Security & privacy
This page summarises how Call Helm protects your data. The full Privacy Policy and Terms of Service are the authoritative documents.
How your data is protected
- Encryption in transit. All traffic between your browser, Call Helm and our service providers uses HTTPS/TLS.
- Encryption at rest. Data is stored on infrastructure that encrypts it at rest. Especially sensitive fields — such as the tax ID you provide for 10DLC registration — are additionally encrypted by the application.
- Tenant isolation. Every organization's data is separated at the database layer with row-level security, so users can only ever read or change data belonging to their own organization. Live updates (new messages, call status) use private, organization-scoped channels.
- Role-based access. What each user can see and do is enforced on the server according to their role — see Agents, roles & permissions.
- Verified webhooks. Events from our telephony, payment and transcription providers are signature-verified before Call Helm acts on them.
- PII redaction in transcripts. Card numbers, bank details, government IDs, contact details and passwords are removed from call transcripts before they're stored or analysed.
- Monitoring. We use error and performance monitoring configured not to send personal identifiers.
Call Helm does not currently hold third-party security certifications (such as SOC 2). We describe our practices honestly rather than claiming certifications we don't have.
Sign-in security
- Sign in with email and password, or with Google or GitHub.
- Passwords must be at least 8 characters. Reset via Forgot your password? on the sign-in page.
- Two-factor authentication is not yet available.
Services we rely on (sub-processors)
| Provider | Purpose |
|---|---|
| Vercel | Application hosting |
| Supabase | Database, authentication and file storage |
| Telnyx | Voice calls, SMS/MMS, phone numbers and 10DLC registration (with The Campaign Registry) |
| Stripe | Subscription billing and payments |
| AssemblyAI | Call transcription and call analysis |
| OpenAI | AI script generation and message analysis |
| Resend | Transactional and notification email |
| Sentry | Error and performance monitoring |
Call recording and consent
Recording is off by default. When enabled, contacts hear an announcement before being connected. You are responsible for complying with recording and consent laws in your jurisdiction and your contacts'.
Data retention
- Account and billing records — kept for the life of your account, and financial records generally up to seven years.
- Customer data (contacts, calls, recordings, transcripts, messages) — kept for the life of your account. After termination it's available for export for 30 days, then deleted or de-identified.
- SMS opt-in/opt-out records — retained to demonstrate compliance.
- Logs and diagnostics — typically 30–90 days.
Your rights and requests
To request an export of your organization's data, deletion of your account, or to exercise privacy rights, email hello@callhelm.com. Self-service export and deletion are not yet available in the app.
Contact details for the business, including the postal address of the data controller, are in the Privacy Policy.