose of identifying a specific individual; because we do none of that, no biometric identifier is created.
- Returning callers are recognised by phone number / CRM-style data, never by voice characteristics.
- If Callio ever introduces a feature that would create a voiceprint or other biometric identifier, we will obtain the opt-in notice and consent required by applicable law before doing so and update this Policy. See our standalone Biometric Data Policy for more detail.
17. Changes
We may update this Policy; we will post the new effective date and, for material changes, notify Customers.
18. Contact
Wojciech Szymański (Alchemicy AI), Poznań, Poland · [email protected]