Effective date: July 29, 2026 · Version: 1.0
Charlotte AI, Inc. (“Charlotte,” “we,” “us”) provides an AI phone receptionist for home-service businesses. This policy explains what we collect, why, how long we keep it, who we share it with, and the controls you have. It covers our websites (charlotte.ai), the Charlotte platform and admin portal, and the calls and text messages we handle on behalf of the businesses that subscribe to Charlotte.
Two hats. For the businesses that subscribe (the “operator”), we are the service provider processing their callers’ data on their behalf and under their instructions. For operator account data, our websites, and our own sales outreach, we act for ourselves. Both are covered below — and if you’re a homeowner who called a business that uses Charlotte, Section 9 is written for you.
1. What we collect
Operator account data (from the business that signs up): your name and email, business name, trade, service area and state, business phone number, the mobile number you want urgent pages sent to, your plan and settings, and the consents you grant at signup (each one recorded with a timestamp and method).
Call and message data (processed for the business you called): the caller’s phone number, the audio recording of the call, its transcript, text messages exchanged with the business’s number, photos a caller texts in (for example an equipment nameplate — we extract the structured details; the photo files themselves remain with our telephony provider), job and booking details captured on the call (problem description, address, preferred times), and the urgency triage outcome. If a caller shares a ZIP code, we may look up local weather to inform triage — only the ZIP code is sent to the weather service.
CRM records (with the business’s authorization): when an operator connects their CRM, we access it through the credentials they grant — for Jobber, reading and writing clients and requests; for Housecall Pro and ServiceTitan (as those integrations roll out), customer, location, job, and appointment records — solely to recognize returning customers and create bookings. Integration credentials are stored encrypted, and operators can revoke them at any time.
Billing data: payments are processed by Stripe. We store your plan, invoice and usage records (for example voice minutes used); we never store your card number.
Website data: our marketing site is deliberately cookie-light. We set a first-party attribution cookie (30 days) recording how you first found us, a similar 30-day cookie noting arrival from an AI assistant, a secure invite cookie if you follow a pilot invitation link, and the session cookies our sign-in provider (Clerk) needs. We do not currently run third-party analytics or advertising cookies. If you join the waitlist, we store your email only to reach you about Charlotte in your area.
Business outreach: if we contacted your business about Charlotte, we obtained your business contact details from public sources (for example public business listings). Every such email includes an unsubscribe link, and you can opt out any time at hello@charlotte.ai.
2. How we use it
We use this data to operate Charlotte: answering and triaging calls, recording and transcribing them, booking jobs into the business’s CRM, sending the service texts described in our SMS Terms, paging the operator on urgent calls, and producing the operator’s digests (including the weekly missed-revenue digest). We also use it to run accounts and billing, provide support, secure the platform (fraud prevention, audit logging, abuse detection), meet legal obligations, and — in de-identified, aggregated form only — to benchmark and improve the service and publish industry research. De-identified research data never identifies a business or a person and never includes verbatim caller utterances.
3. AI processing — and what we don’t do
Charlotte’s voice is AI-generated. During a call, audio is streamed to our speech and language providers (listed in Section 5) to transcribe what the caller says and generate Charlotte’s replies in real time.
We do not sell your data, and we do not use your calls, messages, recordings, transcripts, or CRM records to train AI models. Our AI providers process this content to serve your calls, not as training material for their models, and we engage them under agreements that restrict their use of the data to providing the service to us.
4. Call recording — and no voice biometrics
Every Charlotte call begins with a spoken disclosure: the caller is told they are speaking with an AI assistant and that the call is recorded, within the first seconds of the call. In the 13 US states that require all-party consent, state-appropriate disclosure variants apply automatically — see our Recording Disclosure for the state-by-state posture.
We do not create voiceprints and do not use voice biometrics to identify anyone. Voiceprint processing is disabled platform-wide by default and cannot be enabled for a business without an explicit recorded consent; no biometric identifiers are collected, stored, or processed in the default configuration. Our BIPA Notice covers Illinois specifically.
5. Who we share it with
We share personal data only with: (a) the business you called — your call recordings, transcripts, messages, and booking details are that business’s customer records, and its authorized users see them in the admin portal; (b) the service providers below, bound to process data only to provide their service to us; (c) authorities when legally required, and (d) a successor entity in a merger or acquisition, under this policy.
