Privacy Policy
Last updated: October 2, 2026
ivrloom is a browser-based editor for Five9 IVR scripts. This policy explains, in plain
terms, what data reaches our servers and what never does. The short version: your
.zip bundle is parsed in your browser and never uploaded. In a signed-in project,
a version of the project — its parsed IR JSON, not the file — is saved to our servers automatically,
unless a workspace owner or admin turns that off. Other parts of your IVR reach us only when you
use AI assistance or save a simulator test scenario in a signed-in project. If you use Five9 connected
mode, your Five9 login and the scripts you import pass through our server on their way between
Five9 and your browser; we store neither.
Who we are
ivrloom is operated by ivrloom, a sole proprietorship based in California, United States, which is the data controller for the personal data described in this policy. You can reach us about privacy or data-protection matters at hello@ivrloom.com.
What stays on your device
The .zip / .five9ivr bundle you open, and all parsing, editing, and
simulation, run client-side in your browser. We have no endpoint that receives your
.zip. Your prompt audio files are never uploaded — ivrloom reads and plays them
entirely in your browser, and converting audio for Five9 happens in your browser too. The
one exception is a recording you choose to send to Five9 in connected mode — a new prompt,
or new audio for one Five9 already has — described below.
What we collect
- Account data — your email and name, used for authentication.
- Billing data — handled by Stripe. We never receive or store card numbers.
- Project records — when you create a project while signed in, we store the name and description you give it, who can access it, and whether it is archived.
- Saved version data (automatic unless your workspace turns it off) — in a signed-in
project, ivrloom saves a version after you import or upload a bundle and again a few minutes
after you edit, and whenever you click Save version. We store its IR JSON (which includes skill
names, transfer numbers, and call-flow logic) — not your original
.zipor.five9ivrfile, and never your prompt audio — along with review titles, descriptions, and comments you write in the app, in our database so you can reopen them and so clearing your browser loses nothing. A workspace owner or admin can turn automatic saving off in the workspace settings. The project's owner can delete a saved version, or the whole project, in the app. On the no-signup Try page, nothing is saved. - Saved simulator scenarios — when you save a test scenario in the simulator of a signed-in project, it is stored with that project on our servers whether or not you have saved a version, so it can be re-run on any device. A scenario holds the script name, the inputs you gave the simulated call (digits pressed and starting variable values) and, if you pin one, the expected outcome — which modules the call reaches, its disposition, and variable values at the end of the call. On the no-signup Try page, scenarios stay in your browser.
- Feedback and error reports (only when you press Send) — a message you send from the in-app feedback button reaches us with the page you were on, your browser version, and the id of the project you had open. If a file fails to import, "Report this file" pre-fills that message with the file's name, its size, and the error the importer showed; if the app crashes, the error page can send the error details, the page address and your browser version. The file itself and your IVR content are never attached, and nothing is sent until you press Send.
- Collaboration data — if you invite someone to a project or workspace, we store the email address you enter and send them an invite email that includes your name and the project or workspace name; members of a shared workspace or shared project can access the saved projects in it.
- AI request data (opt-in) — when you use AI assistance, your prompt text and the relevant slice of your IVR are sent to our backend and on to our AI provider to generate a response. You can disable AI in account settings.
- Five9 connected mode (opt-in, Team or the Solo add-on) — Five9's API cannot be called from a browser, so when you connect, each request carries your Five9 login to our server, which uses it for that one request and returns the result: the list of IVR scripts, the scripts you choose to import, your skill list (with which agents hold each skill, by user name and skill level), your inbound campaigns with the script each runs by default and, when you map them, the phone numbers (DNIS) assigned to each, your prompt, disposition and call-variable lists, your Five9 users' names and profiles (to assign agents to a skill — never their passwords, email addresses or phone numbers), or what you send to Five9: a script you upload, a skill, disposition or prompt you create, or new audio for an existing recorded prompt — for a recording, its audio, converted in your browser to Five9's format before it is sent. We never write the login, or any script or prompt audio passed to or from Five9, to our database, files or logs. In your browser the login is held in memory, or for the current tab if you ask; closing the tab or signing out discards it. We record that you connected — your account, the workspace, the time and the version of the notice you agreed to — never the login — and, for each thing you write, its name and when (and a recording's size) — never a script's content, or a prompt's text or audio. Phone numbers read from Five9 are shown to you and not stored by us. Connected mode writes to Five9 only when you upload a script, create a skill, disposition or prompt, replace a recorded prompt's audio after typing its name, or assign agents to a skill, and never deletes anything there. What you import is then yours to edit like any other file, and saving a version of it is covered above.
