Privacy
Last updated 1 August 2026
TyrrexAgent answers phone calls for businesses. That means we handle recordings of conversations between our customers and their customers, which is about as sensitive as business data gets. This page describes what actually happens to it.
Who is who
Tyrrex Tech Labs operates TyrrexAgent. A business that signs up is a customer. The people who ring their phone number are callers.
For caller data we are a processor: our customer decides why a call happens and what the agent is told, and we act on their instructions. For customer account data — an email address, a workspace — we are the controller.
What we collect
- Account details.Email address, and a password hash if one is set. Signing in with Google or GitHub gives us the email address and the provider’s account identifier, nothing more — we never receive a password.
- What a customer configures. Agent instructions, the documents uploaded as knowledge, phone numbers, and SIP credentials.
- Call data. A transcript of what was said, how long the call lasted, which language was detected, and which actions the agent took.
What we do not keep
Call audio is not stored. Speech is converted to text as the call runs and the audio is discarded. There is no recording to request, subpoena, or lose.
Card numbers and similar identifiers are removed before a transcript is written. If a caller reads out a card number, an Aadhaar number, a PAN, or an email address, it is replaced before anything reaches storage. The agent still hears it during the call, because it has to; nothing is kept afterwards.
Zero retention is available.A customer can turn it on for a workspace, after which we record that a call happened and how long it lasted, and nothing about what was said. This is enforced when the record is written, not by deleting it later — “stored then deleted” is a different promise, and only one of them survives a question from a regulator.
Where it is kept
On servers in India. Each customer’s knowledge base and call history live in a separate database file, so a fault in one query cannot reach another customer’s data — it is not in the file.
SIP passwords and API keys are stored outside the main database, in per-customer files readable only by the account the software runs as, and are never returned by any part of the interface once saved.
Who else sees it
As few parties as we can manage. Speech recognition, language understanding, and speech synthesis all run on our own servers, so the contents of a call are not sent to a third-party AI provider.
The exceptions, and only these:
- The customer’s own telephony provider — Twilio, Vobiz, or whoever they hold their number with. They carry the call and see it as they would any other.
- Endpoints the customer points us at. If they configure a tool that looks up an order, we send that tool whatever it needs. That is their integration and their choice.
- Google or GitHub, only if a customer chooses to sign in with them, and only to confirm who they are.
We do not sell data. There is no advertising on this product.
How long
Account data lasts as long as the account. Call transcripts and analysis are kept until deleted, and a customer can delete an agent — which removes its knowledge base too, unless another agent is using it.
We keep an audit record of what agents did, which cannot be edited entry by entry. That is deliberate: a log that can be quietly amended is not evidence, and the whole point of it is answering “what did the agent tell my customer?”
Rights
Under India’s Digital Personal Data Protection Act 2023, and equivalent laws elsewhere, a person may ask what we hold about them, ask for it to be corrected, and ask for it to be erased.
If you are a caller rather than one of our customers, the business you rang holds the relationship and the record. Contact them first; we will help them respond.
Breaches
If data is exposed, we will tell affected customers what happened, what was involved, and what we are doing — without waiting until we have a complete picture, because a late complete answer is worse than a prompt partial one.
Voice is biometric data — and we hold none of it
A recording of somebody’s voice can identify them, which makes it biometric data under India’s DPDP Act and under European law. Products that build voice models keep that data for years and have to say so.
We do not build voice models and we do not keep audio. The agent speaks in a prebuilt synthetic voice that belongs to no particular person, and a caller’s speech exists only as text once the sentence is over. There is no voiceprint of any caller, anywhere in this system.
We do not train on your data
Nothing a customer uploads, and nothing a caller says, is used to train or improve any model. This is not a setting you have to find and switch off — the models run on our servers, unchanged, and there is no pipeline that would carry your data into one.
We may look at aggregate numbers — how many calls, how long, which languages — to know whether the product works. That does not involve reading transcripts.
Cookies
One cookie, for staying signed in. It is HttpOnly, so page scripts cannot read it, and it holds a random token rather than anything about you.
There is no analytics, no advertising, and no third-party tracking on this product. There is no cookie banner because there is nothing to consent to.
Where data goes
Servers in India. We do not transfer personal data outside the country in the normal course of running the service.
The exception is one a customer chooses: if they connect a tool that calls an endpoint hosted elsewhere, or hold their phone number with a provider abroad, data travels there because they configured it to. The sub-processor list names everyone else involved.
Children
TyrrexAgent is a business product and is not for anyone under 18. We do not knowingly create accounts for children.
Callers are a different matter — a child may ring a shop, and we cannot tell. That is one more reason no audio is kept and identifiers are stripped from transcripts.
Security
Passwords are hashed with scrypt. Session tokens are stored only as hashes, so reading the database yields nothing you could sign in with. Each customer’s data sits in its own file rather than behind a filter on a shared table.
We hold no security certification. SOC 2 and ISO 27001 are audits we have not undertaken, and claiming otherwise would be the easiest lie on this page to tell.
Grievances
Under the DPDP Act you may raise a grievance with us before approaching the Data Protection Board. Write to [email protected] and we will respond within thirty days.
You may also nominate somebody to exercise your rights on your behalf if you are unable to.
Changes
We will update this page as the product changes and note the date at the top. If a change materially affects how your data is handled, we will email the address on your account rather than leave you to notice.
Contact
Questions about either document go to [email protected].