Weyvox
Terms ← Home

Privacy Policy

Last updated: 7 September 2026 · Version 22

This Privacy Policy explains how Weyvox collects, uses, shares, and protects your personal data, and the rights you have under Regulation (EU) 2016/679 (the GDPR) and the French Data Protection Act (Loi n° 78-17 du 6 janvier 1978, as amended). Weyvox is the telephone line of your business with an AI on it — an app for iPhone and Android, made for sole traders and small businesses: a real phone number (bought in the app, or your own business number connected by forwarding), an AI agent that answers your customers on that line, places calls on your instruction and texts them a confirmation afterwards, business management (business profile and price list, customers, orders, documents), a team of executors who work the orders assigned to them, and personal chats with people by phone number. This policy covers both the app and the weyvox.com website.

1. Who is responsible for your data

Data controller: Petro Solianyk, operating as an individual entrepreneur (auto-entrepreneur / micro-entreprise) registered in France.

SIREN: 101 887 248

Country / governing law: France (European Union).

Contact for privacy requests: support@weyvox.com

The controller decides why and how your personal data is processed. We have not appointed a Data Protection Officer, as we are not required to under Art. 37 GDPR; the contact above handles all privacy matters.

2. What data we collect

We collect what the line needs in order to work, and we describe it in the order it reaches us: your account, your line and its calls, the SMS the agent sends for you, the agent itself, your business records, your team, your personal chats, and finally billing, technical and website data.

Account & registration

Your phone number is your identity in Weyvox: it opens your account and signs you in, and no email address is involved. Sign-in is confirmed with a one-time SMS code generated and verified by our SMS provider; we do not store the codes — they expire within minutes, and we keep only short-lived anti-abuse counters. With it we keep your first and last name, your confirmation that you are 18 or older (the service refuses an account without it), and — if you choose to give them — your date of birth and gender, which the agent reads live from your account so that it addresses and represents you correctly.

PIN and recovery codes. If you set a PIN on your account (Settings → Account → Security), neither it nor the ten one-time recovery codes issued with it are stored as you typed them: we keep only an irreversible cryptographic digest of each, together with the counters that slow down guessing. Nobody at Weyvox can read them, and nobody will ever ask you for one.

The phone your account is bound to. A Weyvox account is active on one phone at a time, so we record an identifier for the device you signed in on and the time you did so; signing in on a new phone signs the old one out. Section 10 explains what that means for your data.

Your business line

Your line is a real phone number and the calls that run over it. Nothing in this group exists until you have a number.

  • Your Weyvox operator number — the number allocated to you, its country, the state of its monthly subscription and the dates of its charges. If a temporary number is issued while your application is reviewed, the same applies to it.
  • Identity documents for the number (KYC). Some numbers can only be registered with identity information, because telecom regulations and our carrier require it. In that case, during the purchase you upload the requested documents (for example an identity document or proof of address) and form details (such as name, date of birth, address). We use them for one purpose only — submitting your number registration to the carrier — and keep them only as long as the application needs them: while the application is in progress the documents sit in a private storage bucket, separate from ordinary chat media, encrypted with Weyvox's own application-level key on top of at-rest encryption (see section 10); once the number is activated, the documents, the form details and the application record are automatically and permanently erased within 24 hours; a document you replace or remove during the application is purged from storage within about 3 hours; and a cancelled or expired application is cleaned up the same way. Deleting your account removes them as well.
  • Your own business number. If you connect a number you already hold, we store that number, the state of its caller-ID verification and the one-time code exchange that proved it is yours. Forwarding itself you switch on with your own carrier: it lives in their network, and we can neither enable it nor read its state.
  • Calls. Every call runs over the public telephone network, from your Weyvox operator number or your connected business number, and is carried by our telephony carrier. We keep the call metadata — the parties, direction, date, time, duration and outcome, held as the call history of your line — plus the routing and cost data needed to connect and bill the call. Because these calls travel over the telephone network, the carrier necessarily sees the numbers and the duration. Call audio we do not keep: calls are transmitted in real time, with the single exception below. Calls the agent answers or places are processed in real time by our speech and language-model providers so that it can hold the conversation.
  • AI call notes — recording and transcript. When you enable AI notes, the call is recorded solely to produce the note, and the lifecycle is short and fixed: the audio is made by our telephony carrier, used only for transcription and deleted right after our transcription service has processed it (minutes); the transcript — the verbatim record of what was said — is kept for 24 hours, so you can ask the agent follow-up questions about the call while it is fresh, and is then deleted automatically, while turning notes off mid-call discards it at once; the resulting note is ordinary content in that number's thread and stays until you delete it or delete your account.
  • Keypad tones on agent calls (DTMF). When the agent navigates a phone menu for you ("press 1 for bookings"), it sends keypad tones (DTMF) on the call. The digits it presses can be sensitive — a booking reference, an account number, a code you dictated. They are handled accordingly: each sequence is transmitted to our telephony carrier over an encrypted connection solely to press the keys on that call, is not stored anywhere after the key presses are delivered, and our technical logs record only that keys were pressed and how many — never which ones.

