Privacy Policy | Custral
Privacy

Privacy Policy

How Custral collects, uses, shares, and protects information across the product — with a plain-English summary for every section.

Last updated: July 202612 min readPlain-English summaries

The short version

The friendly summary. It doesn’t replace the full policy below, but it’s the gist.

  • We collect what we need to run, secure, bill, and support the Services — and not much more.
  • We never sell your personal information or share it for ad targeting.
  • The communications and records you run through Custral are yours; we only process them on your behalf.
  • You can access, correct, export, or delete your information — just email us.
  • We're US-based; data from the EU and UK is protected by Standard Contractual Clauses.
  • Sensitive things like call recording, messaging, and enrichment follow the settings you control and your local laws.
On this page
01

Who we are, and our two roles

In short

Custral is the controller of your account data, and a processor of the communications and records you run through the platform.

Custral is a customer-lifecycle platform: email, SMS and messaging, voice calls, website chat, calendar and scheduling, a CRM and records system, documents, automation, analytics, and AI assistants — on the web, desktop, and mobile. This Privacy Policy explains what information we collect, how we use and share it, and the choices and rights you have across all of it (together, the “Services”).

We handle data in two different capacities, and which parts of this policy apply depends on which:

  • Account Data (we are the controller). Information about you as a Custral account holder or user, and about visitors to our own website — your name, email, billing details, and how you use the Services. This policy governs how we handle it.
  • Customer Data (we are the processor). The communications and content you and your team load into or generate within Custral to run your business — emails, messages, calls and recordings, chat transcripts, CRM records, contacts, calendar events, documents, and the personal data of your customers and prospects. We process it on your behalf, under your instructions and our customer agreement and Data Processing Addendum (DPA).

If you are a customer, prospect, or contact of a business that uses Custral, that business — not Custral — is the controller of your data. Please direct privacy requests to them; we will assist them as their processor.

02

Information we collect about you

In short

What you give us, what your device and browser send automatically, and a little from third parties.

This section covers Account Data — information about you as a Custral user.

Information you give us. Account and profile details (name, email, password, organization name, role, profile photo), billing information (processed by our payment provider — we do not store full card numbers), and the content of your support requests and other communications with us.

Information we collect automatically. Usage and product-analytics data (features used, actions taken), device and log data (browser and device type, operating system, IP address, and timestamps), approximate location derived from your IP address, and cookies and similar technologies (see our Cookie Policy). We also capture masked session recordings of interactions with our apps to diagnose issues and improve usability; text and form inputs are masked.

Information from third parties. If you sign in through an identity provider (such as Google or GitHub) we receive basic profile information, and we may use enrichment services (such as Gravatar) to display profile avatars.

03

The data you process with Custral

In short

The communications, contacts, records, and content you run through the platform — which we process on your behalf, not for ourselves.

To provide the Services, we process the content you and your team create or bring into Custral. Depending on the features you use, this can include:

  • Communications content — emails, SMS and other messages, website chat conversations, and voice calls, including call recordings, voicemail, and transcripts where those features are enabled;
  • Contacts and CRM records — the people and companies you manage, and the custom fields, notes, and history attached to them;
  • Calendar and scheduling data — events, availability, and bookings;
  • Documents and collaborative content — notes, whiteboards, spreadsheets, presentations, and files, including real-time collaboration and presence;
  • Automation and AI data — workflows, sequences, and the inputs and outputs of AI features you run.

We process this Customer Data only to provide, secure, and support the Services under your instructions and our agreement — not for our own purposes, and never to sell it.

04

Email, messaging, and voice

In short

You connect mailboxes and phone numbers to send and receive; calls may be recorded and transcribed per your settings, and you handle consent.

When you connect a mailbox, calendar, or contacts (for example a Google or Microsoft account), or provision a phone number or messaging service, we access and process the data needed to provide the features you enable, according to the permissions you grant. You can disconnect an integration or release a number at any time.

