Scarlett.
Legal

Privacy Policy

Last updated · 15 May 2026  ·  Effective · 15 May 2026

This policy explains how Alta Vena Technologies Ltd (trading as Scarlett, company number 17330369, registered in England and Wales, registered office in London, UK — “we”, “us”, “our”) handles personal data when you use the Scarlett AI service at getscarlett.ai (and the deployed app at the current Vercel preview URL until our DNS cuts over).

We are the data controller for personal data about you, your staff, and the people who call you through Scarlett. We are registered with the Information Commissioner’s Office in the UK.

1. What we collect

We collect data in four buckets: account data you give us when you sign up,configuration data you give us when you set Scarlett up,call data that flows through Scarlett when your callers ring, and technical data we collect automatically to keep the service running.

1.1 Account data

  • Your name, email address, mobile number, business name, and the trade you operate in.
  • The password you set, stored as a salted hash (we can never see the plain text, including during password reset).
  • Billing details — handled by Stripe; we only hold your Stripe customer ID, the last 4 digits of your card, the brand (Visa/Mastercard/etc.), subscription status, period dates, trial-end date. We never see or store your full card number or CVC.
  • VAT number, company number, and registered address if you provide them.

1.2 Configuration data

  • Your services list (job types, prices, descriptions), call scenarios you’ve enabled, custom instructions, and business hours.
  • The voice you’ve picked for Scarlett.
  • Calendar OAuth tokens (Google or Outlook) if you connect a calendar — held encrypted at rest.
  • The Scarlett phone number we’ve allocated to your account.
  • Optional documents you upload to train Scarlett, the text content scraped from your website if you used the wizard’s scraper.

1.3 Call data

  • The caller’s phone number, the time and duration of the call, and which of your Scarlett numbers they called.
  • An audio recording of the call (see retention below).
  • A speech-to-text transcript of both sides of the call.
  • A summary, intent classification (e.g. quote, urgent, booking, complaint), and any structured data Scarlett extracted such as the caller’s name, postcode, or described problem.
  • Any SMS message Scarlett sent to the caller after the call, including the body and the time of delivery.
  • Any booking Scarlett made on your calendar as a result of the call.

Disclosure at call start. The very first thing Scarlett says on every call is a clear statement that the call is recorded and analysed by AI. This satisfies the lawful-basis requirement under UK GDPR. Callers who object can hang up and reach you by another route.

1.4 Technical data

  • The IP address you connect from, browser user-agent, and referrer — used for rate limiting on signup and sign-in, and for basic abuse prevention.
  • Pages visited inside the dashboard and basic interaction timestamps — used to monitor service health.
  • Server-side logs that may contain your account ID and the shape of API requests for debugging. These logs are automatically purged after 30 days.

2. Why we use it (lawful basis)

We rely on three lawful bases under UK GDPR Article 6:

  • Performance of a contract for account creation, subscription management, taking calls on your behalf, sending you operational emails, providing support, and storing the data needed for any of the above.
  • Legitimate interest for keeping the service secure (rate-limiting, fraud detection), improving Scarlett’s conversational quality through aggregated evaluation, and communicating about service changes. We’ve assessed that these uses don’t override your interests; you can object at any time.
  • Legal obligation for retaining billing records (HMRC), responding to lawful information requests, and complying with safeguarding obligations if any.

We do not rely on consent except for cookies that are not strictly necessary (we don’t currently set any), and optional marketing email which you can opt into separately.

3. Who else processes data for us (sub-processors)

Scarlett relies on third-party providers to deliver the service. Each operates as a data processor on our behalf under a contract that meets UK GDPR Article 28. The current list:

  • Supabase (Supabase Inc.) — primary database, authentication, file storage. EU region (Ireland, eu-west-1). Standard Contractual Clauses where applicable.
  • Vercel (Vercel Inc.) — web hosting for the app and marketing site. Edge network worldwide; data at rest in the EU/US.
  • Twilio Inc. — telephony (inbound calls and outbound SMS). US-headquartered with EU points of presence. Data Privacy Framework certified.
  • Speechmatics Ltd — speech-to-text for dictation inside the app. No longer used on phone calls. UK-based; audio is processed in the EU.
  • Anthropic PBC — the Claude large language model that powers Scarlett’s conversation. US-based; SCCs in place. Anthropic confirms inputs and outputs are not used to train Anthropic’s public models when accessed via the API.
  • ElevenLabs Inc. — handles the live call end to end: speech recognition, the conversation itself, and the voice you hear. Also used for the in-app “try her out” feature. US-based; SCCs in place.
  • Stripe Payments UK Ltd — payment processing and the customer portal. Stripe handles all card data directly; we never receive it.
  • Twilio SendGrid — transactional email delivery (signup confirmation, password reset, billing notifications). US-based; SCCs in place.
  • PostHog — product analytics, so we can see which parts of Scarlett are used and where signup goes wrong. Hosted in the EU (Frankfurt). We do not record sessions and we do not send call recordings, transcripts or your customers’ details to it. Analytics requests are proxied through our own domain, so the data goes to us first.

Where any of the above are based outside the UK or the EEA, we transfer personal data under Standard Contractual Clauses, the UK International Data Transfer Addendum, or the UK Extension to the EU-US Data Privacy Framework as appropriate. We do not transfer data to any country that the ICO considers not to provide adequate protection without one of those mechanisms in place.

We’ll update this list when we add or remove sub-processors and notify you by email if a change affects you materially.

4. AI processing and training

Scarlett is built on third-party AI models (ElevenLabs for speech recognition and voice, Claude for language understanding). When a call comes in, the live audio stream is sent to those services on a per-request basis solely to handle that call. When you dictate inside the app, that audio goes to Speechmatics instead, on the same per-session basis. Our contracts with those providers confirm that:

  • Inputs and outputs are not used to train the providers’ public AI models when accessed via the API on our paid plans.
  • The providers act as our processors and only use the data to provide the service to us, not for their own purposes.

We may use anonymised or aggregated metrics derived from multiple customers (for example, average call duration, transcript-quality scores, common caller intents) to evaluate and improve Scarlett. We never use one customer’s raw call content to train any model that other customers use.

5. How long we keep it

  • Account, profile, configuration data: while your account is active, plus up to 90 days after closure (operational tail).
  • Call recordings (audio): 90 days by default.
  • Call transcripts and summaries: kept while your account is active; deleted within 30 days of account closure.
  • Server logs: automatically purged after 30 days.
  • Billing records (invoices, payment events): 6 years from the end of the relevant tax year, in line with HMRC requirements.
  • Stripe records on Stripe’s side: governed by Stripe’s own retention schedule, see stripe.com/privacy.

On account closure or written request, we’ll delete all data we hold about you within 30 days, except where we are obliged to retain it for legal reasons (e.g. billing records).

6. Your rights under UK GDPR

You have the right to:

  • Access the personal data we hold about you and receive a copy.
  • Rectify inaccurate data and complete data that is incomplete.
  • Erase your data in the circumstances allowed by law. We aim to action erasure requests within 30 days.
  • Restrict our processing while you challenge its accuracy or our lawful basis.
  • Object to processing based on legitimate interest, including for direct marketing (we don’t currently do direct marketing).
  • Portability — receive your data in a structured, machine-readable format so you can move it to another provider.
  • Withdraw consent at any time where we’ve relied on consent. Withdrawing consent doesn’t affect the lawfulness of processing done before withdrawal.

To exercise any of these rights, email hello@getscarlett.ai. We’ll verify your identity (so we don’t hand your data to someone else) and respond within one calendar month.

If you’re unhappy with how we’ve handled your data, you also have the right to complain to the Information Commissioner’s Office at ico.org.uk. We’d appreciate the chance to put things right first.

7. Callers’ rights

People who call your Scarlett number have the same rights as you, but their relationship is primarily with you (your customer-of-customer relationship is governed by whatever agreement they have with your business). You and we are each independent controllers for their data: we process it to provide the receptionist service to you, and you process the outputs (lead, booking, summary) for your own business purposes. If a caller contacts us directly to exercise their rights, we’ll forward the request to you so you can act on it; we’ll also action our own side directly where it makes sense (e.g. shortening the retention window for a specific recording).

