> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zelto.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Privacy Policy

> How Zelto collects, uses, shares, secures, and lets you control personal information and customer content.

**Last updated: July 27, 2026**

Zelto ("Zelto", "we", "us", or "our") provides production analytics and quality
assurance for voice AI agents. This Privacy Policy explains what information we
collect, how we use and share it, how we keep it secure, and the choices and
rights you have. It applies to our website at [zelto.ai](https://zelto.ai), our
application at [dashboard.zelto.ai](https://dashboard.zelto.ai), our APIs, and
related services (together, the "Services").

If you have questions or want to exercise a privacy right, contact us at
**[privacy@zelto.ai](mailto:privacy@zelto.ai)**.

## Who we are and our role

Zelto is a business-to-business service. Our customers connect their voice AI
platforms (such as Vapi, Retell, LiveKit, and others) so we can analyze their
production calls.

* For **account and website data** (the information you give us to sign up and
  use Zelto), Zelto is the **controller**.
* For **customer content** — the call recordings, transcripts, agent prompts,
  and related metadata a customer sends us to analyze — Zelto acts as a
  **processor** on behalf of that customer, who is the controller. Our handling
  of customer content is governed by our agreement with the customer (including
  any Data Processing Addendum). If you are an end user whose call was analyzed,
  please direct requests to the business that operates the voice agent; we will
  support them in responding.

## Information we collect

**Account information.** Name, work email, organization name, role, password
(stored only as a hash), and authentication identifiers (for example, when you
sign in with Google).

**Customer content.** Call recordings and audio, transcripts, agent system
prompts and configuration, call metadata (timestamps, phone numbers, provider
identifiers, durations), and the analyses, findings, and notes generated from
them. This content may contain personal information about a customer's end
users; the customer controls what they send us.

**Integration data.** When you connect a third-party service (voice provider,
Slack, Linear, Google Chat, and similar), we store the credentials or tokens
needed to operate the integration. Credentials are encrypted at rest.

**Usage and technical data.** Log data, device and browser information, IP
address, pages viewed, feature usage, and diagnostic and performance data.

**Billing information.** Plan, usage counts, and billing contact details.
Card payments are processed by our payment provider; we do not store full card
numbers.

**Cookies and similar technologies.** We use strictly necessary cookies to keep
you signed in and, where permitted, analytics cookies to understand product
usage. You can control non-essential cookies through your browser settings.

## How we use information

We use information to:

* Provide, operate, and secure the Services, including analyzing calls and
  generating findings.
* Authenticate users, manage accounts, and enforce access controls.
* Process transactions and manage billing.
* Communicate with you about the Services, support requests, and security or
  service notices.
* Monitor, debug, and improve the Services, and develop new features.
* Detect, prevent, and respond to fraud, abuse, and security incidents.
* Comply with legal obligations and enforce our agreements.

## Automated and AI processing

The core of the Services is automated analysis. We use machine-learning models
to transcribe audio, classify calls, and produce findings and suggested fixes.
This processing runs on our infrastructure and through AI model providers acting
as our sub-processors (see below). We do **not** sell personal information, and
we do **not** use customer content to train third parties' foundation models.

## Legal bases (EEA / UK)

Where the GDPR or UK GDPR applies, we rely on: performance of a contract
(providing the Services); legitimate interests (securing, operating, and
improving the Services); consent (for non-essential cookies and certain
communications); and compliance with legal obligations. For customer content,
our customer is responsible for establishing the legal basis for the processing
they instruct us to perform.

## How we share information

We share information only as needed to run the Services:

* **Sub-processors** who provide infrastructure and functionality under contract
  and on our instructions (see the list below).
* **Within your organization**, according to the roles and permissions your
  administrators configure.
* **Professional advisors** (lawyers, auditors, accountants) under
  confidentiality.
* **Legal and safety** disclosures where required by law or to protect rights,
  safety, and the integrity of the Services.
* **Business transfers** in connection with a merger, acquisition, or sale of
  assets, subject to this Policy.

We do **not** sell personal information and do **not** share it for
cross-context behavioral advertising.

### Sub-processors

We host and operate the Services in the United States (AWS `us-east-1`). Our
principal sub-processors are:

| Sub-processor       | Purpose                                                              | Location      |
| ------------------- | -------------------------------------------------------------------- | ------------- |
| Amazon Web Services | Hosting, storage, compute, transcription, and AI inference (Bedrock) | United States |
| Neon                | Managed PostgreSQL database                                          | United States |
| Vercel              | Application hosting and content delivery                             | United States |
| OpenAI              | AI model inference                                                   | United States |
| Stripe              | Payment processing                                                   | United States |
| Google              | Authentication (sign-in)                                             | United States |
| Resend              | Transactional email                                                  | United States |

Integrations you choose to connect (for example Slack, Linear, or Google Chat)
receive only the data needed to operate that integration, at your direction. A
current, complete list of sub-processors is available on request at
**[privacy@zelto.ai](mailto:privacy@zelto.ai)**.

## International transfers

We process data in the United States. Where we transfer personal data from the
EEA, UK, or Switzerland, we rely on appropriate safeguards such as the Standard
Contractual Clauses. Contact us for more detail on the safeguards in place.

## Data retention

We keep account information for as long as your account is active and as needed
to provide the Services. We retain customer content according to our agreement
with the customer and their configured settings. When an account is closed, or
on a valid deletion request, we delete or de-identify personal information within
a commercially reasonable period, except where we must retain it to meet legal,
tax, accounting, or security obligations. Backups are purged on a rolling
schedule.

## Security

We apply administrative, technical, and physical safeguards designed to protect
information, including encryption in transit (TLS) and at rest, encryption of
stored integration credentials, role-based access control, enforced
multi-factor authentication for our workforce, audit logging, network isolation,
and continuous monitoring. No method of transmission or storage is perfectly
secure, but we work to protect your information and to improve our controls over
time. Zelto's security program is aligned to SOC 2.

## Your rights and choices

Depending on where you live, you may have rights to access, correct, delete,
port, or restrict the processing of your personal information, to object to
certain processing, and to withdraw consent. You will not be discriminated
against for exercising these rights.

**How to make a request.** Email **[privacy@zelto.ai](mailto:privacy@zelto.ai)** with your request. We will
verify your identity and respond within the timeframe required by applicable law.
If your request concerns a call handled by one of our customers (an end user
whose call we analyzed on the customer's behalf), we will refer you to, and
assist, that customer.

**Account holders** can also update profile information and, where available,
delete their organization's data from within the application. Owners and admins
can manage member access under **Settings**.

## Children

The Services are not directed to children and are intended for business use. We
do not knowingly collect personal information from children.

## Changes to this Policy

We may update this Policy from time to time. Material changes will be posted here
with an updated "Last updated" date and, where appropriate, additional notice.

## Contact us

Zelto — San Francisco, California, USA
Privacy requests: **[privacy@zelto.ai](mailto:privacy@zelto.ai)**
General contact: **[hello@zelto.ai](mailto:hello@zelto.ai)**

See also our [Terms of Service](/docs/legal/terms-of-service).