SMS to your customers

When you have a Weyvox operator number, the agent can send SMS to your customers — a confirmation of what was agreed on a call (only after the customer agreed to it on the call), a text-back to a missed call if you switch that on, or a message you ask the agent to send from a customer's card. For each SMS we keep the text, the recipient's number and the delivery status, stored in that number's thread in your Line together with its calls; the customer's number lives in their customer card. The SMS is sent from your operator number through our telephony carrier, which processes the number and the text to deliver it. These records are kept until you delete the thread or your account. A person who does not want to be contacted through Weyvox can block their number at weyvox.com/optout/ — the block covers both the agent's SMS and its calls.

The AI agent

  • Your conversations with it, and what it is working on. The messages you send the agent and the attachments in them, the instructions you give it, and the journals and results of the background tasks it runs for you. Your agent chat history is shown from your phone, and we hold a server copy so it is there again on a new phone; that copy is stored encrypted with Weyvox's own application-level key (see section 10), is never shown to other users and is never used to train any model. Each user's agent data is isolated and used only to provide the agent to that user.
  • Agent memory. A per-user store of durable facts the agent saves in order to help you ("prefers morning appointments", a door code, a supplier's name). It is listed in the app, individual entries can be removed and the whole memory wiped in one action, and it is stored encrypted with our application-level key. Transcripts of the calls it makes or answers are kept for 24 hours as follow-up context, then deleted automatically.
  • Agent voice and voice cloning. You choose the voice your agent speaks with on calls: a ready-made voice, or a clone of your own voice. If you clone your voice, you record a short sample in the app; it is used to build a voice model — held by our text-to-speech provider as our processor — so the agent can speak in a voice modelled on yours. It is your own voice only (you cannot clone anyone else's), used solely for your own agent, is not shared with other users, and you can delete it at any time in Settings, which removes the voice model. We rely on your explicit consent for this (Art. 6(1)(a) GDPR, and Art. 9(2)(a) to the extent a voice model is treated as biometric data); you give it by recording and enabling the clone, and withdraw it by deleting the clone.
  • Location, while the switch is on. If you allow location access on your phone and the agent's location tool is enabled — it is on by default, and you can switch it off at any time in the agent's settings — your approximate coordinates are attached to the messages you send the agent in its chat, so it can answer place questions ("find a pharmacy near me"). Location is passed along with the request to produce the answer and is not stored on our servers, and it is never used on the agent's phone calls — calls carry no location by design. A location pin you share inside a personal chat is different: it is stored with the chat like any other message.
  • Contacts access, if you switch it on. The “Contacts access” switch (Settings → Weyvox AI agent → Agent tools) lets the agent dial someone you name instead of a number you dictate ("call the plumber"). It relies on the phone's contacts permission — nothing is read until you grant it. While it is on, a snapshot of your contacts — names and phone numbers only, no emails, photos or other fields — is uploaded to our servers, replaced when your address book changes, and filtered against the numbers blocked at weyvox.com/optout/. It is never shown to other users and never used for advertising, and it is deleted from our servers when you turn the switch off; deleting your account deletes it as well.
  • The pitch of the other person's voice, during a call. While the agent is on a call it estimates the pitch of the other person's voice in real time, for one narrow purpose: to address them with the correct grammatical gender in languages that require it. The estimate exists only for the duration of the call, is never stored, and is not used for anything else — not for profiling, not for identification, and not for any decision about that person.

Business management

The Business tab is where you keep what the agent needs in order to speak for you. These are your business records: they are kept until you delete them or your account, and they never expire on their own.

