AgentDial / privacy
Privacy with a clear boundary
AgentDial stores an account-linked permanent call ledger: opaque ID, timestamps, normalized states and artifact availability. It is pseudonymous, not anonymous. Phone numbers, prompts, transcript text, carrier identifiers, session identifiers and media links are never placed in that ledger.
Sensitive details are application-encrypted and expire at creation plus 30 days, never 30 days after the latest update. Application checks enforce expiry even if a cache still contains content. Deleting details tombstones access first and terminates active calls; ledger rows remain.
Credentials are encrypted with account-specific wrapped keys and are write-only. Sessions, hashed tokens, email and consent grants are account data with their own lifecycle. No third-party analytics are used on sensitive pages.
OpenAI Live sessions explicitly use store:false. This does not waive vendor processing or abuse-monitoring policies. Telnyx recordings, call records, customer copies and infrastructure backups have separate retention. Upstream recording deletion is best effort; revoked provider access can prevent it. Native recording is gated until verified.
Deleting an account immediately blocks authentication and queues sensitive cleanup. Operational encrypted credential material may remain temporarily if needed to terminate a billable call. Infrastructure backups cannot be instantly physically erased; restored data must respect original tombstones and deadlines.
Customer webhooks are not enabled in v1. Report privacy or abuse concerns to the operator through the deployment support channel; launch requires a monitored contact address.
Review setup prerequisites →