Trust
Privacy Policy
Version 2026-09-27 · Effective September 27, 2026
This policy explains what Bizefy LLC collects, why, who receives it and how long it is kept. It covers this website, the Sona dashboard and the calls Sona answers. If your question is “I called a business and an AI answered: what happened to my data?”, start with the section for callers.
Who we are, and the two roles we play
Bizefy LLC (“we”, “us”) makes Sona, an AI receptionist that answers phone calls for businesses in the United States. We handle personal information in two different roles, and this policy keeps them apart:
- For our own audiences (visitors to this site and the businesses and people who hold Sona accounts) we decide what to collect and why.
- For callers (people who phone a business that uses Sona) the business decides, and we process the information on its behalf and on its instructions, as its service provider under the California Consumer Privacy Act and similar state laws. Our Data Processing Addendum sets out those instructions.
If you called a business that uses Sona
At the start of the call you heard that you were speaking with an AI assistant and, if the business records its calls, that the call may be recorded. Our AI disclosure explains how that works, including what happens if you do not want to talk to an AI or be recorded.
Depending on the call, it produced:
- your phone number as shown by caller ID, and the time and length of the call;
- a written transcript of what you and the receptionist said;
- an audio recording, only if the business has recording turned on;
- anything you chose to leave: an appointment (your name, number, the time and the reason) or a message (your name, callback number and what it is about);
- the questions you asked, if the receptionist looked them up in the business's knowledge base;
- a record of the greeting that was played to you.
That information belongs to the business you called. It appears in the business's dashboard, and the business may receive emails about it: a summary of the call (the last four digits of your number, how long the call lasted and how it ended, and whether you were told to hang up and dial 911), and the details of any message or appointment you left. It uses the information to deal with your request. We do not contact callers, do not send text messages, do not build profiles of callers and do not identify anyone by their voice.
To see or delete this information, ask the business you called: it is their relationship with you, and the law puts the decision with them. If you cannot reach them, write to privacy@bizefy.dev with the number you called from, the business you called and roughly when; we pass your request to the business and act on its instructions. Deletion is currently carried out by our team, not by an automated process, and we confirm to the business when it is done.
What we collect for our own audiences
Visitors to this site
Our hosting provider records standard request logs: IP address, browser type, the page requested and the time. We run no third-party analytics and no advertising trackers, and the site's fonts are served from our own domain. If you open the window to book a call with us, the booking page inside it is run by Calendly and loads from Calendly only when you open it; what you enter there is governed by Calendly's privacy policy.
If you write to us through the contact form on our home page, your name, email address and message reach us as an email in our Microsoft 365 mailbox, and we use them only to reply to you. The IP address your message came from is used to limit repeated messages.
Customers and their teams
- Account data: your name, email address, business name and password (stored by our sign-in provider as a one-way hash, never readable by us), and the email addresses of people you invite.
- Agreement records: when you accept these documents, the version you accepted, the time, and the IP address and browser details your request came from.
- Configuration and content: how you set Sona up (greeting, hours, availability, transfer numbers, who receives alerts) and the knowledge base you give it: web pages you point it at, documents you upload and FAQs you write.
- Billing data: your plan, subscription status, invoices, usage and wallet history. Card details are entered in Stripe's own fields and never reach our servers; we see only the card brand, the last four digits and the expiry.
- Operational and security data: a log of every configuration change in your workspace (visible to you), sign-in and security logs including the IP addresses we use to limit repeated attempts, and your emails to our support team.
Where it comes from
Most of it comes from you: what you enter when you sign up, set Sona up and use the dashboard. Call information comes from the people who call a business's line, and knowledge-base content from the files a business uploads, the FAQs it writes and the public web pages it points our crawler at. Our payment provider tells us whether a payment went through and a card's brand, last four digits and expiry, and our hosting provider records the request logs described above.
How we use information
- To provide the Service: answering calls, doing what the caller asks (booking, messages, transfers) and sending the alerts a business switched on.
- To run the business around it: sign-in, billing, support and fixing problems.
- To keep it safe: rate limits and spend caps against toll fraud, detecting misuse, and enforcing our acceptable use policy.
- To improve it: our staff may review call records when that is needed to support a business, fix a fault or improve quality. When our staff open a call's content in our internal console, that access is written to the business's own audit log before the content is shown.
- To comply with the law and to establish or defend legal claims.
What we do not do, stated plainly:
- We do not sell personal information, in either role.