  • Your business profile and business type. The business name and legal name, the type of business you choose at first launch or later under Business → Business information (a restaurant, a salon, a transport company, or “Other”), a description, who your customers are, contacts, opening hours and their exceptions, payment and cancellation terms, delivery, the FAQ the agent answers from, and what the agent may promise on its own. The business type is used for one thing: to pre-fill the profile and to choose the vocabulary and the fields of your orders. All of it is shown to nobody outside your business and is deleted with your account.
  • Your price list — products and services with their prices, ranges, units and notes. It is the only source the agent quotes a price from.
  • Customers and orders. Customer cards (name, phone number, email, company, notes), orders with their status, payment state, the executor assigned to them and any custom fields your business type adds, and the event feed of each order. Much of this is personal data of your customers — people who may not use Weyvox themselves — so it is handled accordingly: the sensitive fields (names, phone numbers, emails, notes) are stored encrypted with Weyvox's own application-level key (see section 10), and every record is isolated per business. Under the GDPR you act as the controller of your own customer records; Weyvox processes them for you to provide the feature.
  • Business documents. You can upload the paperwork of your business — contracts, invoices, tax filings, registration papers, supplier and HR files, licences — and the documents the agent writes for you are filed there automatically. We store the file itself, the metadata extracted from it (document type, counterparty, number, date, amount, expiry date), a text extract used for search, and any links you make to a customer or an order. These files count towards your storage allowance and are erased when you delete the document or your account.
  • These documents are readable by the agent — that is the point of the feature, and we say so plainly on the upload screen, every time: the agent can answer questions about a document only if it can read it. Concretely, the file — and the text extract we keep for search — is encrypted with Weyvox's own application-level key (AES-256-GCM) before it reaches our storage, on top of transport and provider at-rest encryption, so a raw copy of our database or file storage is unreadable without that key; but we hold the key, so our systems and the AI provider processing the document can read its content in order to work for you. Two consequences before you upload anything sensitive. First, a document is read once when you upload it — sent to our AI provider to extract the text and metadata — and again only if you ask the agent a question its extract cannot answer; files of 8 MB or more are uploaded to the AI provider’s file storage to be read, and we delete them from there automatically within 24 hours, enforced by an hourly clean-up. Second, you can exclude any single document from the agent entirely: the switch “Do not let the agent read this” on the document’s page erases its text extract and search index, so the document stays stored and visible to you while the agent cannot find or read it. This is a per-document choice, not an all-or-nothing one. Voice providers are not involved here: business documents never enter the call pipeline.
  • PDF templates. If you use PDF templates (Business > PDF templates), we store what you put in them: the details you issue documents under — name or company name, address, tax or registration number, bank details, email, phone — an optional logo you upload, the per-type defaults (payment terms, signatory, salutation and so on) and any custom field you add. You may enter these yourself, or the agent may write them into a template on your instruction; either way they are yours to edit or clear at any time on that page, and they are deleted with your account. A template is meant to hold your own details, not a third party's — when the agent produces a document for someone else, that party's details belong in the document itself, not in your template. A PDF the agent writes is laid out on your phone; a copy is then filed into your document archive above, where you can delete it at any time, while a PDF export of a task report stays on the phone and is saved nowhere on our servers.
  • The weekly report. Once a week the agent compiles a report of your line — calls, calls answered by the agent, missed calls, SMS sent, orders and their amounts, paid and unpaid — from the records already in your account, and posts it to your Weyvox system chat. It is ordinary chat content and involves no new data collection.

Team members (executors)

An administrator can add executors — staff who work on the orders assigned to them — under Business → Team. An executor does not register: the administrator enters their first and last name and, optionally, a phone number as a note, and hands them an eight-character access code by any channel. For each executor we store those details, a hash of the access code (never the code itself), the identifier of the device the code was used on, and the times of their sign-ins. What the executor does on the assigned orders (stage changes) appears in the order's event feed under their name, and what they spend on the agent is charged to the administrator's balance and shown in the administrator's usage records with the executor's name; the executor sees only their own spending. Under the GDPR the administrator is the controller of the data of the staff they add; Weyvox processes it to provide the feature.

Removal and deletion are two different things. When the administrator removes someone from the team, the access code stops working at once, their sessions end and their orders are released — but the sub-account itself remains. It is deleted by the person it belongs to, from Settings → Leave team in their own app. Deleting the administrator's account removes every executor attached to it.

Personal chats

Personal chats are a free convenience beside the line: you open one by phone number, and they carry text, photos, videos, files, voice messages, albums, captions and locations you choose to share. They are stored on Weyvox servers in the European Union, encrypted in transit (TLS) and encrypted at rest by our storage provider, with access governed by access policies and per-user isolation; they are not end-to-end encrypted — section 10 explains what that means and who can read what. Your history is therefore available again when you sign in on a new phone. Messages and media are kept until you delete them or delete your account.

  • Delivery metadata. Alongside the content, our servers keep what is needed to deliver and order a conversation: which conversation a message belongs to, who sent it and when, its sequence number and type (text / attachment / album / voice / call record), reply and forward references, emoji reactions, read cursors and unread counters, and, for attachments, the file's size and content type. A sync journal used to bring the app up to date after it has been closed is kept for 90 days.
  • Your profile photo — optional. If you set one, it is shown to the people you communicate with: in their chat list, in the chat itself and on your contact card. They can see it and nothing more — uploading, replacing and deleting a profile photo are restricted to the account that owns it, and our servers reject any attempt to point one account's profile at another account's photo. You can change or remove it at any time in Settings → Personal information; a removed photo stops being served, and deleting your account deletes it too. Without one, other people simply see your initials. Your photo is not published on any public page, not listed in any directory, not shown to people you have no connection with, and never used for advertising or for training AI models.
  • Last seen and online status. So that the person you are chatting with can tell whether you are around, the app records when it was last open on your device and whether it is open right now, shown in the chat header as “online” or a last seen time. We keep one such record per account — the latest time only, not a history of your sessions. In Settings → Notifications → Privacy → Last seen you choose who may see it: Everyone, My contacts (only people you already have a chat with), or Nobody. Those who may not see it get only an approximate indication (“recently”, “within a week”, “within a month”, “a long time ago”), never the exact time, and it works both ways: restrict your own and you see only approximations for everybody else. People you have blocked, or who have blocked you, see nothing at all. The check is performed on our servers, not in the app: when you are not allowed to see someone's exact time, the app is never sent it in the first place.
  • Numbers you block. A number you block is stored as a list on your account, so the block holds wherever you sign in; unblocking removes the entry. Blocking is independent of anything you report to us.
  • Chat wallpapers. A wallpaper is decoration you pick for your own screen from your own photo gallery, not a message; it is stored for your account in access-controlled storage, encrypted at rest.

Billing & usage

Your prepaid balance, top-up transactions (processed by the App Store or Google Play — we never receive or store card details), and usage records (per-day, per-operation charges: calls, agent usage, web searches, SMS, notes, storage, the monthly fees for your number and for each executor seat) needed to charge your balance and show your history. For an administrator with a team, usage records carry the name of the executor who caused the charge.

Technical & device data

Push-notification tokens, a device/app identifier, IP address, and short-lived technical logs generated when the app talks to our servers — used to deliver calls and notifications, keep the service secure, and diagnose problems. Weyvox uses no third-party advertising, analytics, or tracking SDKs in the app.

Website visitors (weyvox.com)

  • The site sets no advertising or analytics cookies and uses no trackers.
  • The on-site demo assistant answers questions about Weyvox. It has no access to any user account or data. Messages you type are processed by our AI provider to generate the reply and are not stored by us afterwards; your IP address is kept for 3 hours solely for rate limiting, then deleted automatically.
  • Our hosting/CDN provider processes standard connection data (such as IP addresses) to serve and protect the site.

Support and abuse reports

If you contact us, we keep your message and contact details for as long as needed to resolve your request. Abuse — spam, threats, fraud, unlawful use of a number or of the agent — is reported by email to support@weyvox.com, with the number and the time concerned; we keep what you send us for as long as the case needs it, and we never tell the reported person who reported them.

3. Why we use your data and our legal bases

PurposeData usedLegal basis (GDPR)
Opening and running your accountPhone number, name, 18+ confirmation, optional date of birth and gender, PIN and recovery-code digests, the identifier of your current phoneContract — Art. 6(1)(b); the PIN and the one-phone-at-a-time binding also rest on legitimate interests in account security — Art. 6(1)(f)
Running your business line (calls in and out)Your operator number and its subscription, your connected business number, call metadata, routing and cost dataContract — Art. 6(1)(b)
Registering a real phone numberKYC documents and form detailsContract — Art. 6(1)(b); compliance with carrier/regulatory identification requirements — Art. 6(1)(c)
AI call notes (recording & transcription)Call audio, transcriptConsent — Art. 6(1)(a): you switch notes on, and can turn them off at any time
Sending SMS to your customers on your behalfRecipient number, SMS text, delivery statusContract — Art. 6(1)(b) towards you; towards your customer you are the controller and must hold a lawful ground to contact them (the agent sends a confirmation only after the customer agreed on the call)
Running the AI agent for youYour agent conversations and attachments, task journals, agent memory, call transcripts held as follow-up contextContract — Art. 6(1)(b)
Agent contacts access, location for the agentContacts snapshot; per-request locationConsent — Art. 6(1)(a), withdrawable at any time in settings
Agent voice cloning (your own voice)Voice sample and the derived voice modelConsent — Art. 6(1)(a), and Art. 9(2)(a) where treated as biometric; withdrawn by deleting the clone
Business management (profile, customers, orders, documents)Business profile and type, price list, customer cards, orders and their events, business documents and their extracts, PDF templatesContract — Art. 6(1)(b) with you; for the personal data of your customers you are the controller and we process it on your instructions
Connecting your calendar (Google Calendar, or the calendars on your phone)Your Google account email, the calendar you choose, access and refresh tokens (encrypted), and the start and end times of your existing events — event titles, guests, locations and descriptions are neither read into our records nor stored. If instead you switch on the calendars already on your phone, the app reads them on the device and sends us only those start and end times; the app may show you your own event names on its calendar screen, but that happens on the phone alone — no Google or Apple account is linked and no event content leaves your phoneConsent — Art. 6(1)(a): you connect the calendar yourself and can disconnect it at any time, which revokes our access at Google
Running your team (executor sub-accounts)Executor name, optional phone note, access-code hash, device id, sign-in times, agent-usage records with their nameContract — Art. 6(1)(b) with the administrator, who is the controller of their staff's data; security of the access code — legitimate interests, Art. 6(1)(f)
Personal chats — delivering and syncing themMessage content and media, delivery metadata, profile photo, blocked numbers, wallpapersContract — Art. 6(1)(b)
Showing your last seen / online status to people you chat withTime the app was last open on your device; whether it is open nowContract — Art. 6(1)(b): it is part of a personal chat. You control who sees it, and can restrict it to your contacts or switch it off entirely in settings
Billing, accounting and tax recordsBalance, top-up and charge recordsLegal obligation — Art. 6(1)(c) (French commercial and tax law)
Security, anti-fraud, anti-abuse, service reliabilityTechnical data, logs, rate-limit countersLegitimate interests — Art. 6(1)(f)
Answering support requests and abuse reportsYour messages and contact detailsLegitimate interests — Art. 6(1)(f)

Where we rely on legitimate interests, we have balanced them against your rights; you may object at any time (see section 9).

4. Call recording and AI notes — your responsibility

Recording calls may be regulated where you or the other party are located. When AI notes are enabled on a call to a phone number, Weyvox plays an audible notice to the other party that the call is recorded for a note. You are responsible for only enabling notes where you are permitted to record. Notes can be turned off entirely in Settings → Call notes.

5. Who we share data with

We do not sell your personal data and we do not share it with advertisers. To run Weyvox we rely on a small number of service providers ("processors") acting on our documented instructions under Art. 28 GDPR contracts. They fall into the following categories:

  • App store and payment platform — app distribution, in-app purchases, push notifications.
  • Telephony and SMS carrier (Telnyx) — real phone numbers, routing of calls to and from regular phones, delivery of the SMS the agent sends to your customers (the carrier processes the recipient's number and the text to deliver it), and — where regulations require — receiving the KYC information you provide to register a number (the carrier processes it under its own regulatory obligations).
  • Cloud hosting, database and storage providers (EU regions) — running our servers and storing your account data, your chats and media, and your business records, encrypted at rest.
  • AI processing providers — speech-to-text, text-to-speech, and the language models that power the agent, the notes, and the website demo assistant. They process this content as processors, solely to provide the feature to us.
  • A mapping/location provider — only when the agent needs place information for a task.
  • An email provider — for messages you send to our support address.

Your own calendar is a separate case. If you connect Google Calendar, Google is not our processor — it is your provider, and we read your calendar on your instruction and with your consent. We take from it only the start and end times of your events, so the agent does not offer a caller a time you are already busy, and we write back the bookings the agent takes. Titles, guests, locations and descriptions are not stored. You can disconnect at any time in the app, which revokes our access at Google, or remove it yourself at myaccount.google.com.

