Legal
Privacy Policy
Effective September 18, 2026
This Privacy Policy explains how DialValet collects, uses, and shares information when you use dialvalet.com, the dashboard, APIs, CLI, and Model Context Protocol server (the “Service”). It should be read with our Terms of Service.
We designed DialValet to collect as little as we need to place a call you asked for, bill it, and keep the Service safe. We do not sell personal information, and we do not use your call content to train our own models.
1. Who we are
DialValet is the service operated at dialvalet.com. For privacy questions, deletion requests, and this policy, email contact@dialvalet.com. That is our only published contact address.
2. What this policy covers
This policy covers information we process as the operator of DialValet. It does not cover websites, models, or phone carriers we do not control. If you connect a third-party AI client, that client may also process information under its own policy. Recipients of your calls hear an AI assistant and whatever you asked it to say; we cannot control how they handle what they hear.
The Service is offered for United States numbers and destinations. We do not currently offer the Service to children or to people who cannot receive a United States one-time code.
3. Information we collect
Account and authentication
- Your United States phone number, used to create the account and send one-time codes.
- Verification status for numbers you want to present as caller ID.
- Session records, API key identifiers and hashes (not the raw key after creation), and OAuth grant metadata for connected agents.
Calls you request
- Destination number, stated objective, optional context, caller-identity choice, duration cap, and your attestation that you directed the call and are allowed to make it.
- Call status, timestamps, connected seconds, charges, and error information.
- Live audio while a call is connected, processed in real time and not stored as a recording.
- Transient transcript text used to operate the live conversation and, if available, to produce a structured result.
- An optional encrypted result: a short summary, resolution, commitments, follow-ups, and speaker-labeled transcript turns.
Billing
- Prepaid credit balance, reservations, and ledger entries.
- Stripe customer and checkout identifiers. Stripe collects payment-method details. We do not store full card numbers.
Technical and security data
- IP address, user agent, and coarse request metadata used for rate limits, fraud checks, and debugging.
- Provider event identifiers needed to reconcile Telnyx and Stripe activity.
- Audit entries for sensitive actions such as key creation, grant revocation, and deletion requests.
We do not ask for your name, email address, or password to create an account. If you email us, we will receive whatever you send, including your email address.
4. How we use information
We use information to:
- create and secure your account, send one-time codes, and keep you signed in;
- verify caller ID, place and monitor calls, and return a status or result;
- apply spend, duration, destination, and concurrency limits;
- take payment, reserve and settle credit, and provide receipts through Stripe;
- prevent abuse, spam, fraud, and prohibited calling;
- debug outages, reconcile provider records, and improve reliability;
- respond to your requests and to lawful demands; and
- comply with tax, accounting, and telecommunications obligations.
We do not use call content for advertising. We do not sell personal information, and we do not share it for cross-context behavioral advertising.
5. Call audio, transcripts, and results
When a call is answered, live audio is streamed between the telephone network and a voice model so the assistant can listen and speak. We do not keep an audio recording of the call. Raw audio buffers are ephemeral.
The live voice provider (currently OpenAI) processes that audio to conduct the conversation. We ask that provider not to store the live session for our later use. That setting is not a guarantee of zero retention. Providers may still process or retain limited data for security, abuse monitoring, or their own legal duties. See their policies.
After some completed calls, we may send a bounded, redacted text extract of the conversation, plus your stated objective, to a separate model request to produce a short structured result. We ask that request not to be stored for our later use. If that step fails, we store no result.
When a result is produced, we encrypt it and keep it for up to 30 days. It may include speaker-labeled transcript turns. You can view those turns in the dashboard while they exist, and you can delete the stored result earlier. After expiry or deletion, the encrypted result is removed from our application database. Call metadata used for billing and security may remain.
Recipients hear an AI disclosure at the start of the call. Anything said on the call may be heard by the other party and by the providers that carry or process the audio.
7. Service providers
These companies process information on our behalf to provide the Service:
- Cloudflare, Inc. Hosts the website, APIs, dashboard, and related infrastructure, including Workers, D1, KV, and Durable Objects.
- Telnyx LLC. Sends one-time codes, verifies caller ID, originates calls, and carries live media.
- OpenAI, LLC. Processes live call audio and optional post-call text used to draft a structured result.
- Stripe, Inc. Processes checkout payments, customer billing portal access, and payment receipts.
Each provider has its own privacy policy and may process data in the United States or other countries where it operates. We do not currently use advertising pixels or a separate product-analytics vendor.
9. How long we keep information
- One-time codes. Kept only long enough to verify sign-in or caller ID, then become unusable.
- Sessions and API keys. Until they expire, are revoked, or the account is closed.
- Structured call results and transcript turns. Up to 30 days, or earlier if you delete the result.
- Call metadata and billing records. Kept as long as needed to operate the account, reconcile charges, handle disputes, and meet tax or accounting duties. That can be several years. Sensitive call content is not kept in those records.
- Security and audit logs. Kept for a limited period to investigate abuse, then reduced or deleted.
- Closed accounts. We disable access after a valid deletion request. We may retain billing, fraud, and legally required records. Provider copies follow those providers’ retention rules.
10. Security
We encrypt sensitive fields such as phone numbers, call objectives, and stored results at the application layer, hash lookup keys, and transmit traffic over HTTPS. API keys are shown once and stored as hashes. No method of transmission or storage is perfectly secure. If we become aware of a breach that requires notice, we will notify you as the law requires, using the account phone or the email you used to contact us if that is all we have.
11. Your choices and rights
You can:
- sign out or revoke API keys and connected-agent grants in the dashboard;
- delete a stored call result before it expires;
- request account closure in Settings or by emailing us; and
- email contact@dialvalet.com to ask for a copy of the account information we can reasonably retrieve, to correct it, or to ask questions.
Self-serve export is not available yet. We will fulfill reasonable access, correction, and deletion requests after we verify that you control the account, usually by the account phone number. We may decline or limit a request where the law allows, including when information is needed for billing, security, or legal holds.
If you are a resident of California or another U.S. state that grants privacy rights, you may have the right to know, access, correct, or delete personal information, to appeal a denial, and to opt out of sale or sharing. We do not sell personal information or share it for cross-context behavioral advertising, so there is no separate “do not sell” signal to honor. We will not discriminate against you for exercising a privacy right. You may authorize an agent to email us on your behalf; we will still need to verify the account.
12. Children
DialValet is not directed to children under 18, and we do not knowingly collect personal information from them. If you believe a child created an account, email contact@dialvalet.com and we will close it.
13. Where information is processed
We operate in the United States. If you access the Service from another country, you understand that your information will be processed in the United States, where protections may differ from those where you live. The Service is not offered for non-United States phone numbers or destinations.
14. Changes
We may update this policy. The current version will be posted at dialvalet.com/privacy with a new effective date. If a change is material, we will also try to provide a notice in the Service. Continued use after the effective date means you accept the updated policy.
15. Contact
For this policy, privacy requests, or complaints, email contact@dialvalet.com.