Calls. Custral can place and receive phone calls on your behalf. Where your organization enables it, calls may be recorded and transcribed according to the recording policy configured for your account, and unanswered calls may go to voicemail that is stored and transcribed. Custral provides tools to present a recording notice to participants.

Messaging. Custral can send and receive SMS and other messages. Message content and metadata are processed to deliver and display them, and we process opt-out keywords (such as STOP) so recipients can unsubscribe.

You are responsible for consent. Laws on call recording and monitoring vary by jurisdiction — some require the consent of all parties — and laws on marketing and automated messaging (such as the U.S. TCPA, CAN-SPAM, and carrier A2P requirements) require appropriate consent from the people you contact. Obtaining those consents is your responsibility.

05

Website chat widgets

In short

When a customer embeds Custral chat on their site, we process visitors' messages and basic technical data on the customer's behalf.

Custral offers a chat widget that our customers can embed on their own websites. When a visitor interacts with that widget, we process, on the website owner’s behalf, the messages they send and basic technical data such as IP address, device and browser type, the pages visited, and any details the visitor provides. The widget may set cookies or use local storage to maintain the conversation.

The business operating the website is the controller of this data. If you chatted with a business through a Custral widget, please contact that business to exercise your rights.

06

Scheduling and booking pages

In short

When someone books time through a customer's scheduling page, we collect their booking details on the customer's behalf.

Custral customers can publish scheduling pages that let people book meetings with them. When someone books, we collect the information they submit (such as name, email, and answers to booking questions) and the resulting calendar event, and we process it on the customer’s behalf to create and manage the booking. The customer who owns the scheduling page is the controller of that information.

07

Data enrichment and lookups

In short

When you ask Custral to enrich a record, we look up publicly available information about that contact and fill in the fields you requested.

Some features enrich your records by retrieving publicly available information — for example filling in a company detail, a professional profile URL, or an avatar. To do this, Custral may run web searches (via our search provider) and query public sources such as Gravatar or public professional profiles, at your direction, to populate the fields you requested. Enrichment retrieves information that is already publicly available; you are responsible for having a lawful basis to enrich and store data about your contacts.

08

AI features

In short

Content you send to AI features goes to our AI providers to generate output, and isn't used to train their models.

Custral includes AI features — an assistant, drafting and summarizing, call transcription, conversation intelligence and coaching, record enrichment, and question answering. To provide them, the relevant content you submit is sent to our AI subprocessors (listed below) to generate the requested output. Under our agreements with these providers and their applicable API terms, the inputs and outputs you send through their APIs are not used to train their models. In addition, Custral does not use your Customer Data to train its own AI models.

AI-generated output can be inaccurate or incomplete, and the same prompt can produce different results for different users. You are responsible for reviewing output before relying on it. See our Terms of Service for more.

09

Automated processing

In short

AI features assist with things like scoring and routing, but you configure them — we don't use them to make legally significant decisions about people.

Some features use automated processing to suggest, score, route, or prioritize — for example scoring a lead or drafting a reply. These features assist you and are configured by you; Custral does not use them to make decisions that produce legal or similarly significant effects about individuals without human involvement. Where you configure Custral to support such decisions in your own workflows, you are responsible for any notice, human review, or consent your local law requires.

10

Integrations and connected services

In short

When you connect a third-party service, data flows to and from it as needed — governed by that service's own terms.

The Services let you connect third-party accounts and tools — for example Google, Microsoft, Slack, GitHub, HubSpot, Stripe, Zoom, and Notion — using OAuth or API keys you provide. When you do, information flows to and from that service as needed to provide the feature, including syncing external records into Custral. Your use of a connected service is governed by that service’s own terms and privacy policy, and you can disconnect it at any time.

11

Analytics, session replay, and product improvement

In short

We use PostHog on web and mobile for analytics, masked session replay, and error tracking — never for advertising.

