Defuse Legal
Privacy Policy
How Defuse collects, uses, discloses, retains, and protects information.
Effective August 29, 2026 | Version 1.0
1. Who we are and when this Policy applies
Defuse is operated by CarterPeak LLC d/b/a Defuse. This Privacy Policy applies to usedefuse.com, Defuse account and subscription services, customer support, and calls transferred to a Defuse AI supervisor (collectively, the "Service").
Defuse has different privacy roles depending on the context. For customer account information, billing, website analytics, security, and support, Defuse generally determines the purposes of processing and acts as a controller or business. For recordings, transcripts, caller numbers, summaries, and related call data processed for a subscribing business, the subscribing business generally acts as controller or business and Defuse acts as its processor or service provider.
If you are an end-caller, you are normally interacting with one of our customers, not purchasing a service from Defuse. Questions about why the call occurred, the underlying customer relationship, or the business's use of your information should be directed to that business.
2. Information we collect
| Category | Examples and sources |
|---|---|
| Account and contact information | Business name, account email, support communications, notification addresses, and authentication identifiers, provided by customers and users. |
| Configuration information | Industry description, selected supervisor name and voice, resolution authority, follow-up instructions, and other settings supplied by the customer. |
| Billing and subscription information | Plan, usage, overage authorization, invoices, Stripe customer and subscription identifiers, and payment status. Stripe processes complete payment-card details. |
| Call data | Caller telephone number, audio recording, transcript, call time and duration, issue, caller sentiment or concern, resolution discussed, outcome, and follow-up actions. Callers and customer personnel provide this information during calls. |
| Device, log, and website information | IP address, browser and device information, page paths, referring page, approximate IP-derived location, timestamps, authentication events, error logs, and security signals. |
| Cookies and analytics | Essential login or session technologies and Google Analytics information about use of public marketing, pricing, login, signup, checkout, terms, and privacy pages. |
Call content is unstructured. A caller may volunteer information that neither Defuse nor the customer requested, including account numbers, addresses, health information, financial information, or other sensitive data. Defuse does not intend the Service to collect prohibited regulated data, and customers must configure and use the Service to minimize such collection.
3. How we use information
- Provide, configure, operate, maintain, and improve the Service.
- Receive and route transferred calls; generate speech; record, transcribe, and summarize interactions; and present results to the customer.
- Authenticate users, maintain tenant separation, provide support, diagnose errors, and prevent fraud or misuse.
- Process subscriptions, measure minutes, apply authorized overage charges, and maintain billing and accounting records.
- Send transactional notices, including secure links to call information in the authenticated dashboard.
- Analyze public-site usage and product performance using aggregated or de-identified statistics.
- Comply with law, respond to legal process, enforce agreements, and protect rights, safety, and security.
Defuse does not use identifiable call recordings or transcripts to train Defuse-owned AI models. Defuse uses third-party business and API services to provide voice, transcription, and summary functions. Their processing is governed by Defuse's configurations and contracts. Defuse may use aggregated or de-identified usage information that is not reasonably capable of identifying a customer or individual.
4. What happens during a Defuse call
- A customer representative transfers a caller to the customer's dedicated Defuse number.
- The AI supervisor gives a recording notice near the beginning of the interaction and states that continuing constitutes agreement to recording.
- The voice provider processes the live audio, caller number, recording, and transcript on Defuse's behalf.
- A third-party AI provider processes the transcript to create structured summary fields.
- Defuse stores the transcript, summary, caller number, and call metadata in its system of record. Audio may remain with the voice provider during the selected retention period; routine dashboard playback is not offered.
- Defuse sends designated customer recipients a transactional email containing the call summary, including the issue, the resolution discussed, and the outcome, together with a link to the full record in the authenticated dashboard. The caller's telephone number is masked in the email, showing only the last four digits; the full number remains available in the authenticated dashboard. A customer may instead configure its account so that the email contains only the call outcome, duration, and a link, keeping caller content behind authentication.
The subscribing customer can access its call information and is responsible for completing promised resolutions, responding to rights requests, and determining how information may be used in its relationship with the caller.
5. How we disclose information
We disclose information only as reasonably necessary for the purposes described in this Policy, as directed by a customer, or as permitted or required by law. Categories of recipients include:
- The subscribing customer and its designated account users or notification recipients.
- Hosting and application infrastructure providers, including Vercel.
- Database and authentication providers, including Supabase and its infrastructure providers.
- Voice, telephony, recording, and transcription providers, including Retell AI and underlying telecommunications providers such as Twilio.
- AI processing providers, including OpenAI, for transcript summarization.
