Privacy Policy

Last updated: July 4, 2026

1. Introduction, Who We Are, and Scope

This Privacy Policy explains how Movoice AI (the "Service") collects, uses, discloses, and protects personal information. The Service is provided by Metawaveai Technologies Private Limited (incorporated in India), together with its affiliate Metawaveai Technologies Inc (collectively "Movoice", "we", "us", or "our").

Movoice AI is a voice-AI software-as-a-service platform. Businesses use it to place outbound AI-powered phone calls and to send SMS and WhatsApp messages to their own customers, with features including call recording, transcription, bulk campaigns, configurable AI agents, wallet and credits, KYC/KYB identity verification, phone-number provisioning, contacts sync, caller-memory profiling, and a super-admin monitoring console.

This Policy covers two groups of people:

  • "Customers" (also "you") — the businesses and their authorized users who register for and pay to use the Service.
  • "Recipients" or "End Users" — the individuals whom a Customer calls, messages, or uploads into the Service, and who never signed up for Movoice themselves.

This Policy applies to our website, web dashboard, mobile applications, and all related services. By using the Service, or by being contacted through it by a Customer, you acknowledge the practices described here.

Last updated: July 4, 2026.

2. Our Two Roles — Controller and Processor

Movoice acts in two distinct capacities depending on whose data is involved.

Controller for Customer (account-holder) data. For personal information about our Customers and their authorized users — such as account, login, billing, KYC/KYB, and usage data — Movoice is the data controller (or "data fiduciary" under India's DPDP Act). We decide why and how that information is processed, and this Policy governs it directly.

Processor for Recipient data. For the personal information of Recipients that a Customer uploads, calls, or messages — including contact lists, phone numbers, call recordings, transcripts, and message content generated in the course of the Customer's outreach — the Customer is the controller and Movoice is a processor (or "data processor") acting on the Customer's documented instructions. We process this data to deliver the Service to that Customer and do not use it for our own independent purposes. Our handling of Recipient data is also governed by the Data Processing Addendum in our Terms of Service and by our agreement with each Customer.

Each Customer is responsible for having a lawful basis and any required consent to contact its Recipients, for providing Recipients with required notices (including recording notices), and for honoring Recipient rights and opt-outs. Where a Recipient asks us directly to exercise rights over data a Customer controls, we will refer the request to the relevant Customer and assist them as their processor.

3. Information We Collect and Our Lawful Basis

We collect the following categories of information. For each, we identify the lawful basis on which we rely (for Customer data as controller); for Recipient data we act on the Customer's instructions and the Customer is responsible for the lawful basis.

  • Account and profile data — name, email, phone number, business name and details, authentication identifiers. Lawful basis: performance of our contract with you.
  • Usage and configuration data — agent configurations, settings, campaign definitions, call logs, delivery status, wallet and credit activity, and in-app actions. Lawful basis: performance of contract; and our legitimate interest in operating, securing, and improving the Service.
  • Call recordings and transcripts — audio of calls placed through the Service and the text transcripts generated from them, created on the Customer's instruction. Lawful basis: performance of contract with the Customer; for Recipients, the Customer's lawful basis and required notice/consent.
  • SMS and WhatsApp message content — the content of messages sent or received through those channels when you use them. Lawful basis: performance of contract; for Recipients, the Customer's lawful basis and any required opt-in.
  • Contacts sync data — where you choose to sync your device address book, the names, phone numbers, and email addresses it contains. Lawful basis: your explicit consent, requested in-app before any upload.
  • Location data — coarse or region/country signals used for localization, routing, and fraud prevention; and any location you provide. Lawful basis: legitimate interest in localization and fraud prevention; consent where required by your device settings.
  • Payment data — billing details and transaction records, processed by our payment providers (we do not store full card numbers). Lawful basis: performance of contract; and legal obligation (tax and financial recordkeeping).
  • KYC/KYB identity-verification data — identity and business-verification information (which may include identity documents and related details) collected to verify Customers before enabling regulated features such as telephony and payments. Lawful basis: legal obligation and compliance; and performance of contract.
  • Device and technical data — device model, operating system, app version, browser, IP address, and randomized identifiers. Lawful basis: legitimate interest in security, compatibility, and Service delivery.
  • Product analytics data — usage events and metadata (features opened, actions taken, aggregate usage). Lawful basis: legitimate interest in operating and improving the Service.
  • Diagnostics data — crash and error reports (error and stack trace, app version, OS and device model, screen, timestamps, randomized identifier). Lawful basis: legitimate interest in keeping the Service secure, stable, and bug-free.
  • Caller-memory profiles — summaries and attributes derived from prior interactions with a Recipient to personalize future calls (see Section 7). Lawful basis (as processor): the Customer's instruction and lawful basis.