We use PostHog to understand how the Services are used, capture masked session replays (text and inputs are masked), and track errors, on both web and mobile. This helps us fix problems and improve the product. We use aggregated and de-identified insights from this data to improve the Services; we do not use it for advertising and do not sell it.

12

Mobile apps

In short

Our mobile apps use push tokens and device info for notifications, and the microphone for calls — all with permissions you control.

Our iOS and Android apps process device information and a push notification token so we can deliver notifications, and — with your permission — access the microphone to place and receive calls. You control these permissions in your device settings, and you can disable notifications or revoke access at any time. Uninstalling the app or signing out detaches your device from your account.

13

Developer platform, API, and webhooks

In short

If you use our API, SDK, or webhooks, event data flows to endpoints you configure — and you're responsible for those endpoints.

Custral offers an API, an SDK, and outbound webhooks. When you create API keys or configure webhooks, we process requests you make and deliver event data to the endpoints you specify. You are responsible for keeping your API keys secure and for the security and lawful use of any endpoint you point Custral at. Access is scoped to what you authorize.

14

How and why we use information

In short

To provide, secure, bill, support, and improve the Services — each with a legal basis under GDPR.

We use Account Data to:

  • Provide, operate, maintain, and secure the Services (legal basis: performance of our contract with you);
  • Process payments and manage your subscription and usage (contract);
  • Provide customer support and respond to your requests (contract and our legitimate interests);
  • Understand usage, debug problems, and improve and develop the Services (legitimate interests);
  • Communicate with you about the Services and, where permitted, send marketing you can opt out of at any time (legitimate interests or consent);
  • Detect, prevent, and address fraud, abuse, and security incidents (legitimate interests);
  • Comply with law and enforce our agreements (legal obligation and legitimate interests).

We process Customer Data only to provide the Services under your instructions and our agreement. Where we rely on legitimate interests, we have balanced those interests against your rights; where we rely on consent, you may withdraw it at any time.

15

How we share information

In short

Only with our subprocessors, the services you connect, and when the law requires it. We never sell your data.

We share information only in these circumstances:

  • Subprocessors. Vetted service providers that run the Services (see the next section). They may process information only to provide services to us and are bound by confidentiality and data-protection obligations.
  • Services you connect. When you authorize an integration or webhook, information flows to that third party as needed to provide the feature.
  • Legal and safety. When required by law or valid legal process, or to protect the rights, safety, and security of our users, the public, or Custral. Where we are permitted to, we will notify you before responding to a request for your data.
  • Business transfers. If Custral is involved in a merger, acquisition, or sale of assets, your information may be transferred; we will notify you and any successor will honor this policy.
  • Aggregated or de-identified data that cannot reasonably be used to identify you.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising.

16

Subprocessors

In short

The vetted providers that help us run Custral — with links to each one.

We rely on the following subprocessors to provide the Services. We keep this list current on this page.

SubprocessorPurposeLocation
Amazon Web ServicesCloud hosting, primary database, object storage, and searchUnited States
MongoDBDocument storage for messages, documents, and related contentUnited States
RedisCaching and background job processingUnited States
CloudflareDNS, content delivery, and network securityGlobal
TwilioVoice calling and SMS/messagingUnited States
NylasEmail, calendar, and contacts synchronizationUnited States / EU
OpenAIAI text generation for AI featuresUnited States
AnthropicAI text generation for AI featuresUnited States
DeepgramSpeech-to-text (call transcription)United States
TavilyWeb search used by AI features and enrichmentUnited States
StripePayment processing and billingUnited States
PostHogProduct analytics, session replay, error tracking, and logsUnited States
Google (Firebase Cloud Messaging)Mobile push notificationsGlobal
ExpoMobile push notificationsUnited States
Gravatar (Automattic)Profile avatar lookupUnited States

We update this list as our providers change. Customers under a Data Processing Addendum receive advance notice of new subprocessors — at least 30 days — and may object on reasonable data-protection grounds. To be notified of changes, email privacy@custral.com.

