Data and Security
Effective October 1, 2026
Businesses trust CallsIn with their customers' calls, texts and addresses. This page explains how we protect that data and what happens to it over time. For what we collect and who we share it with, see our Privacy Policy.
Your data belongs to you
- Your customer data is yours. We use it only to run CallsIn for you.
- We don't sell it, rent it, or use it for advertising.
- You can export your contacts anytime from the Contacts page, and ask us for an export of the rest before you close your account.
Logins and accounts
- Passwords are stored as salted, slow hashes (scrypt), never as plain text.
- You can turn on two-step login with an authenticator app, and get one-time backup codes.
- You can log in with Google instead of a password.
- Login sessions use secure, HTTP-only cookies, expire after a period of inactivity, and end on the server when you log out.
- Repeated wrong passwords and codes are rate limited.
- New owner mobile numbers are confirmed with a texted code, and each mobile number can belong to only one business.
- Each business can only see its own data. Our team members only get the access their job needs.
Protecting data
- All traffic to CallsIn uses HTTPS (encrypted in transit).
- Our database is hosted by Supabase, which encrypts stored data. The app runs on Render.
- Sensitive business details like EINs for texting registration are encrypted again by us before they're saved, and only shown to our admin, with every view logged.
- Card numbers never touch our servers. Payments are handled by Stripe.
- Call recordings and voicemails aren't public links. They only play for someone logged in to that business's dashboard.
- Webhooks from Twilio, Vapi and Stripe are checked for valid signatures, so nobody can fake a call, text or payment.
- Webhooks a business sets up are signed, so the business can check they came from us.
Protecting your phone number and texts
- We only text and call US and Canada numbers. That blocks expensive international and premium-rate fraud.
- Signup codes and texts have limits per number, per visitor and per hour.
- Spam and robocalls are screened and blocked, and they're never charged as AI minutes.
- Opt-outs (STOP) are kept even if a contact is deleted, so nobody gets texted again by mistake.
How long we keep data
| Data | How long |
|---|---|
| Contacts, texts, calls and bookings | While your account is open, unless you delete them sooner. |
| A deleted contact | Their texts, call transcripts, summaries and recordings are deleted right away, including recordings at Twilio and Vapi. |
| Healthcare mode | No transcripts or recordings kept. Call details and message text deleted after 30 days by default. |
| Shorter retention | Any business can ask us to delete call details and message text after a set number of days. |
| Closed accounts | Everything is deleted 90 days after the account closes. We email the owner about two weeks before. |
| Opt-outs and billing records | Opt-outs are kept so we keep honoring them. Billing records are kept as long as tax law requires. |
If something goes wrong
If we learn that someone got into data they shouldn't have, we'll look into it right away, fix the problem, and tell the businesses affected without unreasonable delay, along with what happened and what we're doing about it. We'll also notify anyone else the law requires.
No system is perfectly secure. If you notice something odd in your account, change your password, turn on two-step login, and email us.
Reporting a security problem
If you think you've found a security problem in CallsIn, please email us at support@trycallsin.com with the details. Please don't access other people's data, change or delete anything, or make the problem public before we've had a chance to fix it. We'll reply and keep you updated, and we won't take legal action against good-faith reports that follow these rules.
Changes
We'll update this page as we improve our security. The date at the top shows the last change.