Skip to main content

Privacy Policy

Last updated: September 15, 2026

1. Introduction, Who We Are, and Scope

This Privacy Policy explains how Movoice AI (the "Service") collects, uses, discloses, and protects personal information. The Service is provided by Metawaveai Technologies Private Limited (incorporated in India), together with its affiliate Metawaveai Technologies Inc (collectively "Movoice", "we", "us", or "our").

Movoice AI is a voice-AI software-as-a-service platform. Businesses use it to place and receive AI-powered phone calls and to send SMS, WhatsApp, Telegram and email messages to their own customers. It includes call recording and transcription, bulk campaigns, configurable AI agents, an in-app AI assistant that can operate controls on your behalf, synthetic-voice creation, a prepaid wallet and credits, KYC/KYB identity verification, phone-number provisioning, contacts sync, caller-memory profiling, a public developer API, an embeddable voice widget, and a super-admin monitoring console. It also includes Movoice AI Messaging, a separate end-to-end-encrypted personal messenger described in section 23.

This Policy covers three groups of people:

  • "Customers" (also "you") — the businesses and their authorized users who register for and pay to use the Service.
  • "Recipients" or "End Users" — the individuals whom a Customer calls, messages, or uploads into the Service, and who never signed up for Movoice themselves.
  • Visitors — people who ask for a demonstration call from our website, or who speak to a voice widget embedded on a Customer’s site, without holding a Movoice account at all. Section 22 covers them, and for those interactions Movoice is the controller rather than a processor.

The surfaces this Policy applies to are: our websites and web dashboard, the embeddable voice widget and public demo pages, the iOS app, the Android app, and the macOS desktop application. The desktop application loads the same web dashboard, so section 18 describes only what it adds. We do not currently distribute a Windows, Linux or watchOS application.

2. Our Roles — Controller and Processor

Movoice acts in different capacities depending on whose data is involved, and the distinction decides who you go to about it.

Controller for Customer (account-holder) data. For personal information about our Customers and their authorized users — account, login, billing, KYC/KYB, device, usage and support data — Movoice is the data controller (or “data fiduciary” under India’s DPDP Act). We decide why and how that information is processed, and this Policy governs it directly.

Processor for Recipient data. For the personal information of Recipients that a Customer uploads, calls, or messages — contact lists, phone numbers, call recordings, transcripts, caller-memory profiles, and message content generated in the course of the Customer’s outreach — the Customer is the controller and Movoice is a processor acting on the Customer’s documented instructions. We process this data to deliver the Service to that Customer and not for our own independent purposes. Our handling of Recipient data is also governed by the Data Processing Addendum in our Terms of Service.

Controller for demonstration calls, the voice widget, and Messaging. Where a visitor asks us for a demonstration call from our own website, we decide the purpose and are the controller (section 22). Where a person uses Movoice AI Messaging, they are our user directly and we are the controller for their account, identity and safety records (section 23). A Customer is not involved in either.

Each Customer is responsible for having a lawful basis and any required consent to contact its Recipients, for providing Recipients with required notices (including recording notices), and for honoring Recipient rights and opt-outs. Where a Recipient asks us directly to exercise rights over data a Customer controls, we will refer the request to the relevant Customer and assist them as their processor.

3. Information We Collect and Our Lawful Basis

We collect the following categories. For each we identify the lawful basis we rely on for Customer data as controller; for Recipient data we act on the Customer’s instructions and the Customer is responsible for the lawful basis.

  • Account and profile data — name, email, phone number, business name and details, authentication identifiers. Lawful basis: performance of our contract with you.
  • Usage and configuration data — agent configurations, prompts, settings, campaign definitions, call logs, delivery status, wallet and credit activity, and in-app actions. Lawful basis: performance of contract; and our legitimate interest in operating, securing, and improving the Service.
  • Call recordings and transcripts — audio of calls placed or received through the Service and the text transcripts generated from them, created on the Customer’s instruction. Also voicemail messages left by Recipients, and the short recordings made when a phone number is being verified with a carrier. Lawful basis: performance of contract with the Customer; for Recipients, the Customer’s lawful basis and required notice or consent.
  • Message content — the content of SMS, WhatsApp, Telegram, email and web-chat messages sent or received through the Service. Each AI agent can be issued an address at reply.movoice.ai, and mail sent to it, including the body and attachment details, is stored in the Customer’s account and may be answered automatically by an AI model. Lawful basis: performance of contract; for Recipients, the Customer’s lawful basis and any required opt-in.
  • Voice samples and synthetic voices — where a Customer uses voice cloning, a short speech recording of a person and the synthetic voice model built from it. Section 20 describes this in full. Lawful basis: the Customer’s instruction, and the consent of the person whose voice it is, which the Customer is responsible for obtaining.
  • Contacts sync data — where you choose to sync your device address book, the names, phone numbers, and email addresses it contains. Lawful basis: your explicit consent, requested in-app before any upload.
  • Location data — three separate things, described precisely in section 17: a device coordinate captured only when you open the map picker to share a pin in a conversation or to save your business location; browser location when you use “share location” in a conversation on the web dashboard; and a country code derived from your IP address, used to choose a display currency. We do not collect background or continuous location, and the Android build removes the precise-location permission. Lawful basis: your consent for the first two; legitimate interest in localization and fraud prevention for IP-derived country and for the IP addresses used in rate limiting.
  • Payment data — billing details and transaction records, processed by our payment providers; we do not store full card numbers. Lawful basis: performance of contract; and legal obligation (tax and financial recordkeeping).
  • KYC/KYB identity-verification data — identity and business-verification information, which may include identity documents, collected to verify Customers before enabling regulated features such as telephony, payments and Messaging. The documents themselves are held by our verification provider rather than by us.
  • Face scan during identity verification — a personal identity check includes a short selfie video. Our verification provider checks that you are a live person and compares your face with the photo on your document, which creates a measurement of your face: biometric data. We ask for your explicit consent in the app before the camera opens, and we record that decision. We use it only to verify your identity, never for anything else, and never sell it. It is processed in the European Union and deleted with your verification — after 12 months at most, or sooner when you delete your account or ask us at privacy@movoice.ai. We also compare the name on your document with the name on your account and keep only whether they matched, not the name itself. Lawful basis: your explicit consent (GDPR Art. 9(2)(a); Illinois BIPA and Texas CUBI written release), alongside legal obligation for the identity check it supports.
  • Lawful basis for KYC/KYB data: legal obligation and compliance; and performance of contract.
  • Emergency address data — for United States numbers, a street address, city, state and postal code supplied by the Customer and passed to our carrier for registration. Lawful basis: legal obligation and performance of contract. Section 21 of our Terms explains the limits of emergency calling.
  • Number-porting data — where you ask us to port a number in: the requester’s legal name, whether the account is individual or business, legal business name, full service address, the numbers to be ported, and an optional uploaded phone bill. Lawful basis: performance of contract and carrier requirement.
  • Device and technical data — device model, operating system, app version, browser, IP address, and randomized identifiers. Lawful basis: legitimate interest in security, compatibility, and Service delivery.
  • Product analytics data — usage events and metadata. These events are linked to your account and include your name and email address; see section 13. Lawful basis: legitimate interest in operating and improving the Service.
  • Diagnostics data — crash and error reports, performance traces, app-hang reports, and in-app navigation and interaction breadcrumbs. On the web dashboard this can include a replay of the browsing session in which an error occurred, with text masked and media blocked. Section 13 gives the detail. Lawful basis: legitimate interest in keeping the Service secure, stable, and bug-free.
  • Assistant interaction data — your conversations with the in-app assistant, the proposals it showed you, the facts it saved, and a per-step record of any action it took in your account including the control it operated and the value before and after. Section 19 covers this. Lawful basis: performance of contract and legitimate interest in an auditable assistant.
  • API request logs — for each authenticated developer-API request: the account, the key used, the method, the route, the response status, the duration, and the caller’s IP address. Query strings are stripped. Lawful basis: legitimate interest in security, abuse prevention and billing accuracy.
  • Bug reports and in-app screen captures — where you report a bug, the report text, device and page context, your name and email, and, only if you have switched screen capture on yourself, the screenshots you choose to send. Section 17 describes the masking applied. Lawful basis: your consent for the capture; legitimate interest in fixing defects.
  • Caller-memory profiles — summaries and attributes derived from prior interactions with a Recipient to personalize future calls; see section 7. Lawful basis, as processor: the Customer’s instruction and lawful basis.
  • Movoice AI Messaging data — described separately in section 23.

