Legal
Privacy Policy
Draft — last revised August 2026
1. Information we collect
We collect account information you provide (name, email, company, billing details), communications data generated by your use of the service (call records, recordings, transcripts, voicemail, SMS), and technical data (device information, IP addresses, usage logs). Call recordings and transcripts are created only when you or your administrator enable those features.
2. How we use information
We use your information to operate the service — routing calls, generating transcripts and CallScrub scores, billing, and support. We use aggregate, de-identified usage data to improve platform reliability and features. We do not sell personal information, and we do not use your call content to train models made available to other customers.
3. AI processing
When AI features are enabled, call audio and transcripts are processed by our AI systems to provide agent responses, transcription, and scoring. Processing occurs in US data centers. Administrators control which lines and features have AI processing enabled, and can disable it per extension, per queue, or account-wide.
4. Sharing
We share information only with subprocessors necessary to deliver the service (carriers, cloud infrastructure, payment processors), each bound by contractual confidentiality and security obligations; with your MSP or reseller if you purchased through a partner; and when required by law, including lawful intercept obligations that apply to communications providers.
5. Retention
Call detail records are retained for the life of your account plus 18 months for billing and regulatory purposes.
Recordings, transcripts and voicemail follow the retention tier your administrator sets on the tenant: 30, 60 or 90 days, after which the stored object expires automatically. Tenants that bring their own storage bucket hold recordings for as long as they choose, in their own bucket, under their own lifecycle rules. Deleted data is purged from backups within 35 days of deletion.
6. Security
All data is encrypted in transit (TLS 1.2+, SRTP for media) and at rest (AES-256). Access is role-based and logged, and tenant data is isolated at the database level by row-level security. Our security program is built against the SOC 2 Type II Trust Services Criteria; see our SOC 2 page for the current attestation status.
7. Your rights
Depending on your jurisdiction, you may have rights to access, correct, delete, or export your personal information. Business customers should route requests through their account administrator; individuals may contact us directly and we will respond within 30 days.
Subprocessors named in section 4
- Stripe
- Billing and payment processing. Card details are entered into and held by Stripe; AMP Cortex does not store card numbers.
- ElevenLabs
- Conversational AI. Call audio on an AI agent extension is processed to produce the agent's speech and understanding.
- CallScrub
- Call analytics. Transcription, sentiment analysis and agent scoring run on recorded calls when a tenant has analytics enabled.
- Telnyx · Twilio · BulkVS · Bandwidth
- SIP trunking and PSTN carriage. These carriers move the call and message traffic and see the signaling metadata required to route it.