Trust & Security at Ansora
How we protect your phone line, your business, and your callers — explained plainly.
Last updated July 5, 2026 · Ansora, Miami, FL
The short version
Handing your phone line to an AI receptionist is a real act of trust. Here is exactly how we earn it: your data is encrypted and access-controlled, you own everything and can export or delete it anytime, call recording is configurable and consent-aware, and every outside vendor we use operates under its own data protection agreement. No badge-spam, no vague promises — just concrete answers about who touches your data and how it stays safe.
01Our commitment to you
When you point your business phone at Ansora, you are trusting us with something that matters — the first voice a customer hears, and the details they share on that call. We do not take that lightly.
Ansora is built and run by two people in Miami, Florida: Juan Maciel, who builds and maintains the systems, and Justin Cerro, who runs sales and operations. We are a small, accountable team, and we would rather tell you the honest version of how something works than dress it up. This page is that honest version.
Everything below reflects how we actually operate today. Where something is still on our roadmap rather than finished, we say so. Where a decision is a policy rather than a promise about results, we say that too.
02How we protect your data
Protecting your data comes down to a few unglamorous things done consistently. We encrypt data both in transit and at rest — connections use HTTPS/TLS, and stored data is encrypted on the systems that hold it. That means information moving between a caller, the AI, and your dashboard is protected on the way, and protected once it lands.
Access is controlled by role. People on our team only get to the systems and data they actually need to do their job, and access to sensitive material like call recordings is limited to the staff who need it to build, tune, or support your account. Everyone on the team is bound by confidentiality.
Our marketing site is HTTPS-only with a strict content-security policy, and we use first-party, privacy-friendly analytics — no advertising pixels and no cross-site trackers following your visitors around the web.
- Encryption in transit (HTTPS/TLS) and at rest
- Role-based access — least privilege by default
- Recording access limited to staff who need it
- Staff bound by confidentiality
- No ad pixels or cross-site trackers on our site
03Two kinds of data — and who controls what
It helps to be clear about the two different kinds of data that flow through Ansora, because we play a different role for each.
The first is your business data — the account information you give us to set things up and get billed: your business details, your contact info, billing (your card is handled by Stripe, not stored by us), and legal fields like your EIN for service agreements. For this, Ansora is the party responsible for the data.
The second is your callers' data — the phone numbers, call audio and recordings, transcripts, AI-generated call summaries, and appointment details (caller name, phone, service requested) that come in when your customers call. This data belongs to your business. You are the controller of it; Ansora acts as your service provider (a processor) and only handles it to run the receptionist on your behalf and under your instructions. We do not treat your callers' information as ours to use for our own purposes.
In plain terms: the AI receptionist is our tool, but the customer relationships and the caller information it handles are yours.
- Your business/account data — Ansora is responsible (controller)
- Your callers' data — you are in control; Ansora is your processor
- We handle caller data only to run your receptionist, on your instructions
04Call recording, done right
Calls may be recorded, and we give you the tooling to do that the right way. At the start of a call there is a configurable spoken disclosure that can tell the caller the call is being recorded and that they are speaking with an AI assistant. You can configure it per your business and per state.
Because consent law varies, the disclosure defaults to on for two-party-consent states. This is personal for us — Ansora is a Florida company, and Florida is a two-party-consent state, so getting this right was part of the reason Ansora exists. A caller who stays on the line after hearing the disclosure is consenting to continue; a caller can ask not to be recorded or simply end the call.
If you would rather not record at all, recording can be turned off entirely. One honest note on responsibility: because your callers are your customers, you are the one responsible for making sure the legally required notices and consents are given — including call-recording notices and TCPA consent for any outbound texts or callbacks. Our job is to make that turnkey by giving you the disclosure tooling so it is handled automatically on every call.
- Configurable spoken disclosure: recording notice + AI-assistant notice
- Default-on for two-party-consent states, adjustable per state
- Can be turned off entirely
- You are responsible for required notices/consents; we make it turnkey
05Who else touches your data
Running a real-time AI receptionist takes a handful of specialized providers working together — for voice, telephony, transcription, language understanding, payments, and hosting. We call these subprocessors, and we believe you should be able to see the full list rather than take our word for it.
Each of these providers operates under its own terms and data processing agreement (DPA), and we use their business/API offerings. Where a provider supports it, we configure the service so that your content is not used to train their models. We phrase that carefully on purpose: we can control our own configuration, but we do not make absolute guarantees on another company's behalf.
The complete, current list of the providers we use and what each one does is published alongside this page so you always know exactly who is in the loop.
- Every subprocessor operates under its own terms and DPA
- Where supported, configured so your content isn't used to train their models
- The full, current subprocessor list is published for you to review
06Compliance & certifications — the honest version
We would rather under-claim than overstate here, because trust is the whole point.
SOC 2 Type II is on our roadmap and in progress — we are working toward it, and we will say we are certified only when we actually are, not before.
For healthcare clients — dental, medical, and med-spa practices — protected health information (PHI) is handled under a separate Business Associate Agreement (BAA), with PHI-redaction and short or zero-retention options available for sensitive situations.
