RealGent
Terms of ServiceTermsBack to siteHome

Legal

Privacy Policy

What RealGent collects, which AI providers see it, where it is stored, how long it is kept, and how to get it out or have it deleted. Written to describe what the product actually does, not what a template says.

Effective
August 23, 2026
Last updated
August 23, 2026
Version
1.0

On this page

  1. 01Overview and scope
  2. 02Controller or processor
  3. 03What we collect
  4. 04How we use it
  5. 05AI providers and sub-processors
  6. 06Call recording and transcription
  7. 07Legal bases for processing
  8. 08Multi-tenant security
  9. 09How long we keep data
  10. 10Sharing and disclosure
  11. 11International transfers
  12. 12Your rights, export and deletion
  13. 13If you are a lead or caller
  14. 14Cookies and local storage
  15. 15Children’s privacy
  16. 16Changes to this policy
  17. 17Contact
On this page
  1. 01Overview and scope
  2. 02Controller or processor
  3. 03What we collect
  4. 04How we use it
  5. 05AI providers and sub-processors
  6. 06Call recording and transcription
  7. 07Legal bases for processing
  8. 08Multi-tenant security
  9. 09How long we keep data
  10. 10Sharing and disclosure
  11. 11International transfers
  12. 12Your rights, export and deletion
  13. 13If you are a lead or caller
  14. 14Cookies and local storage
  15. 15Children’s privacy
  16. 16Changes to this policy
  17. 17Contact

01Overview and scope

RealGent (“RealGent”, “we”, “us”) provides AI chat and voice agents that answer, qualify and book leads on behalf of businesses. This policy explains what personal data flows through that product, who processes it, and what you can do about it.

It covers three groups of people:

  • Customers — the businesses and their team members who hold a RealGent workspace.
  • Leads and callers — the individuals who talk to a customer’s AI agent by phone or website chat. See §13.
  • Visitors — anyone browsing our public website.

It should be read with the Terms of Service, which sets out the compliance obligations customers carry when they call, message and record people.

02Controller or processor

The distinction matters for who you contact about a request.

  • For account, workspace and billing data — the people who sign up, and how they use the product — we are the controller. We decide why and how it is processed, and requests come to us.
  • For lead and conversation data — the names, phone numbers, emails, call recordings, transcripts and knowledge sources inside a customer’s workspace — the customer is the controller and we are their processor. We handle that data on their documented instructions, to operate the service, and for no independent purpose of our own.

If you are a lead or caller and want your data corrected or deleted, contact the business you spoke to. We will assist that business in responding, and will pass a request on if it reaches us first.

03What we collect

3.1 Account and workspace data

  • Name, work email address, password hash, and company or brokerage name.
  • Workspace configuration: team members and roles, agent prompts and personality settings, business hours, appointment types, staff and availability, widget design, phone numbers and routing rules.
  • Knowledge base content you upload or import — documents, pasted text, FAQs and pages crawled from a website you nominate — and the vector embeddings derived from it.

3.2 Lead and contact data

Whatever a conversation captures or you import, typically including names, phone numbers, email addresses, property interests, budget and timeline, notes, tags, pipeline stage, activity history, appointments, and an AI-generated lead score.

3.3 Voice call data

  • Call audio and recordings of inbound and outbound calls, and of in-browser test calls.
  • Transcripts and summaries generated from that audio, plus detected intent, outcome and any actions the agent took.
  • Call metadata: the numbers on each leg, direction, timestamps, duration, connection status, transfer events and the credits consumed.

3.4 Chat data

  • Full chat transcripts between a visitor and the agent, including anything the visitor types.
  • Session metadata: the page the chat began on, timestamps, language, referrer, and the widget it came from.

3.5 Billing data

Plan, subscription status, billing period, invoices and credit usage. Payments run through Stripe: card numbers and bank details go to Stripe directly and we neither receive nor store them. We keep the Stripe customer and subscription identifiers and the last four digits and brand of the card as Stripe reports them.

3.6 Technical and usage data

IP address, browser and device type, pages and features used, timestamps, error diagnostics, and security and audit logs, including administrative actions taken inside a workspace.

04How we use it

  • To operate the service — run the agents, hold conversations, book appointments, score and route leads, and deliver notifications.
  • To authenticate you, secure the platform, detect abuse and prevent fraud.
  • To meter credits and voice minutes, bill you, and support billing disputes.
  • To provide support, diagnose faults and investigate incidents you report.
  • To send service, security and billing notices. Product and marketing email is separate and you can opt out of it at any time.
  • To improve the service using aggregated, de-identified statistics that cannot reasonably be linked back to you, your workspace or any individual.
  • To comply with law and to establish, exercise or defend legal claims.

