Privacy Policy
Last updated 19 July 2026
BoltNum's product is, essentially, handling phone calls and voicemails on your behalf — so being clear about what we record, transcribe, and store isn't legal boilerplate, it's the product description. This page explains exactly what we collect and why. Questions: hello@boltnum.com.
1. What we collect
- Account details — your name, email address, and password (stored hashed, never in plain text).
- Business and greeting details — your business name, the greeting text you write, and the voice you choose.
- Your own phone number — the mobile or landline that call-through and outbound calls connect to.
- Call data — for each call to your BoltNum number: the caller's number, time, duration, and whether they pressed through or left a message. The same applies to outbound calls you place.
- Voicemail recordings and transcripts — recordings of up to 3 minutes, and the text transcripts generated from them.
- Extracted caller details — a caller's name, company, reason for calling, and callback number, pulled automatically from transcripts into your private contact book (more below).
- Payment status — subscription state from Stripe. Card details go directly to Stripe; we never receive them.
- Technical data — your IP address, used during signup to suggest UK or US numbers, and for rate limiting and security logs.
2. How voicemails are processed — the honest version
This is the part most privacy policies bury, so here it is up front. When someone leaves a voicemail on your BoltNum number:
- The caller hears your greeting, then the recording tone — so they know they're leaving a recorded message.
- The recording is captured by Twilio, our telephony provider, and stored by us.
- The audio is sent to OpenAI's Whisper API to produce the text transcript you receive by email.
- The transcript is then processed by an OpenAI language model to extract the caller's name, company, reason for calling, and callback number into your contact book. Anything you edit by hand is never overwritten by this process.
OpenAI processes this data as a service provider via its API, which by OpenAI's policy is not used to train its models. Transcripts and extracted details are automated and can contain mistakes; the original audio is always available in your inbox to check. Similarly, your written greeting text is sent to ElevenLabs to generate the greeting audio.
3. Callers' data
People who call your number aren't BoltNum customers, but we process their data — their number, their voice, what they say — so you can return their call. We process it only to deliver the service to you: we don't sell it, build marketing profiles from it, or use it for anything beyond showing it to you and sending it to you by email. You're responsible for using callers' details in line with the laws that apply to your business.
4. Who processes data for us
We use a small number of service providers, each doing one job:
| Provider | What they do | Where |
|---|---|---|
| Twilio | Telephony — provides your phone number, connects calls, and captures voicemail recordings. | US / Ireland |
| Stripe | Payments — handles your card details and subscription billing. We never see your card number. | US / Ireland |
| OpenAI | Transcription (Whisper) and caller-detail extraction from transcripts. API data is not used to train OpenAI's models. | US |
| ElevenLabs | Speech synthesis — turns your written greeting into audio. | US |
| Resend | Email delivery — voicemail notifications, welcome and fair-use emails, login emails. | US |
| Laravel Cloud (AWS) | Hosting — the application and database run in AWS eu-west-2 (London). | UK |
| Cloudflare | DNS and network security in front of the site. | Global edge |
| ip-api.com | IP geolocation during signup — your IP address is used once to suggest UK or US numbers. | US |
Where providers are outside the UK/EEA, transfers rely on the providers' standard safeguards (such as standard contractual clauses and, where applicable, the UK–US Data Bridge). We don't sell personal data to anyone, and there are no advertising or analytics trackers on this site.
5. Cookies
BoltNum sets only the essential cookies the application needs to work: a session cookie and a security (CSRF) token. Your light/dark theme preference is stored locally in your browser and never sent to us. No advertising cookies, no third-party analytics, no cookie banner theatre.
6. How long we keep things
- Voicemails, transcripts, and contacts stay in your account until you delete them or close your account.
- Closing your account deletes your recordings, transcripts, contact book, and greeting audio.
- Billing records are kept as long as tax and accounting law requires.
- Security logs (including IP addresses) are kept briefly for abuse prevention, then rotated.
7. Your rights
Under UK and EU data protection law you can ask for a copy of your data, ask us to correct or delete it, object to processing, and ask for it in a portable format. US state privacy laws give many customers similar rights. Email hello@boltnum.com and we'll handle it — most of it (deleting voicemails, editing contacts, closing your account) you can also just do yourself in the app. UK users can complain to the ICO, though we'd appreciate the chance to fix things first.
8. Security
All traffic is encrypted in transit (HTTPS), passwords are hashed, voicemail audio is served only to your authenticated account, and telephony webhooks are cryptographically verified so call data can't be spoofed into your inbox.
9. Changes and contact
If we change this policy in a way that matters — a new processor, a new use of data — we'll email you before it takes effect. For anything privacy-related: hello@boltnum.com.
See also our Terms of Service — billing, the 14-day money-back guarantee, fair use, and your number.