Legal
Privacy policy
What we collect, who else sees it, where it is stored, and how long we keep it. Written against what the platform actually does — including the parts where the honest answer is not the flattering one.
Last updated 19 September 2026
1.Who we are, and who this covers
Talqing is a platform for building and running AI voice, video and text agents. It is operated by Oggnai Technologies Private Limited (CIN U62011DL2025PTC446040), 293 S/F, Western Marg, Saidulajab, New Delhi, Delhi 110030, India — “Talqing”, “we”, “us”.
This policy covers talqing.com, our documentation at docs.talqing.com, the Talqing dashboard at app.talqing.com, and the Talqing API.
Two different groups of people appear in it, and they are not treated the same way:
- Customers — the people and organisations who hold a Talqing account and build agents. For their data we are the controller, and this policy is the full description of what we do.
- End users — the people who call, message or talk to an agent that a customer has built and published. For their data we are a processor acting on that customer’s instructions. The customer decides what is collected, what the agent says, whether the call is recorded and how long any of it is kept; their own privacy notice governs it, not this one.
If you spoke to an agent and want your data removed
Contact the business that operates it — they can delete the recording and the transcript themselves, and we cannot do it without their instruction. If you cannot identify or reach them, write to hello@talqing.com with the number you called and roughly when, and we will route the request to the workspace that owns the agent.
2.What we collect
Account data. Sign-in is Google OAuth only — there is no password to store, and we never see one. From your Google profile we keep your email address, your Google account identifier, your display name and your profile picture URL, refreshed each time you sign in. We also keep which workspaces you belong to and your role in each, and a record of every personal access token you create — the token text itself is not stored, only the record that authorises it.
Workspace content. The agents you build and every published version of them: prompts, greetings, model choices, tools and their code, agent tasks, knowledge bases, webhook endpoints, and your workspace settings.
Session records. For every agent run we store which agent and published version handled it, the channel (voice, video or text), start and end times, duration, how it ended, latency and usage counters, and the platform fee it was charged. For calls placed over the telephone network this includes the calling and called numbers in E.164 form, and the destination of any transfer to a human.
Conversation content. The transcript of each session as text — what the end user said, what the agent replied, every tool the agent invoked and everything those tools returned, the values the agent captured during the call, and any images sent into the conversation. We strip EXIF metadata, including GPS coordinates, from every image before storing it.
Call recordings. Voice and video agents record by default. One stereo audio file per call — the caller on one channel, the agent on the other. If the agent watched a shared screen and its author asked for that to be kept, a second file holds the screen as low frame-rate video. Both live in object storage and are reachable by the workspace through links that expire after an hour. Section 8 covers recording and consent on its own.
Post-call analysis. Unless the agent’s author turns it off, the finished transcript of a voice or video call is passed once to a language model to produce a summary, optionally a judgement of whether the call succeeded, and any fields the workspace asked to extract. That model call runs on the customer’s own provider key, not ours.
What an agent remembers between calls. Each caller identity a workspace has spoken to — a phone number, a Telegram account, or an identifier the customer supplied — has a contact record that accumulates what the agent learned, so it recognises that person on the next call. It exists until the last conversation with that person is deleted.
Recipient lists. An outbound call batch holds the phone numbers a customer uploaded and whatever per-person fields they attached. An email batch holds email addresses, the message drafted for each recipient and its delivery result.
Credentials you give us. Provider API keys you bring, OAuth tokens for apps you connect, telephony account credentials, messaging bot tokens, and any secrets you store for your tools. These are encrypted at rest and are never returned to the dashboard, the API, a model or a transcript after you save them.
Knowledge base content. When you point a knowledge base at a URL we crawl that site with a headless browser — following its own links and sitemap, up to a thousand pages — and store the text we extract. We also read PDFs linked from those pages and describe a small number of images per page. That extraction runs on our own model account; see section 4.
