Privacy

What we collect, why, and how to delete it

Last updated: June 29, 2026. Plain language. If anything here is unclear, email hello@saperly.com and we’ll explain.

1. Introduction

Saperly is the phone carrier built for AI agents. We provision phone numbers, transmit calls and SMS through an underlying carrier, and provide compliance infrastructure (mandatory AI disclosure, consent records, append-only audit trail) so the AI agents you deploy on our network behave like good-faith carrier customers from day one.

This notice explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and how to ask us to access, correct, or delete it. These rules govern data; our Terms of Service govern the rest of how we work together.

For the purposes of GDPR and UK GDPR, Saperly is the controller of account, billing, and correspondence data, and a processor of the communications content (call audio, SMS bodies, transcripts) that flows over your phone numbers. For CCPA/CPRA we are the business that collects personal information directly from you and from recipients of communications you initiate.

2. Information we collect

Account data. When you sign up we store your email, business name, billing address (collected by our payment processor), and the API keys you generate. Sign-in is passwordless (magic link or Google sign-in), so we never store a plaintext password.

Communications data. For every call or SMS sent or received on a Saperly number we record metadata: the originating number, the destination number, timestamps, duration, delivery status, segment count, and routing zone. We do not store call audio or SMS bodies by default. If you explicitly enable recording on a line, we store the resulting audio for the retention window described in Section 8.

Usage data. We log API key activity, billing transactions, balance changes, and webhook delivery attempts so you can audit your own usage and so we can investigate support tickets, fraud, and abuse.

Correspondence data. When you email us (for example at hello@saperly.com) we keep your message and the details you include — such as your name, work email, company, and what you’re building. We use it only to reply to you and to triage spam and abuse.

Inferred data. We derive routing zone, channel (voice vs SMS), and fraud signals from the metadata above. None of this is sold, shared for advertising, or used to build profiles on the people you call or message.

3. How we use and disclose information

We use personal data to operate the service, transmit your communications, bill you, prevent fraud and abuse, comply with legal obligations (TCPA recordkeeping, FCC traceback, tax), answer support tickets, and improve product quality through aggregated, de-identified metrics.

We disclose personal data only to the sub-processors named in Section 6 (each strictly to deliver Saperly to you), to legal or regulatory authorities when compelled by valid legal process, to the underlying carrier as required to deliver calls and messages, and to a successor entity in the event of a merger or acquisition.

We do not sell personal information, share it for cross-context behavioural advertising, rent it, or use it to train any third-party advertising profile. See Section 5 for our position on AI/ML training specifically.

4. Communications metadata, recordings, and CPNI

Because Saperly is the customer of record on the underlying carrier, we are subject to the Customer Proprietary Network Information rules at 47 U.S.C. § 222. CPNI includes information about the quantity, technical configuration, type, destination, location, and amount of use of telecommunications services. We treat CPNI as confidential and use it only to provide the service, bill you, prevent fraud, and meet our regulatory obligations.

Metadata captured per communication: originating and destination phone numbers, timestamps, duration, delivery status (queued, sent, delivered, failed, undelivered), routing zone, segment count for SMS, and per-leg billing records. This metadata is necessary to operate the service and cannot be disabled.

Recordings. Call audio is recorded only when you enable recording on a specific line. When enabled, recordings are stored for the duration described in Section 8. You are responsible for obtaining any consent required by federal or state two-party-consent recording laws (covered in our Terms of Service Section 5). Saperly does not enable recording by default.

Transcripts. When recording is enabled we may generate transcripts from the audio for billing reconciliation and audit purposes. Transcripts inherit the same retention window as the source recording.

U.S. CPNI opt-out. U.S. customers may opt out of certain Saperly internal uses of CPNI for service-related communications. Email hello@saperly.com with the subject line “CPNI Opt-Out” and we will honour the request within 30 days.

5. AI and ML processing of customer data

Saperly does not train any AI or ML model on your call audio, SMS bodies, transcripts, your correspondence, or any other customer content. We do not license customer content to third parties for model training, and we do not allow our sub-processors to use it for their own model training.

We may use aggregated, de-identified metrics — for example, average call duration per zone, error-rate trends, total messages-per-second per region — to plan capacity, tune fraud detection, and publish service-level transparency reports. None of these aggregates can be re-associated with an individual customer or recipient.

Where Saperly uses a third-party LLM in support tooling (for example, to summarise a long support ticket), the vendor is configured so that inputs and outputs are not used to train the vendor’s models, in line with that vendor’s enterprise no-training default. We list any such tooling in Section 6 if and when it processes customer personal data.

6. Sub-processors

We rely on the following sub-processors to deliver Saperly. Each is contractually bound to handle your data only as part of providing service to Saperly and to maintain security and privacy standards consistent with this notice.

  • Carrier network (United States) — the underlying telecommunications carrier for outbound and inbound voice and SMS, including the in-network voice AI assistant. Conversation audio is processed within the carrier network and does not pass through Saperly compute.
  • Cloud infrastructure provider (United States) — application hosting, the application database, per-call session coordination, and edge email routing. Personal data we store at rest lives within this provider’s infrastructure.
  • Payment processor (United States) — payments, prepaid balance top-ups, and payment-method storage. The processor acts as an independent controller for fraud prevention under its own privacy notice.
  • Email delivery provider (United States) — transactional email (magic-link sign-in, billing notifications, and account alerts).

We name the specific company behind each category in our sub-processor register, available on request at hello@saperly.com.

When we add or replace a sub-processor that processes personal data, we will give at least 30 days’ prior notice on this page so you can object before the change takes effect. (Notice mechanism: “Last updated” stamp bump plus email to the address on your account.)

