Privacy
Last updated: 1 September 2026
Parrot connects a small Bluetooth board to a phone line and lets an AI assistant speak on that line. That means Parrot handles phone calls — including the voice of the person on the other end. This page says exactly what we store, who else sees it, and how to get it deleted.
Parrot is a product of ParrotVoice, LLC, a Delaware limited liability company based in Seattle, Washington, United States (parrotvoice.app). For anything on this page — questions, access requests, deletion requests — write to admin@parrotvoice.app.
What we collect
Your account. When you sign in with Google, Apple, or GitHub we receive and store your email address, that provider's own account identifier for you, and your display name. That is all we ask for: Parrot never gets access to your repositories, your contacts, your files, or the ability to send mail as you. We never see your password — it stays with that provider. An invitation key creates a private account without sending sign-in data to a third party; the key itself is stored only as a hash.
Your devices. For each board bound to your account: its device identifier, the Bluetooth name you flashed onto it, its hardware address, its firmware and bridge versions, and link-quality measurements (signal strength, audio buffer health, frame loss) used to diagnose call quality.
Call records. For every call: the phone number of the other party, whether the call was placed or received, when it started and ended, how it ended, and its duration.
Call content. Parrot records the audio of both sides of the call, produces a transcript, and after the call generates a written summary — plus any specific fields your assistant is configured to extract. The assistant instructions you write are stored with their revision history.
Billing. Your credit balance and the ledger of every grant and charge. API keys are stored only as a hash — we cannot show you a key again after you create it. Provider keys you supply yourself are encrypted before being stored.
Who else sees it
Parrot cannot work without sending call content to other companies. These are all of them:
| Who | What reaches them | When |
|---|---|---|
| The AI voice provider your assistant uses — OpenAI, Google (Gemini), Ultravox, or 火山引擎 (Doubao) | Live call audio and text, in real time | During every call |
| Anthropic | The call transcript | After the call, to write the summary |
Google Cloud (region us-central1, United States) |
Everything above, at rest — database, recordings, logs | Continuously |
| Google, Apple, or GitHub | Only your sign-in. They receive no call data of any kind. | When you sign in with that provider |
If you configure Parrot with your own provider key, your calls go to the provider you chose under your own account instead of ours. The audio still passes through Parrot's servers on its way there.
We do not sell your data, and we do not use your calls, recordings, or transcripts to train any model of our own.
Recording calls is your responsibility
Parrot records both sides of the call. The person on the other end is not told this by Parrot. Laws on recording phone calls differ by country and by state, and many require the consent of everyone on the line. You are responsible for complying with the law that applies to you and to the people you call — including telling them they are being recorded where that is required, and following the rules on automated and marketing calls.
How long we keep it
Today Parrot deletes nothing automatically: your calls, recordings, transcripts and summaries stay until you ask us to remove them or your account is deleted. We would rather tell you that plainly than publish a retention period we do not enforce.
To delete your data, write to admin@parrotvoice.app from the address you sign in with. We remove your account, its device bindings, call records, recordings and transcripts. There is no self-service delete button yet.
One limit worth stating clearly: audio and text already sent to an AI provider during a call are held under that provider's own retention policy, and our deletion cannot reach into their systems.
Your choices
- See what we hold. The console shows your devices, every call, its recording, its transcript and its report.
- Get a copy or have it deleted. Email us; we will act on it.
- Keep calls off our shared provider accounts. Configure your own provider key.
- Stop entirely. Unplug or unbind the board — with no board connected, no call can be placed or answered.
Security
Traffic to the console and to the boards runs over TLS. Session cookies are signed and expire. Every API key is bound to one device, stored hashed, and revocable from the console. Provider keys you supply are encrypted at rest.
The trust model behind those mechanics — how a board and the server prove themselves to each other, and what one key can and cannot reach — is on Security & trust.
No system is perfect, and Parrot is a young one. If you find a security problem, please write to the address above.
Children
Parrot is not directed at children and is not intended for anyone under 16.
Changes
If this page changes materially we will update the date at the top and, for anything that affects how your call data is handled, tell account holders by email.