1. Who we are and who this covers
MairyAI LLC, a Wyoming limited liability company ("MairyAI", "we", "us"), provides an AI phone receptionist to United States businesses.
This policy covers two different groups, and the difference matters:
(a) Our customers. The businesses that buy the Service, and the people at those businesses who sign up, sign in, and use the dashboard. We are the controller of that information — we decide how it is used, and this policy governs it.
(b) Callers. People who telephone one of our customers and reach the AI assistant. We are the processor for caller information — we handle it on our customer's behalf and under our customer's instructions. The business you called is the controller. If you are a caller and want your information corrected or deleted, contact the business you called; we will help them respond. We also handle caller requests sent directly to us, as described in Section 8.
The Service is offered to businesses in the United States only. It is not directed at individuals for personal use and not at children under 13.
2. Information we collect
From our customers (business account information)
- Account and contact details: name, business name, work email, telephone number, job title.
- Authentication data: sign-in identifiers and session records, handled by our identity provider. We do not store your password.
- Billing data: billing contact, billing address, plan, subscription status, invoice history, and the last four digits and brand of your payment card. We never receive or store your full card number — Stripe processes payments and holds card data directly.
- Configuration you provide: business hours, services, pricing, policies, scripts, knowledge content, transfer destinations, and calendar connections.
- Usage and technical data: dashboard actions, feature usage, IP address, browser and device type, timestamps, error and audit logs.
- Support communications: what you send us by email or in the dashboard.
From callers (handled for our customer)
- Call metadata: the caller's telephone number, the number called, date, time, duration, call outcome, and whether the call was transferred or booked.
- What the caller says: the caller's speech is converted to text in real time so the assistant can understand and respond. Whether that text or the audio is stored depends on the customer's settings — see Section 3.
- Information the caller gives: name, callback number, email address, service address, the reason for the call, appointment preferences, and anything else the caller volunteers.
- Structured summaries: an AI-generated summary and qualification result for the call.
We instruct our customers not to use the Service to collect payment card numbers, bank account numbers, Social Security or government ID numbers, health information, biometric data, or passwords by voice. Our terms prohibit it. If a caller volunteers such information anyway, it may appear in call content until it is redacted or deleted.
From website visitors
Pages you view, referring page, approximate location derived from IP address, and information you submit in a contact or demo form. Cookie details are in Section 10.
3. Recording, transcripts, and how long we keep them
Call recording and transcript storage are off by default. They are enabled only when the customer turns them on for their workspace and confirms they have read the Call Recording and AI Disclosure Policy. Recording and transcript storage are independent — turning one on does not turn on the other.
Even when nothing is stored, speech is processed in real time. To answer a call at all, the caller's speech must be converted to text and processed by an AI language model, and the assistant's replies must be synthesized into speech. That processing happens during the call whether or not any recording or transcript is retained afterward.
Callers are told. Before any substantive conversation, the assistant states that it is an AI assistant and, when recording is enabled, that the call is recorded. See the Call Recording and AI Disclosure Policy.
Retention
| Data | Default retention | Configurable range |
|---|---|---|
| Call audio recordings | Not stored (off by default) | If enabled: 30 days maximum |
| Transcripts | Not stored (off by default) | If enabled: 30 days maximum; redacted before storage |
| Call metadata and structured summaries | 90 days | 30, 60, 90, 180, or 365 days |
| Customer account, configuration, and billing records | For the life of the account | — |
| Invoices and financial records | Up to 7 years | Set by tax and accounting law |
| Security and audit logs | 12 months | — |
| Non-identifying aggregate statistics | Up to 24 months | — |
Retention periods above 90 days for call metadata require the customer to choose them deliberately. When a retention period expires, the record is deleted automatically. Deleted content is marked so that restoring a recovery snapshot does not silently bring it back.
4. Why we use information
We use information for these purposes only:
- To provide the Service — answer calls, understand callers, respond, qualify, book appointments into the connected calendar, and show results in the dashboard.
- To operate the account — authenticate users, apply roles and permissions, keep workspaces separated, and send service notices.
- To bill — process subscription payments, produce invoices, and handle refunds and disputes.
- To support customers — answer questions and investigate problems. Support access to call content is restricted, logged, and used only to resolve a specific issue.
- To keep the Service secure and reliable — detect fraud and abuse, investigate incidents, monitor errors, and recover from failures.
- To improve the Service — using usage patterns, aggregated statistics, and error data. See Section 5 for the limits on this.
- To comply with law — meet legal, tax, and accounting obligations and respond to lawful requests.
5. We do not train AI models on customer content
We do not use call recordings, transcripts, call summaries, caller information, or customer configuration content to train, fine-tune, or improve any AI or machine-learning model — not ours and not a third party's.
This is our binding commitment, not a description of a provider's default. We use our AI and speech providers on API terms under which content submitted through the API is not used to train or improve their models. Content sent to a provider is used only to return a result for that call. A provider may retain content for a limited period for abuse and security monitoring under its own terms; the Subprocessors document records the terms we rely on for each provider.
If a provider changed its terms so that we could no longer make this commitment, we would move to a provider where we could, or tell you before anything changed. We would not quietly weaken this statement.
We do not sell personal information, and we do not share it for cross-context behavioral advertising as those terms are used in United States state privacy laws.
Any improvement work described in Section 4.6 uses aggregated, de-identified data — counts, durations, error rates, and similar statistics that cannot reasonably be linked back to a caller, a customer, or a business.
6. When we disclose information
We disclose information only in these situations:
- To service providers (subprocessors) who help us run the Service — telephony, speech, AI language processing, hosting, storage, authentication, payment, monitoring, email, GPU compute, and calendar integration. Each is bound by contract to protect the information and use it only to provide their service to us. The current list, what each one receives, and where it processes data is in SUBPROCESSORS.md.
