← Back to Turtle
Privacy Policy
Effective date: April 5, 2026 · Last updated: April 6, 2026
KafkaLabs Inc. ("KafkaLabs," "we," "us," or "our") operates Turtle, a voice-based AI assistant accessible via a dedicated phone number. This Privacy Policy explains how we collect, use, store, share, and protect information when you use Turtle or visit our website at kafkalabs.com (collectively, the "Service").
By using the Service you agree to the practices described in this policy. If you do not agree, please do not use the Service.
1. Information We Collect
1.1 Information You Provide
- Account information: When you sign up, we collect your name, email address, and authentication credentials (managed through Firebase Authentication).
- Phone number: We provision a dedicated US phone number for your account through our telephony partner, Telnyx.
- Voice interactions: When you call your Turtle number, your speech is converted to text by our telephony provider's speech-to-text system. The resulting text transcripts are processed by our AI to generate responses.
- Agent configuration: Any preferences you set for your AI assistant, such as name, personality, voice selection, and personal context you provide.
- Payment information: If you subscribe to a paid plan, payment processing is handled by our third-party payment processor. We do not store your full credit card number on our servers.
1.2 Information Collected Automatically
- Call metadata: Date, time, duration, and frequency of calls placed to your Turtle number.
- Usage data: Features used, interactions with the AI assistant, and general usage patterns.
- Device and network information: Phone carrier information transmitted as part of standard telephony signaling. When you visit our website, we may collect IP address, browser type, operating system, and referring URL.
- Cookies and similar technologies: Our website uses essential cookies for authentication and session management. We also use analytics services (Google Analytics, OpenPanel, and PostHog) that may set cookies or use similar technologies to collect information about how you use our website, including pages visited, interactions, and referral sources.
1.3 Information from Third Parties
- Telephony provider (Telnyx): Call routing data, transcription of speech, and telephony metadata.
- Voice processing provider (Twilio): Call handling, speech-to-text transcription, and text-to-speech synthesis.
- Authentication provider (Firebase): Account authentication status and identifiers.
- Connected services (Google, Slack, Microsoft): Data accessed with your authorization via OAuth, including emails, calendar events, and messages.
- Analytics providers (Google Analytics, OpenPanel, PostHog): Aggregated usage and browsing data collected through our website to help us understand how users interact with the Service.
2. How We Use Your Information
We use the information we collect for the following purposes:
- Provide and operate the Service: Process your voice queries, generate AI responses, manage your account, and provision your phone number.
- Persistent memory: Your AI assistant stores conversation context and information you share across calls so that it can remember your preferences, follow up on prior conversations, and become more useful over time. This memory is stored in your isolated agent container.
- Improve the Service: Analyze usage patterns to fix bugs, improve AI response quality, and develop new features.
- Communication: Send you account-related notifications, service updates, and respond to your support inquiries.
- Security and fraud prevention: Detect and prevent unauthorized access, abuse, or fraudulent activity.
- Legal compliance: Comply with applicable laws, regulations, and legal processes.
3. AI Processing and Large Language Models
Turtle uses third-party large language model (LLM) APIs, including those provided by Anthropic and OpenAI, to process your queries and generate responses. When you interact with your AI assistant:
- Voice calls are processed through Twilio for speech-to-text and text-to-speech conversion. Your voice audio is transmitted to Twilio for real-time processing during calls.
- Your transcribed speech is sent to LLM providers as part of API requests to generate responses.
- We do not permit LLM providers to use your data to train their models. Our API agreements with these providers include data processing terms that prohibit training on customer inputs.
- Conversation context and memory are managed within your isolated Docker container on our infrastructure, not stored by LLM providers beyond what is necessary to process each request.
4. Data Storage and Security
- Isolation: Each user's AI assistant runs in a separate, isolated Docker container. Your conversation data, memory, and agent configuration are not accessible to other users.
- Infrastructure: Our servers are hosted on Amazon Web Services (AWS) in the United States. Data is stored on encrypted volumes.
- Access controls: We implement role-based access controls, SSH key authentication, and automated security updates on our infrastructure.
- Encryption: All web traffic is encrypted with TLS. All API communications between services use HTTPS.
- Retention: We retain your account data and conversation memory for as long as your account is active. If you delete your account, we will delete your data, including your agent container and all stored memory, within 30 days, except where retention is required by law.
5. How We Share Your Information
We do not sell your personal information. We share data only in the following limited circumstances:
- Service providers: We share data with third-party providers that help us operate the Service, including Telnyx (telephony and speech-to-text), Twilio (voice processing, speech-to-text, and text-to-speech), AWS (hosting), Anthropic and OpenAI (AI model inference), and Firebase (authentication). These providers are contractually obligated to use your data only to provide services to us.
- Connected third-party services (Google, Slack, Microsoft): When you explicitly connect these services via OAuth through your dashboard and direct your AI assistant to take actions, data is shared with these services on your behalf. For example, your assistant may read or send emails via Gmail, manage events via Google Calendar, send messages via Slack, or interact with Microsoft 365 services. Data is shared with these services only at your direction.
- Analytics providers: We use Google Analytics, OpenPanel, and PostHog to collect aggregated usage data about how visitors interact with our website. These providers may collect information such as pages visited, session duration, and general location data. This data is used solely to improve our website and Service.
- Legal requirements: We may disclose your information if required by law, subpoena, court order, or government request, or if we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.
- Business transfers: If KafkaLabs is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you before your data becomes subject to a different privacy policy.
- With your consent: We may share information with third parties when you explicitly direct us to do so.
6. Your Rights and Choices
Depending on your jurisdiction, you may have the following rights:
- Access: Request a copy of the personal information we hold about you.
- Correction: Request correction of inaccurate personal information.
- Deletion: Request deletion of your personal information and account, including all conversation memory and agent data.
- Data portability: Request a machine-readable export of your data.
- Opt out of communications: Unsubscribe from marketing emails at any time using the link in any email we send.
- Agent memory: You can clear your AI assistant's memory at any time through the Turtle dashboard or by asking your assistant to forget specific information.
To exercise any of these rights, contact us at nikhil.kapu@kafkalabs.com. We will respond within 30 days.
7. Children's Privacy
Turtle is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected data from a child under 18, we will promptly delete it. If you believe a child has provided us with personal information, please contact us at nikhil.kapu@kafkalabs.com.
8. International Data Transfers
Our Service is operated from the United States. If you access the Service from outside the United States, your information will be transferred to, stored, and processed in the United States. By using the Service, you consent to this transfer. We take reasonable steps to ensure your data is treated securely and in accordance with this Privacy Policy.
9. Third-Party Links
The Service may contain links to third-party websites or services not operated by us. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies.
10. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by posting a prominent notice on our website at least 30 days before the changes take effect. Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated policy.
11. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us: