Skip to main content
Home How It Works Pricing Case Studies Calculator Blog Book a Call

Privacy Policy

How we handle your data — on this website, and on calls answered by the voice agents we run for client businesses. Written in plain language.

Effective date: August 3, 2026

Who we are

LinearZeta LLC is a Massachusetts limited liability company that builds and runs conversational AI voice agents for local service businesses. Based in Worcester, Massachusetts. You can reach us about anything in this policy at hello@linearzeta.com.

This policy covers three different situations: visiting this website, calling a business whose phone is answered by a voice agent we run, and being a LinearZeta client. They work differently, so we explain them separately.

1. If you visit this website

What we collect

  • What you send us — only if you fill in the contact form: your name, email, and the business name, phone number, and message you choose to include.
  • Nothing from the calculator — the missed-call calculator runs entirely in your browser. It asks for no email, sends us no figures, and stores nothing on your device.
  • Where you came from — if you arrive via a link with campaign tags (UTM parameters), we keep the first set in your browser's session storage. It is deleted when you close the tab and is only sent to us if you submit the contact form.
  • Anonymous analytics — we use Cloudflare Web Analytics, which is cookieless. It does not track you across sites, fingerprint your device, or build a profile of you.

What we do with it

  • Your contact details, your message, and any campaign tags are kept as a single lead record in our lead system, and emailed to us so we can reply. We use them to answer you — not to add you to a mailing list.
  • If you book a free call audit, scheduling is handled by our scheduling provider under its own privacy policy.

What we never do

  • We do not sell or rent your data to anyone.
  • We do not run advertising trackers or third-party ad cookies on this site.
  • We do not email you unless you asked us to.

2. If you call a business that uses our voice agent

When you call a business whose phone is answered by a LinearZeta voice agent, we process your call on that business's behalf. The business decides why your data is collected; we handle it for them under this policy and our agreement with them.

You're told up front

Every call begins with a disclosure that you are speaking with an AI assistant and that the call is recorded. That disclosure is the first thing the agent says, on every call, without exception. If you'd rather not continue, you can ask for a person and the agent will transfer you.

What is collected on a call

  • The call itself — audio and a transcript, processed through Twilio (telephony) and ElevenLabs (conversational AI), and retained for the business you called.
  • What you tell the agent — typically your name, a callback number, and what you need (for example, an appointment request). The agent collects the minimum needed to handle your call.
  • Booking details — if you book an appointment, your name, contact details, and requested time are passed to the business's own scheduling system so the appointment actually exists in their calendar.

Where your contact details are kept, in plain terms

If the agent takes a message for you, books you an appointment, or takes a pickup order, then your name and callback number are stored in readable form — because a business that can't read the number can't return your call. We'd rather say that plainly than imply otherwise.

  • Those records are held for a limited period — 90 days by default — and then automatically removed.
  • They are readable only by the business you called and by our staff when we're supporting that business.
  • They are deleted when you ask us to forget you (see below), along with your caller record — and in any case they are removed automatically within the 90-day window above.
  • No card or payment details are ever taken on a call, so none are stored. Pickup orders are paid in person.
  • The moment-to-moment performance data we keep — whether a booking attempt succeeded, how long it took — contains nothing about you at all: no name, no number, not even a hashed one.
  • We also keep a longer-term booking record of when bookings happened, so a business can see things like how many first-time customers it had last month. It holds no name, no email, and no readable number — only a one-way hash of your number (a scrambled code that can't be turned back into it), and it is deleted whenever you ask us to forget you. Because that code is always the same for your number, we can still tell it's you, just not your name or number — so we don't call it anonymous, and we keep it indefinitely rather than for 90 days, because a first-time-customer count only means something measured over time.

This is the one place we deliberately keep something readable. Everywhere else — the longer-term booking record above, and the returning-caller record described below — your number is a one-way hash and cannot be read back.

