Privacy policy
Last updated: 5 October 2026
This is a translation. In case of any discrepancy the Italian version prevails.
This policy is for people who open an Idra account, visit this site, try the assistant from the page or leave their number to be called back. If you called a business that uses Idra, the notice for you is this one. No numbered clauses: every number you read is the one the system actually applies. The Italian version is the authoritative one.
Who we are
Idra is a service that answers the phone for you, run by Francesco Vitale, sole trader, Via della Repubblica 51, 95040 Ramacca (CT), Italy — VAT IT06178100878. For anything to do with personal data write to info@ciaoidra.com.
We wear two hats. For your account data, for people who leave their number on the site and for people who try the assistant from the page we are the controller: we decide why and how it is processed. For the data of the people who call your business the controller is you, and we are the processor (art. 28 GDPR): we process it only to make the service work for you, on your instructions.
The rules of that second relationship are in the data processing agreement, which you accept when you sign up or, if you pay through a payment link, by ticking the box that refers to it before paying; the commercial conditions are in the terms.
What we collect
Account and business. Email and password (hashed by Supabase, our database provider: we never see it), first and last name, business name, business phone and email, address, city, timezone, working hours, service radius, the rules you write for the assistant, your Telegram chat id and, if you turn that channel on, your WhatsApp number with the date you opted in. If you ask us to put some callers straight through to you, those contacts' numbers with a label. If you sign in with “Continue with Google”, we receive only the e-mail address, name and profile picture of your Google account, and there is no password to store. If you connect Google Calendar we also keep the Google account email and the access token Google issues to us, encrypted.
Billing. Only Stripe's customer and subscription identifiers. Name, email, phone, billing address, VAT number and card details are collected by Stripe, including when you pay through a link we send you on WhatsApp: we do not store them.
The data of people who call your business, which we process on your behalf: name, phone number (the key we recognise the person by), email if given, address and city, the full call transcript, every single turn, the summary written by the AI, the kind of job with its description, urgency and estimated value, appointments and their notes, the reason for an urgent flag, and the raw data the model writes when it takes notes.
On the current line we do not record audio. The caller's voice goes live to the model that answers and is not saved, by us or by the phone carrier: only the text of the conversation remains. Until 11 September 2026 calls went through Vapi, which recorded the audio: those recordings are still held by Vapi, we keep only the link, and they are deleted 30 days after the call.
People who leave their number on the site. Name (if you type it) and phone number, plus the page it came from, the language, the moment of consent and the version of the wording you read, when we called you back and our notes. To keep automated scripts out we look at a hidden field and at how long passes before submitting: we store nothing for that. To limit abuse we count submissions per IP address and per number, but we store only an encrypted fingerprint (SHA-256), not the address or the number, and the counter expires by itself.
People who try the assistant from the page. When you press the button and speak, the browser asks for microphone permission and your voice goes live to OpenAI's model: the audio is not saved. We store the text of the conversation and the sample request it produces, under a demo business, and delete them after 24 hours. Each try lasts about 90 seconds at most, and the number of tries is limited per encrypted fingerprint of the IP address.
The “Chat on WhatsApp” button. It opens a chat with Idra's WhatsApp number. We read what you write in order to answer you; for the running of the chat itself Meta/WhatsApp is an independent controller, under its own terms.
Site visits. The site runs on Vercel, which processes request traffic and function logs. We count page views with Vercel Analytics, which writes nothing to your device and gives you no persistent identifier. The details are in the cookie policy.
Advertising on Meta, only if you consent. If you accept marketing cookies in the banner, the Meta Pixel runs on the site and our server sends Meta three events through the Conversions API: sign-up (Lead), the start of the free trial (StartTrial) and the first payment (Purchase, with the amount). With the events travel your email and the business phone hashed with SHA-256 (Meta matches them against its own users and does not receive them in clear), a hashed identifier of your account, the _fbp and _fbc cookies, your IP address and browser type. On your account we keep whether you consented, when, and which campaign you came from (utm_ and fbclid parameters). If you refuse, none of this happens and the site works just the same.
Why we process it, and on what legal basis
- To run the service for you — account, assistant configuration, answering calls, calls and jobs, notifications, subscription, support. Legal basis: performance of the contract (art. 6.1.b GDPR).
