Privacy notice
Umwise processes information to provide the website, respond to pilot inquiries and operate customer workspaces. We do not sell personal data. A customer organization remains responsible for the customer data it connects to its workspace; Umwise processes that data to deliver the configured service.
Information processed
Pilot inquiries may include a name, company, contact method, lead volume and CRM preference. Product workspaces may process operator accounts, customer contact details, conversation content, request context, consent state, inventory facts, decisions, tasks and technical security events. Telephone operation may also process carrier call identifiers, direction, disposition and duration; Umwise stores caller and called-number references only as one-way fingerprints in its carrier ledger.
Purpose
We use this information to answer requests, qualify and route commercial conversations, provide sourced recommendations, create operator handoffs, maintain auditability, prevent abuse and secure the service. Automated output does not silently approve a high-impact decision; configured policy gates and human review remain available.
Voice concierge and telephone calls
If you start the public voice concierge or call a connected Umwise line, audio is processed in real time by ElevenLabs so the AI agent can respond. The agent identifies itself as AI and discloses transcription. Provider-side voice recording is disabled; audio is deleted and provider conversation retention is configured for no more than seven days. Zadarma processes the current production telephone route and carrier metadata, but Umwise does not request or download Zadarma recordings. Twilio may process organization/account status or telephone connectivity only when its adapter is enabled; OAuth access tokens are short-lived and are not retained. ElevenLabs sends a signed post-call transcript to Umwise, where message content and the call summary are encrypted. Starting an inbound conversation records consent for that interaction only; a later outbound sales call requires separately documented contact consent and an authorized operator action.
Security and minimization
Contacts, full names and message bodies are encrypted by the application using authenticated encryption. Passwords use a one-way memory-hard hash, session tokens are stored only as hashes, access is role-based and external webhook payloads must pass signature verification. Operational logs exclude message bodies and contact details.
Service providers and channels
When configured by a workspace, the current message and limited request memory may pass through OpenRouter to a selected model provider for structured extraction. Routing is restricted to endpoints marked as denying data collection and, by default, zero data retention. OpenRouter retains request metadata such as token counts and latency; model providers have their own privacy terms. ElevenLabs, Zadarma, Twilio, WhatsApp, Telegram, CRM and inventory providers process data only when their adapters are configured. The current provider categories are listed on the subprocessors page.
Retention
Workspace owners configure operational retention from 30 days to 10 years, subject to the customer agreement and legal duties. A daily maintenance job removes messages, webhook records, carrier call metadata and model-usage records after the configured period; expired sign-in sessions are removed automatically. Owners can export workspace data without passwords, sessions or integration credentials. Synthetic public sandbox records contain no real customer identity.
Your choices
You may request access, correction, export or deletion, and may object to or restrict processing where applicable. Channel opt-outs and consent changes should be respected by the connected operator workflow. Contact [email protected] for privacy requests.
Cookies
Umwise uses a secure, HTTP-only first-party session cookie for authenticated workspaces. The public sandbox does not require an advertising or cross-site tracking cookie.
More information
Read the security overview, subprocessor list and website terms.