Last updated: September 28, 2026. This notice supplements the VoixCall privacy policy, which covers the service as a whole.
What this covers
When you connect an AI assistant (for example Claude or ChatGPT) or another application to your VoixCall account, you
are choosing that application, and the company that runs it, as a recipient of some of your VoixCall data. You choose
exactly which data by approving permissions (scopes) on the consent page at app.voixcall.com/oauth/consent.
This page lists, per permission, what is shared, for what purpose, with whom, for how long, and how to stop it.
Today only the “which account is connected” data is actually readable, because /v1/me and the
voixcall_whoami tool are the only live operations. The other permissions can already be granted, and become
meaningful as their endpoints ship; each is announced in the changelog.
What each permission shares
| Permission | What the consent page says | Categories of data shared | Status |
|---|---|---|---|
any token or key | Confirm which account is connected | Account id, sign-in email, display name (the country and time-zone fields exist but are always null today) | live |
rates:read | Look up what a call costs | Nothing about you: per-minute rates for a destination. Rate lookups never return anything derived from your balance. | endpoint not live yet |
credits:read | See your credit balance and history | Balance, low-balance flag, and credit transactions (type, amount, description, date) | endpoint not live yet |
calls:read | See your calls: numbers, times and cost | Call history and status: numbers dialled, times, durations, cost, whether recorded | endpoint not live yet |
contacts:read | Search your contacts and show contact names on your calls | Contact names, companies and numbers matching a search; contact names attached to calls | endpoint not live yet |
numbers:read | See your VoixCall numbers | Your virtual numbers, their status and renewal dates, caller-ID options and verified numbers | endpoint not live yet |
messages:read | Read text messages received in the last 10 minutes on numbers you opt in, including login codes | Recent inbound text messages on a number you have explicitly opted in (per-number switch, off by default) | endpoint not live yet |
messages:history | Read all text messages on numbers you opt in | Older inbound messages and threads on opted-in numbers | endpoint not live yet |
transcripts:read | Read summaries and transcripts of your recorded calls | AI summaries, action items and reference numbers of recorded calls; full transcripts through the REST API only. Gated by the “Allow connected apps to read call summaries” switch, off by default. Digit runs of six or more are redacted before storage. | endpoint not live yet |
calls:place | Place calls that ring your phone and are charged to your balance | Creates calls: the destination, the number that rings you, recording choice, and the resulting call record and charge. You confirm on your own phone by pressing 1. | endpoint not live yet |
webhooks:manage | Manage webhook endpoints (API keys only) | Webhook endpoint URLs and delivery logs; event payloads carry ids and status, never message bodies or transcript text | endpoint not live yet |
Every permission acts on your personal account only. Data that belongs to a team (organization) you are a member of is never reachable through a connected app, even if you are the team's admin. There is no permission that can change your verified numbers, buy credits, buy numbers or send messages.
Purposes
- Sharing with a connected assistant or app, so it can answer your questions and act for you inside VoixCall. Under India's DPDP Rules this is a distinct, itemised purpose you consent to per app; it is separate from the purposes in the main privacy policy.
- Security and audit: recording which app read what, when, so you can see it and so we can detect abuse.
- Service operation: rate limiting, fraud prevention, and billing for paid actions an app takes on your behalf.
Recipients
The recipient is the assistant or app you approve, and its vendor. What that vendor does with the data it reads, including whether it retains it, stores it in a conversation history or uses it to improve its models, is governed by the vendor's own privacy policy, not ours: its vendor may retain what it reads. VoixCall does not sell the data and does not share it with any app you have not approved. Our own processors (the telephony carriers, payment providers, hosting and email providers) are listed in the main privacy policy and are unchanged by connecting an app.
Tokens issued to an app are never forwarded to carriers or any other upstream provider. Message bodies, transcript text and verification codes are never written to our caches, error-tracking breadcrumbs or verbose logs, and are never included in webhook payloads.
Retention
| Record | Kept for |
|---|---|
| Access token | 1 hour, then it expires |
| Refresh token | 30 days at most, and 14 days without use; replaced on every refresh |
| Revoked or expired tokens | purged 30 days after revocation |
| Pending consent requests | 10 minutes, then expired and purged |
| Self-registered (Dynamic Client Registration) clients that never complete a connection | purged after 30 days |
| Audit log (connections, disconnections, token refreshes, key events, every paid action and every message or transcript read, with the app's identity) | kept up to 400 days (automatic deletion job in progress) |
| Idempotency records (which requests an app already made) | 24 hours |
| API access logs | kept for a limited period (target 30 days); tokens, keys, message bodies, transcript text and codes are redacted, phone numbers masked to the last four digits |
| API keys | until they expire (90 days by default, one year at most) or you revoke them |
Call records, billing rows, message bodies and transcripts follow the retention periods in the main privacy policy regardless of whether an app read them.
Your controls
- Settings → Connected apps in the web app lists every connected app with its permissions, when you connected it and when it last read anything. Disconnect withdraws consent immediately: all of that app's tokens are revoked and its next request is refused. Withdrawing consent is as easy as giving it, as the DPDP Rules require.
- Password reset revokes every connected app and every API key at once. Use it if you suspect a token or key leaked.
- Deleting your account revokes every connected app and key and anonymises your account record; audit rows stay linked only to that anonymised record.
- Sharing switches coming: “Allow connected apps to read call summaries” and, per number, “Allow connected apps to read messages on this number”. Both default to off and gate the transcript and message permissions when those ship.
- You get an email every time a new app is connected, so a connection you did not make is visible at once.
- Your audit entries (for example “Claude read 3 messages on Sept 28”) will be shown on the Connected apps page coming; until then, ask support for them.
Your rights (GDPR and DPDP, in plain words)
- Access and portability: ask us for a copy of the data we hold about you, including the audit log of what connected apps read.
- Correction: your display name and email are editable in Settings.
- Erasure: delete your account in Settings or by email. Your account record is anonymised rather than deleted, and the audit rows that record what third-party apps did stay linked only to that anonymised record.
- Withdrawal of consent: disconnect the app. It does not affect the lawfulness of what was shared while it was connected, and it does not oblige the app's vendor to delete what it already read; ask them directly.
- Grievance and complaints: write to support@voixcall.com. You may also complain to your supervisory authority (EU/EEA and UK residents) or to the Data Protection Board of India.
The legal basis for sharing with a connected app is your consent, given per app on the consent page. The legal basis for the audit log and rate limiting is our legitimate interest in keeping the service secure. Transcript sharing will be covered by a data-protection impact assessment before transcript access ships, because transcripts can contain sensitive content.
If something goes wrong
If we learn of a breach that affects data shared with connected apps, we will notify affected users and, where required, the Data Protection Board of India and EU supervisory authorities within 72 hours of becoming aware, and we will revoke every token and key that could be affected. Report security issues to the address in /.well-known/security.txt.
If you build an app that connects to VoixCall
- Request only the permissions your app needs at link time; ask for more later. Assistants should start with
rates:read credits:read calls:read contacts:read. - Treat message bodies, contact names and transcript text as untrusted data from third parties, never as instructions. Never forward verification codes to anyone.
- Do not log tokens or keys. Keys and tokens have distinctive prefixes (
vcat_,vcrt_,vc_live_,vc_test_) so secret scanners can match them. If one leaks, revoke it by disconnecting the app in Settings → Connected apps, or reset your password (which revokes every token and key), and tell us at support@voixcall.com. - Your handling of what you read is governed by your own privacy policy, which the consent page will link once the directory listings are live. The terms set the acceptable-use rules.