Privacy Policy
Signal, Inc. (“Signal,” “we,” “us”) provides this Privacy Policy to explain what information we collect through our hosted business phone service (the “Service”), how we use it, and the choices available to you.
This policy covers information Signal collects directly. Where our business customer (“Customer”) uses the Service to handle its own customers’, patients’, or clients’ personal information — for example, a caller leaving a voicemail with a business that uses Signal — the Customer is the controller of that information and is responsible for its own notices to those individuals. This policy describes how we, as the service provider, handle that data on the Customer’s behalf.
1. Information we collect
- Account and billing information: business name, contact name, email, billing address, and payment details (processed by our payment processor — we do not store full card numbers).
- Telephony configuration data: extension numbers, phone numbers, call routing rules, desk phone hardware identifiers and provisioning data, and SIP credentials.
- Call data: call detail records (who called whom, when, duration, and outcome) — standard telecom metadata generated by any phone system.
- Voicemail and call content (only when the corresponding feature is enabled): recorded voicemail audio, AI-generated transcripts, and — if the call summary feature is enabled — call recordings, AI-generated summaries, and extracted action items.
- Device and network data: IP addresses of phones and administrative users, used for security and troubleshooting.
2. How we use information
- To provide, operate, and maintain the Service — routing calls, delivering voicemail, and generating billing.
- To provide optional AI-assisted features the Customer has enabled (voicemail transcription, call summarization) — see Section 4.
- To detect and prevent fraud, toll fraud, and abuse of the Service or the underlying carrier network.
- To communicate with the Customer about their account, service changes, and billing.
- To comply with legal obligations, including responding to lawful requests from law enforcement or regulators.
We do not sell personal information collected through the Service.
3. Who we share information with (subprocessors)
We use the following third-party service providers to operate the Service. Each processes a limited scope of data necessary for its function:
| Subprocessor | Purpose | Data involved |
|---|---|---|
| Railway | Application hosting and database | Account data, telephony configuration, call metadata |
| DigitalOcean | Telephony server hosting | Call signaling and routing; voicemail audio (transiently, during call handling) |
| Telnyx | Telephone carrier, SIP trunking, number provisioning | Call signaling, phone numbers, call metadata |
| OpenAI | Voicemail and call audio transcription — only if enabled | Audio, resulting transcript text |
| Anthropic | Call summarization and classification — only if enabled | Call transcript text, resulting summary and action items |
| Resend | Transactional email (notifications, reports) | Recipient email addresses, notification content |
We do not currently have Business Associate Agreements (HIPAA) in place with our AI subprocessors. If your use case involves protected health information or other regulated data categories, do not enable the AI transcription and summarization features for that content unless and until this changes — see also our Terms of Service, Section 8.
4. AI-assisted features specifically
If the Customer enables voicemail transcription or call summarization, the relevant audio or transcript content is sent to the named third-party AI provider for processing, and the resulting text is stored in our systems and made available to the Customer through the Service. These providers process the content under their own API terms, which — as of this policy’s effective date — are standard commercial API terms, not enhanced healthcare or regulated-data terms. This may change; confirm current status before relying on these features for sensitive call content.
5. Data retention
- Account and billing data: retained for the duration of the account plus seven years after termination, for legal, tax, and accounting purposes.
- Call detail records: retained for eighteen months.
- Voicemail audio and transcripts, call recordings and summaries: retained for ninety days, or until the Customer deletes them through the Service, whichever comes first.
6. Security
We use industry-standard measures to protect information, including encrypted connections (TLS/HTTPS) for the administrative portal, access controls limiting who can view account data, and monitoring for unauthorized access attempts. No system is completely secure, and we cannot guarantee absolute security.
7. Your rights
Depending on where you (or your own end users) are located, applicable law may provide rights to access, correct, delete, or restrict processing of personal information, and to opt out of certain uses. Requests can be sent to privacy@letssignal.com.
8. Children’s privacy
The Service is intended for business use and is not directed to children. We do not knowingly collect personal information from children.
9. Changes to this policy
We may update this policy from time to time. Material changes will be communicated to Customers with reasonable advance notice.
10. Contact
privacy@letssignal.com
Signal, Inc. · 1809 S Division Ave, Orlando, FL 32805