8. Security

We take security seriously:

  • All data in transit between you, our systems, and our sub-processors is encrypted using TLS 1.2 or higher.
  • Data at rest in our primary database is encrypted using AES-256 (Supabase Postgres).
  • Row-level security policies enforce that no customer can read or write another customer’s data, even via the API.
  • Our service-role keys are restricted to two specific server-side endpoints (Stripe webhook + signup write-back) and never exposed to the browser.
  • Our voice service runs as a non-root user inside a hardened container.
  • Access to production systems by Scarlett AI staff requires multi-factor authentication.
  • We run regular security audits and update sub-processor contracts as their certifications and standards evolve.

Despite all that, no system is perfectly secure. If we ever suffer a data breach that affects you, we’ll notify both you and the ICO within the timeframes UK GDPR requires.

Support access to your account

To help you when something goes wrong, a member of our support or account-management team can open your account and see what you see — your calls, messages, customers and settings. We do this to diagnose problems that we cannot reproduce from our own systems.

Every time it happens:

  • The person has to sign in with multi-factor authentication and write down a reason first.
  • We record who they were, whose account they opened, when, and why. Those records are kept for our audit log.
  • The session ends automatically after 30 minutes.
  • They cannot send messages to your customers, change your billing, change where your calls are transferred, buy you a phone line, or delete your account. Those actions are blocked outright while they are acting on your behalf.

We don’t email you each time, because it usually happens during a support conversation you started. If you’d like a record of when staff have opened your account, ask us and we’ll send you one.

9. Cookies and similar technologies

We use a small number of cookies and similar local-storage entries:

  • An essential session cookie set by Supabase Auth so that you stay signed in.
  • A CSRF protection token set by our framework.
  • A short-lived signup token in component state during the signup wizard so the Stripe payment step can identify you without leaking email addresses.
  • A scarlett-theme localStorage entry that remembers whether you’ve opted into dark mode.

None of these are used for advertising, behavioural tracking across other sites, or audience profiling. We don’t set third-party analytics cookies. If we ever add any, we’ll add a proper consent banner first.

Our product analytics (PostHog, listed in section 3) is deliberately configured to store nothing on your device — no cookie, no local storage. It counts page views and signup steps within a single visit so we can see where the product is confusing, and it cannot recognise you when you come back. That is why it needs no consent banner and why the paragraph above is still true.

10. Children

Scarlett is sold for business use and is not aimed at children. We don’t knowingly collect personal data from anyone under 16. If you believe a child has signed up or had their data captured on a call to a Scarlett number, contact us so we can delete it.

11. Changes to this policy

We may update this policy. The version published at this URL is always the current one and the date at the top is updated when it is. If we make material changes to how we handle your personal data, we’ll email you at the address on file at least 30 days before the change takes effect.

12. Google user data (Calendar and Gmail)

If you connect Google, Scarlett asks for two scopes and nothing wider. This section sets out exactly what we do with the data each one gives us.

  • Google Calendar events (https://www.googleapis.com/auth/calendar.events) — used for two things only. To read when you are already busy, so Scarlett never offers a caller a time you cannot make; and to write an appointment into your calendar when she books one. When we read your calendar we take the start and end times of your events and nothing else — not titles, not attendees, not locations, not descriptions. Your colleagues on the same Scarlett account see those periods marked only as “Busy”.
  • Gmail send (https://www.googleapis.com/auth/gmail.send) — used only to send a reply you have written, from your own address, when you reply to a customer from your Scarlett inbox. It is a send-only permission. Scarlett cannot read your mailbox: we deliberately do not request gmail.readonly or any other read scope, so no email you have received is ever accessible to us.

How the connection is stored. The OAuth tokens Google issues are encrypted with AES-256-GCM before they are written to our database and are only ever decrypted on our servers at the moment a request is made. Disconnecting Google on the Integrations page deletes them.

Limited Use. Scarlett’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not and will not: transfer Google user data to others except as needed to provide or improve the features you have asked for, to comply with applicable law, or as part of a merger or acquisition; use it for advertising; sell it; or allow humans to read it, other than where you have given us specific permission, where it is necessary for security purposes such as investigating abuse, or where the law requires it.

We do not train models on it. Google Calendar and Gmail data is never used to train or fine-tune any AI model, ours or a third party’s. See section 4.

13. Contact

For privacy questions, requests under UK GDPR, or to flag a concern, email hello@getscarlett.ai. Postal correspondence can go to Alta Vena Technologies Ltd, registered office in London, UK — full address available on request or on Companies House (company number 17330369).

Privacy Policy — Scarlett AI