We request Microphone access strictly to let you speak with our AI Copilot and AI voice agents in real time, and Contacts access only to show your contacts and, with your consent, to sync them as described above.

4. How and Why We Use Information

We use the information we collect to:

  • Provide, operate, and maintain the Service, including placing and connecting AI voice calls and sending SMS and WhatsApp messages on your instruction.
  • Record calls and generate transcripts, and store them to your account for review.
  • Run bulk campaigns, configure and operate AI agents, and apply caller-memory personalization.
  • Enable integrations you connect (such as calendars, CRMs, and meeting tools) to the extent needed to perform the requested function.
  • Provision phone numbers, manage your wallet and credits, and process payments.
  • Verify identity (KYC/KYB) and prevent fraud, abuse, and misuse.
  • Send transactional and service communications, notifications, and support responses.
  • Monitor, secure, debug, and improve the Service, including product analytics and diagnostics.
  • Comply with legal obligations and enforce our Terms.

We do not sell your personal information, and we do not use the content of your calls or messages to train general-purpose AI models for our own unrelated purposes.

5. Call Recordings and Transcripts

Calls placed through the Service may be recorded and transcribed. Whether a given call is recorded depends on how it is placed rather than on a per-agent setting: outbound calls to international destinations through our primary carrier are always recorded, and inbound calls are recorded unless your account turns the inbound recording notice off. Recordings and transcripts are created on the Customer's instruction and for the Customer's purposes; Movoice processes them on the Customer's behalf.

The Customer is solely responsible for providing any legally required recording notice to Recipients and for obtaining any consent required in the relevant jurisdiction before recording. Every call handled by an AI agent begins with an automated announcement that the call is AI-powered and may be recorded, and that announcement cannot be disabled. Calls you conduct personally through the Service carry no automated announcement, and you are responsible for giving any recording notice required where the Recipient is located.

Withdrawing consent. To withdraw your consent to call recording and storage, delete your account (in the app: Settings → Delete account; on the web: Settings → Delete account), which permanently deletes your recordings, or contact us at sales@movoice.ai. Because recording is core to how the Service works, withdrawing consent means the Service can no longer place calls for you.

Recording audio is stored in Wasabi object storage in Singapore (ap-southeast-1). Transcripts are stored in our primary database. Recordings and transcripts are deleted from storage upon account deletion and upon expiry of the applicable retention period (see Section 9). Transcription is performed by our cloud transcription providers (see Section 8); we transcribe words only and do not create voiceprints or biometric identifiers of speakers.

6. Recipients — People Our Customers Contact

When a Customer uses Movoice to call, message, or upload information about a Recipient, the Customer is the controller of that personal information and Movoice acts as its processor.

Because the Customer determines why and how Recipient data is used, Recipients who wish to exercise privacy rights — such as access, correction, deletion, or objection — should contact the Customer (the business) that reached out to them. On request, we will help the Customer locate and act on the relevant data as their processor, and where you contact us directly we will forward your request to the responsible Customer.

We honor opt-out and do-not-disturb signals: Recipients can reply STOP to SMS messages to opt out, ask a Customer to stop contacting them, and be added to suppression and do-not-call/DND lists. The Service supports STOP and opt-out handling and suppression lists where technically supported by the channel, and Customers are contractually required to honor opt-outs, DND registries, and applicable calling and messaging laws.

7. Caller-Memory Profiling

To make repeat interactions more helpful, the Service can build a "caller-memory" profile for a Recipient — a summary of prior interactions and derived attributes (for example, previously stated preferences, prior call outcomes, or context relevant to future calls). These profiles are used to personalize subsequent AI calls for the Customer that owns the relationship.

Caller-memory profiling is performed on the Customer's instruction; the Customer is the controller of these profiles and is responsible for the lawful basis and any required notice. Profiles are not used to make legally significant automated decisions about Recipients without human involvement, and they are deleted along with the associated Recipient data on account deletion or retention expiry. A Recipient may ask the relevant Customer to review, correct, or delete their caller-memory profile.