We request Microphone access so you can speak with our AI voice agents and the in-app assistant, record voice notes, and record a voice sample if you choose to create a synthetic voice. We request Contacts access to show your contacts and, with your separate consent, to sync them. Section 17 lists every permission we ask for on each platform, and the things we deliberately do not ask for.

4. How and Why We Use Information

We use the information we collect to:

  • Provide, operate, and maintain the Service, including placing and connecting AI voice calls and sending messages on your instruction.
  • Record calls and generate transcripts and summaries, and store them to your account for review.
  • Run bulk campaigns, configure and operate AI agents, apply caller-memory personalization, and generate follow-up messages after a call.
  • Operate the in-app assistant, including carrying out steps in your account where you have separately agreed to that (section 19).
  • Create and use synthetic voices where you ask us to (section 20).
  • Enable integrations you connect — calendars, CRMs, meeting tools, payment gateways, e-commerce stores and any webhook endpoint you nominate — to the extent needed to perform the requested function.
  • Provision phone numbers, manage your wallet and credits, and process payments.
  • Verify identity (KYC/KYB) and prevent fraud, abuse, toll fraud and misuse.
  • Send transactional and service communications, notifications, and support responses; and, where you have opted in or not opted out as described in section 13, product news.
  • Monitor, secure, debug, and improve the Service, including product analytics and diagnostics.
  • Comply with legal obligations and enforce our Terms.

We do not sell your personal information. Movoice does not use the content of your calls or messages to train AI models, and we contract with our AI sub-processors on terms that do not permit them to train their models on our customers’ content. We do not set a technical no-retention flag on those providers’ APIs, so this is a contractual protection rather than a mechanical one, and we would rather say which it is.

5. Call Recordings, Voicemail, and Transcripts

Whether a call is recorded depends on the account’s recording setting and on which carrier carries the call. Recording is on by default. The position today, honestly stated:

  • Inbound calls answered by an AI agent — recorded, unless you turn recording off in the console. Turning it off stops the recorder, not merely the announcement.
  • Outbound AI calls you place yourself over our international carrier — from the web console, the desktop app or the phone, including a test call you start there — recorded, unless you turn recording off.
  • Every other way a call can be placed — bulk campaigns, scheduled and follow-up calls, the developer API, conversation flows, lead-form and social-message callbacks, WhatsApp call commands, the demonstration call on our own website, and onboarding number verification — is recorded regardless of the setting, because those paths do not yet pass it through. The setting reaches one dial path today. We would rather tell you that than let you believe it covers calls it does not reach.
  • Calls carried by our India domestic carrier and answered by an AI agent — not recorded at all.
  • While you are verifying a number for WhatsApp, every inbound call to that number is answered and recorded for as long as the verification window is open, on either carrier and whatever your recording setting says. We cannot tell the verification call from an ordinary caller, so we capture them all. You open that window yourself and it closes on its own.
  • AI calls held in a web browser without a carrier — never recorded.
  • WhatsApp calls — not recorded. A recording control is visible in the console for this channel; it does not currently take effect.
  • Calls you conduct personally, speaking to someone yourself — not recorded today. The capability exists and is disabled; if it is ever enabled, a spoken recording notice is played into the call first and cannot be switched off, and no recording can start unless that notice has played.

If we cannot read your setting for any reason, we record. A call that was announced as “may be recorded” and then silently was not is a worse outcome in a dispute than one extra recording.

Separately from the conversation itself, we record and store: voicemail messages left by Recipients on both carriers, and the short automated call made when a phone number is being verified with a carrier, which is stored under a key containing the number being verified.

