Privacy Policy
Last updated: 11 August 2026
This policy explains what Vocra collects, why, and what we do with it. It covers vocra.cloud and the Vocra voice server.
Who we are
Vocra is operated by an independent developer, not a registered company. Payments are handled by Paddle.com Market Ltd, our merchant of record — Paddle processes billing on our behalf and has its own privacy policy governing that data.
What we collect
- Account data — your email, name and avatar (the last two only if you sign in with Google or GitHub).
- Agent configuration — the personas, voices, models and policies you set up.
- Provider API keys — encrypted with AES-256-GCM before storage and decrypted only in memory, only to run your sessions. We never display them back to you.
- Call records and transcripts — timings, status, and the text of the conversation, so you can review calls in the dashboard.
- Usage events — session starts and ends, used for your dashboard analytics and to enforce plan limits.
What we do not do
We do not store call audio — audio is streamed through the voice server in memory and discarded. We do not sell your data, and we do not use your conversations to train models.
Processors we use
Supabase (database and authentication), AWS Amplify (web hosting), Hetzner (voice server), and Paddle (payments, as merchant of record). When you connect provider keys, your call content is also sent to whichever providers you chose — Groq, OpenAI, Google, Deepgram, ElevenLabs or Twilio — under their own privacy terms.
If you use a Vocra-provisioned phone number, Telnyx carries those calls and text messages and processes the numbers involved. If you use follow-up or campaign emails, Resend delivers them. Both apply only when you choose those features; nothing is sent to either otherwise.
Messages you send through Vocra
Text messages and emails your agents or campaigns send are stored alongside your call history and deleted on the same schedule. When someone replies STOP to one of your texts, or unsubscribes from one of your emails, we record that address so it is never contacted again on your behalf — that record is kept for as long as your account exists, because forgetting it would mean contacting someone who asked us not to.
Retention
Transcripts are kept for the window your plan specifies (7 days on Free, 90 on Starter, 365 on Pro) and then deleted automatically. Account data is kept until you delete your account, after which it is removed along with your agents, credentials and call history.
Your rights
You can export or delete your data from the dashboard, or by emailing us. Depending on where you live you may also have rights to access, correct, or restrict processing of your data; contact us and we will honour them.
Security
All traffic runs over TLS. Database access is constrained by row-level security so one account cannot read another’s data. Provider secrets are encrypted at rest with keys held outside the database.
Contact
privacy@vocra.cloud