Google API data — Limited Use. Weyvox’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we do not sell that information; we do not transfer it to advertising platforms, data brokers or information resellers; we do not use it to serve or personalise advertising; and we do not use it to determine credit-worthiness or for lending purposes. We do not allow anyone at Weyvox to read it, except with your explicit consent, where it is strictly necessary for security purposes, or to comply with applicable law. We do not use raw or derived data obtained through Google Workspace APIs to develop, improve or train non-personalised artificial intelligence or machine learning models, and we do not store it in conjunction with such models. When the agent needs to know your availability during a call, it is given only the free time windows derived from your calendar — never your event titles or details — and that request is processed by our AI provider under a data-processing agreement that forbids retention and model training, solely to produce the answer you asked for.

We may also disclose data where required by law, or to protect our rights, our users, or the public. A current list of the specific sub-processors is available on request at support@weyvox.com.

6. International data transfers

Some providers process data outside the European Economic Area (notably in the United States). Where that happens, we rely on safeguards recognised by Chapter V GDPR — an adequacy decision (such as the EU–US Data Privacy Framework, where the provider is certified) and/or the European Commission's Standard Contractual Clauses, with supplementary measures where appropriate. You can request more information about these safeguards at the contact address above.

7. How long we keep your data

We keep personal data no longer than needed for each purpose. The concrete periods, as implemented in our systems:

DataRetention
Account and profile (phone number, name, 18+ confirmation, optional date of birth and gender, profile photo)Life of your account; erased when you delete your account (the number is released with the carrier; media storage is wiped)
PIN and recovery codes (irreversible digests) and the identifier of the phone you signed in onWhile the PIN is set and while that phone is the account's device; deleted with your account
Sign-in SMS codesNot stored by us; expire within minutes at the provider
Your line: operator number and its subscription, connected business number, call historyLife of your account, or until you release the number or disconnect the business number
KYC documents and form details for a number purchaseOnly while the application is in progress; erased automatically within 24 hours after activation (replaced/removed uploads — within ~3 hours; cancelled applications are cleaned up the same way)
Call audio recorded for an AI noteDeleted immediately after transcription (minutes)
Call transcripts and note drafts24 hours, then deleted automatically; discarded at once if you turn notes off
AI call notes (the note itself)Life of your account, or until you delete the note or the thread it sits in
SMS sent to your customers (text, recipient number, delivery status)Kept in the number's thread in your Line until you delete the thread or your account
Server copy of your agent chat history (stored encrypted with our application-level key)Life of your account; deleted when you delete your account. The deletion marker left by a chat you deleted is purged within 90 days
Agent memory and background task journalsLife of your account, or until you erase them in the app
Transcripts of calls the agent made or answered (follow-up context)24 hours
Fired agent reminders (follow-ups already delivered)Purged 30 days after they fire
Cached contact names used to label agent remindersDeleted after 12 months without any call with that number
Contacts snapshot for the agent (names + numbers)While the agent's “Contacts access” switch is on; deleted when you turn it off or delete your account
Agent voice clone (voice sample and model)Kept while you keep the clone enabled; deleted when you remove it in Settings or delete your account
Business profile (including business type) and price listLife of your account; deleted when you delete your account
Calendar connection and the busy times taken from itWhile the calendar is connected; busy times taken from the calendars on your phone are erased if the app stops refreshing them for seven days. Busy times are a rolling cache of roughly the next 45 days and are overwritten on every sync; disconnecting the calendar, or deleting your account, revokes our access at Google and erases both the connection and the cached busy times
Customer cards, orders and order events (Business management; sensitive fields encrypted with our application-level key)Until you delete the record or your account — your business records never expire on their own
Business documents (file, extracted metadata and text extract)Life of your account, or until you delete the document; a copy of a file of 8 MB or more held by the AI provider to read it is deleted within 24 hours
PDF templates (issuer details, logo, per-type defaults)Kept until you change or clear them on the PDF templates page; deleted with your account
Executor sub-accounts (name, optional phone note, access-code hash, device id, sign-in times)Until the executor deletes the sub-account themselves with “Leave team”, or the administrator deletes their own account. An administrator who removes someone from the team disables their code, ends their sessions and releases their orders, but does not delete the sub-account. Their charges remain in the administrator's usage records for the usage-record period below
Personal chats — message content and media (stored on our servers in the EU, encrypted in transit and at rest — see section 10)Until you delete the message, the chat or your account. Delivery metadata (ordering, references, reactions) — life of your account; the sync journal — 90 days
Media that no chat participant keeps any morePhysically erased by a nightly clean-up
Last seen / online statusA single latest value per account, overwritten every time the app is opened or closed — no session history is kept; deleted with your account
Blocked numbers and chat wallpapersUntil you unblock the number or change the wallpaper; deleted with your account
Per-operation usage records90 days, then the whole day's records are deleted
Top-up and billing recordsStatutory accounting periods under French law (up to 10 years)
Technical logsShort rotation windows used for operations and security
Website demo-chat IP (rate limiting)3 hours
Abuse reports sent to support and any restriction applied to an accountFor as long as the case needs it, and the record of a restriction for the life of the account. Cases involving illegal content (child sexual abuse material, terrorism, human trafficking) are kept longer as evidence and for any reporting obligation to the authorities

