The short version. We collect your account details, the agents you build, the calls your agents handle, and the transcripts and recordings of those calls. We retain call recordings and transcripts for as long as your account is active — they are the record of your customer conversations, and we do not expire them on a timer. We don’t train AI models on any of it, and we don’t sell it. You can ask us to delete your data at any time, and we will. This summary is for orientation only; the policy below is what governs.
1. About this policy
This Privacy Policy explains how Kindred PM, Inc., doing business as Kindred Voice (“Kindred,” “we,” “us”), collects, uses, and shares information in connection with the Kindred Voice service, including our voice agent platform, the dashboard at app.kindredvoice.ai, and the evaluation experience at /try (together, the “Service”).
If you use Kindred under a signed agreement — an order form, a master services agreement, or a data processing agreement — that agreement governs where it conflicts with this policy.
Two kinds of people are described in this policy. If you are a Kindred customer, you give us information directly and this policy describes how we handle it. If you are a person who spoke with a Kindred customer’s voice agent — a caller — we process your information on that customer’s behalf and under their instructions. In that case the customer decides what is collected and how long it is kept, and your requests are best directed to them. §9 explains this in full.
2. Information we collect
2.1 Account information. When you sign up, we collect your email address and a password, which we store only as a cryptographic hash — we cannot see your password. If you sign in with Google, we receive your identity from Google rather than a password.
2.2 Content you create. The agent configurations you build, the knowledge and reference documents you upload, and any text you enter into the Service.
2.3 Calls, recordings, and transcripts. When your agent handles a telephone call, we process the call audio, we retain a recording of the call, and we generate and retain a text transcript. How this works, and how long we keep it, is explained in §3 and §7 — please read both.
2.4 Caller and contact information. To operate a voice agent we necessarily process information about the people it speaks with: telephone numbers, names, email addresses, message content, and whatever else is said during a conversation or recorded in a contact record.
2.5 Usage and device information. Log data generated when you use the Service, including IP address, pages viewed, timestamps, and actions taken. We use this to operate and secure the Service.
2.6 Agreement records. When you accept our Terms, we record your account identifier, the date and time, your IP address, and which version of the documents you accepted.
2.7 Communications. If you contact us or send feedback, we keep that correspondence.
3. How calls, recordings, and transcripts are handled
This section describes exactly what happens to a call. We have written it out in full rather than summarizing it, because a short version is easy to misread.
When your agent takes a call, the audio is carried by our telephony provider and processed in real time by us and by our third-party AI providers, so the agent can understand what is said and respond.
We retain the recording, and we retain the transcript. The call audio is stored with our telephony provider and referenced from your account. The transcript is stored in our database. Neither is deleted on a schedule. Both remain available until you or we delete the underlying record — see §7.
We want to be precise about this, because “the agent transcribes the call” is easy to read as “the audio is discarded once transcribed.” That is not the case. The recording persists alongside the transcript. If you need call audio to be discarded after transcription, tell us before you rely on the Service — it is not the default behavior.
Transcripts are ordinary text. They are more durable and more easily searched than an audio recording, and they are subject to the same protections and deletion rights as the rest of your information under this policy.
Recording notice is your responsibility. Some jurisdictions require that some or all parties to a call consent to its being recorded. You are responsible for configuring your agents to give whatever notice the law requires of you, and for obtaining consent where it is required. See our Terms of Service.
4. How we use information
We use the information described above to:
- Provide, operate, and maintain the Service;
- Run the agents you build, handle calls, and produce recordings and transcripts;
- Authenticate you and keep your account secure;
- Detect, investigate, and prevent fraud, abuse, and violations of our Terms;
- Diagnose problems, fix bugs, and improve reliability;
- Understand how the Service is used in aggregate;
- Respond to your questions and send you service-related messages;
- Send you marketing emails only if you separately opted in, and you can unsubscribe at any time;
- Comply with law and enforce our agreements.
We do not train AI models on your content
We do not use your content — including your recordings and transcripts — to train, fine-tune, or improve artificial intelligence models.
We have also configured our accounts with our third-party AI providers on service tiers under which those providers do not train their models on content submitted through our accounts.
We do not sell your information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under California law. We have not done so in the preceding twelve months.
5. Who we share information with
We share information only as described here.
5.1 AI providers. The Service sends call audio, transcripts, and text input to third-party artificial intelligence providers so they can be processed. As of the effective date these are:
- Google (Gemini — language, real-time voice, and speech synthesis)
- xAI (Grok — real-time voice, speech synthesis, and web search)
- Amazon Web Services (Bedrock / Nova Sonic, and Polly for speech synthesis)
As stated in §4, these providers are engaged on tiers under which they do not train on our content.
5.2 Telephony. Telnyx carries calls and messages, provisions telephone numbers, and stores call recordings.
5.3 Infrastructure and service providers. Vendors who provide the infrastructure the Service runs on and the tools we operate it with:
- MongoDB Atlas — primary data storage
- Microsoft Azure — application hosting and file storage
- Amazon Web Services and Google Cloud — supporting services and secret management
- Google Workspace — transactional email
- Moss — document indexing and semantic search over reference material you provide
They may process your information only on our instructions and only to provide services to us.
5.4 Integrations you enable. If you connect a third-party system — a CRM, a calendar, an email account — we exchange information with it at your direction. Your use of that system is governed by its own terms and privacy policy, not ours.
5.5 Legal. We may disclose information if we believe it is reasonably necessary to comply with a law, regulation, subpoena, or governmental request; to enforce our Terms; or to protect the rights, safety, or property of Kindred, our users, or the public.