Returning-caller recognition

  • So the agent can say "welcome back" and avoid re-asking for details you've already given, we keep a small caller record (name, email if you provided it, preferences, last visit reason) for the business you called.
  • In this record your phone number is never stored in readable form — it is keyed on a one-way cryptographic hash of the number, which cannot be turned back into the number. (The exception is the callback details described above, which have to stay readable for the business to ring you back.)
  • Records are scoped to the one business you called. Calling a salon never lets a plumber's agent recognize you, or vice versa.
  • Moment-to-moment performance data about a booking attempt carries no personal information about you at all; the longer-term booking record described above identifies you only by that same one-way hash.

Health information

Our agents are not set up to handle protected health information, and we do not currently take on work that requires HIPAA-regulated data handling. Agents never give medical or clinical advice — anything clinical is routed to a person at the business.

Deletion on request

You can have your caller record deleted at any time: ask the business you called, or email hello@linearzeta.com with the business name and the phone number you called from. We delete the caller record, remove your name and contact details from any message, booking, or order taken for you, delete your entries in the longer-term booking record described above, and unlink your call history — and that erasure is marked so a later system retry cannot quietly restore what was deleted. Retention of recordings and transcripts follows the agreement with each business and applicable state law.

3. If you're a LinearZeta client

What you give us during onboarding

When we set up your voice agent, we collect your business contact details — your name, business name, email, and, if you want account notification texts about your own service, a mobile number. We use these to run your service and to reach you about it. Nothing more.

Google user data (Google Calendar)

If you connect your Google Calendar during onboarding, you grant the LinearZeta app access through Google's standard sign-in and consent screen. Here is exactly what that access is and isn't:

  • What we access — two things, and only these two. Your availability (free/busy times), so the agent knows when you are open. And calendar events in a limited forward window (about 60 days) on the one calendar you connect — so the agent can create a booking, and can find, move, or cancel an existing appointment when the caller asks.
  • Why — for one purpose: so your voice agent can offer callers times you're actually free, write each confirmed booking onto your calendar, and reschedule or cancel it later. We do not read your calendar for any other reason.
  • The narrowest permissions that work — we request only calendar.events and calendar.freebusy. We deliberately do not request Google's full calendar permission, which would also expose your calendar settings and every other calendar on your account.
  • What we store, and what we don't — availability and event details are read during a call, used to answer that call, and are not written to our database. What we keep is the booking itself — the Google event ID plus the details of that appointment (the caller's name, contact details, the service, and the time) — so it can be rescheduled or cancelled later. We never copy your calendar.
  • How it's protected — every request to Google travels over TLS, and the credentials that authorize us to reach your calendar are stored encrypted with AES-256-GCM, under a key held separately from the database. See How we protect your data below for the full set of controls.
  • What we never do with it — we do not use Google user data for advertising, do not sell it, do not use it to train AI or machine-learning models, and do not transfer it to anyone except the service providers listed below as needed to run your booking service, or where required by law. No human reads your calendar data except with your permission, when needed for security or debugging, or to comply with the law.
  • Revoking access — disconnect at any time from your Google Account permissions page or by emailing us. When you disconnect or leave the service, we delete the stored credentials and the Google Calendar data we hold for you.

LinearZeta's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

SMS account notifications (LinearZeta Lead Alerts)

  • These are account-notification texts only — a single, transactional category covering new-lead alerts and service updates about your own account. We do not send marketing, promotional, or sales messages on this number, and no marketing consent is collected or combined here.
  • We only text you with your express written consent, given on our opt-in pagenever as part of signing up. The consent box is never pre-checked, and consent is not a condition of creating an account, purchasing, or using the service.
  • You can revoke consent at any time: reply STOP to any message, reply HELP for help, or email hello@linearzeta.com. Lead alerts then switch to email.
  • We keep a record of each opt-in (the number, the time, and where consent was given) for as long as you're subscribed, plus the period carriers require us to be able to prove consent.
  • Message frequency varies with your call volume, and message and data rates may apply depending on your mobile plan.
  • No mobile information will be shared with third parties or affiliates for marketing/promotional purposes. Your opt-in data and consent records are never sold or shared.

Full program terms are in our SMS Policy.

How we protect your data

Security procedures are in place to protect the confidentiality of your data — including any data we receive from Google APIs. These are the specific measures, not a general promise.

