This policy explains what qallin collects, why, who else sees it, how long we keep it, and what you can ask us to do about it. It is written to be read, not to be survived.
It covers qallin — the business phone service at qallin.ai and app.qallin.ai and through our mobile applications — provided by Qallin Technologies, LLC.
A phone system sees more than most software: not only who your customers are, but who called whom, when, for how long, and — where you have turned recording on — what was said. That is why this policy has a section on call records specifically, and why the retention periods are stated as numbers rather than as “as long as necessary”.
1. What this policy covers#
This policy applies to information we handle when a business uses qallin, and to visitors to qallin.ai.
It does not cover what your own business does with the information it collects from its customers. When your customer calls you, you decide why you are talking to them and what you do with the record afterwards. Our role there is to run the system that carries the call.
2. Our two roles#
For your account information — the people who sign in, your billing details, your settings — we decide how it is used, and this policy is the full account of that.
For your business content — your calls, messages, recordings, transcripts, notes and contacts — we act on your instructions. You decide what to collect and why; we process it to run the Service for you, and for nothing else. We do not sell it, we do not mine it to sell you something, and we do not use it to train public AI models (section 8).
3. Information you give us#
- Account and identity
- Business name, the name and email address of each User, and a mobile number used to verify the account. We verify accounts because an unverified phone network becomes a spam network, and then carriers block everyone on it.
- Business registration details
- Legal entity name, address, EIN and similar details, where you text. These are required by carriers for A2P 10DLC registration and are passed to The Campaign Registry — see section 9.
- Payment information
- Handled by our payment processor. We see the card type, the last four digits and the expiry; we never hold the full number.
- Content you put in
- Contacts, notes, saved messages, assistant instructions, and anything else you type into the Service.
- What you send support
- The messages you write to us and anything you attach to them.
4. Information created by using the Service#
- Call detail records
- For every call: the numbers at each end, the direction, the date and time, the duration, which User handled it, and whether it was answered, missed or sent to voicemail. This is the category US law treats specially — see section 5.
- Messages
- The content and metadata of texts sent and received through the Service, including delivery status reported by carriers.
- Voicemail and transcripts
- Voicemail audio, and the transcript we generate so it can be read and searched.
- Call recordings and their transcripts and summaries
- Only for calls you have chosen to record. Recording is off unless you turn it on, and where the law requires everyone’s consent an announcement plays first and cannot be disabled.
- Assistant interactions
- What a caller said to the assistant, what it captured, and what it did.
- Product usage
- Which features are used, from which app version and device type, and diagnostic logs when something fails.
5. Customer Proprietary Network Information#
Who you called, who called you, when, and for how long is Customer Proprietary Network Information — CPNI — and United States law protects it specifically, separately from and more strictly than general privacy law.
What that means in practice:
- We use CPNI to provide the Service, to bill you, to prevent fraud, and to respond to lawful legal process. Nothing else.
- We do not sell CPNI, and we do not disclose it to third parties for their own marketing.
- We will not use your CPNI to market additional services to you without asking first.
- Access inside qallin is restricted to staff who need it for support, security or billing, and access is logged.
If you tell us not to use your CPNI for anything beyond running the Service, that costs you nothing and changes nothing about the service you receive.
6. Device, cookies and analytics#
Our apps report device type, operating system version, app version and crash diagnostics, so we can tell whether a call failed because of the app or because of the network.
On qallin.ai we use cookies that are necessary for the site to work and a small amount of privacy-respecting analytics to see which pages are read. We do not run advertising trackers, and we do not build profiles of visitors across other websites.
7. How we use information#
- To run the Service — place and receive calls and messages, transcribe voicemail, produce summaries, keep the customer record, and let the assistant answer.
- To register you with carriers so your texts can be delivered at all.
- To bill you and to calculate the taxes and regulatory charges a telecom service carries.
- To support you when you ask us for help.
- To keep the network safe — detect fraud, abuse, spam and traffic that threatens other customers’ ability to place calls.
- To improve the product using aggregated and de-identified usage data, never by reading your conversations.
- To meet legal obligations, including lawful requests and record-keeping duties.
8. AI processing#
Transcription, summaries, suggested follow-ups and the assistant are produced by AI models. Some run at providers we use as sub-processors, listed in section 10.