Connecting a third-party integration (such as Slack, HubSpot, or Zoom) is your choice and is governed by that service’s own terms; those services are not our subprocessors.

17

Data from Google and Microsoft

In short

We follow Google's Limited Use requirements and never use your connected mail or calendar data for advertising.

Custral’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Likewise, our use of data from Microsoft services complies with Microsoft’s applicable terms. We use the data you authorize solely to provide and improve the features you enable, and we do not transfer or use it for advertising.

18

International data transfers

In short

We operate from the United States; transfers from the EEA, UK, or Switzerland rely on Standard Contractual Clauses.

We are based in, and operate the Services from, the United States. If you access the Services from outside the United States, your information will be transferred to and processed in the United States. Where we transfer personal data from the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.

19

How long we keep information

In short

As long as your account is active and we need it for legal reasons — then it's deleted.

We keep Account Data for as long as your account is active and as needed to provide the Services, then retain it only as long as necessary for legitimate business or legal purposes (such as tax, accounting, and dispute resolution). We process Customer Data — including communications, recordings, transcripts, and records — for as long as you instruct us to under your agreement; when your account is closed, we delete or return Customer Data in accordance with your agreement. On account closure you have a 30-day window to export your data; after that, we remove it from active systems within 30 days and from encrypted backups within 60 days.

20

How we protect information

In short

Encryption in transit and at rest, access controls, and a SOC 2 program in progress.

We use technical and organizational measures designed to protect your information, including encryption in transit (TLS) and at rest, access controls, and monitoring. Custral maintains an information-security program and is pursuing SOC 2 examination with an independent auditor. No method of transmission or storage is completely secure, but we work hard to protect your information and will notify you and any affected parties of a data breach as required by law. Learn more on our security page.

21

Your rights and choices

In short

Access, correct, export, delete, object, and opt out — email privacy@custral.com and we'll help.

Depending on where you live, you have some or all of the following rights over your personal information:

  • Access a copy of the information we hold about you, and port it to another service;
  • Correct inaccurate information and delete information we no longer need to keep;
  • Restrict or object to certain processing, and withdraw consent where we rely on it;
  • Opt out of the sale or sharing of personal information (we do not sell or share it), and limit the use of sensitive personal information;
  • Not receive discriminatory treatment for exercising your rights.

If you are in the European Economic Area or the United Kingdom, you also have the right to lodge a complaint with your local supervisory authority. If you are a resident of California or another U.S. state with a privacy law (such as Virginia, Colorado, Connecticut, Utah, or Texas), you have the rights to know, access, correct, delete, and opt out described above; we honor recognized opt-out preference signals (such as Global Privacy Control) where required, and you may appeal a decision by replying to our response. We do not sell or share your personal information.

To exercise any of these rights, email privacy@custral.com. We may need to verify your identity, and authorized agents may submit requests on your behalf. For Customer Data, we act as a processor — please direct your request to the Custral customer that controls your data, and we will help them respond.

To delete your Custral account, open Settings → Security in the app, or — if you can no longer sign in — use our account deletion request form. Deleting your account removes your sign-in and your access to every workspace; work you created inside a workspace belongs to that workspace and stays with it, and requests to remove that data are handled with the workspace’s admins.

22

Children

In short

Custral isn't directed to anyone under 16, and we don't knowingly collect their information.

The Services are not directed to children, and we do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal information, contact us and we will delete it.

23

Changes to this policy

In short

We'll revise the date above and give extra notice for material changes.

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date shown above, and we will provide additional notice for material changes.

24

Contact us

In short

Reach our privacy team at privacy@custral.com. A DPA is available to customers on request.

For any privacy question or request, contact us at privacy@custral.com. A Data Processing Addendum is available to customers on request.