AI disclosure. Every call handled by an AI agent begins with a spoken announcement that the caller is speaking with an AI assistant and, where recording is on, that the call may be recorded. It is spoken in the language the agent is speaking. Whether it can be switched off depends on which carrier carries the call, and the honest position is this: on our international carrier it cannot, for any account — that carrier can reach any country, the obligation falls on us rather than on the Customer, and no screen offers a way to turn it off. On our India domestic carrier the Customer may turn it off for its own account. That carrier only places calls within India, where the requirement placed on the caller is to declare automated dialling to the telecom operator rather than to announce it on the call. A Customer may only turn it off after recording that declaration with us, and they must confirm in writing that they have made it. If that declaration is withdrawn, the announcement is restored. One limitation worth stating plainly rather than discovering: this setting is written into each agent when that agent is next synchronised to our voice engine, so a change to it is not necessarily immediate and an agent that has not been saved since may still be announcing. We keep a record of every such change and the Customer can see their own. If that carrier ever begins recording calls, the announcement returns for everyone regardless of the setting, because a recorded call that was never announced is a materially different matter. On the inbound menu that plays before an agent answers, the wording of the AI sentence is a field the Customer edits, so what it says there is the Customer's. In every case our agents are instructed never to deny being an AI when asked. Section 8 of our Terms places the disclosure duty on the Customer in every jurisdiction where its Recipients are.

Transcripts. Transcription is performed by our cloud transcription providers, listed in section 8. We transcribe words only and do not create voiceprints, speaker-identification embeddings, or other biometric identifiers from call audio. That statement is about transcription; voice cloning is a different feature and is described in section 20. Transcripts produced through our AI voice engine pass through an automated masking step by default that removes email addresses and long digit sequences; it is deliberately narrow, does not catch street addresses or every phone-number format, and is not applied on every call path, so a transcript should not be treated as reliably redacted.

Withdrawing consent. To withdraw your consent to call recording and storage, turn recording off in the console, or delete your account, which deletes your recordings. You can also write to privacy@movoice.ai. Because recording is central to how much of the Service works, some features are limited without it.

Where this is stored. Recording audio, voicemail, verification-call captures, encrypted Messaging media, cached synthesized speech and archived transcripts are held in Wasabi object storage in the United States (us-central-1). Transcripts are held in our primary database and may be archived to the same object storage as recordings. Uploaded knowledge-base documents, inbound message media, bug-report attachments, assistant voice notes and generated tax invoices are held in our primary database’s file storage rather than in object storage.

6. Recipients — People Our Customers Contact

When a Customer uses Movoice to call, message, or upload information about a Recipient, the Customer is the controller of that personal information and Movoice acts as its processor.

Because the Customer determines why and how Recipient data is used, Recipients who wish to exercise privacy rights — access, correction, deletion, or objection — should contact the Customer that reached out to them. On request we will help the Customer locate and act on the relevant data as their processor, and where you contact us directly we will forward your request to the responsible Customer. A Customer can search for a Recipient by number in the web console under Settings → Privacy and clear the remembered details or erase the whole caller profile; that control is in the web dashboard and not yet in the mobile apps.

Opt-outs, stated precisely. A Recipient can reply STOP to an SMS, and can ask a Customer to stop contacting them. That opt-out is recorded against that one Customer’s account and suppresses that Customer’s outreach; it does not suppress any other Movoice Customer, and it is not a global list. The Service does not scrub any national or regulatory do-not-call registry — there is no automated lookup against the National DNC, TPS, TRAI NCPR or any equivalent — and compliance with those registries is the Customer’s obligation under our Terms. A Customer can remove an entry from its own suppression list; when it does, an administrative record of the removal is written, and that record is itself deleted if the Customer closes their Movoice account. We would rather describe suppression as what it is than let it read as permanent.

A Customer may also embed a voice widget or share a demo link on its own site. Opening one asks the visitor’s browser for microphone access and streams that audio to an AI agent. Section 22 covers this.

7. Caller-Memory Profiling

To make repeat interactions more useful, the Service builds a “caller-memory” profile keyed to a Recipient’s phone number. A profile holds an extracted name, a set of short free-text facts, verbatim summaries of the most recent calls, a pre-written greeting for the next call, and call counts and timestamps. It is used to personalize subsequent AI calls for the Customer that owns the relationship.

How it is built. The profile is derived by sending the call transcript, together with the agent’s name and an excerpt of its prompt, to our AI language provider. The derived analysis is additionally cached for a short period. A profile is built for AI phone calls generally, not only where a Customer has switched something on.

By default we redact personal detail in the underlying transcript as described in section 5 before it is stored.

Caller-memory profiling is performed on the Customer’s instruction; the Customer is the controller of these profiles and is responsible for the lawful basis and any required notice. Profiles are not used to make legally significant automated decisions about Recipients without human involvement. A Recipient may ask the relevant Customer to review, correct, or delete their profile, and the Customer has a control for exactly that (section 6).

Deletion. Profiles are deleted when the Customer’s account is deleted. Automatic time-based deletion of profiles applies only where the Customer has switched on a retention window and where the profile purge is enabled on the deployment; individual saved facts do not carry a timestamp and are not aged out of a profile that survives. We would rather state that than imply a schedule that does not run for everyone.

8. Sub-processors and International Data Transfers

We share personal information with service providers that help us deliver the Service. Each one processes data only for the purpose described here and is bound by contractual data-protection obligations. Some are used only when a Customer turns on a feature or connects an account.

