Legal · Privacy

Callora Privacy Policy

Last updated: August 21, 2025

Callora (\u201cCallora\u201d, \u201cwe\u201d, \u201cus\u201d) provides AI voice-agent and Locum Tenens credentialing tools. This policy explains, in plain English, exactly what data we collect, why, how long we keep it, and every third-party service that ever sees a byte of your data.

1. Data we collect

We collect the following categories of data. If you are a locum candidate whose data was uploaded by a hospital/agency using Callora, the categories under \u201cMedical\u201d apply to you.

account
  • email
  • hashed password
  • full name (optional)
  • plan/subscription
  • created_at / last_login
telephony
  • phone number(s) purchased or connected
  • call metadata (duration, direction, timestamps)
  • call recordings (only when explicitly enabled)
  • call transcripts
ai
  • agent configurations you author
  • prompts and speech-analysis instructions
  • post-call AI analyses (summary, sentiment, key points)
  • copilot conversation history
medical
  • locum candidate PII you upload (name, NPI, DEA, state licenses, verification documents)
  • assignment records
  • facility onboarding tokens + MSO actions
billing
  • Stripe customer id
  • plan history
  • credit wallet balances
  • topup/pricing events
telemetry
  • IP address (for rate-limits + fraud protection)
  • user-agent
  • request path + status (for error monitoring)
  • error stack traces (scrubbed)

2. How we use your data

  • Deliver the product: place/receive calls, generate AI analyses, manage bookings, run background checks you request.
  • Prevent abuse: rate-limiting, brute-force protection, spam detection.
  • Billing: process subscriptions and credit top-ups via Stripe.
  • Support: respond to your emails and in-app messages.
  • We do not sell your data. We do not run advertising networks. We do not use your data to train foundation models.

3. How AI processes your data

Your data is never used to train foundation models.

Callora sends only the transcripts and structured data you generate to LLM providers (OpenAI, Anthropic) via API. Under those providers’ enterprise / API terms, submitted data is not used to train or fine-tune their public models. Callora itself does not train models on your data.

Specifically, the following flows send data to LLM/voice providers:

  • Live voice sessions stream audio/transcripts to OpenAI Realtime.
  • Post-call analysis sends the transcript to GPT-4o for structured summary.
  • Callora Copilot sends your chat + tool metadata to GPT-4o.
  • Optional voice cloning sends samples you upload to ElevenLabs.
  • Optional locum outreach may use Twilio for calls/SMS.

A self-harm / crisis interception layer scans every AI input and output. If the system detects severe distress it will refuse to respond and return crisis-line resources (988 in the US, plus international lines). This layer runs before any LLM call is made.

4. Sub-processors

Every third-party service that ever processes your data is listed below with its purpose, the data category it sees, its region, and a direct link to its own privacy policy.

ServicePurposeData seenRegionPolicy
OpenAILLM inference for Realtime voice, chat, post-call analysis, embeddings for Knowledge Base.Transcripts, prompts, agent instructions.US (multi-region)Privacy
AnthropicAlternate LLM inference (fallback / Copilot reasoning).Prompts and returned analyses only.USPrivacy
ElevenLabsOptional voice cloning + TTS for AI agents.Voice samples uploaded by owner.US / EUPrivacy
TwilioInbound/outbound telephony, SMS, call recordings.Caller phone number, recordings, transcripts, call metadata.US / EU / globalPrivacy
TelnyxAlternate telephony carrier (BYOK).Caller phone number, call metadata.US / EUPrivacy
StripePayment processing, subscriptions, customer portal.Billing name, email, card details (tokenized — Callora never sees raw PAN).US / EUPrivacy
ResendTransactional email delivery (voicemail forwarding, renewal reminders, alerts).Recipient email, message subject/body.USPrivacy
Cal.comBooking widget integration for locum candidates.Booked slot email/name/phone.US / EUPrivacy
SentryError tracking and performance monitoring.Stack traces + minimal user identifiers (hashed).US / EUPrivacy
UpstashServerless Redis for rate-limiting and short-lived caches.IP + user id for rate-limit counters (ephemeral, TTL ≤ 10 min).US / EUPrivacy
CloudflareDDoS/CDN + Turnstile CAPTCHA.IP address, TLS metadata.GlobalPrivacy
Google (Workspace)Optional per-user OAuth: Calendar events + Gmail send.Only what the user connects (calendar events + gmail send).USPrivacy
MongoDB AtlasPrimary database.All application data at rest.US (primary), region-of-choicePrivacy
SAM.gov / OIGFederal exclusion checks for provider credentialing.Provider name, NPI submitted for match.USPrivacy
LinearOptional ticketing hand-off for admin alerts.Ticket title/description (Callora scrubs PII where reasonable).US / EUPrivacy

This list is versioned in our repository at /lib/legal/sub-processors.js. Material changes are announced by email at least 30 days in advance.

5. Retention & deletion

  • Account data: retained while your account is active.
  • Call recordings + transcripts: 90 days by default. Configurable per-account.
  • Locum candidate documents: 7 years after last assignment (regulatory).
  • Rate-limit + telemetry: \u2264 30 days.
  • Deleting your account: Settings \u2192 Privacy \u2192 Delete all my data. We flag your account as pending deletion (30-day soft-delete grace period), then purge on day 31. You can cancel deletion any time in that window by logging back in.

6. Your rights

  • Access / Portability: request an export of all your data at privacy@callora.ai.
  • Rectification: edit your profile from Settings.
  • Erasure: use the in-app self-service delete (Settings \u2192 Privacy).
  • Objection / Restriction: email us to restrict specific processing.
  • Do Not Call: if you were dialed by a Callora customer, reply STOP to any SMS or ask us to add your number to our global block list.

7. Security

  • All traffic served over TLS 1.2+. HSTS enabled.
  • Passwords stored as pbkdf2-sha256 hashes (100k iterations).
  • Field-level encryption for stored integration credentials.
  • Twilio + Stripe webhooks HMAC-verified.
  • Per-user + per-IP rate limits on public endpoints.
  • Role-based admin access with granular permissions and a step-up flow for destructive actions.

8. SMS and text messaging

No mobile information sharing. No mobile information (phone numbers, SMS opt-in status, or SMS-derived data) will be shared with third parties or affiliates for marketing or promotional purposes. All the above categories exclude text-messaging originator opt-in data and consent; this information will not be shared with any third parties.

Message frequency. Message frequency varies by account activity and account type. You may receive up to approximately 10 messages per week per user for typical Callora workflows (call notifications, verification codes, AI campaign responses, and account alerts).

Message and data rates may apply. Standard messaging rates from your mobile carrier may apply to any messages you send or receive.

Consent, HELP, and STOP. You opt in by providing your mobile number during signup or by texting START to a Callora sender. Reply HELP for support or STOP at any time to unsubscribe. Full opt-in flow and sample messages are documented at /sms-consent.

Categories of SMS you may receive: account verification codes, security alerts, call/voicemail notifications, campaign replies you initiated, billing notifications, and (only with separate opt-in) product updates.

Carrier disclaimer. Callora is not responsible for delayed or undelivered messages caused by your wireless carrier.

9. Contact

Data Controller: Callora, Inc.

Data Protection contact: privacy@callora.ai

Founder & Medical Officer: Dr. Ishmael A. Avery, M.D.

Terms of Service← Back to home