- To call you back if you leave your number — we call you to talk about Idra, and that is all: no newsletter, no other use. Legal basis: your consent, given by submitting the form (art. 6.1.a), which you can withdraw at any time by writing to info@ciaoidra.com or on WhatsApp. Withdrawing it does not make what happened before unlawful.
- To let you try the assistant — the voice demo on the page is a service you ask for by pressing the button. Legal basis: your request, before any contract (art. 6.1.b).
- To keep the service running and secure — security, abuse prevention (including the anti-bot checks and submission limits), diagnosing faults, visit statistics, defending our rights. Legal basis: our legitimate interest (art. 6.1.f).
- To measure our advertising on Meta — to learn which Facebook and Instagram ads bring sign-ups, trials and customers, and let Meta optimise the campaigns for them. Legal basis: your consent, given through the cookie banner (art. 6.1.a GDPR and art. 122 of the Italian Privacy Code), which you can withdraw at any time from «Preferenze cookie» at the bottom of the pages or by writing to info@ciaoidra.com. For collecting and sending the data we are joint controllers with Meta Platforms Ireland (art. 26 GDPR); what Meta does with it afterwards is Meta's decision, as an independent controller, under its privacy policy.
- To comply with the law, in particular keeping accounting records. Legal basis: legal obligation (art. 6.1.c).
- Callers' data is not processed on a legal basis of ours: you choose that, as its controller. We process it because you instructed us to, under the terms of the DPA.
Who we share it with
We do not sell personal data and we do not hand it to anyone for marketing. Only the providers that make Idra work see it:
| Provider | What for | What data it receives |
|---|---|---|
| Supabase | database and authentication | everything listed above |
| Telnyx | the Italian number the forwarded call arrives on | caller's number and dialled number, and the call audio in transit to OpenAI, without recording it |
| OpenAI | the model that answers the phone and the demo on the site, and the one that writes the summary | live audio of the caller or the person trying the demo, the text of the conversation, and for the summary the transcript with name, address and problem; if you connected Google Calendar, on each call a sentence about when you are likely to call back, never the list or the content of your events |
| Google (only if you connect Google Calendar) | knowing when you are free or busy; only if you choose it, permission to add appointments to your calendar (today the phone line books none) | the request to know when you are busy, without reading what your events say; only if you choose the «Can book» mode, the appointment with the customer's name, phone and address |
| Stripe | subscriptions, payments and the portal to manage the subscription | owner's name, email and phone, billing address, VAT number, card |
| Resend | to you: your email and in the body the caller's name, phone, city, job and value; to us: name and number of people who leave their contact on the site | |
| Twilio | SMS to callers, WhatsApp to the owner | recipient numbers and message text |
| Meta / WhatsApp | reached through Twilio for owner notifications | the content of owner notifications |
| Telegram | owner notifications, if you link the channel; internal alerts to us | to you: number and problem of the person who called; to us: name and number of people who leave their contact on the site |
| Vercel | hosting | request traffic and function logs |
| Vercel Analytics | site visit statistics | page viewed, referrer, approximate country and device type — no persistent identifiers and no cookies |
| Meta Platforms Ireland (only if you consent) | Meta Pixel and Conversions API: advertising measurement | pages viewed, sign-up, trial and first-payment events with the amount, hashed email and phone (SHA-256), _fbp/_fbc cookies, IP address and browser type |
Previous providers. Until 11 September 2026 telephony went through Vapi, with Deepgram for transcription and ElevenLabs for the voice. They no longer receive any new data. Vapi still holds only the recordings of calls made before that date, which the nightly job deletes 30 days after each call: by 11 October 2026 none will remain.
OpenAI. Under its API terms, the data we send is not used to train models and may be kept by OpenAI for up to 30 days for abuse monitoring, then deleted. Our deletion does not reach that copy: we tell you so that you know.
Telegram, said plainly. If you receive notifications on Telegram, Telegram receives the number and the problem description of the person who called you. We have no ordinary processor agreement (art. 28) with Telegram: we say so clearly, so you can decide whether to use that channel.
Outside the European Union. Supabase keeps the database in the EU. The others — Telnyx, OpenAI, Google, Stripe, Resend, Twilio, Meta/WhatsApp, Vercel, and Vapi until its last recordings are deleted — also process data outside the European Economic Area: those transfers rely on the EU standard contractual clauses or an adequacy decision, depending on the provider. Telegram is the exception, as said above. We promise you nothing more than that.