Technical data. Our servers log IP addresses, request paths, timestamps and error traces, and emit operational metrics. Both the logging and the metrics stack are our own; neither is sent to a third-party service.
Payment data. Card details never reach us — checkout is hosted by our payment processor. We pass them your email address and name, and we keep the record of which credit pack was bought, what it cost and whether it was paid.
3.What we use it for
- Running the service — authenticating you, executing your agents, connecting calls, and sending each turn to the providers your agent is configured to use.
- Showing you your own data — transcripts, recordings, call history, analysis, usage and cost in the dashboard.
- Billing — metering platform-fee usage against your credit balance.
- Security, debugging and abuse investigation — diagnosing errors and outages, and looking into misuse of the platform.
- Support, when you ask us for it.
- Service messages — changes that affect your account, your agents or this policy.
We do not sell your data, and we do not use your conversations, recordings or knowledge bases to train models. We have no models of our own to train, and the providers your agents run on do so under your account and your settings with them rather than ours — if you have turned training off in your provider’s console, that is the setting in force. We run no advertising, and there is no advertising or analytics tracker anywhere on this site or in the dashboard.
4.Who else sees it
There are two kinds of third party here, and treating them as one list would misdescribe how the platform works.
Providers you connect yourself
Talqing is strict bring-your-own-keys: no credential of ours ever backs an agent run. Every language model, speech-to-text, text-to-speech and avatar an agent runs is called with your key, on your account, and that provider bills you directly. The same is true of the carrier that carries a phone call, the apps you connect for tools, and the messaging channel you attach.
For all of these we transmit data on your instruction, and we hold no relationship with them on your behalf. Your own agreement with each provider is what governs their handling of it, including whatever you have configured there about retention and training. We cannot read or override those settings.
Which of them sees a given conversation depends entirely on how that agent is configured. An agent with no phone number never touches a carrier; an agent with no integrations never leaves its model stack.
| Category | Providers |
|---|---|
| Language, speech-to-text and text-to-speech models | OpenAI, Google (Gemini), xAI, Deepgram, ElevenLabs, Sarvam AI, Soniox, Raya |
| Video avatars | Anam |
| Noise suppression | ai-coustics — the model runs on our servers under your licence, so the audio itself does not leave |
| Telephony carriers | Exotel, Plivo, Twilio, Vobiz |
| Messaging channels | Telegram |
| Apps you connect for tools | Google Calendar, Cal.com, Calendly, Asana, Jira (Atlassian), HubSpot, RocketReach, Exa, Tavily, Resend |
| Anywhere you point an agent | A custom MCP server, an HTTP or code tool, or a webhook endpoint — each reaches the host you name and nothing else |
Some models also offer built-in tools — web search, code execution, file search. Enabling one lets that model’s provider act on the conversation on their own infrastructure, under the same agreement of yours.
Our own processors
These we chose, and they act for us under our contracts. This is the complete list.
| Processor | What they do for us |
|---|---|
| DigitalOcean | Compute, databases and object storage in every region |
| Cloudflare | DNS, and hosting for the public website and the documentation |
| Sign-in over OpenID Connect, and the mailbox that receives support, privacy and legal requests | |
| Dodo Payments | Hosted checkout and payment processing for credit packs |
| OpenAI | The CoPilots in the editors and the knowledge-base builder — never an agent run |
That last row is the one exception to bring-your-own-keys, so it is worth stating plainly. The CoPilots read the workspace configuration you are editing and can call the same API you can; the knowledge-base builder reads the pages you asked it to crawl. Both run on our own OpenAI account. Nothing about a live agent run — no call, no message, no task — ever does.
We disclose data outside these two lists only where the law requires it, or to protect the rights and safety of our users — and we will tell you unless we are legally barred from doing so.
