Legal

Privacy Policy

How we collect, use, and protect your data across the Chivox MCP platform. Each section opens with a plain-language summary; the detail below it is the authoritative version.

Updated August 14, 20262 min readChivox, Inc.
On this page

1. Scope

In short

What this policy covers — and what it leaves to third parties.

This Privacy Policy explains how Chivox, Inc. ("Chivox," "we") collects, uses, and shares personal data when you use the Chivox MCP developer console, websites, APIs, and support channels (the "Service"). It does not cover third-party sites you link to from the Service.

2. Data we collect

In short

The four buckets of data we handle: account, usage/billing, content you submit, and technical signals.

Account data: name, email, authentication identifiers, organization details, and preferences.

Usage and billing data: API call metadata, timestamps, project/key identifiers, available evaluation points, invoices, and payment references (processed by payment providers; we do not store full card numbers).

Content you submit: audio, text, or other inputs sent to evaluation endpoints, solely to provide the Service and as described below.

Technical data: IP address, device/browser type, logs, and security signals.

3. How we use data

In short

We use data to run and secure the Service — never to sell it or train models with evaluation content.

We use account, usage and billing, and technical data to provide and secure the Service, authenticate users, meter usage, process payments, send transactional and product communications, comply with law, and improve reliability (including aggregated analytics). Evaluation content is used solely to provide the Service.

We do not sell your personal data. No audio or other evaluation content is ever used for model training.

5. Sharing & processors

In short

We share only with vetted processors under contract, and disclose otherwise only when legally required.

We share data with infrastructure, analytics, email, identity (OAuth), and payment processors under data processing agreements. Examples include cloud hosting, PayPal/Stripe for billing, and email delivery providers.

We may disclose data if required by law, to protect rights and safety, or in connection with a merger or acquisition with appropriate safeguards.

6. International transfers

In short

Data may cross borders, protected by safeguards like Standard Contractual Clauses.

We may process data in the United States and other countries. Where required, we use Standard Contractual Clauses or equivalent mechanisms for transfers from the EEA/UK.

7. Retention

In short

Audio is dropped after scoring; only the resulting JSON is retained for 30 days.

We retain account and billing records while your account is active and for a reasonable period afterward for legal, tax, and dispute resolution purposes. Audio submitted for evaluation is processed, scored, and dropped. We retain the resulting JSON for 30 days (for debugging and your own dashboard) and nothing else. Customers on enterprise plans can provision a region-locked tenant (US · EU · SG).

8. Security

In short

We protect data with encryption and access controls — though no system is ever 100% secure.

We implement administrative, technical, and organizational measures appropriate to the risk, including TLS 1.3 in transit, hashed API keys at rest, access controls, and monitoring. No method of transmission or storage is 100% secure.

9. Your rights

In short

Access, correct, delete, or port your data — contact us, or your local regulator.

Depending on your location, you may have rights to access, correct, delete, restrict, or port your data, and to object to certain processing. GDPR and CCPA data-subject requests are handled within 10 business days; email bd@chivox.com. You may lodge a complaint with your local supervisory authority.

10. Children

In short

The Service isn’t for under-16s, and we don’t knowingly collect their data.

The Service is not directed to children under 16. We do not knowingly collect their personal data. Contact us to request deletion if you believe we have.

11. Changes

In short

Updates get a fresh “last updated” date and extra notice when required.

We may update this Policy. We will post the revised version with a new "Last updated" date and, where required, provide additional notice.

12. Contact

In short

How to reach us about privacy or your data rights.

Privacy inquiries and data-rights requests: bd@chivox.com. Data protection contact: Chivox, Inc., United States.

Questions about this document?

Reach our team and we’ll usually reply within two business days.

© 2026 Chivox, Inc. · Last updated August 14, 2026