Google Calendar
This section says what happens to your Google account data when you connect Google Calendar to Idra. It is optional: you, the business owner, connect it from the dashboard. If you do not connect it, Idra receives nothing from Google.
What we access. Only the permissions we need, and Google shows you each one before you consent:
calendar.freebusy, read-only — the only calendar permission we ask for by default (the «Read only» mode). It sees only the time ranges when you are busy or free: never event titles, attendees, descriptions or locations. It cannot change anything.calendar.events, only if you choose «Can book» — Google asks you for it only when you choose that mode (if you connected in «Read only» first, with a separate consent), and you can untick it on Google's screen. It is used only to add to your calendar the appointments you have decided to let Idra put there, and to change or delete the ones Idra itself created; we do not read your other events. Today the phone line does not book appointments even in this mode: it only says when you are likely to call back.openidandemail— the email address of the Google account you connected, so the dashboard can show which account is connected.
How we use it. When a call comes in we read from Google when you are busy today and over the next two days, and turn that into a rough sentence, in words (for example «oggi è probabilmente impegnato fino alle tre del pomeriggio, poi ha spazio» — “today he is probably busy until three in the afternoon, then he has time”): the assistant uses it to tell the caller when you are likely to call back. Only that sentence reaches the model that answers the phone (OpenAI, for that call), never the list or the content of your events; what the assistant says ends up in the call transcript, like everything else it says. With «Can book» the permission is used to add appointments. Nothing else.
What we store. The long-lived access token Google issues to us (the refresh token), encrypted with AES-256-GCM before it reaches the database; the Google account email; the permissions you granted and the mode you chose. We do not store your free/busy ranges: we read them on each call and discard them. If an appointment is written to your calendar, we keep its identifier so we can delete it when you erase the customer.
What we do not do. We do not sell data received from Google, we do not use it for advertising, we do not use it to train artificial intelligence models, ours or anyone else's, and we do not pass it to anyone except as described here. No person reads it, unless you ask us to or agree to it, it is needed for security (for example investigating abuse), or the law requires it.
Idra's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
How to revoke and delete. Press «Disconnect» in Idra's settings: we ask Google to revoke the permission and immediately delete the connection row, with the encrypted token and the email. You can also revoke access from Google, at myaccount.google.com/permissions: from then on the token no longer works, Idra stops reading your calendar and tells you so; the row is deleted when you press «Disconnect» or when you close your Idra account. When the account is deleted, the connection goes with the business. Appointments Idra wrote to your calendar remain yours: you delete them in Google like any other, and those of a customer you erase in Idra we delete for you.
Google is one of our providers for this feature (see the providers table above and the DPA); otherwise Google processes your account data under its own privacy policy.
Where the data lives
Database and authentication are on Supabase, in the eu-central-1 (Frankfurt, Germany) region; the site's functions on Vercel are pinned to the fra1 (Frankfurt) region. The rest of the chain — phone carrier, model, calendar, payments, email and messages — also processes data outside the European Economic Area. If that changes, this page changes too.
How long we keep it
No “for as long as necessary”. These are the windows, and the system applies them by itself:
| Data | How long |
|---|---|
| Audio recording | none on the current line; those from the previous line, at Vapi, 30 days from the call |
| Transcript, AI summary, individual turns | 12 months from the call |
| Call data with no content (time, duration, outcome, value) | 24 months, then deleted |
| Customer record, jobs, appointments, urgent flags | until you delete them, or 24 months from the last contact |
| Name and number left on the site to be called back | 12 months from submission, then deleted; sooner if you withdraw consent. If you become a customer, the account rules apply |
| Text and request from the voice demo on the site | 24 hours |
Cookie choice (idra_consent) | 6 months, then we ask again |
Meta cookies and source campaign in your browser (_fbp, _fbc, idra_attr) | 90 days; deleted at once if you withdraw consent |
| Consent given at sign-up and source campaign, on your account | as long as the account exists; they go when it is deleted |
| Events sent to Meta | kept by Meta, under its privacy policy |
| Anti-abuse counters (encrypted fingerprints only) | expire by themselves after the limit's window |
| Closed account | 30 days' grace, then we delete the business and all linked data |
| Invoices and accounting records (at Stripe) | 10 years |
The ten years for invoices are not our choice: they are required by art. 2220 of the Italian Civil Code and override an erasure request. Even when you close your account and we delete the rest, accounting records remain — and we use them for nothing else.