Deletion covers your device as well. When you delete your account in the app, the app erases not only the server copy of your data but also what it kept on your phone: the local encrypted databases together with their device-only encryption key, and cached or temporary media files. Deleting an administrator's account removes every executor attached to it — their access codes stop working at once.

Residual copies may persist briefly in backups before being overwritten in the normal backup cycle.

8. Automated processing and the AI agent

The AI agent acts only on your instructions and within the capabilities you have switched on. It answers and places calls on your line, keeps your customers and orders, and may send an SMS to a customer on your behalf — but only in two cases: to confirm what was agreed on a call, after the customer said yes to receiving it, or when you ask it to write to a customer. Every SMS it sends is visible to you in that number's thread. Once a week it also posts a report of your line to your Weyvox system chat, compiled from your own records. For any concern about an action performed by the agent, you can always reach a human at the contact address above.

No automated decisions with legal effect. Weyvox takes no decision about you that produces legal or similarly significant effects on the basis of automated processing alone (Art. 22 GDPR). Restrictions or closure of an account for a violation of the Terms of Use are decided by a person, after a report reaches us by email; you are told which rule was found to be broken, and you can contest the decision by writing to support@weyvox.com.

AI transparency. Because the agent speaks with other people on your behalf, it always identifies itself as an AI assistant at the start of every call — on outbound calls, on auto-answered incoming calls, and when it takes over a live call — in line with Article 50 of the EU AI Act (Regulation (EU) 2024/1689), which requires that people are informed they are interacting with an AI system at the latest at the first interaction. This is a built-in rule you cannot switch off. The agent speaks in an AI-generated voice; if you have chosen to clone your own voice, this same spoken disclosure ensures the other party is never misled into thinking a human is speaking, and the clone is only ever your own voice, never an impersonation of someone else.

9. Your rights

Under the GDPR you have the right to: access your data; rectify inaccurate data; erase your data ("right to be forgotten"); restrict or object to certain processing (including any processing based on legitimate interests); data portability; and to withdraw consent at any time (e.g. switch off AI notes, the agent's contacts or location) without affecting prior processing. You can delete your account and its data directly in the app at any time (Settings → Account → Delete account). If you no longer have the app, you can request deletion at weyvox.com/delete-account/ — we verify that the account’s phone number is yours and then run the same deletion the app performs.

Under Art. 85 of the French Data Protection Act, you also have the right to give directives about what happens to your data after your death; you can send them to the contact address.

To exercise any right, contact support@weyvox.com — we respond within one month, as the GDPR requires; we may ask you to verify your identity from the phone number on the account. You also have the right to lodge a complaint with the French supervisory authority, the CNIL (Commission Nationale de l'Informatique et des Libertés), 3 place de Fontenoy, 75007 Paris — www.cnil.fr.

If you are not a Weyvox user

Your number can reach our systems without you ever installing Weyvox — because a business that uses Weyvox saved you as a customer, because its AI agent called you or sent you an SMS on the owner's instruction, or because a user who enabled the agent's contacts access has you in their phone book. You do not need an account, and you do not need to write to us, to put a stop to that.

Go to weyvox.com/optout/ and block your number. You confirm the number by SMS or by a dictated phone call, and the block takes effect immediately: the number can no longer register a Weyvox account, calls to and from it through Weyvox are refused, the agent will neither call nor send SMS to it, and it is removed from the contacts snapshots on our servers and rejected from future ones. The whole process is automatic — no document, no waiting, no review.

The block is not permanent by force: you can lift it yourself on the same page, confirming the number by SMS again. This matters because phone numbers get reassigned — whoever holds the number later must not be locked out by a decision they never made.

One order applies: if the number currently has a Weyvox account, delete the account in the app first (Settings → Account → Delete account), then block the number.