5.6 Business transfers. If Kindred is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction. We will notify you of any such transfer and of any material change to this policy that results.
5.7 Changes to this list. We maintain the list in this section as our providers change. If we add a provider that processes customer content, we will update this policy and, for customers under a data processing agreement, give the notice that agreement requires.
6. Regulated information
Kindred is not acting as a HIPAA business associate, and the Service is not within the scope of PCI DSS. Do not configure agents to collect protected health information, payment card numbers, or financial account credentials, and do not upload them to the Service. If your use case requires handling protected health information, contact us before you deploy — it requires a business associate agreement we have not entered into with you.
This is a limit on what the Service is contracted to handle, not a claim that our security is inadequate. See §10 for the measures we do apply.
7. How long we keep information
We do not expire your conversation data on a timer. Recordings, transcripts, and contact records are the operating record of your business, and deleting them automatically would destroy the thing you are paying us to keep. They persist until you delete them, until your account is closed, or until you ask us to delete them.
| Information | Retention |
|---|---|
| Call recordings | Retained indefinitely while your account is active. Deleted when you delete the associated contact, when your account is closed, or on request |
| Transcripts and conversation history | Retained indefinitely while your account is active. Deleted on the same events as recordings |
| Contact records (names, numbers, email addresses, notes) | Until you delete them or your account is closed |
| Agent configurations and uploaded documents | Until you delete them or your account is closed |
| Account information | Until you close your account |
| Audit logs (including IP address) | 365 days, then deleted automatically |
| Application and system logs | 30 days |
| Scheduled-task execution history | 30 days, then deleted automatically |
| Unverified evaluation accounts (/try) | 48 hours, then deleted automatically with anything created in them |
| Agreement records (§2.6) | For as long as needed to evidence your acceptance |
| Backups | Deleted content may persist in encrypted backups for up to 12 months |
Deletion is immediate and permanent. When you delete a contact or we close your account, the records are removed from our live systems at once — there is no recycle bin and no recovery window. We delete the call recordings held by our telephony provider as part of the same operation. Export anything you need first.
Backups are the exception. Encrypted backup snapshots are retained on the schedule above and are not selectively edited. Deleted content may remain in them for up to twelve months before those snapshots age out.
We may retain information longer where required by law or to resolve a dispute.
8. Your rights and choices
8.1 Access, correction, and deletion. You may request a copy of the personal information we hold about you, ask us to correct it, or ask us to delete it. Contact us at the address in §13.
8.2 Delete your data yourself. You can delete contacts, conversations, and agents from the dashboard at any time. Deleting a contact deletes its conversation history and call recordings, subject to the backup period in §7.
8.3 Close your account. Contact us to close your account. We will delete your data as described in §7.
8.4 Marketing email. Marketing emails are sent only if you separately opted in. You can unsubscribe using the link in any such message. Service-related messages are not marketing and cannot be unsubscribed from while your account is open.
8.5 California residents. If you are a California resident, the CCPA as amended by the CPRA gives you the right to know what personal information we collect and how we use and disclose it; to request deletion; to request correction; to opt out of the sale or sharing of your personal information; and to limit the use of sensitive personal information. We do not sell or share personal information. We will not discriminate against you for exercising any of these rights. To make a request, contact us at §13. You may use an authorized agent; we will ask to verify their authority.
8.6 Other U.S. states. Residents of states with comprehensive privacy laws — including Virginia, Colorado, Connecticut, Utah, Texas, and Oregon — have comparable rights of access, correction, deletion, and portability, and may appeal a denied request. Contact us at §13 to exercise them or to appeal.
8.7 Canadian residents. If you are in Canada, PIPEDA gives you the right to access the personal information we hold about you and to challenge its accuracy. Contact us at §13.
8.8 How we verify. To protect your information we will verify your request, usually by confirming control of the email address on your account. We respond within the time required by law.
9. When we act for our customers
Much of the information the Service processes is not about our customers but about the people their agents speak with. For that information, our customer decides what is collected and why; we process it on their instructions. In the language of privacy law, the customer is the controller and Kindred is the processor.
If you spoke with an agent built on Kindred and want to know what was recorded, or want it deleted, the business you called holds that decision. Contact them. If you contact us instead, we will refer you to them, or pass your request along where we can identify the account.
Customers who need a data processing agreement should contact us at §13.
10. Security
We use technical and organizational measures to protect your information, including encryption in transit, encryption at rest for stored data, hashed passwords, role-based access controls, tenant isolation, audit logging, and secret management.
We maintain written information security, access control, change management, and incident response policies, and we review them periodically.
If we discover a breach of security affecting your personal information, we will notify you without undue delay and provide what we know about what happened, what was affected, and what we are doing about it.
No system is completely secure. If you discover a vulnerability, please report it to security@kindredvoice.ai.
11. Where the Service is available
The Service is offered to customers in the United States and Canada, and our systems are located in the United States. If you are in Canada, your information is transferred to and processed in the United States.
The Service is not directed to individuals in the European Economic Area, the United Kingdom, or Switzerland, and we do not offer it to them.
12. Children
The Service is not directed to anyone under 18, and we do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
13. Changes to this policy
We may update this policy. Each version is dated. If we make a material change, we will notify you by email or by notice in the Service before it takes effect.
14. Contact us
Kindred PM, Inc. d/b/a Kindred Voice
350 W 55th St, Unit 7C
New York, NY 10019
Privacy and data requests: privacy@kindredvoice.ai
Security reports: security@kindredvoice.ai
General: info@kindredvoice.ai