Privacy Policy
Last updated: July 11, 2026
ivrloom is a browser-based editor for Five9 IVR scripts. This policy explains, in plain terms, what data reaches our servers and what never does. The short version: your IVR bundle is processed in your browser by default, and only leaves your device for two features you explicitly choose — AI assistance and Cloud Save.
Who we are
ivrloom is operated by ivrloom, a sole proprietorship based in California, United States, which is the data controller for the personal data described in this policy. You can reach us about privacy or data-protection matters at [email protected].
What stays on your device
The .zip / .five9ivr bundle you open, and all parsing, editing, and
simulation, run client-side in your browser. We have no endpoint that receives your
.zip. Your prompt audio files are never uploaded — ivrloom reads and plays them
entirely in your browser.
What we collect
- Account data — your email and name, used for authentication.
- Billing data — handled by Stripe. We never receive or store card numbers.
- Cloud Save data (opt-in) — if you save a project to the cloud, we store its IR JSON (which includes skill names, transfer numbers, and call-flow logic), along with other project data you create in the app — review titles, descriptions, and comments, and saved simulation scenarios — in our database so you can reopen them. You can delete it at any time.
- Collaboration data — if you invite someone to a project or workspace, we store the email address you enter and send them an invite email that includes your name and the project or workspace name; members of a shared workspace or shared project can access the Cloud Save projects in it.
- AI request data (opt-in) — when you use AI assistance, your prompt text and the relevant slice of your IVR are sent to our backend and on to our AI provider to generate a response. You can disable AI in account settings.
- Operational logs — standard request/error logs for reliability and security.
Subprocessors
- Anthropic — processes AI requests (your prompt + the IR slice you send) to generate responses.
- Stripe — payment processing.
- Resend — delivers transactional email (verification, password reset, invites); processes recipient email addresses and names.
- Cloudflare — network and edge provider; traffic to our servers is routed and TLS-terminated at Cloudflare's edge.
We do not sell your data, and we do not use your IVR content to train models.
Legal basis for processing (GDPR)
- Contract — account and billing data, to provide the service you sign up for.
- Consent — AI request data. You opt in by using AI assistance and can withdraw consent at any time by disabling AI in account settings.
- Legitimate interest — operational and security logs, to keep the service reliable and secure.
International data transfers
Our subprocessors (including Anthropic, Stripe, and Cloudflare) process data in the United States. Where personal data is transferred from the EEA, UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (SCCs), or the subprocessor's equivalent approved safeguards, as the transfer mechanism.
Cookies
ivrloom uses only strictly-necessary cookies: a Keycloak single-sign-on session cookie for authentication, and cookies Stripe sets during checkout. The app stores your sign-in token in your browser's local storage. We set no advertising or analytics tracking cookies, so no consent banner is required.
Your rights
Depending on where you live, you have some or all of the following rights over your personal data. To exercise any of them, email [email protected]; we respond within 30 days.
- Under the GDPR (EEA/UK) — access, rectification, erasure, restriction, portability, and objection; the right to withdraw consent; and the right to lodge a complaint with your local supervisory authority.
- Under the CCPA/CPRA (California) — the right to know, delete, and correct your personal information, and to opt out of its sale or sharing. We do not sell or share personal information, and we will not discriminate against you for exercising your rights.
Data Processing Agreement
Business customers who need a Data Processing Agreement (DPA) — for example, to cover Cloud Save or AI processing of call-flow data — can request one at [email protected].
Security & retention
Data in transit is encrypted (HTTPS). Cloud Save data is currently stored as JSON in our database; application-layer encryption at rest is on our roadmap (see Security).
- Account & Cloud Save data — retained for as long as your account is active. You can delete Cloud Save projects yourself at any time.
- Operational logs — retained for up to 90 days, then deleted or aggregated.
- AI usage records (token counts and timestamps, used to enforce plan limits) — retained for the current and prior billing periods.
- Account deletion — email us and we delete your account and associated data within 30 days.
Your choices
- Use ivrloom entirely offline — never use Cloud Save or AI — and nothing about your IVR reaches us.
- Disable AI in account settings.
- Delete saved projects, or request full account deletion.
Contact
ivrloom, a sole proprietorship based in California, United States. Questions or data requests: [email protected].