Privacy Policy
Last updated: October 2026
GoldNovaAI provides Voice Agent Compliance & QA for businesses that run AI voice agents, and a research evidence workspace for qualitative researchers. It is offered to businesses and professional users only, not to consumers. This policy explains what we store when you use it, why, for how long, and what control you have over it.
Who is responsible
GoldNovaAI is a product operated by M. Amin Sayegh, trading as AIProCraft, Paul-Bertz-Str. 38, 09120 Chemnitz, Germany (imprint). Contact for all privacy questions and requests: hello@goldnovaai.com. No data protection officer is currently appointed.
For your account, billing and the operation of the service we are the controller. For the recordings, transcripts and call data you send us about other people (for example the people on a recorded call, or the participants of a research interview) we process the data on your instructions as your processor; you are the controller. Contact us to agree a data processing agreement (Auftragsverarbeitungsvertrag).
What we store
Account data: your email address and a hashed password, handled by our authentication provider (Supabase Auth). When you are signed in we use strictly necessary session cookies; we use no advertising or tracking cookies.
Recordings and transcripts: the interview audio you upload, the machine transcript produced from it, your corrections (kept as a revision history alongside the original machine output), and everything you build on top: quotes, tags, themes, findings, notes and project descriptions.
Voice QA data: call transcripts, recordings and metadata (call id, agent name, duration, end reason) that you send through the API or provider webhooks or upload in the app; the policy rules you configure; QA results with their evidence quotes; API keys (only a one-way hash is kept); and provider credentials you add for Retell or Twilio (encrypted). We do not store the customer phone-number fields contained in Vapi, Retell or Twilio payloads (numbers spoken in a call stay in its transcript), and we store any metadata you choose to send.
Billing data: your Stripe customer id, subscription plan and status, and the audio duration you have processed. Card details are entered on Stripe’s pages and never reach our servers. Paid plans are not open yet; billing currently runs in a test mode in which no real payment is taken.
Contact form and email: if you write to us through the contact form or by email we receive your name, email address, subject and message, and use them only to answer you. The form does not store your message in our database; it is delivered as an email to our mailbox. We keep it only as long as needed to answer you and document the request, and as long as the law requires. There is no marketing opt-in and we send no newsletters.
Audit trail: for Voice QA organizations, an append-only record of administrative actions (for example creating an API key or changing a policy) with the internal id of the acting user or API key prefix. It is kept as long as the organization exists.
Operational logs: request and processing events (ids, timestamps, statuses, durations). Our application logs do not contain audio or transcript text. Our hosting provider also keeps technical request logs, which can include IP addresses, for a limited period. To limit abuse, rate limits are kept per client address or, for the contact form, per sender email address (both stored only as a hash), or per API key.
Why we process it, and the legal basis
To provide the service you ordered and to run your account (Art. 6(1)(b) GDPR); to keep the service secure, prevent abuse and fix errors (our legitimate interest, Art. 6(1)(f)); to keep billing and tax records (legal obligation, Art. 6(1)(c)). For the content you send us about other people we act on your instructions (Art. 28 GDPR). You are responsible for having a legal basis for sending that content and for informing the people concerned, including that a call is recorded.
How recordings are handled
Recordings are stored in a private storage bucket that is not publicly reachable. Playback in the app uses short-lived, signed access generated on our servers only for the account that owns the interview. Exports never include links to audio.
To produce transcripts and optional AI suggestions we send audio and saved evidence text to our AI provider (currently OpenAI) under its API terms, which do not permit using that data to train its models. We do not use your audio, transcripts or findings to train any model of our own.
Who can see your data
Only the members of your organization. Each organization is a private workspace; access is enforced by database row-level security so one customer’s data cannot be read by another. Our staff do not access customer content except when you ask us to investigate a specific problem.
How long we keep it
- Raw recordings (research interviews and Voice QA calls): deleted automatically 90 days after upload by default. You can delete a recording earlier at any time without deleting its transcript.
- Transcripts, QA reports, evidence quotes and research findings: kept while the account or project exists, unless you delete them earlier.
- Deleting an interview, project or account in the app removes it from our active systems immediately, including the recordings. If you ask us to delete data by email, we do it within 30 days. Database backups kept by our hosting provider expire on their own within a further 30 days at most, so in the normal case deleted data is gone everywhere within 60 days.
- Billing, tax and legal records are kept only for as long as the law requires (Stripe keeps payment records on its own legal basis).
Deleting your data
You can delete an interview (its recording, transcript and every quote derived from it), only the recording of an interview or a call, a whole project, or your entire account from inside the app.
Deleting your account also deletes every Voice QA organization in which you are the only member: its calls, transcripts, reports, API keys, provider connections and recordings. An organization that still has other members is not deleted; if you are its only owner, deletion is blocked until ownership is transferred, which you can ask us to do. Individual Voice QA calls and organizations can also be deleted on request (see the imprint page for contact).
Website analytics
The public pages (not the signed-in app) use Vercel Web Analytics to count page views. It does not use cookies and we do not send it sign-in, password-reset or account pages, nor query strings.
Service providers (sub-processors)
- Supabase (database, authentication, file storage): data is stored in the AWS region eu-central-1 (Frankfurt, Germany), under Supabase’s data processing agreement, which is part of its terms and includes the EU Standard Contractual Clauses where applicable.
- Vercel (hosting, and page-view statistics for the public pages): our application currently runs on Vercel’s servers in the USA, under Vercel’s data processing addendum, which includes the EU Standard Contractual Clauses (2021).
- OpenAI (speech-to-text, optional AI assessment of call transcripts, and AI assistance in the research workspace): under OpenAI’s Data Processing Addendum, which is incorporated into its services terms; for customers in the European Economic Area the contracting entity is OpenAI Ireland Ltd. OpenAI may process data in the USA and may keep API inputs and outputs for a limited period under its terms, for example for abuse monitoring.
- Stripe (payments): under Stripe’s Data Processing Agreement, which forms part of the Stripe Services Agreement; international transfers are governed by the transfer mechanisms in Stripe’s terms.
- IONOS (email hosting for hello@goldnovaai.com): receives and sends the emails described above, including contact-form messages and, once enabled, the account emails of the service such as password-reset links.
- Voice platforms you connect (Vapi, Retell, Twilio) send data to us at your request.
International transfers
Some of these providers process data outside the European Economic Area, in particular in the USA. We do not claim that all data stays in Germany or the EU. Where data is transferred, we rely on the providers’ agreements described above, which use the EU Standard Contractual Clauses and, where the provider is certified, the EU-U.S. Data Privacy Framework.
Your rights
You have the rights to access, rectification, erasure, restriction, data portability and objection under the GDPR, and to withdraw consent you gave. Exports of your research content are available in the app; for anything else, write to hello@goldnovaai.com. You can also complain to a data protection supervisory authority.
Changes
We will note material changes to this policy here and, for significant changes, by email.