- Transactional email providers, including Resend.
- Payment providers, including Stripe, for subscriptions and charges.
- Website analytics providers, including Google Analytics, for measurement of public pages.
- Professional advisers, authorities, or transaction counterparties when reasonably necessary for legal compliance, protection of rights, financing, merger, acquisition, or sale of the business.
Defuse does not sell personal information for money. Defuse does not use personal information for cross-context behavioral advertising or targeted advertising. If Defuse changes those practices, it will update this Policy and provide any legally required choices before doing so.
6. Data retention and deletion
| Information | Typical retention approach |
|---|---|
| Call records | Customers select 30, 60, 90, 180, or 365 days. The default is 90 days. A customer may affirmatively select indefinite retention, in which case records remain until the customer deletes them, changes the setting, or the account is terminated. |
| Single-call deletion | Authorized customer users can delete an individual call. Defuse deletes associated call data from its system and instructs the voice provider to delete the associated call record, subject to limited legal or backup exceptions. |
| Cancelled accounts | Call data remains available for export for 30 days after the subscription ends and is then deleted according to Defuse processes, subject to limited legal, security, and backup retention. |
| Account and billing records | Retained while the account is active and afterward as reasonably needed for tax, accounting, fraud prevention, dispute, and legal obligations. |
| Website analytics and logs | Retained according to provider settings and for periods reasonably necessary for analytics, troubleshooting, fraud prevention, and security. |
Retention periods are designed to be no longer than reasonably necessary for the stated purposes. Deletion from active systems may not immediately remove information from disaster-recovery backups, security logs, or records that law requires Defuse to preserve; such information is isolated and removed under ordinary retention schedules.
7. Privacy rights and requests
Depending on where you live and whether applicable law covers the relevant organization and data, you may have rights to access, correct, delete, or obtain a copy of personal data; appeal a denied request; or opt out of certain sales, targeted advertising, or profiling. Defuse does not sell personal data or use it for targeted advertising.
Account users and website visitors may submit a request to support@usedefuse.com. Defuse will verify requests as appropriate and may ask for information reasonably necessary to locate records and protect against unauthorized disclosure. You may appeal a denial by replying to the decision and stating that you are appealing.
End-callers should ordinarily submit call-related requests to the business that transferred the call because that business controls the call relationship and can verify the caller. If an end-caller contacts Defuse directly, Defuse may redirect the request to the applicable customer, ask for call date, approximate time, business name, and caller number, and take reasonable steps to avoid revealing whether a record exists before identity and authority are verified.
Defuse will not discriminate against an individual for exercising a legally protected privacy right. Rights are subject to legal limitations and may not apply in every circumstance.
9. Security and access
Defuse uses reasonable administrative, technical, and organizational measures designed to protect information. Measures include encrypted transmission, provider encryption at rest where supported, authentication, row-level access controls, tenant separation, least-privilege support access, deletion controls, monitoring, and vendor management.
Defuse personnel do not routinely review customer call data. Authorized personnel may access it when necessary to respond to support, investigate an incident, diagnose a defect, maintain security, comply with law, or protect the Service. No method of transmission or storage is completely secure.
10. Restricted data and uses
The Service is not offered for emergency communications, services directed to children, debt collection, or the handling of protected health information, complete payment-card information, financial-account credentials, Social Security numbers, authentication secrets, biometric templates, or other prohibited regulated data unless Defuse expressly agrees in writing after appropriate safeguards and contracts are in place.
Insurance businesses may use Defuse only for permitted customer-service purposes and may not use it for underwriting, eligibility, coverage, claims, or other consequential decisions or submit restricted information.
11. Children
Defuse is a business service and is not directed to children. Customers may not use the Service for services directed to children or knowingly transfer calls from children. If Defuse learns that it has collected personal information from a child contrary to these restrictions, it will take reasonable steps to delete it.
12. United States processing
Defuse is initially offered for United States business use. Information is processed in the United States by Defuse and its service providers. The Service is not designed for customers established in the European Economic Area, United Kingdom, Canada, or other non-U.S. jurisdictions.
13. Changes to this Policy
Defuse may update this Policy to reflect changes in law, providers, or practices. The updated version will be posted with a new effective date. Defuse will provide additional notice when legally required or when a change is material.
14. Contact us
Privacy questions and requests may be sent to support@usedefuse.com or mailed to CarterPeak LLC d/b/a Defuse, 221 Main Street, Suite N, Nashua, NH 03060.
© 2026 CarterPeak LLC d/b/a Defuse · 221 Main Street, Suite N, Nashua, NH 03060 · support@usedefuse.com