10. Security and encryption

We use technical and organisational measures appropriate to the risk (Art. 32 GDPR). In plain terms: one layer under everything (transport, storage and access), a second layer of our own over the sensitive business data of your account, and — said plainly rather than implied — no further layer over personal chats. For each we say what it does and what it does not protect against.

Transport, storage and access. Everything between the app and our servers travels over TLS. Our servers, database and file storage run in EU regions of our hosting providers, where data is encrypted at rest by the provider. Access to the data is governed by per-user (and, for a team, per-business) isolation enforced at the API and database level, row-level policies in the database itself, access controls and least-privilege keys; media is reachable only through short-lived signed links, never a public URL; sensitive files such as identity documents live in private storage buckets; and the automatic deletion schedules in section 7 keep the most sensitive data (call audio, transcripts, identity documents) alive for the shortest possible time. The app contains no advertising or analytics SDKs.

Application-level encryption under Weyvox's own key. On top of that, the sensitive business data in your account — business documents and their text extracts, customer cards and orders, the agent's memory, the server copy of your chats with the agent, and KYC files — is encrypted with AES-256-GCM under a key held in our server configuration before it reaches the database or file storage, so a raw copy of either is unreadable without that key. This is not end-to-end encryption: we hold the key, and the agent reads this data in order to work for you — answer a customer, look up an order, cite a document. For business documents you decide per document: the switch “Do not let the agent read this” on the document's page erases its text extract and search index, so the document stays stored and visible to you while the agent cannot find or read it.

Personal chats are not end-to-end encrypted. Messages and media in personal chats are stored on our servers under the transport, at-rest and access protections above, and are not under the application-level layer. Stated honestly, this means they are readable by Weyvox's systems in the ordinary course of delivering the service — storing, delivering and syncing them, and, when you use the agent inside a chat (a toggle that is on by default and that you can switch off in the agent's settings), passing the messages you ask about to the agent — and that message content can be disclosed on a lawful request from a competent authority. People at Weyvox do not read your chats: they are opened only for a lawful request or for a support case at your own request. Calls and SMS pass through the public telephone network, where the carrier by its nature handles the numbers, the audio and the text.

One phone at a time, and your history on a new phone. A Weyvox account is active on one phone at a time: signing in on a new phone signs the old one out. Because your chats, your business records, your balance, your number and your agent's memory are stored on our servers, they are all there again when you sign in on the new phone — an executor signs in on a new phone by entering their access code again, and the administrator is notified.

Protection on the phone. The app keeps a local database on the device so it opens instantly and works offline; that database is encrypted with a key that exists only on that device, marked so that it is never copied to other devices through the platform's cloud keychain sync. You can additionally set a PIN on your account and lock the app behind it or behind your phone's biometrics (Settings → Account → Security).

No system is perfectly secure, but if a breach occurs we will notify the CNIL and, where required, you, in line with Arts. 33–34 GDPR.

Your conversations with the AI agent

Your chat history with the Weyvox agent is shown from a local database on your phone, and we hold a server copy so that it is there again when you change your phone. That copy is stored encrypted with Weyvox's own application-level key, never shown to other users, never used to train any model, and it is deleted when you delete your account. To generate each reply, the message is transmitted to the AI provider whose model produces the answer and is processed there as our processor under a data-processing agreement (Art. 28 GDPR); we do not retain it there. What we do keep, deliberately and visibly to you, is the agent's long-term memory (facts you asked it to remember or that it learned while helping you — you can review and erase them at any time), the background tasks it is running, and transcripts of calls it made or answered, kept for 24 hours so you can ask follow-up questions about a call. When you use the agent inside a personal chat, the agent sees the recent messages your request concerns, and it is barred from copying another person's messages into its long-term memory.

11. Children

Weyvox is not intended for children. In line with our Terms of Use, you must be at least 18 years old to use Weyvox: registration requires you to confirm that you are 18 or older, and the service refuses accounts without that confirmation; providing your date of birth is optional. We do not knowingly collect data from anyone under 18; if you believe a minor has provided us data, contact us and we will delete it.

12. Changes to this policy

We may update this Privacy Policy from time to time. We will change the "Last updated" date above and, for significant changes, notify you in the app or by other appropriate means before they take effect.

13. Contact

For any privacy question or request: support@weyvox.com.

© 2026 Weyvox Home · Terms of Use · Privacy Policy · Community Rules