What we collect, and what we never do with it
Last updated September 22, 2026
Related: Security and Terms of service.
The short version
- We collect what's needed to run your business through Vocartes: account details, the operational data you feed in, and, where it's part of your business, your customers' personal information.
- We don't sell your data, and we don't use it to train any AI model, ours or a third party's.
- When you use Vocartes to manage your own customers' information, you're the controller of that data and we're your processor.
- You have the right to know, correct, delete, and export what we hold, under California, Virginia, Colorado, Connecticut, and Utah privacy law, among others.
- We don't collect protected health information, and we don't sign Business Associate Agreements. See Security: protected health information.
- Your data is deleted two months after your account closes. You can export everything before then.
Information we collect
Business and account information: your business name, owner and admin contact details, billing information, and the systems you connect (accounting, CRM, email, calendar, hosting credentials or API tokens).
Business operational data: the substantive content you feed in to get outcomes, such as financial records, contracts, vendor data, schedules, and marketing materials.
Your customers' personal information, where it's part of your own business data: names, contact details, and in some industries, sensitive categories such as client legal matters in a law context. Vocartes does not collect protected health information as a category, and our Service isn't designed to receive it. See "If health information is submitted anyway" below for what happens if it arrives despite this.
Usage data: how you interact with the product.
How we use it
To provide the Service: routing your requests to the right role, drafting and executing approved actions, and maintaining your business's context over time.
To maintain and improve the Service in aggregate, not to train shared models on identifiable customer content. See the model-training commitment below.
To bill you and to communicate with you about your account.
What we don't do: sell your data to third parties, or use it for advertising unrelated to the Service.
The model-training commitment
We do not use your business data or your end customers' personal information to train any AI model, whether ours or a third-party model provider's. Our contracts with model providers prohibit them from training on data submitted through Vocartes. This is the same commitment stated on our Security page, and it should read the same way in both places.
Subprocessor disclosure
The same subprocessors named on our Security page apply here: our cloud host, our named model provider or providers, our email and communication vendor, and any other vendor with access to personal data. We'll update that list and notify you before adding a subprocessor with material data access.
If health information is submitted anyway
Despite the limits described above, health information may occasionally be submitted to the Service by mistake, for example through a connected email inbox or an uploaded document. When this happens, we quarantine or delete it, we don't use it to provide or improve the Service, and we don't retain it beyond what's necessary to complete the deletion and document the incident.
This is different from our general retention policy for other business data, described above. Protected health information doesn't benefit from that retention commitment, because we shouldn't have received it at all. Our obligation is to remove it, not hold it. See Terms: no protected health information for the full prohibition and what you're responsible for.
Retention and deletion
Your data is retained for the life of your account, plus two months after cancellation. You can export everything during those two months; after them, we delete it. For regulated categories, such as legal records, we retain data consistent with your own regulatory retention duty, commonly 7 to 10 years depending on your state and profession. We don't delete data automatically at plan downgrade, non-payment, or a usage threshold, and we don't shorten the two-month window for any of those reasons either.
You, or where applicable an end customer whose data your business holds, can request deletion. The one exception: if deleting the data would put you in violation of your own recordkeeping law, such as a state requirement that a law firm retain client billing records for a set period, we can't delete it on request in a way that creates that violation.
Your state privacy rights
If California law applies to you: you have the right to know what we hold, delete it, correct it, and opt out of the sale or sharing of your personal information. We don't sell personal information, which keeps this a simple opt-out. You also have the right not to be discriminated against for exercising any of these rights.
If Virginia, Colorado, Connecticut, or Utah law applies to you, you have the same core set: access, correction, deletion, portability, and opt-out of targeted advertising, sale, or certain profiling.
To exercise any of these rights, email . We'll respond within the timeframe the applicable law sets, and we'll verify your identity in a way that matches the sensitivity of the data involved.
These rights apply regardless of which state statute covers you: the FTC Act treats deceptive privacy claims as actionable nationwide.
Controller and processor roles
When you use Vocartes to manage information about your own customers, you're typically the controller (or "business," under California law) of that information, and Vocartes acts as your processor (or "service provider"). That means you're responsible for having the legal right to collect and share that information with us, and for responding to your own customers' privacy rights requests, though we'll support you in fulfilling them.
A Data Processing Agreement is available for customers who need one to satisfy their own controller obligations.
Protected health information is not part of this relationship. We don't accept it, we don't sign Business Associate Agreements, and we're never your business associate under HIPAA. See Security: protected health information and Terms: no protected health information for the full prohibition.
Children's data
The Service isn't directed to children under 13, and we don't knowingly collect personal information directly from children. Vocartes processes whatever personal information our business customers input as part of running their business, which is a business-to-business data flow, not a direct-to-consumer children's service. It excludes protected health information entirely, including a minor's, since that category is prohibited across the board.
Security
See our Security page for how we protect this information, including encryption, access controls, and our current certification roadmap. We keep that detail in one place so it can't drift out of sync with this policy.
Contact
Privacy questions or rights requests: .