Privacy Policy

How Vagle AI handles account data, call data, recordings, transcripts, lead data, connected tools, credentials, and support messages. Last updated: July 1, 2026.

What we collect

Vagle AI collects the information needed to provide and operate the service. This can include account details, workspace details, company details, login activity, billing and usage records, assistant settings, phone number settings, provider configuration, support messages, and basic service logs.

When you use voice calling, campaigns, follow-up funnels, or call logs, we may process phone numbers, caller or lead names, email addresses where provided, lead fields, call time, call duration, call direction, call status, transcripts, summaries, recordings where enabled, detected intent, detected outcome, interest score, tool actions, and estimated usage cost.

When you use MCP, API access, ChatGPT, Codex, or another MCP-compatible client with Vagle AI, we may process token metadata, token scopes, workspace permissions, approval requests, audit logs, tool names, requested actions, idempotency keys, and safe input or output summaries. Raw MCP tokens are shown only when created and are stored hashed after that.

Connected tools and credentials

If you connect Google Sheets, Airtable, Notion, Gmail, Google Calendar, webhooks, REST APIs, or another business tool, Vagle AI uses that connection only to perform the actions you configure. For example, the platform may update a lead row, create a note, send a configured email, create or update a calendar event, or call your webhook.

For Google tools, Vagle AI uses the connected Google account only for user-configured actions such as writing selected call fields to Sheets, creating or updating Calendar events, or sending configured Gmail messages. We do not use Google data for advertising, sell Google user data, or independently browse a user account outside the configured workflow.

Vagle AI’s use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements.

OAuth tokens, API keys, MCP tokens, provider keys, and connected tool credentials are treated as sensitive. We protect them with access controls and encryption where applicable, limit access based on workspace permissions, and avoid exposing secrets in normal UI, logs, and tool responses.

How we use data

We use data to provide the service, place and receive calls, run AI voice agents, create transcripts and summaries, run follow-up funnels, update configured tools, calculate usage, troubleshoot errors, improve reliability, prevent abuse, protect accounts, and support customers.

We do not sell customer call data, lead data, transcripts, recordings, connected tool data, Google user data, or MCP/API token data.

AI, voice, and telephony providers

Vagle AI may use third-party providers for telephony, speech-to-text, language models, text-to-speech, voice streaming, hosting, storage, payment, email delivery, and monitoring. The providers used for a call depend on the workspace configuration, provider keys, phone number setup, and selected assistant settings.

We send providers only the information needed for the configured workflow, such as call audio, text needed to generate a response, selected tool instructions, or usage information. Provider availability, pricing, latency, and behavior may change based on the provider and account configuration.

Recordings and transcripts

Call recording and transcription can contain personal or business information. Customers are responsible for giving required notices, obtaining required consent, and using recordings, transcripts, and automated calling in a lawful way.

Call logs, transcripts, summaries, recordings where enabled, detected outcomes, and tool actions are shown to workspace users based on their access level.

When data is shared

We share data with service providers only when needed to operate the product, process configured workflows, deliver support, handle payments, protect the platform, or meet legal obligations.

Data is also shared with connected tools when a customer configures Vagle AI to send it there. For example, a call summary can be saved to a Sheet, an appointment can be sent to a calendar, or a webhook can receive lead fields selected by the customer.

Retention

We keep information for as long as needed to provide the service, maintain security, handle billing, resolve issues, support customers, and meet legal obligations. Some records may remain in backups, audit logs, security logs, or billing logs for a limited period.

Customers can ask us to delete or export data where applicable. Some deletion requests may need to be handled by the business that collected the lead or caller data, because that business controls why the call happened.

Access, correction, and deletion

You can contact us to request access, correction, export, or deletion of personal information where applicable law gives you those rights. We may need to verify the request and may ask for information needed to locate the relevant account or workspace.

Callers who received a call from a Vagle AI customer should usually contact that business first. The business decides why the call was made, what lead data was used, and how long its business records should be kept.

Children and sensitive data

Vagle AI is designed for business users. It is not intended for children under 13. Customers should not use Vagle AI to collect sensitive personal information unless they have a lawful basis, proper consent where required, and a clear business need for that data.

Customers should avoid collecting payment card numbers, passwords, government identifiers, health information, or other sensitive data through voice agents unless they have reviewed the legal and security requirements for that workflow.

Your regional privacy rights (GDPR, UK GDPR, CCPA/CPRA)

Depending on where you live, you may have rights to access, correct, delete, port, or restrict the processing of your personal information, and to object to certain processing. To exercise any of these, contact us and we will respond within the timeframe required by applicable law.

For EU/UK users (GDPR): we process personal data on the legal bases of performing our contract with you, your consent where required, our legitimate interests in operating and securing the service, and compliance with legal obligations. Where Vagle AI processes data on behalf of a business customer, that customer is the data controller and Vagle AI acts as a data processor.

For California users (CCPA/CPRA): we do not sell or share personal information as those terms are defined under the CCPA/CPRA. You have the right to know, delete, correct, and to be free from discrimination for exercising your rights.

International transfers: where data is transferred across borders, we use appropriate safeguards (such as standard contractual clauses) where required by law.

Contact

For privacy, data, or account questions, or to exercise your privacy rights, contact info@vagle.ai.

Explore next