- To our customer, for caller information — this is the point of the Service.
- To systems the customer connects, such as Google Calendar or a CRM, at the customer's direction. Once information is written into a system the customer controls, that system's policies govern it, and deleting data from MairyAI does not delete it there.
- For legal reasons — to comply with law, a subpoena, or a court order, to enforce our agreements, or to protect the rights, safety, and property of MairyAI, our customers, or the public. Where we are legally permitted, we will tell the affected customer before disclosing their data.
- In a business transfer — in a merger, acquisition, financing, or sale of assets, subject to this policy continuing to apply. We will notify affected customers.
We do not disclose information to advertisers or data brokers.
7. How we protect information
- Encryption in transit using TLS, and encryption at rest. Stored call recordings and transcripts, when enabled, use AES-256-GCM envelope encryption with per-tenant keys.
- Tenant isolation enforced in the application and at the database level, so one customer's data cannot be read by another.
- Role-based access control — owners, admins, and members see only what their role allows. Sensitive actions such as exports require recent reauthentication.
- Redaction applied to transcripts before they are stored durably. Automated redaction reduces risk but cannot be guaranteed to catch every sensitive detail.
- Audit logging of access to and export of call content, retained for 12 months.
- Restricted internal access — our staff do not have routine access to customer call content. Access is limited to what is needed to run and support the Service, and it is logged.
- Deletion markers so that restoring a recovery snapshot cannot silently reinstate deleted content.
- Recovery, not long-term backup. We rely on the point-in-time recovery our hosting provider offers for the managed database — currently a window of roughly three days — rather than keeping an independent long-term backup of our own. Recent accidental loss can be recovered; a problem found much later may not be.
No system is perfectly secure. We cannot guarantee that information will never be accessed without authorization. We hold no security certification. We are not SOC 2 certified, not ISO 27001 certified, not PCI DSS certified, and not HIPAA compliant, and we make no such claim.
If we become aware of a breach affecting personal information, we will notify affected customers without undue delay as described in the Data Processing Addendum, and we will notify individuals and regulators where the law requires.
8. Your rights and how to exercise them
Depending on where you live, you may have the right to know what personal information we hold about you, to get a copy of it, to correct it, to delete it, to limit how sensitive information is used, to opt out of sale or targeted advertising (we do neither), and not to be discriminated against for exercising these rights. Residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws have rights of this kind.
If you are a MairyAI customer: email support@mairyai.com or use the privacy tools in your dashboard, which support export and deletion of workspace data.
If you are a caller: contact the business you telephoned. That business decides what happens to your information, and it is the only party that can act on your request. We cannot act on a caller request on our own initiative. If you write to us at support@mairyai.com we will acknowledge you, tell you to contact that business, and forward your request to them within five business days so they can respond. This is the same rule as in Section 7 of our Data Processing Addendum — there is no second route.
What happens next: we verify identity before acting on a request, which usually means confirming control of the email address or telephone number on the record. We respond within 45 days and may extend once by 45 days where the law allows, telling you why. There is no charge unless a request is excessive or repetitive.
Appeals. If we decline a request, you may appeal by replying to our decision with the word "appeal". We will respond within 45 days with our decision and reasons.
Authorized agents may submit requests with written proof of authorization.
We may keep information despite a deletion request where the law requires it, for financial records, to resolve disputes, to enforce agreements, or to maintain security. Data held in our hosting provider's recovery snapshots is removed as those snapshots age out.
9. Where data is processed
We store data in the United States. Our databases, our call recordings and transcripts where enabled, and our hosting provider's recovery snapshots are held in United States regions.
Processing and network transit are a separate question, and we do not claim they are US-only.
- Our network and routing provider operates a global edge network. Web and API requests, and the encrypted storage of call content, may be routed through or cached at edge locations outside the United States depending on where the request originates. All of it is encrypted in transit.
- Our AI, speech, and infrastructure providers operate globally. Although we configure United States processing where a provider offers that choice, a provider may process or support from outside the United States under its own terms, and some do not offer a region guarantee at our tier.
- Our providers may provide engineering and support from other countries, which can mean incidental access from outside the United States.
The Subprocessors document identifies, for each provider, what it receives and what we currently understand about where it processes.
We do not offer data residency guarantees, and we do not commit that a given call is processed only within the United States. The Service is sold to businesses in the United States and is not offered in the European Economic Area, the United Kingdom, or Switzerland. If you have a contractual or regulatory requirement for United States-only processing, tell us before you sign up — we currently cannot meet it.
10. Cookies and website tracking
Our website uses cookies and similar technologies that are strictly necessary to run the site, sign you in, keep your session secure, and remember preferences. We use limited analytics to understand which pages are used.
We do not use advertising cookies and we do not run cross-site advertising trackers. Because we do not sell personal information or share it for cross-context behavioral advertising, a Global Privacy Control signal does not change our practices, but we honor it as an opt-out where the law treats it as one.
You can block or delete cookies in your browser, though the dashboard may not work correctly without necessary cookies.
11. Telephone numbers and communications
We use the contact details you give us to send service messages — billing notices, security alerts, and important changes to the Service. You cannot opt out of these while you have an account.
Marketing email, if we send any, always includes an unsubscribe link, and unsubscribing does not affect service messages.
The Service answers inbound calls. It does not make outbound telemarketing calls, and customers are prohibited from using it for that purpose.
12. Changes to this policy
We may update this policy. If a change is material, we will notify customers by email or in the dashboard at least 30 days before it takes effect, and update the "Last updated" date. The current version is always at https://mairyai.com/privacy.
13. Contact us
MairyAI Privacy: support@mairyai.com Security: support@mairyai.com Support: support@mairyai.com