- We do not share personal information for cross-context behavioral advertising, and there is no advertising anywhere in the product.
- We do not use your calls or your content to train AI models.
- We do not create voiceprints or any other biometric identifier.
We may compile aggregated, de-identified statistics, such as how many calls the platform answers, that identify neither a business nor a caller. We keep them in that form and do not try to re-identify anyone from them.
How the AI processing works
During a call, the caller's speech is turned into text, a large language model reads the conversation and the business's instructions and decides what to say and do, and the reply is turned back into speech. Telephony and the speech steps run on Twilio and the speech providers it works with; the language model comes from Anthropic or, if a business chooses it, OpenAI. When a caller asks something the business's knowledge base can answer, the words of the question are sent to OpenAI to be turned into a search vector, without the caller's number or any call identifier. These providers receive the data as our sub-processors, to provide the Service.
The receptionist's replies are generated automatically, within the instructions the business gives it. It is not designed to make decisions that have legal or similarly significant effects on anyone, such as decisions about credit, employment, housing, insurance or education. It answers questions, books from the availability the business sets, takes messages and transfers calls, and the business decides what to do with each request.
Who receives data
| Provider | What it does | What reaches it |
|---|---|---|
| Twilio | Telephony: the phone numbers, inbound call routing, call transfer, the live speech pipeline (ConversationRelay) and, when a business turns recording on, the call recording. | Call audio, the caller's phone number and call metadata. Recordings are copied to our storage and then deleted at Twilio. |
| Amazon Web Services: Amazon S3 | Stores call recordings: when a business turns recording on, Twilio uploads each finished recording to our storage bucket on Amazon S3, where it is kept and played back from. | The call recording, kept for the business's recording retention period and then deleted. |
| Deepgram (through Twilio) | Speech recognition: turns the caller's speech into text during the call. | Call audio, in real time. |
| Google (through Twilio) | Speech recognition and synthesized voices. | Call audio (recognition) or the receptionist's reply text (voice). |
| Amazon Web Services: Amazon Polly (through Twilio) | Synthesized voices. | The receptionist's reply text. |
| ElevenLabs (through Twilio) | Synthesized voices. | The receptionist's reply text. |
| Anthropic | The language model that decides what the receptionist says and which action it takes. | The text of the live conversation and the business's receptionist instructions. |
| OpenAI | Embeddings for the knowledge base (turning a business's pages, documents and FAQs, and a caller's question to them, into search vectors), and the language model when a business selects an OpenAI model. | Knowledge-base text and the words of a caller's question to it, sent without any phone number or call identifier. Conversation text only if an OpenAI model is selected. |
| Supabase | Database, file storage and sign-in for the dashboard. | All service data at rest: accounts, configuration, call records, transcripts, recordings, messages, appointments and knowledge-base content. |
| Vercel | Hosts this website, the customer dashboard and our billing endpoints. | Web requests (including IP address and browser details), request logs, and the dashboard pages a signed-in user views. |
| Voice service hosting provider (to be named before publication) | Runs the voice service: call routing, the live conversation, the receptionist's tools and the post-call workers. | Everything a call produces passes through it: conversation text, tool actions, messages, appointments and, when recording is on, the recording on its way to storage. |
| Stripe | Subscription billing, invoices, card payments and wallet credit. Card details are entered in Stripe's own fields and never reach our servers. | The billing contact, card details and the usage we invoice. |
| Microsoft (Microsoft 365) | Email: sends the email alerts a business asks for (a post-call summary after each call an agent answers, for agents that have it switched on, and alerts for messages taken and for appointments booked, moved or cancelled) and the account emails (sign-up confirmation and password reset), receives the email sent to our contact addresses, and carries the messages visitors send through the contact form on our home page to that mailbox. | The recipient's email address and the email's content. For an alert: the last four digits of the caller's number, the call's length and outcome, the caller's name, callback number, reason and appointment time, and a note when the receptionist told the caller to hang up and dial 911. Never a transcript or a recording. For an account email: the confirmation or reset link. For a contact-form message: the name, email address and message the visitor wrote. |
The same list, with when each provider is used, is on our sub-processors page. Beyond it: the business you called receives what its calls produce, because it is theirs; professional advisers and authorities receive information when the law requires it, and we ask for valid legal process before we respond; and if Bizefy LLC is acquired or reorganized, information passes to the successor under this policy's commitments, with notice to customers.
