← Back to Convault

Privacy & GDPR

Last updated: June 2026

Convault helps small businesses record, transcribe, and summarize their customer phone calls. This page explains what we process and how we protect it. We aim to be plain and honest rather than legalistic; if anything is unclear, email privacy@convault.app.

Who is responsible (controller vs processor)

For your account data (your email, your company) Convault is the controller. For the call recordings and transcripts you create, you are the data controller and Convault acts as your processor— we process that data on your instructions to provide the service. You are responsible for having a lawful basis to record and for informing the people you call (see “Recording & consent”).

What we process

  • Account data: name, work email, company, number of agents.
  • Call data: phone numbers, call metadata (time, duration, direction), audio recordings, transcripts, AI-generated summaries and action items.
  • Contacts you create and the timeline of calls grouped under them.
  • Basic product analytics (page views, feature usage) to improve Convault.

Where it’s stored — EU

Account data, recordings, transcripts and summaries are stored in the European Union (Supabase, EU region). Recordings live in a private storage bucket and are served only through short-lived, access-checked links.

Sub-processors

We use a small set of trusted providers to run the service:
  • Supabase (EU) — database, authentication, and recording storage.
  • Telnyx — telephony (calls, numbers, recording) and speech-to-text.
  • Vercel — application hosting.
  • AI summarization — call transcripts are sent to an AI model (via Telnyx’s AI, which may use models operated outside the EU) to generate summaries and action items. Where processing occurs outside the EU it is covered by Standard Contractual Clauses. Your data is never used to train AI models.

Recording & consent

Convault records the calls you make and receive through it. Recording laws vary by country, but as a rule you should inform the other party that the call is recorded. You are responsible for obtaining any consent required in your jurisdiction. We’re adding an optional automated recording announcement; until then, please disclose recording yourself.

Retention & deletion

You can delete a recording or a call at any time from your dashboard; deletion removes the recording and its transcript/summary from your workspace. If you close your account we delete your workspace data within 30 days, except where we must retain limited records for legal or billing reasons.

Your rights

Under the GDPR you can access, correct, export, or delete your personal data, and object to or restrict processing. To exercise these rights (yours or, as a controller, on behalf of someone you recorded), email privacy@convault.app. We respond within 30 days. You may also request a Data Processing Agreement (DPA).

Security

Data is encrypted in transit and at rest. Tenant data is isolated per account (row-level security). Telephony credentials are never exposed to the browser.

This is an early-access product and this policy will evolve. Material changes will be announced to account holders. Questions: privacy@convault.app.