The categories of providers we use are:

  • Telephony and messaging carriers — placing and carrying calls, SMS, WhatsApp, Telegram and email; call-recording transport; phone-number provisioning and lookup; and, for US business texting, registering the sender's business details (United States, India and international).
  • Real-time media — carrying call audio and, for Movoice AI Messaging, voice and video that is not end-to-end encrypted (United States).
  • AI language, speech and voice providers — understanding and generating language, transcribing calls, analysing calls and caller memory, holding knowledge-base documents for retrieval, synthesising speech and creating voice clones (United States, India, Singapore and, only where a Customer selects the mainland-China voice endpoint, China). Some of this runs on systems Movoice hosts itself.
  • Web search — searches an agent or the in-app assistant performs on your behalf (United States).
  • Cloud hosting, database and storage — hosting the web app and voice engine, the primary database, and storage of call recordings, voicemail, verification captures, message media and transcripts (United States).
  • Security and fraud prevention — sign-in, rate limiting keyed on IP address, phone digits and user id, malware scanning of uploaded files (which can include identity documents), and a check of each new account's email address against known disposable-email services. A positive disposable-email result blocks or removes the account; you can ask us to have that decision reviewed by a person.
  • Identity and age verification — KYC/KYB and age checks, including your identity document and a selfie (European Union).
  • Payments and billing — processing Movoice's own fees, in-app purchases and receipt validation, and, where a Customer connects its own payment account, sending a payment link to a Recipient during a call (United States and India).
  • Analytics, diagnostics and support — product usage events linked to your account, crash and error reports including session replay, and support conversations (United States).
  • Notifications — delivering push and VoIP notifications. Notification content passes through these services, not only a device token, and some notifications contain a Recipient's name, phone number or message text (United States).
  • Website services — scripts our web pages load for cookie consent, search, QR codes and code delivery, and a service that receives a visitor's IP address, including on public pages, to show prices in the right currency (international).
  • Maps — map display and address lookup when you open the location picker.
  • Integrations you choose to connect — CRMs, calendars, meeting tools, e-commerce stores, automation platforms and any webhook endpoint you nominate. These receive the data the integration requires, and we do not control processing at a destination you choose.

The current list of named providers, with each one's purpose and location, is available to Customers on request at legal@movoice.ai.

We may also disclose information where required by law, to protect our rights, or in connection with a merger, acquisition, or asset sale, subject to this Policy.

International transfers. Your personal information may be transferred to and processed in India, the United States, the European Union, Singapore, China (only where the mainland-China voice endpoint is selected) and other jurisdictions where our providers operate. Where personal information is transferred across borders we rely on appropriate safeguards, including the European Commission’s Standard Contractual Clauses and equivalent UK and other mechanisms, adequacy determinations where they apply, and contractual and technical protections such as encryption. Copies are available on request at privacy@movoice.ai.

Data residency. We do not offer customer-selectable data residency, and we do not operate Indian, EU or other dedicated regional clusters. Call recordings and the primary database are hosted outside India. Where any other Movoice page or document says otherwise, this section is the operative statement and the other is wrong.

We update the named list before a new provider begins processing Customer Content. We do not currently operate a separate notification subscription; material changes to the categories above appear here, with the revised date in section 24.

9. Data Retention, Deletion, and What Survives

We retain personal information only as long as needed for the purposes in this Policy, after which it is deleted or anonymized.

  • Account and profile data — for the life of the account, then deleted or anonymized, subject to legal retention needs.
  • Call recordings, voicemail and transcripts — retained for the life of the account unless you switch on a retention window. Automatic time-based deletion is OFF by default; the control is currently in the mobile app under Settings → Data retention, the shortest window is 30 days, and there is no retention screen in the web console or desktop app today. The sweep is suspended for all accounts while a litigation hold is in force (see below).
  • Message content — SMS, WhatsApp, Telegram and web-chat messages follow the same retention window where you switch it on; email-channel messages are not covered by that sweep and are retained for the life of the account.
  • Contacts sync data — until you delete it, turn off sync, or delete the account.
  • Administrative audit logs — up to 5 years, then deleted automatically, unless a longer period is required for legal, security, or billing reasons. The period is set by how long a claim about a call or a consent can still be brought. They are also deleted when the account is deleted.
  • Recording access records — the log of who played or downloaded a recording is kept for the life of the account and has no separate expiry.
  • API request logs — 30 days. Webhook delivery records, which contain the payload we delivered including a Recipient’s number, summary, recording link and transcript, are kept until the account is deleted.
  • Movoice AI Messaging safety records — a report is deleted 12 months after it is filed, provided the case has been closed by then; an open case is never deleted at any age. A block record placed on a number is deleted 3 years after it is written, and is not removed by deleting the account it was attached to. Cases and block records involving child sexual abuse material are held indefinitely.
  • Diagnostics data — approximately 90 days.
  • KYC/KYB and payment/financial records — as required to meet legal, tax, and anti-fraud obligations.
  • Tax invoices and credit notes — 72 months from the due date of the relevant annual return, as Indian GST law requires, and the equivalent period under other tax rules. A tax invoice is only valid if it identifies the buyer, so these keep your name, billing email and any GSTIN, including after you delete your account. This is the one category we cannot delete on request: the right to erasure does not extend to records we are legally required to keep, and your own accountant needs the named document.
  • Pre-signup and prospect records — demonstration-call leads, demonstration opt-outs, phone-verification records and the email bounce/complaint suppression list are currently retained without an automatic expiry. We are giving these a retention window; until we have, you can ask us to delete yours at privacy@movoice.ai and we will.

Deleting your account. Deletion is requested in Settings. Billing stops immediately, and the erasure itself runs 7 days later, so that a deletion made in error can be undone — clicking the cancel link in the confirmation email cancels it, and on mobile signing back in also cancels it. On the web console your login is destroyed at once, so there the emailed link is the only way back.

Two consequences worth knowing before you press it: your provisioned phone numbers are given up and cannot be recovered — international numbers are released back to the carrier automatically, and Indian numbers are released by hand, because our Indian carrier offers no automatic release; and if you subscribed through the App Store, Apple continues to charge until you cancel there, because Apple is the merchant and we cannot cancel it for you. The product asks you to acknowledge this before proceeding.

When the erasure runs we delete your account data and the associated Recipient data: call recordings and transcripts, message content across every channel, contacts and caller-memory profiles, conversations with the in-app assistant and its activity records, appointments and orders, your uploaded knowledge base, campaigns and drip sequences, device and browser registrations, API keys and webhook endpoints, and the access tokens for any accounts you connected.

