Privacy Policy
Effective Date: January 1, 2026 | Last Updated: September 24, 2026
1. Overview & Controller Identity
Aevra AI ("Aevra," "we," "our," or "us") is an enterprise-grade AI voice receptionist and customer conversation orchestration software system operated by THORE Agency ("THORE"), headquartered in Sacramento, California.
This Privacy Policy sets forth the principles, security standards, and legal bases under which we collect, process, transmit, and safeguard personal information obtained through our marketing site (aevra.thoreagency.com), client portals (portal.thoreagency.com), and inbound telephony automation systems deployed on behalf of business subscribers.
By placing calls to an Aevra-enabled telephone number, initiating an interactive browser voice demo, submitting lead forms, or subscribing to our software, you acknowledge and agree to the information practices described herein.
2. Two-Party Consent & Voice Recording Disclosures
Explicit Notice of Real-Time Audio Processing: When interacting with an Aevra AI-powered phone line, phone forwarding trunk, or web voice demo:
- Inbound and outbound telephone audio streams are monitored, recorded, and converted to textual transcripts in real time using automated speech-to-text (STT) models and natural language processing pipelines.
- Audio processing is conducted strictly to enable conversational interaction: answering business inquiries, extracting service requirements, assessing emergency dispatch criteria, and scheduling calendar bookings.
- Two-Party Consent Compliance: In jurisdictions requiring two-party or all-party recording consent (including California Penal Code § 632, Florida, Pennsylvania, and others), Aevra agents are configured with mandatory initial automated audio notices informing the caller that the line is recorded or powered by an automated AI assistant.
- Tenant Isolation Guarantee: Voice audio and transcript data captured for one subscriber business are compartmentalized with cryptographic and logical database isolation. Data from one client is strictly inaccessible to any other business subscriber.
3. Information We Collect
We collect information across three primary channels: directly from callers during telephone calls, directly from agency clients registering for software access, and automatically via web telemetry:
A. Caller & Lead Information
Caller ID phone numbers, caller names, requested service addresses, job descriptions, urgency indicators, booking dates/times, and full audio recordings with matched transcripts.
B. Client Account & Billing Data
Business owner legal name, corporate business name, billing email, notification phone numbers, CRM integration credentials, and tokenized payment identifiers. Credit card transactions are processed directly by Stripe under PCI-DSS Level 1 compliance; Aevra never retains raw cardholder account numbers.
C. Device & Network Telemetry
IP addresses, browser client configurations, HTTP referral headers, session timestamps, and web interaction logs collected to monitor system performance, mitigate DDoS attacks, and enforce rate limits.
4. How We Use Information & AI Model Safeguards
We process collected data exclusively for legitimate operational purposes:
- Synthesizing and streaming dynamic voice conversations to address caller questions and schedule service calls.
- Dispatching real-time lead summaries and appointment confirmations via SMS and email to business owners and callers.
- Syncing call details directly to authorized client CRMs (e.g., ServiceTitan, Housecall Pro, Jobber, GoHighLevel, Google Sheets).
- Diagnosing call latency, acoustic echo, and speech recognition accuracy.
Neither Aevra nor THORE Agency sells private client call recordings or caller transcripts. Private client conversation transcripts are never contributed to public, foundational large language model (LLM) training datasets.
5. Authorized Sub-Processors & Third-Party Services
To deliver real-time voice intelligence, telephony switching, and secure cloud infrastructure, we engage vetted third-party sub-processors bound by strict confidentiality and data protection agreements:
- Retell AI & Deepgram: Low-latency automated speech recognition (ASR), voice synthesis, and conversation turn-taking.
- Twilio Inc.: Carrier SIP trunking, telephone number routing, and 10DLC-registered A2P SMS transmission.
- Vercel Inc.: Global edge hosting, serverless computing, and web content delivery.
- Google Cloud / Firebase: Secure multi-region encrypted document storage and authentication.
- Stripe, Inc.: Payment orchestration and recurring subscription billing infrastructure.
6. SMS, TCPA & 10DLC Messaging Terms
When clients or callers request callbacks, confirm appointments, or submit online inquiries, they provide express consent to receive automated transactional SMS notifications.
- Message frequency varies based on appointment volume and caller interaction.
- Standard message and data rates may apply depending on your cellular service provider.
- You may opt out of SMS communications at any time by replying
STOPto any message received. - For assistance, reply
HELPor contact customer support at thoreaiagency@gmail.com.
7. Data Retention & Security Standards
We enforce comprehensive administrative, physical, and technological security controls designed to safeguard your information:
- Encryption: All data in transit is protected using TLS 1.3 encryption. Stored transcripts and database assets are encrypted at rest using AES-256 standards.
- Retention Periods: Call transcripts and summaries are retained for the duration of the client's active subscription to provide historical reporting and CRM synchronization. Clients may configure automated audio purge windows (e.g., 30-day, 60-day, or 90-day retention policies).
- Access Controls: Database records are protected by strict role-based access controls (RBAC) and programmatic isolation keys.
8. California Consumer Privacy Rights (CCPA / CPRA)
California residents possess statutory rights under the California Consumer Privacy Act and California Privacy Rights Act:
- Right to Know & Access: You may request the categories and specific pieces of personal information collected about you over the preceding 12 months.
- Right to Deletion: You have the right to request the permanent deletion of your personal records and call logs across our primary systems and third-party storage.
- Right to Correction: You may request correction of inaccurate personal records.
- Zero Sale of Personal Information: We do not sell or share personal consumer information for cross-context behavioral advertising.
- Right to Non-Discrimination: You will not face denial of service, altered pricing, or diminished service quality for exercising your privacy rights.
9. GDPR Compliance (EEA & UK Users)
For individuals residing in the European Economic Area (EEA) or United Kingdom, processing of personal information is conducted under lawful bases established by the General Data Protection Regulation (GDPR):
- Contractual Necessity: Processing required to fulfill software and receptionist obligations to business subscribers.
- Legitimate Interests: Securing network endpoints, preventing fraudulent telephony attacks, and maintaining service reliability.
- Consent: Express consent granted by callers during voice interactions and SMS confirmations.
10. Children's Privacy (COPPA)
Our website and voice receptionist services are engineered exclusively for commercial and business service operations. We do not knowingly solicit or collect personal information from individuals under the age of 16. If we discover that personal information of a minor has been inadvertently collected, we will take immediate steps to delete the data permanently.
11. Privacy Requests & Contact Information
To exercise your rights to access, update, or permanently delete personal call records or business details, please submit a written request to our designated privacy desk:
THORE Agency / Aevra Compliance Desk
Email: thoreaiagency@gmail.com
Web: https://www.thoreagency.com
Location: Sacramento, CA, United States