Artificial intelligence
Idra is a conversational assistant: it answers with a synthetic voice, understands what the person says and takes notes. The model that speaks on the phone is OpenAI's GPT-Live; a second OpenAI model reads the transcript and writes the summary, the problem, the urgency and the estimated value of the job.
It always identifies itself. Before anything else the assistant says it is an automated or virtual assistant: with the standard sentence «Buongiorno, sono l'assistente automatico di {Nome Attività}: non sono una persona, ma prendo i suoi dati e la faccio richiamare dal titolare.» — “Hi, I'm the automated assistant of {Business Name}: I'm not a person, but I'll take your details and have the owner call you back.” — or with the business's own greeting, if it already says so. The sentence is written in the code and cannot be switched off from the dashboard: that is what art. 50 of the EU Artificial Intelligence Act requires.
No decision taken solely by a machine produces legal or similarly significant effects on a person (art. 22 GDPR). On the current line the assistant collects the details and tells the person that you will call back: it does not book appointments and does not agree prices. Google Calendar is optional and you connect it yourself: the assistant only reads when you are free or busy, to say when you are likely to call back. The «Can book» mode grants permission to add appointments, but today the phone line books none: see Google Calendar.
Emergencies. The assistant does not put the call through to you. If the person mentions a danger — a smell of gas, smoke or fire, carbon monoxide, water on the electrics — a check written in the code, which does not depend on what the model decides, makes it say first how to get safe and to call the emergency number: 115 for gas and fire, 112 for carbon monoxide. The notification reaches you right after, marked urgent. Urgent requests with no danger are flagged as urgent, not put through on the phone.
Voice and biometric data
A voice is personal data, so we say it plainly: on the current line and in the demo on the site the audio is used only so that the model can understand and answer, and it is not saved. We do not use it to recognise anyone by their voice, we create no voiceprints, we do not compare one call with another. We do not process biometric data intended to identify a person and we do not intend to process special categories of data (art. 9 GDPR): if someone on the phone mentions a health problem it ends up in the transcript because they said it, not because we look for it, and it disappears with the windows above.
How we protect it
We hold transcripts of people who are not our customers, so here is the exact list:
- Every table in the database has row-level access control: a business's data can be reached only by that business.
- The service key, the one that bypasses those controls, is used only by server routes that first verify who is calling them: OpenAI, Stripe, Twilio and Resend by signature verification, Telnyx by confirming the call with Telnyx's API, Telegram by a secret token, scheduled jobs by a secret, Vapi (previous line) by a constant-time comparison.
- The Google Calendar token is encrypted by us (AES-256-GCM) before it reaches the database.
- Credentials are scrubbed from error messages, no personal data ends up in application logs, traffic always travels over TLS, and the call between the phone carrier and the model travels encrypted.
- Encryption of data at rest is the providers', starting with Supabase, as described in their documentation: it is not extra encryption written by us.
Two things that are not in place today, so you don't find out later: login is by email and password, with no second factor, and we have not yet configured browser security headers (HSTS, CSP). In the meantime use a password you use nowhere else.
Your rights
Over your data you have the rights in articles 15–22 GDPR: to know what data we hold and get a copy (access), to correct it (rectification), to have it deleted (erasure), to freeze its use (restriction), to take it elsewhere in a machine-readable format (portability), to object to processing we carry out on our legitimate interest (objection), and to withdraw consent where the processing rests on it, as for a number left on the site or for advertising measurement on Meta.
To exercise any of them write to info@ciaoidra.com. We answer within one month (art. 12 GDPR); if the request is complex we may take up to two more months, but we tell you within the first. There is not yet a button in the dashboard to close your account: for now we do it at your request by email, with the 30-day window in the table above. The subscription, on the other hand, you cancel yourself from Stripe's customer portal: enter the email you paid with and Stripe sends you a link to sign in.
If the request comes from a person who called your business, the controller is you: they must contact you, and we give you the help set out in the DPA to answer them in time.
If you think we are getting it wrong you can lodge a complaint with the Italian Garante per la protezione dei dati personali: Piazza Venezia 11, 00187 Rome, +39 06 696771, garante@gpdp.it, PEC protocollo@pec.gpdp.it, garanteprivacy.it. You can also go to the ordinary courts.
Changes to this policy
We will update this page when the product changes: a new provider, a different window. The last-updated date at the top changes with the text. If the change is substantial, we email you before it takes effect.