How VoiceboxMD handles information in Hello AI — what we collect, why, who we share it with, and the choices you have.
Last updated July 24, 2026
This policy applies to hello.voiceboxmd.com and the Hello AI service. We act in two capacities:
From customers (account holders): name, business name, email, phone, business address, time zone and hours, billing details (processed by Stripe — we do not store full card numbers), the knowledge-base content you upload, and your configuration.
From calls to your number: caller telephone number, call date, time and duration, call audio and recordings, transcripts and AI summaries, and any details a caller provides — such as a name, callback number, reason for calling, or, for healthcare customers, limited health-related information needed to take a message or route an urgent call.
Automatically from our website and dashboard: IP address, device and browser data, pages viewed, and similar analytics. We use Vercel Analytics for aggregate usage measurement.
We ask customers not to submit payment-card numbers, Social Security numbers, or other sensitive identifiers through the assistant; it is not designed to collect them.
Calls to a customer's Hello AI number may be recorded and transcribed so the customer can review them. Recording and disclosure obligations rest with the business you called — some jurisdictions require all parties to consent. If you are a customer, you are responsible for providing the disclosure your jurisdiction requires (see our Terms, §5).
We do not sell or share personal information as those terms are defined under U.S. state privacy laws, and we do not serve cross-context behavioural advertising. We do not use customer call content or knowledge-base content to train our own AI models, and our AI vendors process it only to return a response for that call.
We share information only with vendors who process it for us under contract:
| Provider | Purpose | Data |
|---|---|---|
| Vapi | Voice call orchestration and recording | Call audio, recordings, transcripts, caller number |
| Twilio | Telephony (phone numbers, call delivery, SMS) | Caller and recipient numbers, call metadata, SMS content |
| Deepgram | Speech-to-text transcription | Call audio |
| ElevenLabs | Text-to-speech voice | Assistant response text |
| Anthropic | AI model powering the assistant | Conversation text and approved knowledge-base context |
| Voyage AI | Knowledge-base embeddings | Knowledge-base document text |
| Supabase | Application database and storage | Account, call log, request, and knowledge-base data |
| Vercel | Application hosting | Request metadata and logs |
| Stripe | Payment processing | Billing contact and payment details |
| SendGrid | Transactional email | Recipient email address and message content |
We may also disclose information to comply with law or legal process, to enforce our terms, to protect rights and safety, or in connection with a merger or acquisition (with notice where required).
For customers that are HIPAA covered entities, we act as a business associate and will enter a Business Associate Agreement (BAA). Where a BAA is in place, it governs our handling of protected health information and controls over conflicting terms here. The assistant is designed to collect the minimum necessary to take a message or route a call, and never provides medical advice. See our HIPAA page for what we do and do not promise.
We keep account and configuration data for as long as your account is active. Call logs, transcripts, recordings, and captured requests are retained while your account is active so you can review them, and are deleted or de-identified after termination, subject to legal, tax, and audit obligations — including escalation audit trails a healthcare customer may be required to keep. Customers can delete knowledge-base documents at any time. Contact us to request earlier deletion.
We use encryption in transit, access controls that isolate each customer's data, signed webhooks, hashed API keys, and audit logging. No system is perfectly secure, but we work to protect information and will notify affected customers of a breach as required by law. See Security & Compliance.
Depending on where you live, you may have the right to access, correct, delete, or port your personal information, to opt out of sale/sharing (we do neither), and to appeal a decision. Exercise these by emailing privacy@voiceboxmd.com. We will verify your request and respond within the time the law allows, and we will not discriminate against you for exercising a right. If you were a caller to a business using Hello AI, contact that business first — we act on their instructions.
The service is for businesses and is not directed to children under 13, and we do not knowingly collect their information. A caller's message may reference a child (for example, a parent calling a pediatric practice); that information is handled as the customer's data under this policy.
We operate in the United States and process information there. The service is offered to U.S. businesses; if you access it from elsewhere, you understand information is transferred to and processed in the United States.
We will update this policy as the service evolves and revise the date above; material changes will be notified by email or in the dashboard. Questions or requests: privacy@voiceboxmd.com, or VoiceboxMD, 8 N Jersey Ln, Wayne, NJ 07470, USA.