Twring Privacy Notice (draft)
This draft describes what the software does; have it reviewed before it becomes a legal policy.
Operator: Gowrishankar Sivasankaran
Contact: support@saasage.in
Effective: 1 August 2026
Twring is a voice layer for an AI agent you already use. You connect your agent, press Call, and talk to it. Twring handles the audio; your agent does the thinking.
1. What Twring processes during a call
| Data | Where it goes | Kept? |
|---|---|---|
| Your voice (call audio) | Streamed through LiveKit to Deepgram for speech-to-text | Never stored by Twring (ADR-008) |
| Text of what you say | Sent to your own agent (the endpoint you connected) | Not kept by Twring; your agent's own policy applies |
| Your agent's replies (text) | Streamed to the speech provider to become audio | Not kept by Twring |
| Reply audio | Streamed back to your phone | Not kept |
Speech providers: Deepgram (speech-to-text and text-to-speech). Some deployments may use Cartesia for text-to-speech instead; if so, it receives only the reply text. LiveKit carries the real-time audio between your phone and the Twring server.
2. What Twring stores
- Your account: you sign in with Google. Twring's sign-in service, Supabase (Supabase Auth), keeps your email address, your Google account id, and the name and profile picture link Google shares, plus sign-in times. Twring never sees your Google password. Your agents and call summaries are tied to this account so only you can reach them.
- Agent settings: name, endpoint address, protocol, chosen voice, and the words to listen for.
- Agent credential (API key): encrypted with AES-256-GCM on the Twring server. It is never shown again, never logged, and decrypted only in the server process when a call or connection test connects to your agent.
- Call summaries: agent, start time, duration, outcome, end reason, and usage counts (seconds of speech, characters spoken, interruptions, reconnects, an optional cost estimate). No audio, no transcript. Only your most recent 200 calls are kept.
- Ringing (when an agent rings you): each phone's push token (from Firebase Cloud Messaging), platform, and app variant, so Twring can make it ring; your Do Not Disturb and quiet-hours settings; and each ring's reason, agent, time, and outcome (answered, declined with your short note, missed, or cancelled). A missed ring also appears in your call summaries.
- Linked computers (agents on your computer): each linked computer's name (as it reports it, e.g. its hostname), the agents it found (such as Claude Code or Codex), whether it is online, and a hashed connection token. Remove a computer in the app to delete these.
- Daily usage counters: how many calls you started and how many seconds you called today (UTC), to apply the daily calling allowance. Kept for two days at most.
- Operational logs: request and call events with ids and error codes, with credentials, tokens, and URL query strings redacted. Crash reports (Sentry) carry the same redacted information: no transcripts, no tokens, no email addresses, and your user id only in hashed form.
The camera is used only to scan the code your computer shows when you link it. The picture is read on your phone and never stored or sent anywhere; only the code it contains is sent, to link the computer.
Twring does not sell data, show ads, or use your calls to train models.
3. Retention
| Data | Retention |
|---|---|
| Call audio, transcripts | Not retained |
| Account (email, Google profile) | Until you ask us to delete your account |
| Agent settings and encrypted key | Until you delete the agent or your data |
| Call summaries | Last 200 calls per user, or until you delete your data |
| Daily usage counters | Two days |
| Push tokens, ring settings | Until you remove the phone (sign out) or delete your data |
| Ring history | One day for the ring itself; a missed ring stays with your call summaries |
| Server logs and crash reports | 30 days |
4. Deletion
- Delete an agent (agent screen → Delete agent): removes its settings and key at once, and ends any call using it.
- Delete my data (Settings → Delete my data): removes all your agents, keys, call summaries, push tokens, ring settings, and rings, and ends any call in progress. The app shows what was deleted.
- Delete account (Settings → Delete account): removes all of the above and your sign-in account (email and Google profile at Supabase), then signs you out. Signing out alone (Settings → Sign out) removes the session from your phone but keeps the account.
- Without the app: the account deletion page (
/account-deletionon the Twring server) explains how to ask by email; write to support@saasage.in from the address you sign in with. We delete within 30 days and reply to confirm.
5. Security
TLS for every connection; agent endpoints must be public https:// or wss:// addresses; server-side SSRF protection; encrypted credentials; short-lived call tokens; rate limits.
6. Children
Twring is not directed at children under 13 (or the minimum age in your country).
7. Changes
We will update this notice and its effective date when data handling changes.
Google Play Data safety answers
| Data type (Play category) | Collected | Shared | Purpose | Optional | Notes |
|---|---|---|---|---|---|
| Audio → Voice or sound recordings | Yes (processed in transit, not stored) | Yes: Deepgram, LiveKit as service providers | App functionality | Required to make a call | Ephemeral processing only |
| Personal info → Email address | Yes | Supabase as service provider (sign-in) | App functionality, account management | No (sign-in is required) | From Google sign-in |
| Personal info → Name | Yes | Supabase as service provider (sign-in) | Account management | No | Google profile name |
| Personal info → User IDs | Yes | Supabase as service provider (sign-in) | App functionality, account management | No | Google account id and Twring user id |
| Personal info → Other (agent name, endpoint address) | Yes | No | App functionality | Yes | User-entered |
| App activity → Other user-generated content (text of speech, sent to user's agent) | Yes (in transit) | Sent to the user's own chosen agent at the user's direction | App functionality | Required for calls | Not stored by Twring |
| App activity → App interactions (call summaries) | Yes | No | App functionality, analytics (usage counts) | No | Last 200 calls |
| App info and performance → Crash logs, Diagnostics | Yes | Sentry as service provider | App functionality | No | Redacted |
| Other: credentials (agent API key) | Yes | No | App functionality | Yes | Encrypted at rest |
| Location, contacts, financial, health, photos, files | No | — | — | — | — |
- Data encrypted in transit: Yes.
- Users can request that data be deleted: Yes (in app: Settings → Delete my data or Delete account; on the web:
/account-deletion; or support@saasage.in). - Independent security review: No (as of this draft).
- Account: Yes, Google sign-in through Supabase Auth (ADR-021). Account deletion: in the app (Settings → Delete account) and on the web (
/account-deletion).