  • Encrypted in transit — every connection is encrypted with TLS: this website, our booking and caller-memory systems, and every call we make to a provider such as Google Calendar. We do not accept unencrypted connections.
  • Encrypted at rest — the access credentials that let us reach a connected account (your Google Calendar, your scheduling software) are stored encrypted with AES-256-GCM, using a unique data key per record that is itself wrapped by a master key. Our database holds ciphertext only; the master key lives in isolated secret storage, never in the database, and the credential exists in readable form only in memory, for the single request that books an appointment.
  • Least privilege — we request the narrowest permissions a feature can run on, rather than broad ones that would be convenient. Internally, each part of the system carries its own credential scoped to what it needs, and every query behind a business owner's dashboard login is pinned to that one business.
  • We collect and keep the minimum — calendar and availability data read to answer a call is used for that call and not written to our database. Caller phone numbers in our caller-memory system are stored only as a one-way cryptographic hash, never in readable form. (A booking or a message you leave does keep the number you gave, so the business can call you back — those are deleted on the retention schedule below.) Our moment-to-moment performance data contains no personal information at all; the longer-term booking record a business's reporting is built on identifies a caller only by that same one-way hash.
  • Access control — administrative access is strictly limited to authorized LinearZeta personnel, and reaching the administrative interface requires signing in through our identity provider with two-factor authentication. There is no shared login, access is revocable immediately, and the database has no public access path.
  • Retention limits, enforced by the system — records that contain readable personal details (callback requests, bookings and pickup orders) are deleted automatically once they pass the retention window — 90 days by default — rather than relying on someone remembering to do it. The longer-term booking record described above is kept indefinitely for the reporting reason given there; it carries no readable detail and is erased on request like everything else. We also delete the credentials for a connected account when it disconnects or leaves the service.
  • Deletion on request — the erasure paths described elsewhere in this policy are built into the system as operations we can run on request, not manual database surgery.
  • No secondary use — we do not sell data, do not use it for advertising, and do not use it to train AI or machine-learning models.
  • Hardened infrastructure — our systems run on Cloudflare's platform, in isolated environments with no standing public access to the database. Credentials are rotatable, and we rotate them on suspicion of exposure.
  • If something goes wrong — we investigate suspected security incidents promptly, and we notify affected businesses (and, where the law requires it, individuals and regulators) without undue delay. Reach us at hello@linearzeta.com if you believe you've found a vulnerability.

No system is perfectly secure, and we won't claim otherwise. What we can say is that these controls are how the service is actually built, and we review them as it changes.

Sub-processors we rely on

We use a small, deliberate set of service providers ("sub-processors"), each of which processes data only to provide its service to us. This is the current list; we keep it up to date and note material changes by updating the effective date above.

  • Twilio — telephony: carries the inbound phone calls our agents answer.
  • ElevenLabs — conversational AI and speech processing: the voice agent itself, including speech-to-text transcription of calls.
  • Cloudflare — hosting and CDN for this website, cookieless web analytics, and the infrastructure that runs our caller-memory and booking systems.
  • Buttondown — our lead system: stores the lead record created when you submit the contact form (name, email, business, phone, your message, campaign tags).
  • Resend — email delivery: sends us the notification that you submitted the contact form.
  • Cal.com — scheduling for the free call audit booked from this website.

If a business connects its own scheduling or intake system (for example, its existing appointment software), booking details go to that system under the business's own terms with that provider.

Your rights & choices

You can ask us what we hold about you, ask us to correct it, or ask us to delete it — email hello@linearzeta.com and we'll respond promptly. Depending on where you live (for example, under California, Colorado, Connecticut, Virginia, and other state privacy laws), these may also be legal rights; we honor them either way, and we won't discriminate against you for exercising them.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. Because there is nothing to opt out of on that front, we don't show a "Do Not Sell or Share My Personal Information" link.

Global Privacy Control (GPC). Some browsers and extensions let you broadcast a Global Privacy Control signal. We honor recognized GPC signals as a valid opt-out of any sale or sharing of personal information. Since we don't sell or share in the first place, there's nothing further you need to do — but if that ever changes, an active GPC signal is treated as your opt-out automatically.

If we change this policy, we'll update the effective date at the top. Material changes to how caller data is handled are also communicated to the businesses we serve.