Your calls, messages, recordings and transcripts are not used to train public or third-party AI models. Our agreements with AI sub-processors prohibit them from training on content we send and require them to delete it after processing.
Transcripts and summaries contain errors — accents, crosstalk, bad lines and background noise all degrade them. Treat them as a convenience, not as a verbatim record.
10. Our sub-processors#
We use a small number of vendors to run the Service. Each is under contract to process data only on our instructions.
- Telecom carriers — to originate and terminate calls and messages on the US network.
- Cloud hosting — to run the application and store data, in the United States.
- AI providers — for transcription, summarization and the assistant, under agreements prohibiting training on your content.
- Payment processing — to take payment. Card numbers go to the processor, not to us.
- Transactional email — to send account email such as verification and receipts.
- Error and performance monitoring — to find out why something broke.
The current list of named vendors is available at privacy@qallin.ai on request, and we will give notice before adding one that handles call content.
11. How long we keep things#
These are commitments, not descriptions of the general case.
- Call detail records
- 24 months, then deleted. Retained this long because billing disputes, fraud investigations and carrier queries arrive months after the call.
- Voicemail and its transcript
- Kept until you delete it, or 12 months after account closure, whichever is first.
- Call recordings, transcripts and summaries
- Kept until you delete them, or 12 months after account closure. You can set a shorter automatic deletion period in your account.
- Messages
- Kept until you delete them, or 12 months after account closure.
- Account and billing records
- 7 years after closure, because tax and telecom record-keeping rules require it.
- Support correspondence
- 24 months.
- Backups
- Deleted content disappears from live systems immediately and from backups within 35 days.
You can export your data before closing an account. After the periods above, deletion is permanent and we cannot restore it.
12. How we protect information#
- Data is encrypted in transit and at rest.
- Access by our staff is limited to those who need it, requires multi-factor authentication, and is logged.
- Recordings and transcripts are stored separately from account data.
- We review access and dependencies regularly and patch on a schedule.
What we do not have. qallin holds no SOC 2, HIPAA or GDPR certification today. These are being pursued and none is held. Any page, salesperson or AI assistant claiming otherwise is wrong. If your business requires a certified provider, we are not one yet.
If a breach affects your information, we will tell you promptly and tell you what we know, including what we do not yet know.
13. Your choices and your rights#
Depending on where you live — California, Colorado, Connecticut, Virginia, Texas, Oregon, Montana and a growing list of other states — you may have the right to:
- know what personal information we hold about you and how we use it;
- get a copy of it, in a portable form;
- correct it if it is wrong;
- delete it, subject to the record-keeping duties in section 11;
- opt out of sale or of sharing for targeted advertising — which for us is already the position: we do neither;
- not be discriminated against for exercising any of these.
To exercise a right, write to privacy@qallin.ai. We will verify who you are before acting, and answer within the period the applicable law requires — 45 days in most states. An authorized agent may act for you with written proof.
If you are the customer of a qallin user — someone whose call was answered or recorded by a business using qallin — that business decides what happens to that record. Ask them, and if they need us to act, we will act on their instruction.
14. Consent: what is yours to obtain#
Two obligations sit with you rather than with us, and they are the two that most often go wrong.
Recording. Some states require every party to consent to a recording. qallin plays an announcement where that applies and it cannot be disabled — but knowing which rule applies to your calls, and having the consent, is yours.
Messaging. Texting someone requires their prior express consent under the TCPA, and every message must offer a way to stop. Our Acceptable Use Policy sets out what that means in practice. Consent must be yours before the first message, not collected afterwards.
15. Children#
qallin is a business product and is not directed at children. We do not knowingly collect information from anyone under 18. If we learn that we have, we delete it.
16. Where information is processed#
qallin is offered in the United States and your data is stored and processed there. Some sub-processors may provide support from outside the US; where they do, they are contractually bound to the same protections.
17. Changes to this policy#
When this policy changes we update the date at the top. For a change that materially affects how we use information, we give at least 30 days’ notice by email before it takes effect.
Earlier versions are available on request, so you can see exactly what changed.
18. Contact and complaints#
Qallin Technologies, LLC — privacy@qallin.ai. Write to us first: we would rather fix something than have you escalate it.
If we cannot resolve it, you may complain to your state attorney general, and for matters concerning call records, to the Federal Communications Commission.
Questions about anything on this page: privacy@qallin.ai.