5.Where your data lives
Talqing runs one global control plane and two independent regions. You choose a region by which API you call. Nothing is copied or replicated between them, and no screen in the product merges them.
| What | Where it is stored |
|---|---|
| Identity, workspace membership, access tokens and payment records | Frankfurt, Germany |
| India region — agents, calls, transcripts, analysis, credit balance | Bengaluru, India |
| India region — call recordings and image attachments | Singapore |
| United States region — everything a workspace owns there | San Francisco, United States |
The Singapore row is a limitation, not a preference
Our object storage provider does not currently offer buckets in Bengaluru. Recordings and image attachments belonging to Indian workspaces are therefore held in the nearest datacentre it does offer, in Singapore. Transcripts, analysis, contact records and every other row for those workspaces stay in India. We would rather say this than let “stored in India” stand as a claim that is three-quarters true, and we will move these objects to India when that becomes possible.
Beyond our own footprint, running an agent generally means an international transfer, because the providers you connect are wherever you have chosen to run them. For transfers to our processors we rely on the standard contractual clauses in their terms; for the providers you connect yourself, it is your own agreement with them that carries the transfer.
6.How long we keep it
By default we keep call content indefinitely. A workspace can set a retention policy — any number of days between 1 and 3650 — and when a call reaches that age its content is deleted while the record of the call survives, because an invoice has to keep resolving. Only an admin can set it. Each call’s deadline is fixed when the call ends, so changing the policy later does not move a deadline that already exists, in either direction.
The same erasure runs immediately when a customer deletes a call themselves. It is not an audio feature: a transcript is personal data in exactly the way the recording is, and it is the copy that travels into analysis, webhooks and the model provider.
| An erased call | What happens |
|---|---|
| Deleted | The recording and the screen video; the whole transcript, in both directions; every tool call and its result; the images attached to it; the captured values, the summary, the outcome rationale and the extracted fields; the runtime trace; and the phone numbers on the call |
| Kept | The call record itself — duration, status, outcome, how it ended and every cost column — the usage counters behind those costs, and a stamp saying the content was erased. Also one event, timestamp only, if a caller withdrew consent to being recorded: it is the evidence the content was handled correctly, which is exactly what someone asks for after the content is gone |
Customers can delete a call and its content, or just its audio, from the dashboard or the API, and can delete agents, tools, knowledge bases, secrets, provider keys, integrations and webhooks at any time. A text conversation has no delete of its own today; its content goes when the sessions inside it are erased, and the contact record goes with the last conversation.
| Everything else | Retention |
|---|---|
| Account, workspace and membership records | Until you ask us to delete them |
| Stored credentials and OAuth tokens | Until you remove the connection |
| Knowledge base content | Until you delete the knowledge base |
| Billing, credit and payment records | As long as tax and accounting law requires |
| Server logs and operational metrics | Short-lived, rotated |
There is no self-serve account deletion yet
Leaving a workspace, or being removed from one, does not delete anything it holds. To have a workspace and everything in it erased, write to hello@talqing.com from the address on the account and we will do it. We would rather tell you that than put “delete your account” in a policy and leave you looking for the button.
Backups age out on their own cycle and are not selectively edited.
7.How it is protected
- Traffic between your browser, our API and our infrastructure is encrypted with TLS.
- Provider keys, OAuth tokens and stored secrets are encrypted at rest with a key held outside the database, and are write-only over the API — no endpoint, model or support path returns one.
- Recordings and attachments sit in private buckets. Every link to one is signed, expires within an hour, and is scoped to a single object.
- Every workspace's data carries its identifier and every query is scoped to the workspace making it. Storage operations additionally refuse to touch an object outside the workspace's own prefix.
- Databases, queues and caches listen on no public interface. The signing key that mints sessions and tokens exists only on the control plane, so no region can forge another region's credentials.
- Requests that agents make outward — HTTP tools, code tools, webhooks — are blocked from reaching private, loopback and internal network addresses.
- One honest exception: the leg of a phone call that crosses the public telephone network is carried by the carrier in the clear, as PSTN telephony everywhere is. It is not encrypted end to end and we do not claim it is.
