Privacy Policy
CallShield helps adult children protect their parents from scam calls. This policy explains — in plain language — what we collect, how long we keep it, who processes it, and how you can ask us to delete it.
What CallShield does with call audio
CallShield uses Twilio Media Streams to forward live audio from an active call into our detection pipeline — the carrier forwards the stream to a live-transcription vendor that converts it to text, and an AI model provider then scores the transcript for scam patterns. Only text, never raw audio, is sent to that provider. The participant-facing disclosure described below runs first — no Media Stream or recording opens until the caller consents.
- Audio is streamed over Twilio's media channel while the call is in progress — it is processed in real time.
- Audio is processed only for the duration of the call. Raw audio is never written to disk and is not stored after the call ends.
- CallShield does not store raw audio recordings — only the text transcript and the AI analysis are kept, and only so the caregiver can review flagged calls later.
In-call disclosure before any recording or AI analysis
Every inbound call to a CallShield-protected line from a number that is not on the caregiver's trusted-contact list first hears a short recorded notice that the call may be recorded, transcribed in real time, and AI-scored for scam patterns. The caller is asked to press 1 to continue or 2 to end the call without any monitoring.
- No Media Stream or recording opens until the caller presses 1. Pressing 2 (or providing no input within the prompt window) ends the call without ever starting recording, transcription, or AI analysis.
- Trusted contacts — the family members and friends you have explicitly added — are bridged straight through to the protected line without hearing the disclosure and without being recorded.
- Refusing the disclosure does not prevent the protected person from completing the call. Bridged calls to the parent via trusted contacts never reach the disclosure path.
This is a product safeguard, not a legal determination. Recording, transcription, retention, and jurisdictional-scope compliance require attorney review of the specific jurisdictions in which the protected line and the caller operate, and is not a substitute for the consent rules of any particular state or country. The live-call disclosure feature does not by itself satisfy every wiretap, two-party-consent, or caller-notification rule that may apply.
Transcripts and caller-info retention
When a call ends, what remains is the text transcript, the caller phone number, and a brief AI-generated summary. Those records are written to the calls table for your account.
- Records are kept while your subscription is active.
- After cancellation, records are retained for 30 days, after which they are deleted on the next scheduled retention sweep.
- If you request deletion sooner, see "How to request deletion" below.
Who processes the calls
Call audio passes through a small chain of vetted service providers. Each one sees only what is necessary for its step, and nothing is shared with third parties for marketing.
Telephony carrier
Twilio carries the call and forwards a media stream to our pipeline. See Twilio's privacy policy for what Twilio itself logs.
Transcription provider
A live-transcription vendor converts the streamed audio into text. Audio is processed in real time and is not stored by the vendor after the call ends.
AI threat-detection provider
An AI model provider scores the running transcript for elder-scam patterns. Only text transcripts are sent to this provider — never raw audio.
Account-holder consent responsibilities
When you register a parent's phone line through CallShield, you affirm that you have the consent of the protected person (or their legal guardian) to monitor inbound calls on that line. CallShield is intended for use by family caregivers on phone lines they (or the protected person) own. You are responsible for keeping that consent current.
How to request deletion
You can ask us to delete your account data at any time. Send a request to [email protected] with the subject line Data deletion request. The team responds within 30 days and will purge the transcripts and caller records tied to your account in that window.
Records that have aged past the 30-day post-cancellation retention window are already deleted, but we will still confirm in writing.
Email addresses
CallShield collects email addresses from four places:
- Account signup — used to sign you in and send transactional account notifications (subscription receipts, cancellation confirmations).
- Lead capture ("Caregiver Guide") — used once to deliver the guide you requested.
- Family-notify form — used to alert a relative that a flagged call was captured on the protected line.
- Waitlist — used to send optional product updates. Every waitlist email includes an unsubscribe link.
CallShield does not sell, rent, or share email addresses with third parties for marketing.
Payments
Billing is handled by Stripe via Stripe Checkout and the Stripe Billing Portal. CallShield never sees or stores your full card number, CVC, or expiration date — Stripe handles card data directly and is responsible for PCI compliance. Please review Stripe's privacy policy for how card data is handled.
Changes to this policy
If we materially change this policy, we update the "Last updated" date at the top of this page and, where appropriate, notify account holders by email. Continued use of CallShield after a change is posted constitutes acceptance of the updated policy.
Questions? Email [email protected].