We do not sell personal information and do not share it for cross-context behavioral advertising. No mobile information — phone numbers, text opt-in data, or message content — is sold, rented, or shared with third parties or affiliates for marketing or promotional purposes.
| Provider | Role | Data it touches |
|---|---|---|
| Twilio | Phone calls, warm transfer, photo (MMS) intake, phone numbers | Call audio, caller phone numbers, texted photos |
| Telnyx | Text messaging (registered 10DLC traffic) | Phone numbers, message content, delivery status |
| Retell AI | Real-time voice-agent orchestration | Live call audio, transcripts |
| Deepgram | Speech recognition, voice-agent, speech synthesis | Live call audio, transcripts |
| Cartesia | Charlotte’s synthesized voice | Charlotte’s spoken replies |
| Anthropic | Language model (conversation reasoning; reading texted equipment photos) | Conversation context, transcripts, photo content |
| Neon | Primary database (PostgreSQL, US East) | Account, call, and booking records |
| Cloudflare R2 | Encrypted storage for call recordings and data exports | Encrypted recordings (ciphertext) |
| Amazon Web Services (KMS) | Encryption-key management (US East) | Encryption keys only, bound per business |
| Fly.io | Application hosting (US regions) | Data processed by the platform |
| Upstash | Redis cache (rate limiting, transfer session state) | Transient operational data |
| Inngest | Background-job orchestration (digests, retention jobs) | Job metadata |
| Clerk | Sign-in and account security | Operator emails, sessions |
| Stripe | Payments and subscriptions | Billing details (card data held by Stripe) |
| Resend | Transactional email (sign-in links, digests, notices) | Operator email addresses, digest content |
| Sentry | Error monitoring | Technical error context |
| Cal.com | Demo scheduling (only if you book a demo) | The name/email you provide |
| OpenWeather | Local weather for call triage | ZIP code only |
| PagerDuty / Slack | Internal operational alerting | Incident metadata |
We update this list when a provider is added or replaced; material changes are announced to operators in advance.
6. How long we keep it
| Data | Retention |
|---|---|
| Call recordings | 13 months by default; each business can configure 1–84 months (up to 7 years) |
| Transcripts | Up to 25 months |
| Call and booking metadata, audit trail | 7 years (regulatory audit horizon; audit entries carry no more personal data than needed) |
| Billing records | 7 years |
| Consent records | Life of the account plus the audit horizon (proof of consent) |
| Waitlist / pre-signup emails | Up to 12 months, then purged |
| Attribution cookies | 30 days |
| Deleted accounts | Personal data scrubbed on deletion, with a 30-day recovery window before final purge; encrypted backups age out within 90 days |
7. How we protect it
Call recordings are encrypted with a unique key per call (AES-256-GCM), and each key is itself encrypted by a master key in AWS KMS that is cryptographically bound to the individual business — a key wrapped for one business cannot decrypt another’s recordings, even by an administrator. Data moves over TLS. Tenant data is isolated with database row-level security and least-privilege access roles; inbound vendor webhooks are signature-verified; recording playback runs through short-lived (5-minute) access URLs; and every access to a recording is written to the audit trail. No system is perfectly secure, but we build so that a single failure does not expose your data.
8. Your choices and rights (operators)
You can access and update your account details in the admin portal, and you can ask us at any time to: export your data (a machine-readable archive of your records plus your call recordings), correct it, delete individual recordings, or delete your account entirely (immediate deactivation and scrub, final purge after the 30-day recovery window, except records we’re legally required to keep — see Section 6). Disconnect CRM integrations or revoke their credentials any time. Email hello@charlotte.ai; we verify the request against your account and respond within 45 days. We never discriminate for exercising privacy rights, and if we decline a request you can appeal by replying to our response.
9. If you called a business that uses Charlotte
The business you called decides how Charlotte handles its customer records — for your call recordings, transcripts, and booking details, that business is the data controller and we act on its instructions. To exercise privacy rights over those records (access, deletion, correction), the fastest path is the business itself; if you contact us at hello@charlotte.ai instead, we’ll route your request to the business and help fulfill it. For text messaging, reply STOP any time to stop texts (see the SMS Terms).
US state privacy rights. Depending on your state (for example California, Colorado, Connecticut, Texas, or Virginia), you may have rights to access, correct, delete, and port personal information, and to opt out of sales, sharing, or targeted advertising. We don’t sell or share personal information for advertising — including in response to Global Privacy Control signals, which we honor by default because there is no sale or share to opt out of. Requests: hello@charlotte.ai.
10. Where data lives, children, and changes
- Charlotte serves US businesses, and data is stored and processed in the United States.
- The service is not directed to anyone under 18, and we do not knowingly collect children’s personal information — if you believe a child’s data reached us, email hello@charlotte.ai and we will delete it.
- When this policy changes materially, we’ll update the date above and notify operators by email or in the product before the change takes effect.
11. Contact
Charlotte AI, Inc. · hello@charlotte.ai · charlotte.ai