Privacy Policy
Last updated 14 September 2026
ColdWork provides AI phone receptionists to businesses. This policy explains what data we handle, why, where it goes, and how to get it removed. It covers both our business customers and the people who call them.
1. Who this policy is for
Our customers are businesses who use ColdWork to answer their phone. Callers are the members of the public who ring those businesses. We handle data belonging to both. Where a business uses ColdWork, that business is the controller of its callers’ data and ColdWork is its processor.
2. Google user data
ColdWork connects to a customer’s Google Calendar only after that customer explicitly grants access through Google’s own consent screen. We request exactly two scopes, and no others:
| Scope | What it lets us do | Why we need it |
|---|---|---|
calendar.freebusy |
See which periods are free or busy. It does not reveal event titles, guests, locations, or descriptions. | So the receptionist only offers times the business can actually take. |
calendar.events |
Create and update calendar events. | So the receptionist can book the appointment the caller asked for, and reschedule it. |
We do not request permission to read the contents of existing events, to delete calendars, or to share calendars with anyone.
How we use Google user data
- Free/busy periods are read when a call begins and while a caller is choosing a time. They are held in memory for the duration of that call and are not written to our database.
- When a caller books, we create one calendar event containing the caller’s name and phone number and the agreed time.
- We record our own copy of the appointment (time, caller name, caller phone number) so the business can see its bookings and so a repeated request does not create a duplicate.
How we store Google credentials
The tokens Google issues are encrypted at rest using AES-256-GCM before being written to our database. They are used solely to perform the two operations above on behalf of the customer who granted them.
Limited Use
ColdWork’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically: we do not sell Google user data, we do not use it for advertising, we do not use it to train generalised artificial intelligence or machine learning models, and we do not allow humans to read it except with the customer’s explicit permission, where required for security or to comply with the law, or where the data has been aggregated and made anonymous.
3. Call data
When someone calls a business that uses ColdWork, we process:
- the caller’s phone number and the number they dialled;
- audio of the call, which is converted to text so the receptionist can understand and respond;
- a written transcript of the conversation;
- any details the caller gives for a booking or message — typically their name, a callback number, and the reason for calling.
ColdWork transcribes what callers say. We do not create voiceprints, perform voice authentication, or identify callers by their vocal characteristics.
Callers are speaking to an automated system. Businesses using ColdWork are responsible for disclosing this and for any call-recording notice their jurisdiction requires.
4. Who we share data with
We do not sell data. We share it only with the service providers needed to operate the product:
| Provider | What they handle |
|---|---|
| Retell AI | Telephony and the real-time voice conversation, including speech-to-text, the language model that generates replies, and text-to-speech. |
| Calendar free/busy reads and appointment creation, for customers who have connected a calendar. | |
| n8n | Post-call automation, such as routing a message to the business. |
| Resend | Delivery of notification emails to the business. |
| Our hosting and database provider | Storage of the records described above. |
We may also disclose data where the law requires it.
5. How long we keep it
- Free/busy data — held only for the duration of a call, never stored.
- Transcripts and call records — retained for 12 months, then deleted.
- Messages and appointment records — retained for as long as the business remains a customer, and deleted within 30 days of the account closing.
- Google tokens — deleted immediately when a customer disconnects their calendar or closes their account.
6. Your choices
Disconnecting Google Calendar
A customer can revoke ColdWork’s access at any time from their Google Account permissions page, or by asking us. Revoking access stops all calendar reads and bookings immediately; the receptionist falls back to taking messages.
Access and deletion
Customers and callers can ask what we hold about them and ask us to delete it, by emailing privacy@coldwork.app. We respond within 30 days. Where a caller asks, we will pass the request to the business they called, since that business controls its own records.
7. Security
Google refresh tokens are encrypted at rest. Traffic between ColdWork and every provider above travels over TLS. Requests from our telephony and automation providers are authenticated before they are accepted. No system is perfectly secure, and we do not claim otherwise; if a breach affects your data we will tell you.
8. Children
ColdWork is sold to businesses and is not directed at children. We do not knowingly collect data from anyone under 13. A child may nonetheless call a business that uses ColdWork; such a call is treated exactly like any other and is subject to the retention periods above.
9. Where we operate
ColdWork is run from Illinois, United States, and data is processed in the United States. If you contact us from elsewhere, you are consenting to that transfer.
10. Changes
If we change this policy we will update the date at the top. Material changes to how we handle Google user data will be notified to affected customers by email before they take effect.
11. Contact
ColdWork — privacy@coldwork.app