8. Sub-processors and International Data Transfers

We share personal information only with the service providers (sub-processors) needed to deliver the Service. Each processes data for the stated purpose and region and is bound by contractual data-protection obligations. Our current sub-processors are:

  • Twilio — telephony and SMS (United States).
  • Vobiz — SIP telephony for India (India).
  • Meta / WhatsApp Business Platform — WhatsApp messaging and calling (United States / global).
  • Bolna — AI voice call engine (self-hosted by Movoice).
  • OpenAI — large-language-model processing and Whisper transcription (United States).
  • Anthropic — large-language-model processing (United States).
  • Google — AI language and speech services, and OAuth/Calendar integration (United States).
  • AWS Bedrock — voice AI processing (United States).
  • ElevenLabs — voice synthesis and speech-to-text (United States).
  • Sarvam — Indian-language speech-to-text (India).
  • Wasabi — call-recording audio object storage (Singapore, ap-southeast-1).
  • Convex — primary database and file storage (United States).
  • Clerk — authentication (United States).
  • Didit — KYC/KYB identity verification (European Union).
  • Razorpay — payment processing (India).
  • Stripe — payment processing (United States).
  • Polar — billing and checkout (United States).
  • HubSpot — CRM synchronization (United States).
  • Salesforce — CRM synchronization (United States).
  • Zoom — meeting data for reminder calls (United States).
  • PostHog — product analytics, usage events only (United States).
  • Sentry — crash and error diagnostics (United States).
  • Resend — transactional email (United States).
  • LiveKit — WebRTC call-audio bridging (United States).
  • Apple Push Notification service and Expo — push and VoIP notification delivery (United States).

We may also disclose information where required by law, to protect our rights, or in connection with a merger, acquisition, or asset sale (subject to this Policy). We maintain an up-to-date sub-processor list and reference it in our Terms of Service.

International transfers. Because our sub-processors operate in multiple countries, your personal information may be transferred to and processed in India, the United States, the European Union, Singapore, and other jurisdictions. Where personal information is transferred across borders, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (and equivalent UK and other mechanisms), adequacy determinations where they apply, and contractual and technical protections such as encryption. Copies of the relevant safeguards are available on request at privacy@movoice.ai.

9. Data Retention and Auto-Deletion

We retain personal information only as long as needed for the purposes described in this Policy, after which it is deleted or anonymized. Default retention periods are:

  • Account and profile data — for the life of the account; deleted (or anonymized) within a reasonable period after account closure, subject to legal retention needs.
  • Call recordings and transcripts — retained for the life of the account, or a shorter period the Customer configures in Settings, after which they are automatically deleted, including the recording audio in Wasabi. They are also deleted when the account is deleted.
  • SMS and WhatsApp message content — retained for the life of the account or the Customer-configured period, then deleted.
  • Contacts sync data — retained until you delete it or turn off sync, or until account deletion.
  • Activity and audit logs — retained for up to 5 years, then automatically deleted, unless a longer period is required for legal, security, or billing reasons. This period is set by how long a claim about a call or a consent can still be brought, so the record is still there if that happens. They are also deleted when the account is deleted.
  • Diagnostics data — retained for approximately 90 days.
  • KYC/KYB and payment/financial records — retained as required to meet legal, tax, and anti-fraud obligations, then deleted.

When you delete your account, we delete your account data and associated Recipient data — including call recordings (from Wasabi), transcripts, message content, contacts, and caller-memory profiles — except where a limited retention is required by law or for legitimate security, dispute-resolution, or billing purposes. Deletion of most content is automated on account closure and on retention expiry.

10. Your Privacy Rights

Subject to your jurisdiction, you have rights over your personal information. These may include the right to access the data we hold about you, to correct inaccurate data, to delete your data, to receive a portable copy, to object to or restrict certain processing, and to withdraw consent at any time (without affecting prior processing).

How to exercise your rights. Customers can access, export, correct, and delete data directly in the product — including Settings → Export my data and Settings → Delete account — or by emailing privacy@movoice.ai from your account email. We respond to verified requests within 30 days (or the shorter period required by applicable law) and will tell you if we need more time. If you are a Recipient, please see Section 6: contact the business that reached out to you, and we will assist that business as its processor.

India — Digital Personal Data Protection (DPDP) Act. If you are in India, you have the right to access, correction, and erasure of your personal data, the right to grievance redressal, the right to nominate another individual to exercise your rights in the event of death or incapacity, and the right to withdraw consent at any time as easily as it was given. We have appointed a Grievance Officer who can be reached at privacy@movoice.ai; we will acknowledge and address grievances within the timelines required by the DPDP Act and its rules.

California — CCPA/CPRA. If you are a California resident, you have the right to know the categories and specific pieces of personal information we collect, use, and disclose; the right to correct inaccurate information; the right to delete; and the right to opt out of the sale or sharing of personal information and to limit the use of sensitive personal information. We provide notice of the categories collected at or before the point of collection. We do not sell or share your personal information as those terms are defined under the CCPA/CPRA, and we use sensitive personal information (such as identity-verification documents and call audio) only as necessary to provide and secure the Service and to meet legal obligations, which is exempt from the CPRA right to limit; you may still submit a "Do Not Sell or Share My Personal Information" request, and a request to limit the use of Sensitive Personal Information, at privacy@movoice.ai. We will not discriminate against you for exercising any of these rights. You may use an authorized agent, and we will verify requests before acting on them.