- Five9 snapshots kept in ivrloom (Team or the Solo add-on; on unless a workspace owner or admin turns it off) — a member can save a Five9 snapshot they took to the workspace, by choosing "Save to workspace"; nothing is saved otherwise. A saved snapshot holds the names of your Five9 skills, prompts, dispositions, call variables and inbound campaigns, which script each campaign runs by default, a fingerprint (SHA-256) of each script — never its content — how many agents hold each skill — never who — the Five9 user name it was read with (never the password), and which member saved it. Every member of the workspace can see it. It is kept until the member who saved it or a workspace owner or admin deletes it, until an owner or admin turns the setting off and deletes them, or until the workspace is deleted.
- Operational logs — standard request/error logs for reliability and security.
- Usage events (opt-in) — see Usage analytics below. Off unless you say yes.
Usage analytics
The app asks you once, after you sign in, whether to share usage events. Nothing is collected unless you answer yes, and not answering counts as no. If you say yes, your browser reports these events, linked to your account:
- you imported a file, with how many scripts it held as a range (1, 2–5, 6–20 or 21+);
- you ran the simulator;
- you opened the AI assistant;
- the assistant reached your plan's monthly limit;
- you clicked an upgrade link, with where it was (the assistant or the billing page);
- you saved a version, with the script range;
- you exported a
.zip, with the script range; - the export check opened because it found something to warn about;
and the time of each. An event never contains a script, script or node name, variable, prompt, skill, phone number or any other file content. Our server accepts only the events and ranges listed here and refuses anything else. We use the events to learn which parts of the product people reach and where they stop, and — if you receive product-update email — to choose which of those emails is relevant (for example, how to run the simulator after you have imported a file but not yet tried it). We use them for no other purpose. They are not shared with anyone and no third-party analytics service is involved.
To withdraw, turn off Share usage events on your Account page. Collection stops at once and the events already sent are deleted. Events are otherwise kept while your account exists and deleted with it.
Email we send
Two kinds, governed differently. Account email — confirming your address, resetting your password, project and workspace invitations — is necessary to provide the service, so it is sent on the basis of performing our contract with you and cannot be switched off while you have an account. If you registered but never confirmed your address, we may send one reminder with a fresh confirmation link, once per account.
Product updates are of two sorts: a note to everyone about what has shipped, and short tips sent to people who are at a particular point in using the product. To pick who receives a tip we use account and usage facts we already hold: whether you have created a project, whether you have ever saved a version, whether you have ever used AI assistance, whether a request was refused in the last day because your AI allowance ran out, when you last signed in, and — if the latest saved version of a project you own lists holiday dates — the last of those dates, so we can remind you before the list runs out. If you chose to share usage events, we may also use them — for example, that you imported a file but have not run the simulator yet. Each message is sent to you at most once, you receive at most one tip in any seven days, and we do not email accounts that have not signed in for six months. Every send is started by a person on our side, not by an automatic schedule. They are sent on the basis of legitimate interest in keeping our own customers informed, and you can stop all of them at any time with the unsubscribe link in any of them, the one-click control your mail app shows, or the Product update emails switch on your Account page. The link opens a page with an Unsubscribe button; it works without signing in and takes effect as soon as you press it.
We record that you opted out, and when, because we have to honour it. We do not use tracking pixels or per-recipient click tracking, and the contents of your IVR scripts are never included in an email. See Email preferences.
Subprocessors
- A third-party AI provider — processes AI requests (your prompt + the IR slice you send) to generate responses. We identify the current provider on request, and notify customers before we change it.
- Stripe — payment processing.
- Resend — delivers our email: account messages (verification, password reset, invites) and product updates; processes recipient email addresses and names.