What is kept afterwards, and why:

  • Tax invoices and credit notes, because the law requires it.
  • A record of payments with no person attached to it — amount, date, currency and payment reference — so the money still reconciles against those invoices. Your usage ledger, recording what each call and message cost, is deleted in full.
  • A record that a deletion was requested, which holds the email address and the payment-provider customer identifiers, so we can show the request was made and honoured.
  • Compliance and consent records — an append-only log of consent decisions, do-not-contact entries and overrides, and acknowledgement of the emergency-calling advisory. Some of these rows contain a Recipient’s phone number. They exist to answer the question “was this person asked, and did someone override it” after the account that did it is gone.
  • If your number was blocked from Movoice AI Messaging for abuse, the block record. It outlives the account on purpose — a block you could shed by deleting your account and signing up again on the same SIM would not be a block at all, and the people it protects would have no protection. It does not store your phone number: it stores a one-way scrambled fingerprint of it, computed with a different salt from the one used to find your contacts, so it cannot be turned back into the number and a contact-discovery hash cannot be tested against it. It carries the reason and the date. If the block is lifted, that is recorded too rather than erased, so the decision stays reviewable. The block record is deleted three years after it is written, unless the case behind it is one we are required to hold.
  • If someone reported you to our safety team in Movoice AI Messaging, the report they filed, with the reason, date, any note and the messages they attached as evidence — the one place message content exists in readable form in our systems. A case file is deleted 12 months after it was filed, provided the case has been closed by then. Cases involving child sexual abuse material are held indefinitely. An open case is never deleted at any age.
  • A small number of operational records that our own erasure tooling reports as not yet covered — today: file-scan results, platform alerts, push-delivery attempts, live-chat team assignments and voice-identity rows. We are listing them rather than leaving them out of a list that claims to be complete. They are being brought into the cascade.

Litigation hold. Where a legal hold is in force, scheduled deletions are suspended — including the audit-log purge and every Customer’s configured retention sweep, not only the one the dispute concerns. A hold does not currently stop an account-deletion request from running.

Before you decide, Settings → Export my data returns what we hold that is tied to you.

10. Your Privacy Rights

Subject to your jurisdiction, you have rights over your personal information: to access the data we hold, to correct inaccurate data, to delete your data, to receive a portable copy, to object to or restrict certain processing, and to withdraw consent at any time without affecting prior processing.

How to exercise them. Customers can access, export, correct, and delete data in the product — Settings → Export my data and Settings → Delete account — or by emailing privacy@movoice.ai from the account email. We respond to verified requests within 30 days, or the shorter period your law requires, and will tell you if we need more time. If you are a Recipient, see section 6: contact the business that reached out to you, and we will assist them as their processor.

India — Digital Personal Data Protection Act. You have the right to access, correction and erasure, the right to grievance redressal, the right to nominate another individual to exercise your rights in the event of death or incapacity, and the right to withdraw consent as easily as it was given. Our Grievance Officer is Sai Safalya Tudu, at privacy@movoice.ai. As required by the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, we acknowledge every complaint within 24 hours and dispose of it within 15 days.

California — CCPA/CPRA. You have the right to know the categories and specific pieces of personal information we collect, use and disclose; to correct; to delete; to opt out of sale or sharing; and to limit the use of sensitive personal information. We give notice of the categories collected at or before collection. We do not sell or share personal information as those terms are defined under the CCPA/CPRA. We use sensitive personal information — identity-verification documents, call audio, precise location where you share it, and voice samples — only as necessary to provide and secure the Service and to meet legal obligations, which is exempt from the right to limit; you may still submit a request at privacy@movoice.ai. We will not discriminate against you for exercising any right. You may use an authorized agent, and we verify requests before acting.

EEA/UK. You may lodge a complaint with your local supervisory authority. To exercise any right, contact privacy@movoice.ai.

Automated decisions. Two automated checks can affect access to the Service without a person in the loop: a disposable-email check at signup, and an automatic pause on sending in Movoice AI Messaging when a report of child sexual abuse material is filed. In both cases you can ask for a human review at privacy@movoice.ai.

11. Security and Data-Breach Notification

We implement technical and organizational measures to protect personal information, including encryption in transit, least-privilege access controls, authentication safeguards, network protections, malware scanning of uploads, logging, and regular review. Traffic to our services and to our object storage is carried over TLS, and stored objects are reached through short-lived signed links rather than public URLs.

Encryption at rest is provided by our storage and database providers at the platform level rather than configured per object by our own code. We are stating it that way because it is what we can evidence, and a security questionnaire deserves the accurate version rather than the flattering one.

No method of transmission or storage is completely secure, but we work to protect your information and to limit access to those who need it.

Data-breach notification. If we become aware of a personal-data breach likely to result in a risk to affected individuals, we will notify the relevant supervisory authority and affected individuals as required by applicable law — within 72 hours to the competent authority under the GDPR where feasible, in the manner and timelines required by India’s DPDP Act, and as required by applicable U.S. state breach-notification laws. Where Movoice acts as a processor we will promptly notify the affected Customer so they can meet their own obligations, and assist them as required.

12. Administrative Access and Activity Logs

To operate, support, secure, and bill the Service, our authorized administrators may view account information and activity metadata — login times, in-app actions, call and message counts, duration, delivery status and cost, abuse and security signals, your API key inventory (name, masked prefix, scopes, last used) and API request activity including the caller’s IP address. IP address and browser details are held in infrastructure and API logs; they are not written into the administrative audit log.

A small number of authorized staff can also view call metadata across accounts for a chosen day, with destination numbers shown only as the last four digits, and a platform-wide feed of administrative events.

What we log about ourselves. Administrative actions such as suspensions are recorded. Opening a customer record or an abuse case is recorded from the staff member’s browser. Playing a call recording from the call log or the inbox writes an access record, and any review of a recording by Movoice staff requires a written reason, which is logged against your account and shown to you in your own access history — that one is the strongest of these controls. Two gaps we would rather name than let you assume away: a campaign-call recording played from the campaign screen is not written to that access log, and a download is not recorded separately from a playback.

