← Dexavox

Privacy Policy

Last updated 29 July 2026

Dexavox provides an AI receptionist that answers a business's phone. This policy explains what we collect, why, who we share it with, and how to get it deleted. It covers both the businesses that use Dexavox and the people who call them.

Who this covers

Two groups. "Customers" are the businesses that sign up for Dexavox. "Callers" are the people who phone those businesses and speak to the AI receptionist. Customers decide what their receptionist does; we process caller information on their behalf and under their instructions.

What we collect

From customers, when they sign up and configure their agent:

  • Account details: name, email address, and an encrypted password hash (handled by our authentication provider — we never see the password itself).
  • Business configuration: business name, phone number, address, opening hours, services, pricing, and the answers given during setup.
  • Documents uploaded to train the agent, such as menus, price lists, and FAQs, plus the text extracted from them.
  • For dental customers who choose to use it, a patient roster (name, date of birth, phone number, and appointment notes) uploaded by the practice or synced from their practice-management system.

What we collect about callers

When someone calls a business using our service, we process what the call itself produces:

  • The caller's phone number, as provided by the telephone network.
  • An audio recording of the call and a written transcript of it.
  • Anything the caller tells the agent — name, callback number, appointment or reservation details, the reason for calling, and any message left for the business.
  • A short summary of the call and its outcome, generated automatically.

Call recording

Calls are recorded and transcribed so the business can review them and so the agent can improve. Where the law requires all parties to consent to recording, the agent announces the recording at the start of the call and this cannot be switched off. Customers remain responsible for compliance with recording laws that apply to them.

How we use information

We use what we collect to:

  • Answer calls, take bookings and messages, and answer questions on the customer's behalf.
  • Show the customer their call history, transcripts, bookings, and messages.
  • Deliver the notifications a customer has asked for, by email or text message.
  • Write bookings and call logs into the customer's own Google Calendar and Google Sheets, when they have connected Google.
  • Diagnose faults, prevent abuse, and improve the accuracy of the service.

Google user data

Connecting Google is optional. If a customer chooses to connect it, they grant access through Google's own consent screen, and we request only the narrowest permissions that make the feature work:

  • See your primary email address — used solely to show which Google account is connected, so the customer can tell at a glance. It is not used for marketing and is not shared.
  • View and edit events on your calendars — used only to create a calendar event when the agent takes a booking, and to move that event if the caller reschedules. We do not read, list, or store the customer's existing events.
  • View your availability in your calendars (free/busy) — used only to avoid offering a time the customer is already busy. This permission returns busy time ranges and nothing else: no event titles, descriptions, locations, or guests are available to us, and none are stored.
  • See, edit, create, and delete only the specific Google Drive files you use with this app — used only to create one spreadsheet in the customer's own Drive at connect time, and to append a row to it for each booking and message. This permission is limited to files we created ourselves: the rest of the customer's Drive is not visible to us and cannot be read, modified, or deleted.

Limited Use of Google data

Dexavox's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to develop, improve, or train generalised artificial intelligence or machine learning models. We do not sell Google user data, transfer it for advertising purposes, or allow humans to read it, except with the customer's explicit consent, to resolve a specific support issue the customer has raised, where required by law, or where necessary for security purposes.

The spreadsheet and calendar events we create live in the customer's own Google account. Disconnecting Google in the dashboard immediately deletes the stored access tokens; the customer's existing spreadsheet and calendar events remain theirs and are untouched.

How information is protected

All traffic is encrypted in transit. Sensitive fields are additionally encrypted before they are written to the database, using AES-256-GCM with a key held outside the database: this covers call transcripts and summaries for healthcare customers, patient roster records, and the access tokens for any connected Google account.

Access to production data is limited to personnel who need it to operate the service.

Who we share it with

We do not sell personal information. We share it only with the service providers needed to run the product, each acting on our instructions:

  • Vapi — real-time voice orchestration, including speech-to-text, text-to-speech, and call recording.
  • Twilio — telephone numbers, call connectivity, and text messages.
  • Anthropic — the language model that powers the agent's understanding and replies.
  • Supabase — database, authentication, and file storage.
  • Vercel — application hosting.
  • Resend — transactional email.
  • Google — only where the customer has connected their own Google account.
  • NexHealth — only for dental customers who connect their practice-management system.

How long we keep it

Account and configuration data is kept while the account is open. Call recordings, transcripts, bookings, and messages are kept while the account is open so the customer can review their own call history, and are deleted when the account is closed. Patient roster records are replaced on each sync and deleted when the account is closed or the roster is removed.

A customer can ask us to delete their account and everything in it at any time by writing to us, and we will do so within 30 days.

Your choices

Customers can edit or delete their business configuration and uploaded documents at any time from the dashboard, disconnect Google in one click, and delete their patient roster. Callers who want a recording, transcript, or message about them deleted should contact the business they called; if they contact us directly at abyebez03@gmail.com we will pass the request to that business and assist with it.

Depending on where you live, you may have rights to access, correct, export, or delete personal information about you, and to object to certain processing. Write to us and we will honour those rights.

Children

Dexavox is a business tool and is not directed at children. We do not knowingly collect information from children. A dental practice's roster may include the details of a minor patient; those records are provided and controlled by the practice, are encrypted at rest, and are only ever disclosed on a call after a name and date of birth are verified.

International transfers

Our infrastructure and our service providers operate in the United States. If you use the service from elsewhere, information about you will be processed in the United States.

Changes

If we change this policy in a way that materially affects how we handle personal information, we will update the date at the top and notify account holders by email before the change takes effect.

Contact

Questions, requests, or complaints: abyebez03@gmail.com.