Privacy Policy

Last updated: March 26, 2026

1. What we collect

Outcall collects the minimum data necessary to operate the service. The free core tier is fully self-hosted and no data is transmitted to Outcall servers.

For Pro and Enterprise subscribers, we collect:

  • Account data: Email address, name, and organization name at registration.
  • Payment information: Billing is processed by Stripe. Outcall does not store full payment card details. Stripe stores payment information under their own privacy policy.
  • Usage data: Approval request metadata (not tool input payloads), audit log export requests, and dashboard page views. We do not log the content of your agents' tool calls.
  • Technical data: IP address, browser user agent, and session tokens for authentication.

2. How we use your data

  • To provide and operate the Pro/Enterprise dashboard.
  • To process payments via Stripe.
  • To send transactional emails (account confirmation, invoices, security alerts).
  • To improve the product using aggregated, anonymized usage analytics.
  • We do not sell your data to third parties.
  • We do not use your data to train AI models.

3. Third-party services

  • Stripe: Payment processing. Subject to Stripe's Privacy Policy.
  • Analytics: We use privacy-respecting analytics (no cross-site tracking, no fingerprinting). Analytics data is stored in the EU.
  • Telegram / Discord: If you configure approval channels, approval request notifications are transmitted to the respective platform under their privacy policies.

4. Data storage and security

Pro/Enterprise data is stored on servers located in the United States and European Union, depending on your account region selection. Data is encrypted at rest (AES-256) and in transit (TLS 1.3).

Audit logs you export are processed ephemerally and are not retained by Outcall after delivery.

5. Data retention

  • Account data is retained for the duration of your subscription plus 90 days.
  • Approval event metadata is retained for 90 days by default. Enterprise subscribers may configure custom retention policies.
  • Payment records are retained as required by applicable financial regulations (typically 7 years).

6. Your rights (GDPR / CCPA)

Depending on your jurisdiction, you may have the right to access, correct, delete, or export your personal data. To exercise these rights, contact us at privacy@outcall.dev.

For CCPA requests, California residents may submit a "Do Not Sell My Personal Information" request to the same address. We do not sell personal information, but we will confirm this in writing upon request.

7. Cookies

The dashboard uses session cookies (strictly necessary) and optional analytics cookies. You can opt out of analytics cookies in your account settings. We do not use advertising cookies.

8. Children

Outcall is not directed at children under 16. We do not knowingly collect data from children.

9. Changes to this policy

We will notify subscribers by email at least 30 days before making material changes to this policy.

10. Contact

Privacy questions: privacy@outcall.dev
Outcall, Inc. — privacy@outcall.dev