Skip to content

Privacy Policy

What we collect, why, who processes it for us, how long it is kept, and what you can ask us to do about it.

Last updated 2026-09-07. Operated by Aqeel Shamsudheen, trading as Wixzel, India. Questions to aqeel@wixzel.com.

1. Who we are and what this covers

Wixzel Phone is operated by Aqeel Shamsudheen, trading as Wixzel, India. Contact for anything in this policy: aqeel@wixzel.com.

This policy explains what personal data we handle when you visit this website, use the console, call the API, or are on the other end of a call an agent makes. It is written to satisfy India’s Digital Personal Data Protection Act 2023, the EU and UK GDPR where they apply, and comparable laws elsewhere, and to be readable.

Two roles. For your account, your keys and your billing we are the controller (a “data fiduciary” in Indian law). For the people your agents call and the contacts you upload, you are the controller and we are your processor, acting on your instructions under the Data Processing Addendum. Section 2 covers the first; section 4 the second.

2. What we collect about you

  • Account: your name, email address, and a hash of your password (never the password). With Google sign-in, the Google account id, name and email Google returns; we ask for the profile and email scopes only.
  • Consent record: when you accepted the Terms and which version.
  • API keys: a peppered hash and a prefix. The key itself is shown once and not stored.
  • Telephony setup: your SIP trunk host and username, the trunk password (stored encrypted and never returned by the API), and the phone numbers you register.
  • Usage and billing: per-call and per-component usage rows, credit top-ups, the ledger, and payment status from Dodo Payments. We do not receive or store card numbers.
  • Request logs: for each API request, the method, path, status, timing, your account and key id, the request id and the client IP address, kept for 3 months. Request bodies are not logged.
  • Technical data: the IP address of requests and sign-in attempts, held briefly in cache for rate limiting; the process logs of the service, which record request lines, are rotated daily and kept for 14 days.

3. Why we use it

  • To provide the Service — to run your agents, place and receive your calls, meter and bill usage, and show you what happened. Basis: performing our contract with you.
  • To keep it secure — authentication, rate limiting, abuse prevention, fraud checks on payments. Basis: our legitimate interest in a service that works and is not abused.
  • To talk to you about the Service — verification codes, receipts, security notices, changes to the Terms. Basis: contract and legal obligation. We do not send marketing email.
  • To meet legal obligations — tax and accounting records, lawful requests from authorities. Basis: legal obligation.

We do not use your data or your Customer Data to train machine-learning models, and we do not sell personal data to anyone.

4. Calls, recordings and the people you call

When an agent is on a call, audio is streamed in real time to the speech-to-text, language and text-to-speech providers configured for that agent, and back. The transcript of the call, and a recording where the call is recorded, are stored with the call log on our servers in Finland. Contacts you upload as leads, and appointments the agent books, are stored the same way.

All of this is your Customer Data. We process it only to provide the Service to you, only on your instructions, and only through the sub-processors listed below. It is you who decides whom to call, whether calls are recorded (on by default, switched off on request), what the agent says, and how long to keep the results — and it is you who must have a lawful basis for each of those, tell your callers what the law requires, and honour their rights. If you are a person who received a call from an agent built on Wixzel Phone and have a question about your data, the business that called you is the right first contact; we will help them answer you, and you can also write to us.

5. Who processes data for us

We use these providers to run the Service. Each receives only what its function needs — the model providers receive call audio and text for the calls that use them; the payment processor receives your email and the amount; the email provider receives your address and the message.

ProviderWhat forWhere
Hetzner Online GmbHHosting of the API, databases and call media (Helsinki, Finland)Germany / Finland
Vercel Inc.Hosting of the console and this websiteUnited States
Deepgram, Inc.Speech-to-text and the Deepgram voice agent engineUnited States
ElevenLabs Inc.Text-to-speechUnited States
OpenRouter, Inc.Language-model routing for the classic engineUnited States
Sarvam AISpeech, language and voice models for Indian languagesIndia
Google LLCGemini Live realtime engine; Google sign-inUnited States
Dodo PaymentsPayment processing, as merchant of recordUnited States / India
Brevo (Sendinblue SAS)Transactional email, such as the signup verification codeFrance

We will update this table before adding a provider that handles Customer Data. Which model providers a given call uses depends on the engine you choose for that agent.

6. International transfers

The API and stored data live in the European Union (Finland). Several providers are in the United States or India, so call audio and text, and some account data, are transferred there to be processed. Where the GDPR applies, those transfers rely on the providers’ standard contractual clauses and, for eligible US providers, the EU–US Data Privacy Framework. Where Indian law applies, transfers are to countries that are not restricted by the central government.

7. How long we keep it

  • Account data: while your account exists. Closing the account from the console deletes it, and every piece of Customer Data below, immediately.
  • Pending signups: a signup that is never verified is discarded after 15 minutes; nothing about it is kept.
  • Call logs, transcripts, recordings, leads, appointments: until you delete them or your account is closed. You can delete each through the API; deleting a call removes its transcript and recording with it.
  • Request logs: 3 months, then dropped automatically.
  • Billing and usage ledger: as long as tax and accounting law requires, typically 8 years in India, in a form that no longer identifies call content.
  • Rate-limit counters: minutes, held in cache. Service logs: 14 days, rotated daily.

8. How we protect it

Traffic is encrypted in transit with TLS. Passwords are hashed with bcrypt; API keys are hashed with a server-side pepper; SIP trunk passwords and third-party credentials are encrypted at rest with a dedicated key. Every request carries an id we can trace. Sessions can be revoked everywhere at once from the console. Access to production is limited to the operator. No system is perfectly secure, and if a breach affects your data we will tell you without undue delay, and within 72 hours where the law requires it.

9. Cookies and local storage

This website and the console use no analytics and no advertising trackers. We set one cookie, wv_session, which is your sign-in session: httpOnly, secure, same-site, and valid for up to 30 days. The console also remembers your light-or-dark theme choice in your browser’s local storage. Neither is shared with anyone.

10. Your rights

Depending on where you are, you may have the right to access, correct, delete or export your personal data, to restrict or object to how we use it, to withdraw consent, to nominate someone to exercise your rights, and to complain to a supervisory authority — in India the Data Protection Board, in the EU your national authority, in the UK the ICO.

Much of this you can do yourself: your keys, calls, contacts and recordings are deletable through the API, and keys and calls are managed in the console too. You can close your account yourself from the Account page in the console, which deletes everything at once. For anything else, email aqeel@wixzel.com from the address on your account. We answer within 30 days. We will not treat you differently for exercising a right.

11. Children

The Service is for businesses and developers. We do not knowingly collect personal data from anyone under 18, and accounts may not be created for them. If you believe a child has given us data, write to us and we will delete it.

12. Changes to this policy

We will update this policy when the Service or the law changes. The date at the top is the version in force; for material changes we will email the address on your account before they take effect.