1 What we collect, and why
Four things, plus the logs any web server keeps. No hidden fifth thing.
Public pages from the URL you give us
When you hand an agent a website address, we crawl a handful of pages on that same domain and store the text as searchable chunks, plus the topics and company/person names we find. It's what lets the agent talk about your business two turns later instead of reading a script. We only read pages that are already public — no logins, no paywalls, and we never scrape LinkedIn.
What you say or type to an agent
Voice and chat turns are stored as transcripts against the agent you spoke to. We periodically read our own agents' transcripts to pull out the email addresses and URLs people share, so a request for a dossier doesn't get lost in a chat log.
Only what you choose to share
Your email and company URL, from the dossier form or from the conversation itself. We use them to build and send your dossier, to create your demo agent, and — this is the part most sites bury — to add you to the Voxvani Monthly newsletter. One email a month, unsubscribe in one click, or change the cadence at news.voxvani.com.
Status and amounts, never card numbers
Checkout runs entirely on Stripe's hosted page. Card details never touch our servers and we couldn't show them to you if we tried. What we store is the outcome: trialing, active or cancelled, plus the amount and date of each payment.
- Server logs and rate limits. Requests to our public endpoints record the calling IP address so we can stop abuse and cap how many demo agents get created in a day. Same as any web server.
- Referral codes. If you arrive with a
?ref=link we store which code brought you, so the person who referred you gets credit. - No advertising trackers. There are no ad pixels, no third-party analytics scripts and no cross-site tracking cookies on voxvani.com today. Your browser's local storage holds small things like "you've already seen the launch checklist" and a referral code — nothing that leaves your machine.
2 How long we keep it
The honest answer: indefinitely, unless you ask us to delete it.
Most companies quote a retention window here. Ours is a deliberate business decision and we'd rather state it plainly: research and prospect records are not automatically deleted. Crawled research, the topics and entity graph built from it, and the prospect record tied to your email are kept as ongoing business intelligence — they inform what we build and who we follow up with.
Two things we do alongside that. Companies we've researched are re-crawled roughly every two weeks, so what we hold reflects your site as it is now rather than as it was months ago. And every record is tagged with where it came from, so we can always tell you how we got something.
What this policy is not: we don't sell data, we don't rent lists, and we don't feed one customer's research into another customer's agent. Each tenant's knowledge, conversations and leads are isolated from every other tenant's.
3 Remove my data
Self-serve, no ticket, no account required. Takes about a second.
Enter the email address you shared with us. We'll delete the prospect record, the person node in our entity graph, and your newsletter subscription — immediately, not "within 30 days".
Prefer a human? Email dev@rbdesigntech.com and we'll do it by hand and confirm.
4 Get a copy of your data
Available on request today; not yet a button you can press.
You can have a full copy of everything we hold about you — the prospect record, the research we crawled for your domain, the transcripts of conversations with your agents, and your payment history. We assemble it as CSV and JSON and send it back to you.
Being straight about the mechanism: this is a request we fulfil by hand, usually within a few business days. A self-serve export button is on the launch checklist and hasn't been built yet. Asking costs you one email either way.
Request a data export5 Who else touches your data
Every third party in the pipeline, and the one job each of them does.
| Provider | What it does | What it sees |
|---|---|---|
| HetznerGermany | The dedicated server everything runs on — app, databases, entity graph, newsletter engine. | All of it, as the hosting provider. No third-party managed database service is involved. |
| CloudflareDNS & certificates | DNS hosting, and the DNS challenge used to issue our TLS certificates. | DNS queries only. Our records are unproxied, so your page and voice traffic goes straight to our server rather than through Cloudflare. |
| ResendTransactional email | Sends your dossier email and other one-to-one messages from noreply@voxvani.com. | Your email address and the contents of the message. |
| ListmonkSelf-hosted | Runs the newsletter and the frequency preference centre at news.voxvani.com. | Nothing leaves our server — Listmonk is our own software on our own machine. It hands finished emails to Resend for delivery. |
| StripePayments | Hosts the checkout page and handles cards, subscriptions and invoices. | Your card and billing details, which we never receive — they go straight to Stripe. Checkout is live; we store only the resulting subscription status against your email. |
| MercuryBanking | Our business bank. We read account balances and draft invoices for a human to review and send. | Only what appears on an invoice we draft — company name, amount, description. Nothing is ever emailed to you by the automation. |
| GroqModel inference | Runs the language model behind agent replies, transcribes speech, and screens new agents for unsafe content before they can be published. | The conversation turns and audio sent for that request. |
| MicrosoftSpeech synthesis | Turns the agent's reply text into the voice you hear (Edge text-to-speech). | The text the agent is about to speak. |
| OllamaSelf-hosted | Generates the embeddings that power semantic search over crawled research. | Nothing leaves our server — the embedding model runs locally on the same machine. |
This is the schedule as the product is built today. If we add or swap a provider, this page changes with it, and the dated schedule attached to a signed DPA is the authoritative version.
6 Compliance status
The same rule as our public checklist: green only when it's real.
We hold no security or privacy certifications today. If you need a badge on this page to sign, we're not there yet, and we'd rather you find that out here than three weeks into a procurement review.
What we do actually have
- TLS everywhere. Every public surface — the site, the agent API, the dashboards, the newsletter — is HTTPS only, with certificates issued and renewed automatically.
- Gated admin surfaces. The prospect dashboard, the newsletter admin and the tenant console all sit behind authentication. The public endpoints are a deliberately short list: intake, checkout, the agent library, the health check, and the deletion form on this page.
- Per-tenant isolation. Knowledge, conversations, leads and stats are scoped to a single tenant. One customer's agent cannot read another customer's knowledge base.
- Rate limiting and abuse caps. Public endpoints are capped per IP and globally, and automatic demo-agent creation is limited to one per email address and ten per day.
- An audit log. Administrative actions — provisioning an agent, publishing or rejecting one, honouring a deletion request — are written to an append-only log with a timestamp.
- Secrets off the repo. API keys live only in a root-owned, permission-restricted file on the server. None are in source control, and none appear in any page we serve.
- No resale, no ad pixels. We have never sold or brokered prospect data, and there is no advertising or analytics tag on this site exporting your behaviour to anyone.
7 Data processing agreement
Available on request, signed by a human.
If your organisation needs a Data Processing Agreement before you can use Voxvani, email us and we'll send one for review and signature, along with the current dated subprocessor schedule. We'll also answer a security questionnaire — with the same honesty as this page, which sometimes means answering "no".
Request a DPAThis page describes how we operate as of the date above. It is written to be understood, not to be airtight — it is not legal advice, and it isn't a substitute for a signed agreement. Where this page and a signed contract disagree, the contract wins.