How long information is kept
| Information | Kept for | Notes |
|---|---|---|
| Call recordings | As the business sets it, within its plan's limits: from 30 days up to 5 years | Deleted automatically when the period ends. Twilio's copy is deleted once the recording is stored with us. |
| Transcripts, call records, messages and appointments | For as long as the business keeps its account | There is no automatic expiry today. Deleted on the business's request, or after it closes its account as described below. |
| Knowledge-base content | Until the business deletes the source or closes its account | Deleting a source removes its content and its search index at once. |
| Account and configuration data | For the life of the account | Deleted after the account closes, as described below. |
| Billing and payment records | As long as tax and accounting law requires, generally seven years | Kept after an account closes. |
| Audit logs and agreement records | As long as we may need them to show what was done and agreed | Kept after an account closes. |
When a business closes its account, it has 30 days to ask us for a copy of its data. After that we delete its call records, recordings, messages, appointments, knowledge base and configuration, except the billing, audit and agreement records the law or our legitimate interests require us to keep. That deletion is carried out by our team today, and we confirm it on request.
Security
Our security page describes the controls in place, including the ones we do not have yet. In short: every business's data is separated in the database itself, data travels encrypted and is encrypted at rest by our providers, recordings are only reachable through short-lived private links, and our staff's access to call content is recorded where the business can see it. If we confirm a security incident affecting personal information, we notify the affected businesses without undue delay, and within 48 hours for customers under our Data Processing Addendum.
Your rights
Customers and site visitors
Write to privacy@bizefy.dev to access, correct, delete or get a copy of the personal information we hold about you. We verify requests against the email address on the account and respond within 45 days; if we need longer, we tell you why within those 45 days and take no more than 45 days more. You can also have an authorized agent make a request for you: we ask the agent for your signed permission, and may ask you to confirm your identity with us directly. We never treat you differently for asking. If we decline a request we say why, and you can appeal by replying to the same email; where your state provides it, you can also contact your state attorney general.
Callers
Your rights run against the business you called, because the information is theirs. The section for callers explains how to use them and how we help.
California
In the categories the CCPA uses, we collect: identifiers (name, email address, business name, caller phone numbers, IP addresses); commercial information (plans, invoices, appointment records); audio and electronic information (call recordings and transcripts); internet activity (site and dashboard logs); and professional information (your role at your business). The sources, purposes and recipients are the ones described above. We have not sold or shared personal information, as the CCPA defines those terms, in the past twelve months. We do not collect precise geolocation or biometric information, and we do not use sensitive personal information to infer characteristics about anyone; a caller may still volunteer sensitive details on a call, which then sit in that call's record. We treat the Global Privacy Control signal as a valid opt-out request where state law gives it that effect; because we neither sell nor share, it changes nothing about how you are treated.
Emails
We send account emails, such as sign-up confirmations and password resets, and the alerts a workspace's editors switch on; editors choose who receives alerts in the dashboard's settings. We do not send marketing email.
Children
Neither the site nor the Service is directed to children, and we do not knowingly collect children's information for our own purposes. A child may still call a business that uses Sona; that call belongs to the business like any other.
Cookies
The marketing pages set no cookies for visitors who are not signed in. Your light or dark theme choice is stored in your browser and never leaves your device. The dashboard uses strictly necessary cookies to keep you signed in. When you add a card or wallet credit in the dashboard, Stripe's payment fields load and may set cookies Stripe uses to prevent fraud. If you open the window to book a call with us, Calendly's page inside it may set Calendly's own cookies, which Calendly's policies govern. Our own pages set nothing optional, so there is no consent banner: no analytics cookies, no advertising pixels and no fingerprinting. Because we do not track visitors across other sites, a browser's Do Not Track signal changes nothing about how we treat you.
Where information is processed
Sona is built for businesses in the United States. The service's database and file storage, which hold account details, call records, transcripts, recordings, messages and appointments, are hosted in Ireland, in the European Union. Our other providers process information where they operate, which includes the United States and may include other countries; we do not currently guarantee that information stays within one country. Wherever you are, you can exercise the rights above through privacy@bizefy.dev.
Health information
Sona is not designed for protected health information. Businesses that are covered by HIPAA may not use it to process such information without a signed business associate agreement, and we do not offer one at this time (see our Terms).
Changes to this policy
When this policy changes, the version at the top changes with it. For a material change, we email account owners before it takes effect and ask them to review it the next time they sign in. We do not apply a change retroactively to information already collected.
Contact
Privacy questions and requests: privacy@bizefy.dev. Anything else: support@bizefy.dev.