We hold no security certification
Talqing has not completed a SOC 2 audit, an ISO 27001 certification or any equivalent programme, and nothing on this page should be read as implying one. What is described above is what the software does, so you can weigh it against your own obligations. If you need something in writing for a procurement or legal review, ask us at hello@talqing.com.
No system is perfectly secure. If we discover a breach affecting your data we will tell you and the relevant regulator as the law requires.
8.Recording, and the people your agents call
This is the section most likely to matter to you, whichever side of an agent you are on.
- Voice and video agents record by default. One setting on the agent turns it off. Recording follows whichever agent is speaking, so an agent with it off records silence for as long as it holds the call.
- Whether callers are told is a separate setting, and it is off by default. Turned on, the agent must speak a notice in its greeting — checked when the agent is published, so it cannot be switched on and then quietly dropped.
- Recording can always be stopped. Whenever a call is being recorded, the agent carries a tool that stops it, and is instructed to reach for that tool as soon as a caller objects or asks for the recording to be deleted. Stopping discards the whole file, not merely what would have followed. That right does not depend on anyone having announced anything first.
- Screen recording is off by default and only applies where a caller has chosen to share their screen with the agent.
Talqing does not decide whether recording is lawful where your callers are
Recording law differs by jurisdiction and by who is on the call — all-party consent rules, the DPDP Act, the GDPR, TRAI’s regulations. If you operate an agent, determining what applies to your calls and configuring the agent accordingly is yours to do. The default is on; that is a default, not advice.
9.Your rights
If you hold a Talqing account. Depending on where you live you may have the right to access your data, correct it, delete it, export it, object to processing, or withdraw consent. Most of these you can exercise yourself: agents, tools, knowledge bases, connections, calls and recordings are all deletable in the dashboard, and everything the dashboard shows you is readable over the API in a portable form. For anything else — including deleting the account itself — write to hello@talqing.com. We will respond within 30 days.
If you spoke to an agent someone built here. Your rights are against that business, not against us; they control what was collected and they can delete it. Contact them first. If you cannot reach them, write to hello@talqing.com and we will pass the request on and tell you that we have.
If you are unhappy with how a request was handled you may complain to your data protection authority. In India, that is the Data Protection Board.
11.Google user data
Talqing’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We touch Google in two places and nowhere else.
Sign-in. We request openid, email and profile, and use them only to identify you and to show your name and picture to the other members of your workspace.
Google Calendar, and only if you connect it. We request the narrowest scopes that let an agent do scheduling work: your list of calendars and their events, read-only; free/busy information; and write access limited to events on calendars you own — deliberately not the broader scope that would reach every calendar shared with you. We request no Gmail, Drive or Contacts scope, and there is no way to add one from the dashboard.
Calendar data reached this way is used only to run the tools your agent calls. It is not transferred to anyone except as needed to provide that feature, it is never used for advertising, and no human at Talqing reads it — except with your explicit permission, where it is necessary for security, or where the law requires it. Disconnecting the integration in the dashboard revokes the token; you can also revoke it yourself at myaccount.google.com/permissions.
12.Children
Talqing is a business product and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a child has given us data, write to hello@talqing.com and we will delete it.
13.Changes to this policy
We update this page when what we do changes, and revise the date at the top. If a change materially affects how we handle your data, we will tell account holders by email to the address on the account, or in the dashboard, before it takes effect.
14.Contact
For anything in this policy — a question, an access or deletion request, or a complaint — write to hello@talqing.com. Under India’s data protection rules that address also reaches our grievance officer, who will acknowledge a grievance within the period the rules require.
Oggnai Technologies Private Limited
293 S/F, Western Marg, Saidulajab, New Delhi, Delhi 110030, India
CIN U62011DL2025PTC446040
hello@talqing.com
+91 99101 80529
The engineering detail behind sections 6 and 8 — exactly what an erasure deletes, and how the recording settings behave — is documented at docs.talqing.com.