What is not logged, stated plainly. Staff with super-admin access can read message content in the in-app inbox and the full body of email the platform sent, and those reads do not currently write an audit record. We do not routinely access the content of your calls, transcripts, or messages, and access is limited to acting on your instructions or a narrow support or security need — but we are not going to describe content access as logged when for those two surfaces it is not. Closing that gap is engineering work, not wording.

Retention of these logs is described in section 9. We rely on our legitimate interest in operating a secure, reliable, and abuse-free service.

13. Product Analytics, Diagnostics, and Product News

Product analytics. We use PostHog to understand how the Service is used so we can improve it. PostHog session replay is disabled and we do not send it the content of your calls or messages. However, analytics events are linked to your account and the profile we send includes your account identifier, email address, full name and account creation date, and page views include the full URL. That is more than “usage events only”, so we say so. Lawful basis: our legitimate interest in operating and improving the Service.

Diagnostics. When our apps or website crash or hit an error we send diagnostic data to Sentry: the error and stack trace, app version, operating system and device model, the screen involved, timestamps, a randomized identifier, performance traces, on-device profiles, app-hang reports, and navigation and interaction breadcrumbs. On the web dashboard, and in the desktop application on every platform we ship it to, Sentry Session Replay records a reconstruction of the session in which an error occurred, with all text masked and all media blocked; no session replay runs in the mobile apps. We configure Sentry to scrub personal identifiers, phone numbers and query strings, and we do not intentionally send call recordings, transcripts, message content, contact lists or phone numbers. Diagnostic data is processed in the United States under appropriate transfer safeguards and retained for approximately 90 days.

You can turn crash reporting off in the Movoice mobile app under Settings → Security & Compliance. There is no equivalent switch in the web dashboard today.

Bug reports. Where you submit a bug report, the report text, the automatically captured device and page context — which on the web includes the full address of the page you were on, query string included, and your browser user-agent — and any last recorded error are sent to our AI provider for automated triage. Your name and email are attached to the report and included in the alert emailed to authorized staff; they are not sent to the AI provider. Section 17 describes the optional screen capture and the masking applied to it.

Product news. Product-news email operates on an opt-out basis for accounts created before we added the consent checkbox at onboarding, and on consent for accounts created after it. Marketing push notifications require an explicit opt-in, and unsubscribing from email also withdraws marketing push. Announcements shown on the in-product notification bell are not subject to an opt-out.

The newsletter, if you sign up from our website. Anyone can subscribe from the form in our website footer, with or without a Movoice account. We store your email address, the date, and which page you subscribed from — that last one only so we can show, if asked, where your consent came from. Our lawful basis is your consent, and consent is the whole mechanism: we send one email asking you to confirm, and until you click the link in it your address is inert and can receive nothing else. If you never confirm, nothing is ever sent. Every newsletter carries an unsubscribe link that works without signing in, because you may not have an account to sign in to. Unsubscribing deletes your address rather than marking it inactive, and if you have a Movoice account, deleting that account deletes any newsletter subscription for its email address too. This list is entirely separate from the incident notifications you can subscribe to on our status page: those tell you when something is broken and carry no marketing, and subscribing to one never subscribes you to the other.

Daily summaries. Two different things go out, and they behave differently. The push recap on your phone follows the Daily recap switch in Settings, daily or weekly, and turning it off stops it. The separate activity summary sent by email, by SMS to the number you verified, and where an approved template exists by WhatsApp, reads no preference at all: it goes to every account that has finished onboarding and has had any call in the past seven days — including on days when you made no calls — and the email carries no unsubscribe link. We are giving it the same switch the push recap has; until then, write to privacy@movoice.ai and we will stop it for your account.

14. Cookies, Local Storage, and Similar Technologies

On our website and web dashboard we use cookies and similar technologies for authentication and to remember your preferences, and we use the analytics and diagnostics described in section 13.

We are not going to claim a consent banner we do not have. There is no cookie-consent gate in the product today: on page load, including on public pages, we make a third-party request that discloses your IP address to return a country code for currency display, and we write a local-storage entry for your chosen currency. We also write local-storage entries for your chosen currency, your interface preferences, your device identifier and prompts you have dismissed. You can control or clear cookies and site data through your browser, though disabling some will affect functionality. Where a consent gate is legally required we will implement one rather than assert one.

15. Children’s Privacy

The Service is intended for business use and is not directed to children under 18. We do not knowingly collect personal information from children under 18. Movoice AI Messaging additionally requires a completed identity check establishing that you are 18 or over. If you believe a child has provided us personal information, contact privacy@movoice.ai and we will delete it.

16. Contacts Sync

In our mobile app, if you choose to sync your phone contacts, we upload the names, phone numbers, and email addresses from your device’s address book to your private Movoice account so you can call, message, and manage them from the app and web dashboard. We ask for your explicit consent in the app before any contacts are uploaded, we never upload your contacts in the background, your contacts are never sold, and you can delete them at any time. You can turn sync on or off in Settings → Contacts sync.

On iOS the operating-system contacts permission is requested during onboarding, before you have used a contacts feature; granting it does not upload anything, and the separate in-app consent still gates the upload.

If you sync contacts, you are responsible for having any consent required to share that information with us and to contact those individuals through the Service. Movoice AI Messaging discovers which of your contacts also use it without uploading your address book; see section 23.

17. Your Devices — Permissions, Capture, and Sign-in

What we ask for, on each platform, and why.

iOS — microphone (speaking with agents and the assistant, voice notes, and recording a voice sample if you create a synthetic voice); contacts; camera and photo library (sending and saving media); location when in use (only for the map picker); notifications; and Face ID or Touch ID for App Lock.

Android — microphone; contacts; approximate location; notifications; full-screen intent (so an incoming call can show); Bluetooth (routing call audio to a headset); phone state (required by the system call integration); and biometrics for App Lock.

macOS desktop — microphone and notifications only.

What we deliberately do not ask for, on any platform: calendar access on the device, motion or activity recognition, health data, SMS or call-log access, precise location on Android (the fine-location permission is removed at build time), and any advertising identifier. We do no cross-app or cross-company tracking, and no advertising SDK ships in our apps.

