01Overview
Autophonix, LLC d/b/a ThunderPhone ("ThunderPhone," "we," "us") provides an AI-assisted telephony platform. This Privacy Policy explains what we collect, how we use and share it, and your rights. It applies to our website, product, and related services (the "Service").
If you use ThunderPhone through a business account, our Terms of Service govern your use, and our Data Processing Addendum describes our processor commitments when we handle Customer Personal Data on your organization's instructions.
02Who we are and how to contact us
Autophonix, LLC d/b/a ThunderPhone is the controller for website, account, and billing data.
Controller for website, account, and billing data: Autophonix, LLC d/b/a ThunderPhone.
Address: 505 Montgomery St. Suite 1100 #1019, San Francisco, CA 94111, USA
Contact: Privacy: privacy@thunderphone.com · Security: security@thunderphone.com · Legal: legal@thunderphone.com
EU representative (GDPR Art. 27)
Rickert Rechtsanwaltsgesellschaft mbH — Autophonix LLC, Colmantstrasse 15, 53115 Bonn, Germany · art-27-rep-autophonix@rickert.law
UK representative (UK GDPR Art. 27)
Rickert Services UK Ltd — Autophonix LLC, PO Box 1487, Peterborough, PE1 9XX, United Kingdom · art-27-rep-autophonix@rickert-services.uk
When we process Customer Content, such as call audio, recordings, transcripts, and related call data, for a business customer, we act as a processor under our DPA and your organization is the controller.
03What we collect
A. You provide
- Account details: name, email, phone, company, role, and workspace settings.
- Payment details: processed by Stripe. We receive tokens or identifiers; we do not store full card numbers.
- Support tickets, feedback, and communications.
B. Collected automatically
- Device and technical data: IP address, device/browser type, event logs, and diagnostics.
- Service usage and call metadata: numbers dialed or received, timestamps, duration, routing, and diagnostics.
- Cookies and similar technologies: essential storage for consent, login, sessions, and security. We also use OpenReplay and Google Analytics where configured — with your consent in the EEA, UK, and Switzerland, and by default with a working opt-out elsewhere. Inside the signed-in product dashboard, operational product analytics and privacy-filtered session replay may run under the same regional rules to operate, secure, support, debug, and improve the Service. See our Cookie Policy.
C. Optional recordings and transcripts
If your admin enables recording or transcription, we process call audio and derived transcripts to provide those features. We do not intentionally collect special categories of data; customers should avoid including them in Customer Content.
04How we use data
- Provide, maintain, and improve the Service; route calls; provide optional recording and transcription.
- Billing and account management, including per-minute usage charges.
- Security, fraud and abuse prevention, and DNC/TCPA compliance tooling.
- Troubleshooting, quality assurance, and product analytics, aggregated or de-identified where possible.
- Legal compliance and enforcement of our Terms.
- Recording and transcription responsibilities: customers are responsible for providing legally required notices and consents, including one-party or two-party recording consent where applicable, before enabling recording or transcription.
05In-app assistant and support chat
- Copilot (in-app assistant): when you use the in-product Copilot, we store your conversations with it — including transcripts of any voice interactions — to answer your requests, operate and secure the feature, and improve it.
- Support chat: messages you send through in-app support chat are recorded, stored, and processed by our support-desk software so our team can respond, and support threads are retained so you can continue the same conversation when you return.
- Support and screen-share calls: live support voice and screen-share sessions are shown in real time and are not recorded; any chat messages exchanged alongside them are stored as described above.
06Legal bases
Under GDPR and UK GDPR, we rely on contract to provide the Service, legitimate interests for security, abuse prevention, and product improvement, consent where required, and legal obligations for tax, audit, telecom, and other compliance needs.
08Google user data (Calendar and Sheets integrations)
What we access when you connect Google Calendar or Google Sheets, how we use and protect it, and our Limited Use commitment.
Customers can optionally connect a Google account so their ThunderPhone agents can work with Google Calendar and Google Sheets. If you connect Google, we access only the data covered by the scopes you approve on Google's consent screen, and only to provide the features below:
- Google Calendar: we read availability and event details, and create, update, or cancel events, when your agent performs a scheduling task you have enabled for it (for example, booking an appointment a caller requests). Our access is limited to calendars you own, and you control which calendar operations each agent may perform.
- Google Sheets: we read the tab names, header columns, and rows of the spreadsheet you select during setup, and append rows (for example, caller details and call outcomes) to that configured spreadsheet and tab. You choose that spreadsheet through Google's own file picker, and our access is limited to that single file — we cannot see anything else in your Google Drive.
Storage: Google OAuth tokens are encrypted at rest. We store only the configuration metadata needed to operate the integration (such as the selected spreadsheet and tab). Calendar and spreadsheet content is processed transiently to perform the requested operation, and appears in your call transcripts and logs only as part of the conversation record your organization controls.
Sharing: we do not sell Google user data, do not use it for advertising, and do not transfer it to third parties except to subprocessors acting on our instructions to provide the Service, for legal compliance, or as part of a business transfer as described above.
Human access: our personnel do not read Google user data except with your explicit permission (for example, a support request), where necessary for security or abuse investigation, to comply with applicable law, or where the data has been aggregated or anonymized.
AI/ML: we do not use Google user data to develop, improve, or train generalized artificial intelligence or machine-learning models.
Retention and revocation: disconnecting a Google connection in the dashboard deletes the stored tokens for that connection. You can also revoke ThunderPhone's access at any time from your Google account permissions.
ThunderPhone's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
09International transfers
Where we transfer personal data internationally, we rely on EU Standard Contractual Clauses and the UK Addendum with our vendors and subprocessors. See our DPA for details.
10Retention
We keep data only as long as needed for the purposes above or as required by law.
- Account and billing data: for the life of the account and for tax/audit after closure.
- Call recordings, transcripts, and other account data: retained until you delete the specific content or your account, you request erasure, or the agreement between us is formally terminated — whichever comes first. A lapsed subscription alone does not delete your data; your account and its data persist until you delete them. Billing records are kept for 7 years for tax and audit purposes; backups age out on an approximately 35-day cycle.
- Analytics: typically up to 24 months, then aggregated or deleted unless a shorter period is configured.
- Technical logs and diagnostics: typically about 13 months, unless needed longer for security, legal, or compliance reasons.
11Your rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to processing of, and port your personal data. To exercise rights, contact privacy@thunderphone.com or our EU/UK representatives for local authority matters. We will respond per applicable law.
12Security
We use industry-standard technical and organizational measures. If we learn of a Security Incident, we will notify affected customers without undue delay and within 72 hours of awareness where required.
13Children
The Service is not directed to children under 13, or the age defined by local law. We do not knowingly collect personal data from children. If you believe a child provided data, contact privacy@thunderphone.com.
14Changes to this policy
We may update this policy from time to time. We will post the new version here and update the Last updated date. If changes are material, we will provide additional notice, such as email or in-product notice.
15Contact us
Autophonix, LLC d/b/a ThunderPhone
505 Montgomery St. Suite 1100 #1019, San Francisco, CA 94111, USA
privacy@thunderphone.com · security@thunderphone.com · legal@thunderphone.com