Callenova ("we," "us," or "our") provides AI voice and text agents that help businesses answer calls and messages from their customers. This policy explains what information we collect and how we use it.
Information We Collect
- Business account information: name, email, business details provided when a business signs up for Callenova.
- Call and message content: when a business's customers call or text a Callenova-powered number, we process the audio/text content of that conversation in order to answer questions, collect information, and book appointments on behalf of the business.
- Contact information: names, phone numbers, and other details a caller or texter provides during a conversation, in order to fulfill their request (e.g., booking an appointment, sending a confirmation).
- Payment information: businesses that subscribe to Callenova provide payment details, processed securely through Stripe. Callenova does not store full payment card numbers.
- Integration data: if a business connects services like Google Calendar, we access only the data necessary to check availability and book appointments as authorized by that business.
How We Use Information
- To operate and improve the AI voice and text agent service.
- To fulfill requests made during a call or text (e.g., booking an appointment, answering a question, sending a confirmation).
- To send call summaries and notifications to the business that owns the Callenova agent.
- To bill business customers for their subscription.
How We Share Information
- We do not sell personal information.
- We share information with service providers who help us operate (e.g., Twilio for calling/texting infrastructure, Stripe for payments, Google for calendar integrations), only as needed to provide the service.
- We may disclose information if required by law.
Google Workspace and Calendar Data
If you choose to connect Google Calendar, Callenova requests only the access needed to check your availability and to create the appointments you book through Callenova. We request these scopes and no others: your Google account email address (userinfo.email), calendar events access (calendar.events), and read-only calendar access (calendar.readonly).
What we access and why. We read free/busy time blocks from your primary calendar so that Callenova never offers an appointment slot when you are already busy, and we create calendar events for the appointments booked through Callenova. We read the calendar's name to show you which account is connected. We do not read the contents, titles, attendees, or descriptions of your unrelated calendar events, and we do not access Gmail, Drive, Contacts, or any other Google product.
What we store, and for how long. We store the connection credential for your Google account in encrypted form, the name of the connected calendar, and — for appointments you book through Callenova — the calendar identifier and the identifier of the event we created, so the booking can be kept in sync. We do not store copies of your calendar events, your free/busy data, or any other Google content; free/busy times are requested when needed and used only to calculate the slots shown to you or your customer. Stored Google information is kept for as long as the connection is active, and is deleted when you disconnect or close your account.
How to disconnect and delete. In Dashboard → Settings → Your data, Delete Google Calendar data deletes the stored credential, revokes Callenova's access with Google, and clears the Google calendar details saved on your appointments. Closing your account does the same. Deletion is only reported to you once our database confirms it; if it cannot be confirmed we tell you so and nothing is described as deleted. If Google cannot be reached at that moment, the credential is already gone from your connection and only an encrypted copy is held in a private, staff-inaccessible queue solely to complete the revocation — it is destroyed as soon as revocation succeeds, and in every case within 14 days, whether or not Google becomes reachable. You can also remove Callenova's access from your Google Account permissions page at any time.
Google-derived information is used only to provide the calendar availability, booking, and synchronization features you asked for. It is never used for advertising, never sold, and never transferred into Callenova's voice, website-chat, or SMS AI systems.
Callenova's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Callenova does not use, transfer, or disclose raw, aggregated, anonymized, or derived Google Workspace API data to develop, improve, or train generalized artificial intelligence or machine-learning models.
No human at Callenova reads your Google calendar data except where you have given permission for a specific support issue, where it is needed for security purposes, or where the law requires it.
Data Protection
These are the specific safeguards in place today for Google information and for your account data:
- All traffic between your browser, Callenova, and Google travels over HTTPS/TLS.
- Your Google connection credential is encrypted (AES-256-GCM) before it is written to our database, using a key held only in the server environment.
- Google credentials are used only by Callenova's servers. They are never included in any response sent to a browser, never written to application logs, and never passed to an AI provider.
- Every calendar operation requires a signed-in user who is verified as a member of the workspace that owns the connection, and all calendar records are scoped to that workspace, so one business can never read or act on another business's calendar.
- Calendar requests are made with the narrow set of Google scopes listed above, and only against the connected calendar.
- When a Google request fails, we record only the HTTP status, a general category such as "authentication failed" or "rate limited", the name of the operation, and a random reference code. Google's response text, calendar names, event details, attendee information, request addresses and credentials are never written to our logs, never stored, and never returned to the browser.
- You can disconnect Google and delete the stored Google information yourself at any time. The credential is removed from your connection straight away; if Google is temporarily unreachable, an encrypted copy is held privately only until the revocation completes, and never for more than 14 days.
Artificial Intelligence Providers
Callenova uses two separate AI systems, and Google Workspace data is used by neither.
Voice calls. Phone calls are handled by Retell AI on a pay-as-you-go plan, operating from Amazon Web Services infrastructure in the United States. Retell directly coordinates the providers in this path: OpenAI for dialog generation and post-call analysis, Deepgram for English (US) speech recognition, MiniMax for the synthesized voices, and Twilio, through a Retell-managed subaccount, for telephony. There is no separate AI aggregator in this path. Retell has confirmed that it and these subprocessors do not train models on Callenova call data under its production API terms. Call data at Retell is currently stored with post-call scrubbing of personal information, under Retell's default retention setting, which is indefinite until changed.
Website chat and text-message assistant. These use the Lovable AI Gateway on a Lovable Pro workspace, whose downstream model provider is Google. This is an entirely different path from the voice system.
Google Workspace data — including availability derived from your calendar — is not transferred to Retell AI, OpenAI, Deepgram, MiniMax, Twilio, the Lovable AI Gateway, or Google's Gemini models, for AI processing, model training, or any unrelated purpose. This is enforced in Callenova's own code: the scheduling engine refuses to supply Google-derived data to the voice or SMS channels at all, rather than relying on a provider policy.
Service Providers
The providers that may process data on our behalf are: Retell AI and its subprocessors OpenAI, Deepgram, MiniMax and Twilio (voice calling); Twilio (text messaging); the Lovable AI Gateway with Google as its model provider (website chat and the text assistant); Google (calendar integration, where you connect it); Stripe (payments); Supabase (database and authentication hosting); Cloudflare (hosting, security, and bot protection); and Resend (email delivery). Each processes only what is needed to provide its part of the service.
Data Retention
We retain call and message records for as long as necessary to provide the service and for the business's own record-keeping, unless a business requests deletion.
How to Delete Your Data
Business customers can remove their data at any time from Dashboard → Settings → Your data:
- Delete Google Calendar data disconnects your Google account, revokes Callenova's access, deletes the stored credential, and clears the calendar details saved on your appointments. This takes effect immediately.
- Close my account deletes your calls, recordings, transcripts, appointments, leads, messages, and profile. Anything connected to Google is removed right away; the remainder is deleted after a 7-day window in case the request was a mistake.
If you cannot sign in, email support@callenova.com from the address on the account and we will process the deletion for you.
Your Choices
Individuals who interact with a Callenova-powered phone number can contact the business they reached out to directly with questions about how their information is used, or contact us at support@callenova.com for questions about Callenova's own data practices.
Text Messaging (SMS)
Our text messaging program sends transactional and conversational messages related to an inquiry, conversation or appointment you initiated with a Callenova-powered number. Message frequency varies depending on your interactions (for example, appointment confirmations, reminders, and responses to inquiries). Message and data rates may apply. Reply STOP to any message to opt out, or HELP for assistance. Support is available at support@callenova.com.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with third parties, except service providers acting solely on our behalf to deliver the messaging service.
Contact Us
Questions about this policy can be sent to support@callenova.com.