EEA/UK. You also have the right to lodge a complaint with your local supervisory authority. To exercise any right, contact privacy@movoice.ai.

11. Security and Data-Breach Notification

We implement appropriate technical and organizational measures to protect personal information, including encryption in transit and at rest, least-privilege access controls, authentication safeguards, network protections, logging, and regular review. No method of transmission or storage is completely secure, but we work to protect your information and to limit access to those who need it.

Data-breach notification. If we become aware of a personal-data breach that is likely to result in a risk to affected individuals, we will notify the relevant supervisory authority and affected individuals as required by applicable law — including within 72 hours to the competent authority under the GDPR where feasible, in the manner and timelines required by India's DPDP Act, and as required by applicable U.S. state breach-notification laws. Where Movoice acts as a processor, we will promptly notify the affected Customer so they can meet their own notification obligations, and assist them as required.

12. Administrative Access and Activity Logs

To operate, support, secure, and bill the Service, our authorized administrators may view your account information and activity metadata — for example login times, IP address and device/browser, in-app actions, and call/message counts, duration, delivery status, and cost, plus abuse and security signals. This access is restricted to authorized super-admin staff, follows least-privilege, and is itself recorded in an audit log (we log who viewed what).

We do not routinely access the content of your calls, transcripts, or messages; access to such content is limited to acting on your instructions or a narrow, logged support or security need. Activity and audit logs are retained for up to 5 years and then deleted automatically, unless a longer period is required for legal, security, or billing reasons. That period is set by how long a claim about a call or a consent can still be brought — an audit trail is only useful if it still exists when someone disputes what happened. They are also deleted when the account is deleted. We rely on our legitimate interest in operating a secure, reliable, and abuse-free service.

13. Product Analytics and Diagnostics

Product analytics. We use PostHog to understand how the Service is used (features opened, actions taken, and aggregate usage) so we can improve it. Analytics captures usage events and metadata only; session replay is disabled, and we do not record on-screen content and do not send the content of your calls or messages to PostHog. We rely on our legitimate interest in operating and improving the Service.

Diagnostics. When our app or website crashes or hits an error, we send diagnostic data to Sentry to detect, triage, and fix the problem. This may include the error and stack trace, app version, operating system and device model, the screen involved, timestamps, and a randomized identifier. We configure Sentry to scrub personal identifiers and do not intentionally send call recordings, transcripts, message content, contact lists, or phone numbers. Diagnostic data is processed in the United States under appropriate cross-border transfer safeguards (including Standard Contractual Clauses where applicable and equivalent mechanisms) and is retained for approximately 90 days. We rely on our legitimate interest in keeping the Service secure, stable, and bug-free. You can turn crash reporting off at any time in Settings.

14. Cookies and Similar Technologies

On our website and web dashboard we use cookies and similar technologies for authentication, to remember your preferences, and for analytics. Strictly necessary cookies are required to run the Service; others are optional. You can control or disable cookies through your browser settings, though disabling some may affect functionality. Where required by law, we obtain consent before setting non-essential cookies.

15. Children's Privacy

The Service is intended for business use and is not directed to children under 18. We do not knowingly collect personal information from children under 18. If you believe a child has provided us personal information, contact privacy@movoice.ai and we will delete it.

16. Contacts Sync

In our mobile app, if you choose to sync your phone contacts, we upload the names, phone numbers, and email addresses from your device's address book to your private Movoice account so you can call, message, and manage them from the app and web dashboard. We ask for your explicit consent in the app before any contacts are uploaded, we never upload your contacts in the background, your contacts are never sold, and you can delete them at any time. You can turn sync on or off in Settings → Contacts sync. If you sync contacts, you are responsible for having any consent required to share that information with us and to contact those individuals through the Service.

17. Changes to This Policy, Effective Date, and Contact

We may update this Privacy Policy from time to time. When we do, we will post the updated Policy on our website and in the app and revise the "Last updated" date below; material changes may be communicated by additional notice. Your continued use of the Service after an update takes effect constitutes acceptance of the revised Policy.

Effective / Last updated: July 4, 2026.

Contact us:

  • Support: sales@movoice.ai
  • Privacy questions and DPDP Grievance Officer: privacy@movoice.ai
  • Legal notices: legal@movoice.ai

Governing law. This Policy and any dispute relating to it are governed by the laws of India. Disputes will be resolved by arbitration seated in India under the Arbitration and Conciliation Act, 1996; the courts at the location of the company's registered office have exclusive jurisdiction for injunctive and equitable relief.

Movoice AI is provided by Metawaveai Technologies Private Limited (incorporated in India), together with its affiliate Metawaveai Technologies Inc.