What we do not do

We do not sell personal data, and we do not share it for cross-context behavioural advertising. We do not train our own AI models on your Customer Data, and we contract with our AI providers on terms that direct them not to train their models on data submitted through the service.

05AI providers and sub-processors

Running an AI agent means sending conversation content to model providers, and carrying calls means sending audio across a telephone network. We use established enterprise providers, under contracts covering confidentiality, security and — where applicable — GDPR Article 28 processing terms and standard contractual clauses.

These are the sub-processors that may handle personal data today:

ProviderPurposeData involved
OpenAIChat and voice models, speech-to-text, text-to-speech, embeddingsConversation text, call audio, knowledge-base content
Google (Gemini)Chat and voice models, speech-to-text, text-to-speechConversation text, call audio
Anthropic (Claude)Chat modelsConversation text
TwilioTelephony — inbound and outbound calls, phone numbers, SMSPhone numbers, call metadata, call audio, message content
SupabaseManaged database, authentication and file storageAll workspace data at rest, including recordings and transcripts
StripeSubscription billing and payment processingBilling contact, plan and payment status. Card details go to Stripe directly and are never stored by us
ResendTransactional email — confirmations, notifications, alertsRecipient email address and message content
n8nWorkflow automation for notifications and lead routingLead and appointment details passed between systems

We also use cloud hosting and content delivery providers to run the application and store data at rest. Which model provider handles a given conversation depends on the engine selected in your workspace; the choice is yours and is shown in the app.

This list changes as the product does. We keep it current here and, where required, will give notice of a new sub-processor before it starts processing. To be told about changes, write to privacy@realgent.ai.

06Call recording and transcription

Voice conversations are recorded and transcribed

Calls handled by a RealGent voice agent are recorded, transcribed and stored in the customer’s workspace. Audio is streamed to the selected AI provider in order to understand speech and generate a reply, and transcripts are retained so the conversation can be reviewed, summarised, scored and audited.

Recordings and transcripts are used to operate the agent, for quality assurance, to resolve disputes, to verify billing, to improve a customer’s own configuration, and to troubleshoot faults. Workspace members with the right role may also listen to a call live or read a chat as it happens, and take the conversation over from the agent.

Notice and consent are the customer’s responsibility. Recording law differs by jurisdiction and many require all parties to consent. Under the Terms of Service, the customer must give the required notice at the start of the call and honour any objection. RealGent supplies the greeting and prompt controls to do it, but does not make the disclosure on a customer’s behalf.

07Legal bases for processing

Where the GDPR or UK GDPR applies, we rely on:

  • Contract — to provide the service to a customer and to bill for it.
  • Legitimate interests — to secure the platform, prevent abuse and fraud, keep the service working, and understand aggregate usage, balanced against the rights of the people concerned.
  • Consent — for marketing email, non-essential cookies, and any recording or outreach where consent is the required basis. Consent can be withdrawn at any time.
  • Legal obligation — for tax, accounting and lawful requests.

For lead and conversation data we process on a customer’s instructions, the customer identifies the lawful basis for the underlying contact. That is part of the compliance obligations in §7 of the Terms.

08Multi-tenant security

One agency cannot reach another agency’s data

Tenant isolation is enforced in the database itself, by PostgreSQL row-level security, not only in application code. Every table carrying workspace data has policies that restrict each row to the organisation that owns it, and those policies are evaluated on the authenticated session — so a query that tries to read another organisation’s rows returns nothing, whatever the application asks for.

Alongside that:

  • Data is encrypted in transit with TLS and encrypted at rest by our hosting provider.
  • Row-level security is enabled automatically on every new table, so a table added later is closed by default rather than open by oversight.
  • Privileged operations — plan and credit changes, platform settings — are not callable by a tenant session at all; they are restricted at the grant layer.
  • Access within a workspace is role-based, and administrative actions are written to an audit log.
  • Passwords are hashed by our authentication provider and never stored in plain text.

No system is perfectly secure. If a breach affects your personal data we will notify you, and any regulator, as applicable law requires and without undue delay. To report a vulnerability, write to privacy@realgent.ai.

09How long we keep data

  • Workspace data — leads, conversations, recordings, transcripts, appointments and knowledge sources — for as long as the workspace is active, or until you delete it. You can delete individual records at any time.
  • After cancellation — data stays available for export for 30 days, then is scheduled for deletion within a further 60 days, save where law requires us to keep it.
  • Billing and tax records — retained as long as tax and accounting law requires, typically seven years.
  • Security and audit logs — typically up to 12 months.
  • Backups — encrypted backups may hold deleted data for a short rolling window before they expire on their own schedule.

