Privacy Policy
1. Who operates CallPilot
CallPilot is developed by Azores Labs ("we" or "us"). It connects a SIM card in a supported modem attached to your computer with the CallPilot mobile app and optional AI calling features. Questions can be sent to support@bondings.ai.
2. Data and storage locations
| Data | Where it is handled | Retention |
|---|---|---|
| SMS, call history, AI transcript, summary | Your Edge computer | Until you delete it or the configured local retention policy removes it |
| Call recording | Your Edge computer | Recording is off by default. When enabled, the default local retention period is 30 days |
| Mobile content cache | Your iPhone or Android device | Protected locally and cleared when you unpair, clear content, or authorization is revoked. iOS cache files are excluded from iCloud backup; Android stores encrypted content whose key is not exportable from Android Keystore |
| Device and routing metadata | Our Cloudflare-based control plane | Device identifiers, credential hashes, online state, opaque call/session state, and security audit events are retained as needed to operate and secure the beta service |
| iOS VoIP notification token | Encrypted in our control plane and used with Apple Push Notification service | Retained while the device remains paired; deleted when the device unpairs, is revoked, or Apple reports the token invalid |
| Media and requested content in transit | Cloud relay and LiveKit media infrastructure | Processed only to complete the live request; content is not written to our content database or application logs |
3. Cloud relay boundary
When the app displays an SMS or call record, the requested content travels from your Edge through our control plane to your phone over TLS. It is held in memory only while servicing that request and is discarded on completion, timeout, or authorization failure. The current content relay is not end-to-end encrypted at the application layer, so the relay process can briefly access plaintext while forwarding it.
Live voice is routed through LiveKit infrastructure. We do not enable cloud recording or egress for ordinary CallPilot calls. Infrastructure providers may process network information such as IP address and connection diagnostics to deliver and secure their services.
4. Microphone, AI, and third parties
- The mobile app uses the microphone only while you place, answer, or take over a call.
- AI calls use the model provider configured on your Edge, such as OpenAI or Alibaba Cloud Model Studio. Audio or text sent to that provider is governed by your account and the provider's terms.
- On iOS, Apple Push Notification service receives an opaque incoming-call notification containing no caller identity, phone number, message, transcript, or audio.
- We do not use advertising SDKs, sell personal data, build advertising profiles, or track you across apps and websites.
- CallPilot does not request your contacts or location.
5. Recording and AI disclosure
Recording is disabled by default. Laws governing call recording, automated calling, and synthetic voices vary by location. You are responsible for obtaining any required consent and for providing required disclosure that a participant is an AI. CallPilot is not an emergency calling service.
6. Your choices
- Clear cached messages and call details from Settings on the mobile device.
- Unpair a phone, which revokes its access and clears its protected local content cache.
- Revoke a lost device from the Edge. An offline device cannot be remotely erased; it clears protected content after reconnecting and receiving the revocation.
- Delete local call records from the Edge and disable recording or content synchronization.
- Request deletion of cloud device and audit metadata by contacting support.
7. Security and children
Credentials are stored in iOS Keychain or Android Keystore-backed encrypted storage. Connections use TLS, content access is separately authorized, and credentials can be revoked. No system is perfectly secure. CallPilot is intended for adults and is not directed to children under 16.
8. Changes
We will update this page and its effective date when our practices change. Material changes will be communicated in the app or release notes where appropriate.
隐私政策
1. 运营主体
CallPilot 由 Azores Labs 开发。产品把连接在电脑通信模组中的 SIM 与手机 App、可选 AI 通话能力连接起来。隐私问题请联系 support@bondings.ai。
2. 数据与存储位置
- 短信、通话记录、AI 转写与摘要保存在你的 Edge 电脑上,直至你删除或本地保留策略清理。
- 录音默认关闭;启用后只保存在 Edge,默认保留 30 天。
- 手机缓存受系统数据保护;解除配对、清除内容或授权撤销时删除。iOS 缓存文件排除 iCloud 备份;Android 内容以 Android Keystore 中不可导出的密钥加密。
- 云端保留运行与安全所需的设备标识、凭证哈希、在线状态、不透明会话状态与审计元数据,不保存内容正文。
- iOS VoIP 推送令牌加密保存在控制面,仅用于通过 Apple 推送服务唤醒系统来电界面;解除配对、撤销设备或 Apple 判定令牌失效时删除。
3. 云中转边界
手机读取短信或通话记录时,内容经 TLS 从 Edge 通过控制面转发,只在完成请求所需的时间内存于内存,完成、超时或鉴权失败即丢弃。当前内容链路尚未实现应用层端到端加密,中转进程在转发时会短暂接触明文。实时语音经 LiveKit 基础设施路由,普通通话不启用云录制。
4. 麦克风、AI 与第三方
- 手机 App 只在你拨打、接听或接管通话时使用麦克风。
- AI 通话使用你在 Edge 配置的模型服务商,例如 OpenAI 或阿里云百炼;发送给服务商的音频或文本受你的账号及服务商条款约束。
- iOS 的 Apple 推送服务只接收不透明来电通知,不包含来电人身份、电话号码、短信、转写或音频。
- 我们不接入广告 SDK,不出售个人数据,不跨 App 跟踪,不请求通讯录或位置权限。
5. 录音与 AI 披露
录音默认关闭。不同地区对通话录音、自动拨号与合成语音有不同规定;你负责取得必要同意并依法披露 AI 身份。CallPilot 不能用于紧急呼叫。
6. 你的选择
- 在手机设置中清除短信和通话详情缓存或解除配对。
- 在 Edge 撤销遗失设备。离线设备无法远程抹除,再次联网并收到授权失效后才会清除受保护缓存。
- 在 Edge 删除本地通话记录,关闭录音或内容同步。
- 联系支持请求删除云端设备与审计元数据。
7. 安全、未成年人及变更
凭证存放在 iOS Keychain 或 Android Keystore 支持的加密存储中;连接使用 TLS,内容读取需独立授权,凭证可撤销。本产品面向成年人,不面向 16 岁以下未成年人。实践发生变化时,我们会更新本页及生效日期。