Your calls are private. Here’s how we keep them that way.
Recordings carry names, numbers and money. This page says exactly what protects them today, who else handles them, and what we haven’t built yet.
What protects your calls today.
Sign-in
Passwords are hashed with argon2id; we never see them. Sessions are random tokens in httpOnly cookies, every change carries a CSRF token, and repeated failed sign-ins lock the account for a while.
One door to every workspace
Every request for workspace data passes through a single, tested membership check. Apart from share links you create yourself, it is the only way in.
Encrypted source credentials
Tokens and passwords for your phone systems are encrypted at rest. The app won’t even start without its encryption key.
Verified email before spending
No call is transcribed for an account until its email address is verified.
Audit log
Sensitive actions, like adding a source or deleting a call, are recorded with who did them and when.
Delete for good
Delete a call, or a whole source with everything synced from it. The audio goes first, then the transcript and every finding attached. Deleting a call takes an admin.
Share links that end
A shared call link expires on the date you set, can be revoked at any time, and counts its views.
Outbound requests guarded
Webhooks we send and websites we read for your knowledge base can’t be pointed at internal addresses.
Four roles. Each sees what it should.
Invite your team by email and give each person a role.
Everything, including deleting calls for good.
Runs the team: coaching, digests and team-wide settings.
Reads calls, dashboards and contacts, and uses Ask.
Only their own calls.
Where your data lives, and who else touches it.
ListenFox runs on servers we manage at Hetzner, in the EU. These are the only other companies that receive your data, and what each one gets. Anything you connect yourself, such as Slack, Telegram or Google, receives what you send it.
| Provider | Used for | What it receives |
|---|---|---|
| AssemblyAI | Transcription, Standard engine | The audio of a call; returns the transcript |
| Deepgram | Transcription, Precise engine | The audio of a call; returns the transcript |
| OpenRouter | Reading calls, suggestions and Ask | Transcript text; returns structured answers |
| Stripe | Card payments | Billing email and plan; your card stays with Stripe |
| Brevo | Account email | Your email address and the message |
| Hetzner | Hosting and storage | Everything above, at rest, in the EU |
Transcription and analysis providers receive a call’s audio or transcript in order to process it, and their own retention terms apply. We haven’t yet switched on every provider’s opt-out from retention and model training; this page will say so when we have. We don’t sell your data, and we don’t use your calls to train models of our own.
Not available yet.
If any of these is a must-have for you, say so when you book a demo. It changes what we build next.
Remove card, ID and bank numbers from transcripts
On the roadmapSingle sign-on (SSO)
On the roadmapCustom roles
On the roadmapSelf-serve account deletion and retention settingsToday, deletion beyond a call or a source is by email request
On the roadmapSecurity certificationsListenFox doesn’t hold SOC 2, ISO 27001, HIPAA or similar today
Not yet
Found a security problem?
Email hello@listenfox.com with what you found and how to reproduce it. Please don’t test against other customers’ data.
Read the privacy policy for what we hold, why, and how to have it deleted.
Bring your security questions to the demo.
We’ll answer them against the code, not a brochure.