Deleting a record removes it from the workspace and from our active systems; where a third-party provider has processed a copy, deletion is requested from that provider on the terms of our agreement with them.

10Sharing and disclosure

We share personal data only:

  • with the sub-processors in §5, for the purposes stated there;
  • with people inside your own workspace, according to the roles you assign, and with services you choose to connect;
  • with professional advisers, auditors and insurers, under confidentiality obligations;
  • where required by law, court order or a valid request from a public authority — and where we are legally permitted to, we will tell the customer first;
  • to establish, exercise or defend legal claims, or to protect the rights, property or safety of RealGent, our customers or the public;
  • in a merger, acquisition, financing or sale of assets, with notice to affected customers and subject to this policy continuing to apply.

We do not sell personal data and we do not share it for cross-context advertising.

11International transfers

RealGent and its providers operate globally, so personal data may be processed in countries other than your own, including the United States. Where data leaves the European Economic Area, the United Kingdom or Switzerland, we rely on an adequacy decision or on standard contractual clauses, together with technical and organisational measures appropriate to the transfer. Details are available on request from privacy@realgent.ai.

12Your rights, export and deletion

Depending on where you live, you may have the right to access your personal data, correct it, delete it, receive a portable copy, restrict or object to processing, withdraw consent, and not be subject to a decision based solely on automated processing that produces legal or similarly significant effects.

12.1 GDPR and UK GDPR

Rights of access, rectification, erasure, restriction, objection and portability apply, as does the right to withdraw consent and to complain to your supervisory authority. We respond within one month, extendable by two further months for complex requests.

12.2 CCPA and CPRA (California)

California residents may request the categories and specific pieces of personal information collected, the purposes and the categories of recipients; request deletion or correction; and limit the use of sensitive personal information. We do not sell or share personal information as those terms are defined by the CCPA, so there is nothing to opt out of — but you may still exercise the request rights above, and you will not be discriminated against for doing so. Similar rights exist under other US state privacy laws.

12.3 How to exercise them

  • Export — workspace owners can export leads, conversations, transcripts and appointments from the app. For a complete account export, write to us.
  • Delete — individual records can be deleted in the app. To delete a whole workspace and the account behind it, write to privacy@realgent.ai from the account email address.
  • Everything else — email privacy@realgent.ai. We will verify your identity before acting, and an authorised agent may act for you with proof of authority.

Requests are free unless manifestly unfounded or excessive. Where a request concerns data we hold as a processor for a customer, we will forward it to that customer and assist them in responding.

13If you are a lead or caller

If you spoke to a RealGent agent by phone or website chat, the business you contacted — not RealGent — decides what happens to your data. We process it for them as their processor.

  • Your conversation, and any recording and transcript of it, is stored in that business’s workspace.
  • To access, correct or delete it, or to withdraw consent to be contacted, ask that business. They are also the party responsible for honouring do-not-call and opt-out requests.
  • If you cannot reach them, write to privacy@realgent.ai with enough detail to identify the conversation and we will route the request to them and support their response.

14Cookies and local storage

Essential by default

We use cookies and browser storage that are strictly necessary to run the service: keeping you signed in, protecting against cross-site request forgery, and remembering interface preferences such as theme, appearance and sidebar state. The chat widget stores a session identifier so a conversation survives a page reload.

We do not use advertising cookies or third-party tracking pixels for cross-site advertising. Any analytics we use is limited to understanding aggregate product usage. Blocking essential cookies in your browser will stop you from signing in.

15Children’s privacy

RealGent is a business product and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child’s data has reached the platform, write to privacy@realgent.ai and we will delete it. Customers must not use the service to contact minors.

16Changes to this policy

We update this policy as the product and the law change. The current version is always the one at this address, with its effective date at the top. For a material change we will notify customers by email or in-app before it takes effect. Continuing to use the service afterwards means you accept the updated policy.

17Contact

Privacy questions, requests and complaints:

  • Privacy and data requests — privacy@realgent.ai
  • Everything else — support@realgent.ai

If you are in the EEA or the UK and are not satisfied with our response, you may complain to your local supervisory authority.

Data requests are answered by a human. Email privacy@realgent.ai from the address on the account and we will verify you before acting, then respond within the period the applicable law allows.

A postal address for formal notices is available on written request.

Terms of ServiceLicence, compliance duties, billing and liability.