Payment security is handled through Stripe, our payment processor. Card data is processed by Stripe and is not stored on Ansora's systems, which keeps the most sensitive part of billing with a provider built specifically for it.
- SOC 2 Type II: in progress / on our roadmap (not yet certified)
- HIPAA: BAAs available for healthcare, with PHI-redaction and short/zero-retention options
- PCI: card data handled by Stripe, never stored by Ansora
07Data retention & your ownership
You own your data. The caller information, transcripts, summaries, and appointments that flow through your receptionist are yours, and you can export them whenever you want.
Our defaults are set to sensible values that you can adjust. Call recordings are kept for about 90 days by default and are configurable, with a zero or short-retention option for sensitive verticals. Transcripts, summaries, and appointment data are kept while your account is active so your system keeps working and your history stays available.
If you ever leave, there is a clean exit. You can export your data, and Ansora deletes it within about 30 days of termination — unless we are legally required to keep something. Marketing and prospect data (for people who reach out through our site) is kept until the person asks us to delete it.
- You own your data and can export it anytime
- Call recordings: ~90 days by default, configurable; zero/short-retention option
- Transcripts, summaries, appointments: kept while your account is active
- On exit: export your data; we delete it within ~30 days unless legally required to keep it
08Your rights and your callers' rights
You can access, correct, delete, and take a portable copy of your data, and you can exercise those rights directly with us.
Your callers have rights too. Because your callers' data belongs to your business, they exercise their rights through you as the controller — and we assist you as your processor to make that straightforward. Under state privacy laws like California's CCPA/CPRA and similar laws in Virginia, Colorado, Connecticut, and Utah, one important point stands out: Ansora does not sell or rent personal information. There is no 'sale' or cross-context sharing of your data or your callers' data happening behind the scenes.
Our service is meant for businesses and is not directed to children under 13 or 16, and we do not knowingly collect their information.
- Access, correction, deletion, and portability
- You exercise rights directly; callers exercise theirs through you, with our help
- We do not sell or rent personal information
- Not directed to children; we don't knowingly collect their data
09Reach a real person or request documents
There is no ticket maze here. If you have a security or privacy question, want a copy of our data processing agreement, need a BAA for a healthcare practice, or want to make a data request, email us at hello@ansora.net and a real member of our team — one of the two people who actually build and run Ansora — will get back to you.
Available on request: our subprocessor list, data processing agreement (DPA), Business Associate Agreement (BAA) for eligible healthcare clients, and details on how to export or delete your data.
This page is written in plain English to explain how we handle security and data. It is not legal advice, and it is not a substitute for our formal agreements. For anything you intend to rely on, please review our full terms, privacy policy, and any DPA or BAA — and, if it matters to your business, have your own attorney review them too.
- Email hello@ansora.net to reach a real person
- Request our subprocessor list, DPA, or a healthcare BAA
- Ask us to export or delete your data anytime
Current subprocessors
These are the vendors that process data on our behalf to run the service. Each operates under its own data-processing terms. If we add or change one, we'll update this list and notify clients per our DPA.
| Provider | What they do | Data handled |
|---|---|---|
| Vapi vapi.ai | Real-time AI voice agent orchestration (runs the live phone conversation) | Call audio and transcripts while a call is in progress |
| Twilio twilio.com | Phone numbers, inbound/outbound telephony, and SMS text-backs | Caller phone numbers, call audio, and text messages |
| Deepgram deepgram.com | Speech-to-text transcription of calls | Call audio converted to text |
| OpenAI / large-language-model providers openai.com | Language understanding and AI-written call summaries | Call transcript text |
| Stripe stripe.com | Payment processing for your Ansora subscription | Your business billing details (card data is handled by Stripe, not stored by Ansora) |
| Supabase supabase.com | Database and authentication hosting for the platform | Account data plus caller, call, and appointment records |
| DigitalOcean digitalocean.com | Cloud infrastructure hosting (the servers Ansora runs on) | All platform data in transit and at rest on the hosting servers |
| Cal.com cal.com | Scheduling for booked consultations and demos | Name, email, and phone of people who book a time with Ansora |
| Resend resend.com | Transactional email (invites, receipts, notifications) | Email addresses and message contents we send |
| Google Workspace workspace.google.com | Ansora's internal team email and productivity | Internal communications; incidental client contact details |
Legal & trust documents
Privacy Policy →
What we collect, and how we handle your data and your callers'.
Terms of Service →
The terms of working with Ansora.
Data Processing Addendum →
How we process caller data as your service provider — signable on request.
AI Transparency →
How the AI works, and when callers are told they're speaking with it.
Service Level Agreement →
Our availability and support-response targets.
HIPAA & BAA →
For healthcare clients — PHI handling and a signable BAA.
Security overview →
Plain-English data handling, at a glance.
This document is written in plain English and isn't legal advice. Have it reviewed by an attorney before relying on it. Questions? Email hello@ansora.net.