Privacy Policy
Last updated: August 8, 2026
Draft — pending legal review
This document describes how the service actually works, but it has not yet been reviewed by counsel. Do not rely on it as a final agreement.
The short version
We are a phone company. To connect your calls we necessarily process who called whom, when, and for how long. We store call audio only when you switch recording on or a caller leaves voicemail. We do not sell your data, we do not use your calls or recordings to train anything, and we do not run advertising or third-party analytics trackers on your account.
What we hold, and where
Account and configuration
Postgres (Neon)Your organisation name, billing contact, users, extensions, phone numbers, dial plans and voicemail settings.
Call detail records
Postgres (Neon)For each call: the numbers involved, direction, start and end time, duration, disposition and rated cost. CDRs are how we bill you and how your usage reports are produced.
Live call and registration state
Redis (Upstash)Which devices are currently registered, which calls are in progress, and presence status. This is transient operational state, not history.
Call recordings and voicemail
Object storage (Cloudflare R2)Audio is stored only when you enable a recording policy for a tenant, extension or trunk, and whenever a caller leaves voicemail. Recordings are stereo — each party on their own channel.
E911 registered addresses
Postgres (Neon)The physical address associated with each extension, required so emergency services can be dispatched. Emergency calls are logged separately from ordinary CDRs.
Call recording
Recording is off unless you turn it on. When you do, you become responsible for complying with the recording laws that apply to you and to the people you call. Many jurisdictions require the consent of one or every party on the call. We provide the capability; the legal obligation to announce or obtain consent is yours.
You can delete recordings through the dashboard. Deletion removes the object from storage; backups are cycled out on our ordinary backup schedule.
Emergency calls and E911
If you register an address for an extension, we share it with emergency services and the routing providers who deliver 911 traffic when a call is placed to emergency services from that extension. This sharing is required for the service to work and cannot be switched off while the extension is enabled for emergency calling. Emergency calls are recorded in a separate log from your ordinary call records.
Who else processes your data
We use the following subprocessors. Each one only receives what it needs to do its job.
- Neon Managed Postgres — account data, CDRs, configuration
- Upstash Managed Redis — live registration and call state
- Cloudflare R2 object storage for recordings and voicemail; CDN and DNS
- DigitalOcean Compute hosting for the SIP proxy, media relay and API
- Carrier partners Origination and termination of calls to the public network
- Apple APNs / Google FCM Push notifications to wake mobile apps for incoming calls
Your rights
You can ask us for a copy of the personal data we hold about you, ask us to correct it, or ask us to delete it. Some records we must keep — call detail records underpin billing and are subject to retention obligations that apply to telecoms providers, so we cannot always delete them on request.
Write to privacy@ariaroute.com and we will respond within 30 days.
Changes
If we change how we handle your data in a way that materially affects you, we will tell you before the change takes effect rather than quietly updating this page.