Privacy Policy
Last updated August 18, 2026 · Sir Callsalot
1. Who we are
This service is operated by TamerinTECH GmbH, Seestr. 19, 83727 Schliersee, Germany (contact: [email protected]) — full company details are in the imprint. We are the data controller for the personal data described here.
2. What the service does with data
You make phone calls to businesses yourself, from your browser, and speak for yourself. The service assists you during the call: it shows live captions of what the other side says, can suggest replies, speaks sentences you type, and translates when your language differs from the call language. No AI conducts the conversation; the assistance follows the task you defined and confirmed ("the calling card").
3. Data we process
- Account data: email address, display name, language and call preferences.
- Policy acceptance records: which version of the Terms and Acceptable Use Policy you accepted and when — at sign-up and with the declaration you confirm before every call — together with your IP address and browser identifier. We keep these as evidence of the agreement and of responsible use (Art. 6(1)(b) and (f) GDPR).
- Task data: the business you name, its phone number, your goal, time windows, and constraints you set. Destination numbers are checked against a business directory before a call is allowed (see Section 7).
- Call data: a temporary text transcript of the conversation — produced live from the call audio for your captions (and translated when you chose that), together with the sentences you typed to be spoken — encrypted at rest; a structured result (e.g. appointment time, price, reference number); and a technical call log (dial/answer/hang-up events, latency — no conversation content).
- Your own phone number, if you provide one: used for the SMS verification of your own number (the self-call test path) and, as a callback number, given to a business only when you chose that for a task.
- Payment data: handled by Stripe; we never see full card numbers.
- Human-check data: at sign-in, a Cloudflare Turnstile check may process technical browser signals to tell humans from bots (see Section 7). We only receive and store the pass/fail outcome, never the signals.
- Technical data: server logs limited to technical events — no conversation content, no unmasked phone numbers.
4. What we deliberately do not do
- No audio recordings. Call audio is processed as a live stream — to carry your call and to produce your captions — and never stored; only the caption text remains, briefly.
- Transcripts auto-delete after at most 7 days; the structured result you see in your history is kept.
- No AI training with your data. Our AI providers are used under agreements that exclude training on API data.
- No cold calls or marketing calls. The service is technically limited to individual tasks you request, each screened and individually confirmed by you.
5. Legal bases (GDPR)
- Performance of contract (Art. 6(1)(b)) for account, task, call and payment processing, and for recording your policy acceptances.
- Legitimate interests (Art. 6(1)(f)) for the live captioning and translation of the called party's speech during your own conversation (comparable to what you could hear and note down yourself on your own call), for abuse prevention and security (screening, human check, rate limits, suppression list), and for short-lived technical logs.
- Consent (Art. 6(1)(a)) for marketing cookies and optional notifications; you can withdraw consent at any time.
6. If you received a call made through our service (information for called parties)
- You spoke with a person — our user conducts the call personally. If they typed a reply, it was read out by a synthetic voice with exactly their words; the conversation partner remains the user.
- Calls are not audio-recorded. A temporary text transcript of the conversation exists only so our user can read and keep the result of their own call; it is deleted automatically within at most 7 days.
- What we process about you: the phone number dialed, the business name our user entered, and what was said on the call (as text, temporarily).
- If you ask not to receive such calls — during the call or by contacting us — your number goes on a suppression list and will not be called again for any user. The list stores only the number and the request; keeping it is what honors your objection, so it survives even the requesting user's account deletion.
- You can exercise your GDPR rights (access, erasure, objection) at [email protected], and you may complain to a supervisory authority.
7. Processors and recipients
- Hosting: OVHcloud (EU data centers, Germany/France).
- Telephony: Twilio and/or Vonage (call delivery; EU routing where available).
- AI processing during the call: Microsoft Azure OpenAI and/or OpenAI (live transcription of the call audio for your captions; text-to-speech of sentences you typed; short text processing for suggestions and translation) and/or ElevenLabs (text-to-speech of typed sentences — it receives only your typed text, never call audio). All are used under agreements that exclude training on API data; we prefer EU processing options where offered.
- Destination check: Google (Places directory lookup of the business number you enter — the number, never your identity).
- Payments: Stripe.
- Email delivery: our email provider (sign-in links and result notifications). Push notifications: your browser's push service.
- Network, TLS and bot protection: Cloudflare (including the Turnstile human check at sign-in).
Where processors operate outside the EU/EEA, transfers rely on adequacy decisions (including the EU-US Data Privacy Framework) or Standard Contractual Clauses. We prefer EU processing options wherever the provider offers them.
8. Retention
- Transcripts: deleted automatically within at most 7 days (you can delete them earlier per task).
- Technical call events: deleted after 30 days.
- Structured results & task history: until you delete them or your account.
- Policy acceptance records: kept while your account exists, deleted with it.
- Account: until deletion; billing records as required by tax law (kept by Stripe and in our ledger).
- Encrypted database backups age out after 14 days.
- Suppression list (opt-out numbers): kept until the number's holder asks us to remove it — it exists to honor the opt-out.
9. Your rights and the tools for them
- Export: download all your data as JSON in Settings → "Your data".
- Erasure: delete your account and all its data in Settings, or delete individual call transcripts ahead of their auto-deletion.
- You additionally have the rights to access, rectify, restrict, and port your data, and to object to processing based on legitimate interests: [email protected].
- You may lodge a complaint with your supervisory authority; in Germany this is the data-protection authority of your federal state.
10. Changes
We will announce material changes to this policy in the app before they take effect.
11. Users in the United States
We are a German company: your data is processed as described above, on servers in the European Union, with the GDPR as our baseline for everyone — wherever you are. If you are a US resident, the following applies in addition:
- We do not sell your personal information, and we do not share it for cross-context behavioral advertising (as those terms are defined in the California Consumer Privacy Act and similar state laws).
- State privacy laws (such as the CCPA/CPRA in California) may give you rights to know, access, correct, delete, and port your personal information, and to opt out of sale or sharing. The tools in Section 9 (export, deletion) serve those rights too; for anything else, write to [email protected]. We do not discriminate against you for exercising your rights.
- We process your data only for the purposes in this policy; the retention rules in Section 8 apply unchanged.
- Where state law provides for it, an authorized agent may submit a request on your behalf; we will verify the request before acting on it.