- Cloudflare — network and edge provider; traffic to our servers is routed and TLS-terminated at Cloudflare's edge. Cloudflare also provides aggregate, cookieless analytics for this website (page views by path, referrer, country, browser, operating system, and device type) with no cookies, local storage, or fingerprinting.
Five9 is not our subprocessor: in connected mode our server reads from your Five9 account, at your instruction, under your agreement with Five9.
We do not sell your data, and we do not use your IVR content to train models.
Legal basis for processing (GDPR)
- Contract — account and billing data, to provide the service you sign up for; and relaying Five9 connected mode requests, which you start and which we perform for you.
- Consent — AI request data. You opt in by using AI assistance and can withdraw consent at any time by disabling AI in account settings. Usage events, which are collected only after you say yes and which you can withdraw on your Account page (see Usage analytics).
- Legitimate interest — operational and security logs, to keep the service reliable and secure; product-update email to existing account holders, including choosing who receives a tip from the account and usage facts listed under "Email we send", which you can stop at any time with the unsubscribe link in any such message or on your Account page; and feedback and error reports you choose to send, to answer them and fix what they describe.
International data transfers
Our subprocessors (including Stripe and Cloudflare, and our AI provider) process data in the United States. Where personal data is transferred from the EEA, UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (SCCs), or the subprocessor's equivalent approved safeguards, as the transfer mechanism.
Cookies
ivrloom uses only strictly-necessary cookies: a Keycloak single-sign-on session cookie for authentication, and cookies Stripe sets during checkout. The app stores your sign-in token in your browser's local storage. We set no advertising or analytics tracking cookies, so no consent banner is required.
Your rights
Depending on where you live, you have some or all of the following rights over your personal data. To exercise any of them, email hello@ivrloom.com; we respond within 30 days.
- Under the GDPR (EEA/UK) — access, rectification, erasure, restriction, portability, and objection; the right to withdraw consent; and the right to lodge a complaint with your local supervisory authority.
- Under the CCPA/CPRA (California) — the right to know, delete, and correct your personal information, and to opt out of its sale or sharing. We do not sell or share personal information, and we will not discriminate against you for exercising your rights.
Data Processing Agreement
Business customers who need a Data Processing Agreement (DPA) — for example, to cover saved versions or AI processing of call-flow data — can request one at hello@ivrloom.com.
Security & retention
Data in transit is encrypted (HTTPS). Saved version data is currently stored as JSON in our database; application-layer encryption at rest is on our roadmap (see Security).
- Account, project & saved version data — retained for as long as your account is active. A project's owner can delete any saved version from the editor's History list (a pull request that compares that version is deleted with it), or delete the whole project — with its saved versions, pull requests and saved scenarios — from the Projects list, at any time. Your personal workspace itself cannot be deleted from the app; deleting your account removes it.
- Operational logs — retained for up to 90 days, then deleted or aggregated.
- AI usage records (for each AI request: the account, the workspace and project it was charged to, the model, token counts, an estimated cost and a timestamp — never the prompt or your IVR content) — kept for as long as your account exists and deleted with it. Plan limits count only the current calendar month. Records of AI requests that were refused (the reason, the token estimate and a timestamp) are kept too; if your account is deleted they are kept without any link to it. Corrected 25 September 2026: this policy previously said AI usage records were kept only for the current and prior billing periods. No such deletion was ever in place; the records have been kept for the life of the account, as described here.
- Usage events (opt-in) — kept while your account exists and your consent stands; deleted when you turn sharing off or when your account is deleted.
- Account deletion — email us and we delete your account and associated data within 30 days.
Your choices
- Use ivrloom without saving a version, saving a simulator scenario, or using AI — or use the no-signup Try page — and nothing from your IVR reaches us.
- Disable AI in account settings.
- Leave usage events off, or turn them off on your Account page at any time, which also deletes the events already sent.
- Turn off product update emails on your Account page, or with the link in any of them.
- Delete saved versions and projects you own in the app, or email us to delete your whole account.
Contact
ivrloom, a sole proprietorship based in California, United States. Questions or data requests: hello@ivrloom.com.