App Lock. The app can lock behind Face ID, Touch ID or a fingerprint. The check is performed entirely by your operating system; we receive only a success or failure and never the biometric itself.

Screen capture, and the difference between platforms. On Android the app blocks screenshots and screen recording at the operating-system level across the app, lifted only for the moment you take an in-app capture yourself. On iOS no such block exists or can exist; the only protection is that the app’s snapshot in the multitasking switcher is blurred.

The in-app capture tool is off by default. You switch it on in mobile Settings, it switches itself off after 15 minutes, it holds at most six images in app-private storage and never in your photo gallery, and nothing is uploaded until you press Send. Before upload it masks phone numbers, email addresses and names on the calls, call-detail and lead screens, and records how many fields it masked. Captures are readable only by authorized Movoice staff and are deleted when the report is deleted.

Your devices. Settings lists every device signed into your account with its platform, name and last-active time, and lets you rename one, stop it ringing, or stop it receiving calls and notifications. We want to be precise about that last control: it clears the device’s push tokens and stops it ringing. It does not end that device’s signed-in session. To end a session, change your password or sign out on the device itself.

Notifications. Push content passes through Expo and then Apple’s or Google’s push services, and some notification bodies contain a Recipient’s name, phone number, or message text. On iOS, chat notifications are delivered as Communication Notifications: we hand iOS the sender’s name, their number or handle, the conversation identifier and the message text so the alert can show as a conversation with the sender’s photo, and we download that photo. iOS records this on your device and may surface it elsewhere in the system.

18. The Desktop Application

Our macOS desktop application is a native shell that loads the same web dashboard over HTTPS. It collects nothing the web application does not, and everything in this Policy about the web dashboard applies to it, including the Sentry session replay described in section 13.

What it adds: it requests microphone and notification access; it stores locally only its window position, an optional launch-at-login item, and the webview’s own session cookies; and a caller’s name or number is shown in the macOS Notification Center.

It checks for, downloads and installs updates automatically in the background. Updates are cryptographically verified against our signing key and take effect the next time you quit and reopen the app.

19. The In-App AI Assistant

There are two assistants, and they send data to different providers.

Ask Movoice (the Helper), on the web dashboard and desktop, sends your question, recent messages in that chat, facts about your account, the names and current values of the controls on the screen you asked from, and the records you ask about — calls, transcript-derived quality notes, inbox conversations, voicemails, orders, appointments and follow-ups — to Anthropic in the United States. Helper conversations are stored in our primary database and are removed by your account’s message-retention window or when you delete your account.

The mobile Copilot sends your question, account statistics and knowledge-base snippets to OpenAI, and sends voice input to OpenAI Whisper or to Sarvam. You can clear Copilot chat in the app.

The assistant acting on your behalf. Once you accept a separate in-app agreement — which is versioned, and re-asked whenever the capability widens — the assistant can operate controls in your account: opening screens, highlighting a control, changing reversible settings, and at higher settings making changes that matter after showing them to you. Before you accept, it can only point. You choose the level: point only, ask me before each change, or work unattended. It cannot spend money, delete anything, contact anyone, touch credentials, or submit identity or regulatory documents.

We keep a per-step record of what it did: the control, the route, the outcome, and the value before and after. That record is review-only — it is removed by your retention window or on account deletion, and there is no separate control to erase it on its own.

Generated messages. The Service can compose and send messages to your Recipients on your behalf after a call — a follow-up on WhatsApp, SMS or email, an optional call summary, and the personalised greeting spoken at the start of that Recipient’s next call. The wording is machine-generated from the call. Do-not-contact and opt-out suppression is applied before sending. These messages do not carry an AI-content label; where the law requires one, that is the Customer’s responsibility under our Terms.

Knowledge base. Documents you upload and pages we crawl at your instruction are transmitted to and held by our AI sub-processor for retrieval, and re-uploaded periodically while they remain in use.

20. Voice Cloning and Synthetic Voices

The Service can build a synthetic voice from a short speech recording, so an agent can speak in that voice.

What is collected: a speech sample, typically between ten and sixty seconds, recorded in the app or the web console or uploaded by you.

Where it goes: the sample is sent to the voice provider selected for the request — ElevenLabs, Alibaba Cloud (DashScope/Qwen), or our self-hosted MOSS-TTSD server — which builds a persistent voice model. Where the mainland-China endpoint is selected, the sample is processed in China. The model persists with that provider until it is deleted.

This is different from transcription. Our transcription does not create voiceprints or biometric identifiers, and section 5 says so. A cloned voice is a persistent model derived from a specific person’s speech, and depending on where you are it may be treated as biometric information under laws such as Illinois’ BIPA, Texas’ CUBI, Washington’s HB 1493 and Tennessee’s ELVIS Act. We are calling it out separately rather than letting the transcription sentence appear to cover it.

Whose voice may be cloned: your own, or someone else’s only with their informed written consent. Our Terms make this a warranty you give us, with an indemnity behind it. Do not clone a voice you do not have the right to clone.

Deleting a clone: delete the voice in the product, or write to privacy@movoice.ai and we will delete it and ask the provider to delete the model.

21. The Developer API, Webhooks, and Onward Destinations

Where you use our developer API, we record for each authenticated request the account, the API key used, the HTTP method, the route, the response status, the duration and the caller’s IP address. Query strings are stripped so identifiers in them are not logged. These records are kept for 30 days. The IP address is visible to authorized Movoice staff and is not exposed on any customer-facing screen.

Agent configuration submitted through the API — including the system prompt and welcome message — is transmitted to our voice engine at the moment of the call, before any local record is created.

Webhooks. You can register endpoints to receive call events. The payload we deliver contains the Recipient’s phone number, call metadata, the AI summary, the recording link and the full transcript. We sign each delivery so you can verify it came from us. We keep a record of each delivery, including the exact body sent; those records are kept until your account is deleted. You choose the destination, and once data reaches it we do not control what happens to it.

