ListenFox is operated by [operating entity, legal name to be inserted], a company registered in India. We are the controller for your account details and a processor for the call data you connect. The short version: we do not sell your data, we do not use it to train models of our own, and you can have all of it deleted by asking.
1. What we hold
About you
- Name, email address and a hashed password (argon2id). We never see the password itself.
- Workspace membership and role, plan, credit balance and a ledger of what was spent on what.
- Session records: an opaque token, when it was created and from which IP address.
About your calls
- Call records from the sources you connect: caller and target numbers, time, duration, agent, and any revenue field your source provides.
- The recordings themselves, stored in our object storage so we can play them back to you.
- Transcripts, split by speaker, with timings.
- The answers extracted from each call, the findings built from them, and any questions you ask and their answers.
- Credentials for your sources, such as an API token or a Google sign-in grant, encrypted at rest.
Callers are not our customers and we have no relationship with them. You are responsible for being allowed to record and process their calls (see the terms, section 3).
2. Why we hold it
- To run the service: sync, transcribe, analyse, display and play back.
- To bill you and to tell you when credits are low.
- To keep the service secure: sign-in lockout and session checks.
- To email you about your account. We do not send marketing email.
We do not sell personal data, we do not share it with advertisers, and we do not use your recordings, transcripts or findings to train machine-learning models of our own.
3. Who else processes it
These are the only third parties that receive your data, and what each one receives. Services you connect yourself, such as Slack, Telegram or Google, receive what you send them.
| Provider | Used for | What it receives |
|---|---|---|
| AssemblyAI | Transcription (Standard engine) | Audio of a call; returns the transcript |
| Deepgram | Transcription (Precise engine) | Audio of a call; returns the transcript |
| OpenRouter | Analysis: reading calls, suggestions and Ask | Transcript text; returns structured answers |
| Stripe | Card payments | Billing email and plan; your card is handled by Stripe |
| Brevo | Transactional email | Your email address and the message |
| Hetzner | Hosting and storage | Everything above, at rest, in the EU |
Transcription and analysis providers receive a call’s audio or transcript in order to process it, and their own retention terms apply. We have not yet switched on every provider’s opt-out from retention and model training; we will update this page when we do. Which transcription provider handles a workspace depends on the engine you choose in settings.
4. How long we keep it
- Call records, recordings, transcripts and findings: for as long as your workspace exists, so the evidence behind every finding stays playable.
- Public share links you create expire on the date you set (30 days by default) and can be revoked at any time before that.
- Sessions: until you sign out or they expire.
- The credit ledger: for the life of the account, because it is the record of what you were charged.
- After an account is closed: everything is deleted within 30 days, except billing records we must keep under Indian tax law.
5. Deletion and your rights
You can delete a call, or a source and everything synced from it, inside the product. For a workspace or the whole account, email us from the address on the account and say what you want removed. Deleting a call removes its recording, transcript and findings. Deleting the account removes everything in section 1. We confirm by email when it is done, within 30 days. Self-serve account deletion is planned; until it ships, email is the way.
You can also ask us for a copy of what we hold about you, ask us to correct it, or object to a use of it. We answer within 30 days. Under India’s Digital Personal Data Protection Act, and under the GDPR if you are in the EU or UK, you may also complain to your data-protection authority.
6. Cookies
This website sets no cookies and runs no analytics or advertising scripts. The product sets two first-party cookies: a session cookie so you stay signed in, and a theme cookie that remembers light or dark.
7. Security
- Everything travels over HTTPS.
- Passwords are hashed with argon2id; sessions are opaque random tokens in httpOnly cookies; requests that change anything carry a CSRF token.
- Source credentials are encrypted at rest. Every request for workspace data passes through a single membership check.
- If we discover a breach that affects you, we will tell you without undue delay and say what was involved.
More on the security page.
8. Contact
Privacy questions and deletion requests: hello@listenfox.com, from the email on your account. We update this page in place and change the date at the top when we do.