7. International data transfers

Saperly is based in the United States and our sub-processors are all U.S.-headquartered. If you are based in the EEA, the United Kingdom, or Switzerland, your personal data is transferred to and processed in the United States.

We rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum) as the transfer mechanism for personal data moving to the United States, together with equivalent transfer mechanisms (such as Brazil SCCs) where local law requires.

You can request a copy of the SCCs that govern Saperly’s transfers by emailing hello@saperly.com.

8. Data retention

We keep personal data only as long as we need it for the purpose we collected it, plus any period required by law. Concrete durations:

  • Call recordings — 30 days from the call end time, then deleted.
  • Transcripts — 90 days from the call end time, then deleted.
  • SMS bodies — not stored unless you explicitly opt in on a line; if opted in, 30 days from delivery.
  • Communications metadata — life of the line plus 7 years for billing and tax recordkeeping.
  • Correspondence (emails you send us) — kept until you ask us to delete them.
  • Account data — for the lifetime of your account, then 30 days post-termination as a recovery window, then deleted.
  • Consent records (TCPA) — 4 years from creation (TCPA statute of limitations).
  • Compliance events (append-only audit trail) — 7 years (FCC and state telemarketing recordkeeping).
  • Billing records — 7 years (tax).

Where law requires longer retention than your deletion request would permit (notably consent records and compliance events), we keep only the minimum necessary record and segregate it from other personal data.

9. Security and breach notification

We use technical and organisational measures appropriate to the risk of the personal data we hold: TLS in transit, encryption at rest for the database and recording storage, passwordless authentication, scoped API keys, role-based access for the small number of Saperly staff who need it, audit logging of administrative actions, and regular dependency patching.

No system is unbreachable. If we confirm a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify affected users within 72 hours of confirmation, consistent with GDPR Articles 33 and 34, and we will notify the applicable supervisory authority within the same window where required. We will also comply with U.S. state breach-notification laws on their own timelines.

Notification will identify what was affected, what we know about the cause, what we are doing to contain and remediate, and what you can do to protect yourself.

10. Your rights — GDPR (EU, EEA, UK)

If you are in the EU, EEA, or United Kingdom, you have the following rights under GDPR / UK GDPR:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure — ask us to delete your data, subject to the legal retention exceptions in Section 8.
  • Portability — receive your data in a structured, commonly used, machine-readable format.
  • Restriction — limit how we process your data while a dispute is resolved.
  • Objection — object to processing based on our legitimate interests.
  • Withdraw consent — where processing is based on consent, you can withdraw it at any time without affecting prior lawful processing.
  • Lodge a complaint — with your local supervisory authority.

To exercise any right, email hello@saperly.com from the address tied to your account. We respond within 30 days and free of charge for the first request in a 12-month period.

For EU and UK data-protection matters, contact us directly at hello@saperly.com.

11. Your rights — California (CCPA / CPRA) and other U.S. states

Categories of personal information we collect (per CCPA categories): identifiers (name, email, IP), commercial information (transactions), internet/network activity (API logs), geolocation (zone-level routing), professional information (company, expected volume you share), and inferences drawn from the above (fraud signals, usage tier).

Do Not Sell or Share My Personal Information. Saperly does not sell personal information and does not share personal information for cross-context behavioural advertising. You do not need to submit an opt-out — there is nothing to opt out of. We provide this notice as required by law.

If you are a California resident, you have the right to:

  • Know what personal information we collect, the sources, the purposes, and the categories of third parties we disclose to.
  • Delete personal information we collected from you, subject to retention exceptions in Section 8.
  • Correct inaccurate personal information.
  • Limit use of sensitive personal information to purposes necessary to deliver the service.
  • Non-discrimination — exercising any right does not affect your service or pricing.
  • Designate an authorized agent to make requests; we may verify the agent’s authority.

Other U.S. states. Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and Montana have substantially similar rights under their respective state consumer privacy statutes (VCDPA, CPA, CTDPA, UCPA, TDPSA, OCPA, MCDPA). We honour those rights via the same process described below.

To exercise any right, email hello@saperly.com from the address tied to your account. We respond within 45 days (extendable once for another 45 if reasonably necessary).

12. Cookies and tracking

Saperly sets a small number of first-party functional cookies: a session cookie set after sign-in, and short-lived state cookies set during Google sign-in to prevent CSRF. We do not set any third-party cookies, advertising cookies, fingerprinting beacons, or analytics trackers.

We do not use cookies for advertising. We do not permit advertising networks to set cookies on Saperly properties.

13. Children’s privacy

Saperly is a developer-API product not directed to children. We do not knowingly collect personal information from anyone under 13 in the United States or United Kingdom (per COPPA), or from anyone under 16 in the EEA (per GDPR Article 8). Our Terms of Service set the minimum age to use the service at 18.

If we learn that we have collected personal information from a child in violation of these rules, we will delete it promptly. If you believe we have collected such information, email hello@saperly.com.

14. Correspondence — retention note

When you email us at hello@saperly.com, we store your message so we can reply and keep a record of the conversation. We do not share it with third parties or use it for marketing.

The details you include (name, email, message, optional company and volume) persist until you ask us to remove them, consistent with the retention table in Section 8.

15. Changes to this notice

When we make material changes to this notice, we will bump the “Last updated” date at the top and email the address on your account at least 30 days before the change takes effect. Your continued use of Saperly after the change date constitutes acceptance of the updated notice. You always have the right to terminate your account before any change applies — see Terms of Service Section 10.

This page is the source of truth for our data handling. We’ll note material changes here and bump the “Last updated” date at the top.