Security & Privacy
Your .zip bundle is parsed in your browser and never uploaded. In a signed-in project,
ivrloom saves a version of the project — its structured IR JSON, not the file — to our servers automatically,
so work is not lost when a browser's data is cleared; a workspace owner or admin can turn that off.
Two more things send data only when you do them — AI assistance and saving a simulator test scenario
— and we tell you exactly what and where. Five9 connected mode, if you use it, passes your Five9
login, the scripts you import and any prompt recording you upload to Five9 through our server without
storing any of them.
Never leaves your browser
-
The
.zipbundle you upload and the.five9ivrXML inside it. -
ZIP parsing, IR transformations, and the visual editor — they run client-side. We have no
backend endpoint that accepts your
.zip. - Your prompt audio files. ivrloom plays them locally, straight from the bundle in your browser — the audio is never uploaded. Converting a file for Five9 with the prompt audio converter happens in your browser too. The one exception is a recording you choose to upload to Five9 in connected mode (below).
Saved to ivrloom automatically (unless your workspace turns it off)
- Saved versions. In a signed-in project, ivrloom saves a version after you import
or upload a bundle and again a few minutes after you edit. Each version is the IR JSON for that
project — which includes skill names, transfer numbers, and your call-flow logic — stored in
our database so you can reopen it across devices and so clearing your browser loses nothing,
along with review titles, descriptions, and comments you write in the app. This covers every script in the bundle, not only the one open on screen, so a multi-flow export can be reopened intact. Your
prompt
.wavaudio is still never uploaded — it stays in your browser, which is why the original.zipremains worth keeping. A workspace owner or admin can turn automatic saving off in the workspace settings; a version is then saved only when someone clicks Save version. The project's owner can delete any saved version from History, or the whole project with all of its versions from the Projects list. (It is stored as JSON in our database; it is not yet separately encrypted at the application layer — see Roadmap.) On the no-signup Try page, nothing is saved to ivrloom.
Leaves your browser — only when you choose it
- AI assistance. When you ask the AI for help, your prompt text and the relevant slice of your IVR are sent to our backend and on to a third-party AI provider (a subprocessor) to generate the response. The assistant reads what it needs from any flow in the loaded bundle, not only the one on screen, so that slice can come from several flows. We name our current subprocessors on request — email hello@ivrloom.com. You can disable AI entirely in account settings so no part of your IVR goes to the AI provider.
- Saved simulator scenarios. In a signed-in project, a test scenario you save in the simulator is stored with the project on our servers — even when automatic saving is off — so it re-runs on any device. It holds the script name, the digits and starting variable values you gave the simulated call, and, if you pin one, the expected outcome: the modules the call reaches, its disposition, and end-of-call variable values. On the no-signup Try page, scenarios stay in your browser.
- Five9 connected mode (Team, or the Solo add-on). Five9's API cannot be called from a browser, so each request carries your Five9 login to our server, which uses it for that request only — to list your IVR scripts and fetch the ones you choose; to read your skill list (with which agents hold each skill and at what level), your inbound campaigns with the script each runs by default and the phone numbers assigned to each, your prompt, disposition and call-variable lists and your Five9 users' names and profiles (never their passwords, email addresses or phone numbers); or to upload a script, create a skill, disposition or prompt, or give a recorded prompt new audio, as you choose (audio is converted in your browser to Five9's format first) — and returns the result. The login, and any script or prompt audio passed to or from Five9, are never written to our database, files or logs. In your browser the login lives in memory, or in this tab's session storage if you tick "Keep it for this tab"; closing the tab or signing out discards it. It writes to Five9 only when you upload a script, create a skill, disposition or prompt, replace a recorded prompt's audio, or assign agents to a skill; it never deletes anything there, and replaces an existing script or a prompt's audio only after you confirm it. We record that you connected and which notice you agreed to, and the name of each thing you write (and, for a recording, its size) — never the login, a script's content, or a prompt's text or audio. Connect with a dedicated Five9 user with the least access your Five9 domain allows. Five9 snapshots stay in your browser unless a member saves one to the workspace (a workspace owner or admin can turn that off); a saved snapshot holds names, counts and script fingerprints, never a script, a password or who holds a skill. How connected mode works.
- Feedback you send us. If you use the in-app feedback button, your message is sent to our servers along with the page you were on, your browser version, and the id of the project you had open — so a bug report is actionable without a round of "which screen were you on?". When a file fails to import, "Report this file" pre-fills the message with the file's name, its size, and the importer's error message; after a crash, the error page offers to send the error details. Nothing is sent unless you press Send, and neither the file nor your IVR content is attached.
- Usage events, if you say yes. The app asks once whether to share which features you use — imported a file, ran the simulator, opened the assistant, reached the AI limit, clicked an upgrade link, saved a version, exported, or the export check opened. An event carries its name, the time, and at most a script-count range (for example "2–5"); never a script, a name, a prompt or any file content, and our server refuses anything outside that list. Off unless you opt in; turning it off on your Account page deletes what was sent. Details.
- Account profile (email, name) for authentication, and the name and description you give a project when you create one while signed in.
- Billing, handled by Stripe — we never see or store card numbers.
How it works
ZIP parsing, IR transformations, and the visual editor all run in your browser. We don't
have a backend endpoint that accepts your .zip — by design. The only data that reaches
our servers is what's described above, and only on your action.
For business & compliance teams
- DPA on request. Need a Data Processing Agreement before sending call-flow data through saved versions or AI? Email hello@ivrloom.com and we'll provide one.
- Subprocessors & data rights. Our current subprocessors, the legal basis for each type of processing, international-transfer safeguards (SCCs), retention periods, and your GDPR/CCPA rights are all itemized in the Privacy Policy.
Roadmap (not yet implemented)
- Encryption at rest for saved version data (today it's stored as JSON in our database).
- End-to-end encryption for saved versions with passphrase-derived keys.
- A self-hosted option for enterprise customers.
- SOC 2 — a goal for a later stage, not yet underway.
Plan limits and AI token usage are covered on Pricing, and common questions are answered in the FAQ.