Privacy Policy

Last updated 21 September 2026

Switch Automatic (Sole Proprietorship — MSME Registered, India) is the data fiduciary for the information described here. Questions or requests: [email protected].

1. What we collect

  • Account details — name, email, phone, business name, and which plan you chose.
  • Payment records — the transaction reference, amount and status from our payment gateway. We never see or store your card or UPI credentials.
  • What you build — agents, prompts, workflows, and the credentials you connect. Provider keys are encrypted and are never readable back out; only a four-character hint is ever shown, including to you.
  • Contacts you upload — the phone numbers and fields you import to call. You are responsible for having a lawful basis to hold them.
  • Call records — time, duration, outcome, cost, a transcript, and where enabled an audio recording. A recording contains the other person's voice, so treat it accordingly and tell them if the law where you are calling requires it.
  • Usage and audit — what was consumed, what it cost, and which admin action changed what. IP addresses in audit records are stored as a one-way hash, which is enough to rate-limit abuse and not enough to identify a person.
  • Site analytics — Google Analytics on this marketing site, for aggregate traffic. Not linked to a workspace.

2. Why we process it

  • To run the service you asked for — contract.
  • To bill accurately and keep an auditable record of it — contract and legal.
  • To prevent abuse: repeated free trials, disposable-address signups, and per-IP signup floods — legitimate interest.
  • To answer support requests — contract.

We do not sell personal data, do not share it for advertising, and do not use your content, transcripts or recordings to train any public model.

3. Where it lives

Our application, database and automation engine run on cloud servers we operate in India. Phone calls are carried by licensed telecom carriers and handled in real time by a managed voice platform (LiveKit Cloud), which does not keep the call audio. To understand and answer a caller we send that call’s audio or text to AI providers (speech recognition, language models and speech synthesis); they process it to give us the result for that call. Where we use a managed AI provider on your behalf, that is disclosed in-product and you can switch it off and use your own keys instead.

Sub-processors we rely on: a cloud host for compute and storage, a managed voice platform, AI providers for speech, language and voice models, a telecom carrier to place calls, a payment gateway, and an email provider for transactional mail. Some of them process data outside India.

4. How long we keep it

  • While your workspace is open — for as long as you keep it, unless you delete something sooner.
  • After you cancel — a short read-only window in which you can export everything, then the workspace and its contents, including recordings and transcripts, are deleted.
  • Anti-abuse record, 18 months. After deletion we keep a minimal record purely to stop the same free trial being taken over and over: a hash of the normalised email, a payment reference if one exists, a hash of the signup IP and a coarse device fingerprint, the trial dates and outcome, and a count of prior trials. We do not keep names, workflow content, prompts, recordings, transcripts, contact data or tokens. After 18 months it is purged. The rule it enforces is a limit, never a permanent ban — a returning customer can always pay.
  • Financial records — kept as long as tax and accounting law requires.

5. Your rights

You can ask us to give you a copy of your data, correct it, delete it, or explain what we hold. Export is self-serve in-product for workflows, contacts and call records. Write to [email protected] for anything else and we will respond within 30 days. If you are unhappy with the response, say so in the same thread before escalating — we would rather fix it.

If you resell to your own clients, their personal data is data you brought. You are their first point of contact for these rights, and we will help you action them.

6. Security

  • Encrypted in transit, and provider keys encrypted at rest.
  • One customer cannot read another. The separation is enforced by row-level rules in the database and again in the server layer, and read access and write access are tested separately.
  • Administrative actions are recorded with who did them and to what.
  • No system is perfect. If you find something, email [email protected] — we will thank you and we will not threaten you.

7. Cookies

This marketing site uses a Google Analytics cookie for aggregate traffic. The platform uses cookies that are strictly necessary to keep you signed in and to remember which workspace you are looking at. No advertising or cross-site tracking cookies.

8. Children

The service is for businesses. We do not knowingly collect data from anyone under 18.

9. Changes

A revised version will be posted here with a new date, and a material change will be notified in-product rather than relying on you re-reading this page.

Terms · Refunds · Back to home