Your conversations are
your conversations.
Auricall handles call recordings, transcripts and customer messages — some of the most sensitive material a business holds. Here is how that data is separated, retained, and removed when you ask for it to be.
Every account is its own tenant.
Multi-tenancy is enforced at the data layer, not by hoping a filter was applied in the right place.
Tenant boundaries
Contacts, conversations, recordings, tasks and AI memory are scoped to your account and never cross into another.
Roles and permissions
Members are granted a role on invitation, controlling what they can see and change — including billing and number purchasing.
Device & session management
See where the account is signed in and revoke a device or session that should not be there.
Login detection
Unfamiliar sign-ins are detected and surfaced rather than passing silently.
Widget domain locking
Chat widget keys can be restricted to the domains you own, so a lifted key is useless elsewhere.
Payment separation
Card details are handled by Stripe. Auricall stores subscription state, not payment instruments.
Kept by default. Expired on request.
Out of the box nothing is deleted on a schedule — your conversations stay for the life of the account. Set a retention window and it becomes a real expiry date on the record: a nightly sweep clears whatever is due, and the derived AI material goes with the source rather than lingering in an index.
- No expiry at all unless you configure one
- An optional default retention window per account
- A separate, shorter window just for transcripts
- Applies to calls, chats and notes
- Nightly sweep expires anything due
- Indexed chunks removed with the source
- Relationship memory snapshots removed too
- Private assistant sessions deleted
- Interaction restricted, not silently emptied
What expiry removes, once you set one
Transcript text
RedactedChat message text
RedactedNote text
RedactedLinked task & commitment text
RedactedIndexed chunks
DeletedRelationship memory snapshot
DeletedPrivate assistant sessions
DeletedRecording audio
Recording policyRecording audio is governed by the recording storage policy rather than by relationship retention, because deletion has to be provable across both our storage and the telephony provider. We would rather say that plainly than imply a guarantee we cannot make.
Removing a person, properly.
When someone asks to be forgotten, the request has to reach the derived data as well as the original record. Anonymisation in Auricall does both.
Anonymise a contact
Redacts authoritative transcript, chat message and note text for that person in one operation.
Clears the AI index
Indexed chunks and the relationship memory snapshot are deleted, not just hidden from the UI.
Reaches linked records
Task, commitment and insight text derived from that person is redacted where applicable.
Export on request
Contacts, call history and conversation records can be exported before removal.
Where the line sits between us.
Auricall as processor
For calls, recordings, transcription, AI analysis, live chat and visitor messaging, Auricall acts as a data processor on your behalf. You are the controller for that material.
Auricall as controller
For your account, billing, support and security monitoring, Auricall is the controller. That processing is described in the privacy policy.
Telling your visitors
If you run the chat widget or record calls, informing the people on the other end — and collecting any consent required where you operate — remains your responsibility.
Need this in writing for procurement?
Security questionnaires, data processing agreements and retention specifics — talk to us and we will answer them properly.
No card required to explore · Cancel any time · UK & EU data handling