Billing PortalSupportPartner Portal+1 407 598 TALK
Legal

Privacy Policy

Last updated: August 6, 2026

Signal, Inc. (“Signal,” “we,” “us”) provides this Privacy Policy to explain what information we collect through our hosted business phone service (the “Service”), how we use it, and the choices available to you.

This policy covers information Signal collects directly. Where our business customer (“Customer”) uses the Service to handle its own customers’, patients’, or clients’ personal information — for example, a caller leaving a voicemail with a business that uses Signal — the Customer is the controller of that information and is responsible for its own notices to those individuals. This policy describes how we, as the service provider, handle that data on the Customer’s behalf.

1. Information we collect

  • Account and billing information: business name, contact name, email, billing address, and payment details (processed by our payment processor — we do not store full card numbers).
  • Telephony configuration data: extension numbers, phone numbers, call routing rules, desk phone hardware identifiers and provisioning data, and SIP credentials.
  • Call data: call detail records (who called whom, when, duration, and outcome) — standard telecom metadata generated by any phone system.
  • Voicemail and call content (only when the corresponding feature is enabled): recorded voicemail audio, AI-generated transcripts, and — if the call summary feature is enabled — call recordings, AI-generated summaries, and extracted action items.
  • Device and network data: IP addresses of phones and administrative users, used for security and troubleshooting.

2. How we use information

  • To provide, operate, and maintain the Service — routing calls, delivering voicemail, and generating billing.
  • To provide optional AI-assisted features the Customer has enabled (voicemail transcription, call summarization) — see Section 4.
  • To detect and prevent fraud, toll fraud, and abuse of the Service or the underlying carrier network.
  • To communicate with the Customer about their account, service changes, and billing.
  • To comply with legal obligations, including responding to lawful requests from law enforcement or regulators.

We do not sell personal information collected through the Service.

3. Who we share information with (subprocessors)

We use the following third-party service providers to operate the Service. Each processes a limited scope of data necessary for its function:

SubprocessorPurposeData involved
RailwayApplication hosting and databaseAccount data, telephony configuration, call metadata
DigitalOceanTelephony server hostingCall signaling and routing; voicemail audio (transiently, during call handling)
TelnyxTelephone carrier, SIP trunking, number provisioningCall signaling, phone numbers, call metadata
OpenAIVoicemail and call audio transcription — only if enabledAudio, resulting transcript text
AnthropicCall summarization and classification — only if enabledCall transcript text, resulting summary and action items
ResendTransactional email (notifications, reports)Recipient email addresses, notification content

We do not currently have Business Associate Agreements (HIPAA) in place with our AI subprocessors. If your use case involves protected health information or other regulated data categories, do not enable the AI transcription and summarization features for that content unless and until this changes — see also our Terms of Service, Section 8.

4. AI-assisted features specifically

If the Customer enables voicemail transcription or call summarization, the relevant audio or transcript content is sent to the named third-party AI provider for processing, and the resulting text is stored in our systems and made available to the Customer through the Service. These providers process the content under their own API terms, which — as of this policy’s effective date — are standard commercial API terms, not enhanced healthcare or regulated-data terms. This may change; confirm current status before relying on these features for sensitive call content.

5. Data retention

  • Account and billing data: retained for the duration of the account plus seven years after termination, for legal, tax, and accounting purposes.
  • Call detail records: retained for eighteen months.
  • Voicemail audio and transcripts, call recordings and summaries: retained for ninety days, or until the Customer deletes them through the Service, whichever comes first.

6. Security

We use industry-standard measures to protect information, including encrypted connections (TLS/HTTPS) for the administrative portal, access controls limiting who can view account data, and monitoring for unauthorized access attempts. No system is completely secure, and we cannot guarantee absolute security.

7. Your rights

Depending on where you (or your own end users) are located, applicable law may provide rights to access, correct, delete, or restrict processing of personal information, and to opt out of certain uses. Requests can be sent to privacy@letssignal.com.

8. Children’s privacy

The Service is intended for business use and is not directed to children. We do not knowingly collect personal information from children.

9. Changes to this policy

We may update this policy from time to time. Material changes will be communicated to Customers with reasonable advance notice.

10. Contact

privacy@letssignal.com
Signal, Inc. · 1809 S Division Ave, Orlando, FL 32805

We are here to help.

Talk to a Signal specialist about the right package for your team, your industry, and your budget.

Let's Talk