The same applies to any automation platform, CRM or store you connect: we send what the integration is configured to send, to a destination you nominated.

22. Demonstration Calls and the Embeddable Voice Widget

Two surfaces process the personal data of people who have no Movoice account. For both, Movoice is the controller.

Demonstration calls. Where you ask for a demonstration call from our website, we collect your name, email address and phone number, send a one-time code to that number to confirm you are in possession of it, store a verification record containing the number and a hashed copy of the code, and place an outbound AI call to you. Lawful basis: your consent, given by requesting the call. A request to stop received on a demonstration call is recorded against the demonstration service only and does not create an opt-out against any Customer. These records do not currently have an automatic expiry; we are giving them one, and in the meantime you can have yours deleted at privacy@movoice.ai.

The voice widget. A Customer can embed a voice widget or share a demo link on its own website. Opening one asks your browser for microphone access and streams that audio to an AI agent so it can answer you. The Customer that embedded the widget decides why it is there and what happens to the conversation, and is responsible for telling you about it on their own site.

23. Movoice AI Messaging — End-to-End Encrypted Personal Messages

Movoice AI Messaging is a separate, optional feature inside the mobile app: a private messenger for your own personal conversations. It is not the business calling and campaign product described above, and it works differently in ways that matter to you.

End-to-end encryption, and its edges. Your messages, photos and voice notes are end-to-end encrypted. The keys are generated on your device. We hold the ciphertext and cannot open it.

There are two honest qualifications. First, voice and video calls in Messaging are not end-to-end encrypted today: they are encrypted in transit between your device and our media server, LiveKit, which is technically able to access the audio and video. Second, the encryption has no forward secrecy — identity keys are long-lived, so anyone who obtained a device’s secret key could read that device’s past messages. We do not implement a ratchet, and we are not going to imply one.

If you enable the optional PIN unlock for your encrypted backup, we store a copy of your recovery code encrypted under a key we hold separately from the database. Someone who obtained both could recover that code and open your backup. If you want a secret we cannot be compelled to produce, use the written recovery code and do not enable the PIN.

What we can still see. Encryption protects content, not the fact that a conversation happened. We hold: who is in a conversation, when each message was sent and what type it was, read-receipt timestamps, typing activity, which message a message replies to or reacts to, whether a message was edited or deleted and when, your list of devices with their names and public keys, your handle, and — once a conversation exists — the verified phone number of each participant. We hold the encrypted message itself and an object key for encrypted media. Push notifications carry the sender’s handle and the message type through Apple’s and Google’s push services.

For calls we keep who called whom, whether it was video, when it rang, was answered and ended, and who ended it — for as long as the conversation exists.

For account security we also hold a Registration Lock PIN hash and its failure counters, your list of permitted devices, the public keys of devices you removed, and records of security-delayed actions with the alarms we sent.

Your identity, and what we discard. To use Messaging you verify your phone number, prove the SIM is in your device, accept the Messaging Terms and Community Rules in our Terms of Service, and complete a one-time identity check confirming you are 18 or over. From that check we store the outcome, an over-18 flag, the provider’s own status wording and the provider’s session reference. We do not store your date of birth, your document images or your document number — the date of birth is used to compute the age check and then discarded. The documents themselves are held by our verification provider.

Finding people. To show which of your contacts use Messaging, your device converts each number into a salted hash and sends only the hashes; your address book is never uploaded or stored for this feature. You may claim a public handle so people can reach you without knowing your number. A handle lookup returns no phone number — but once either of you starts a conversation, each of you can see the other’s verified number, as in any messenger where the number is the identity.

Keeping people safe. Because we cannot read messages, safety depends on what you tell us and on behaviour we can observe without reading anything. When you report someone, the messages you attach are sent to us in readable form — your copy, your decision, and the only place message content exists in readable form in our systems. We keep records of reports, enforcement actions (warnings, sending pauses, device revocations, bans), and behavioural signals such as how many new people an account contacts, how often they are replied to, and how many people block them. None of these signals involve reading a message. A report of child sexual abuse material triggers an immediate automatic pause on sending before any human looks at it, and is flagged for immediate human review, after which we report to the relevant authorities where we are required or able to do so.

Deleting messages, precisely. You can delete a message you sent, for everyone, within about 60 hours. Deleting anything else — including messages sent to you — hides it on your device only; the encrypted copy stays on our servers until you delete your account. There is no way to delete a whole conversation.

Deleting your account. This removes your Messaging conversations, messages, encrypted media, device keys, encrypted backup, handle and directory entry. Because a one-to-one message is a single record carrying sealed copies for both of you, deleting your account also removes the other person’s copy of your shared conversation. Abuse reports filed against you survive, as described in section 9. A block placed on your number also survives, which is the point of blocking a number rather than a login.

Law-enforcement requests. We respond to valid legal requests with what we actually hold: account details, the verified phone number, message and call metadata, the encrypted message blobs and encrypted key backup, and any abuse report and the plaintext evidence attached to it. We cannot provide the content of ordinary messages, because we cannot read it, and we say so in response to any request that asks — subject to the PIN-unlock qualification above.

Age. Messaging is for adults only. Access requires a verified identity showing you are 18 or over.

24. Changes to This Policy, Effective Date, and Contact

We may update this Privacy Policy from time to time. When we do, we post the updated Policy on our website and in the apps and revise the “Last updated” date; material changes may be communicated by additional notice. Your continued use of the Service after an update takes effect constitutes acceptance of the revised Policy.

Contact us:

  • Support: sales@movoice.ai
  • Privacy questions and Grievance Officer (Sai Safalya Tudu): privacy@movoice.ai
  • Legal notices: legal@movoice.ai

Governing law. This Policy and any dispute relating to it are governed by the laws of India. Disputes will be resolved by arbitration seated in India under the Arbitration and Conciliation Act, 1996; the courts at the location of the company’s registered office have exclusive jurisdiction for injunctive and equitable relief.

Movoice AI is provided by Metawaveai Technologies Private Limited (incorporated in India), together with its affiliate Metawaveai Technologies Inc.