Your customer's data is yours.
Last updated · —
Kresa answers phones and replies to chats for businesses. The conversations we handle on your behalf are your data — not training fodder, not a marketing asset. This page explains what we hold, why, where it goes, and what we have not built yet.
The short version
- Kresa answers calls and chats on behalf of the businesses that hire us. For those conversations we are a processor — the business decides what happens to the data.
- For your own Kresa account — name, email, billing, team — we are the controller, and this policy governs it directly.
- Your data is stored in Canada (Google Cloud, Toronto). Some processing — speech recognition, speech synthesis, AI models, telephony, email — happens in the United States. The sub-processor table below says exactly which and why.
- We do not train shared AI models on your conversations, and we do not sell or share personal information for advertising.
- Live call audio is not stored. It is streamed for real-time transcription and discarded. The text transcript is kept, and after-hours voicemail is recorded where a business has turned voicemail on.
- If you are a caller or website visitor, the business you contacted controls your data. Contact them first; we will help them respond.
What we never do
- No advertising cookies, and no third-party analytics in the product.
- No selling or sharing of personal information.
- No training of shared AI models on your conversations.
- No profiling of callers for anything beyond answering their call.
Who we are
Kresa is a product of Prism Cloud Consulting Inc., a Canadian software company. Questions about this policy, and any request to access, correct, export or delete data, go to hello@kresa.ai.
The two roles we play — read this first
Almost every question about this policy resolves once you know which column you are in.
| Account data | Conversation data | |
|---|---|---|
| Whose | The subscribing business, its owner and team | That business's own customers — the people who call or chat |
| Our role | Controller | Processor |
| Who decides why | Us | The Kresa customer |
| Who to contact | Us | The business you contacted |
If you are a caller or a website visitor, nearly everything about you sits in the right-hand column. We hold it and protect it, but we act on the business's instructions.
Account data — what we collect as controller
| What | Examples | Why |
|---|---|---|
| Identity and sign-in | Name, email, Google sign-in id, session cookie | Create and secure your account |
| Workspace configuration | Business name, industry, website, hours, persona, brand | Run the service |
| Team and access | Member emails, roles, invitations, API keys — stored only as SHA-256 hashes, so we cannot recover the original key | Access control |
| Billing | Stripe customer and subscription ids, plan, currency, status. We never see your card number — Stripe collects it directly | Take payment; meet tax and corporate obligations |
| Telemetry | Sign-ins, plan tier, usage against plan caps | Enforce limits and bill accurately |
| Support access records | Staff identity, timestamps, endpoints, request bodies with secrets redacted — only under a grant you issue | So you can audit what our staff did |
| Abuse controls | Rate-limit records keyed to email on public endpoints | Prevent account enumeration and mail-bombing |
We run no third-party analytics and no advertising trackers in the product or on this website. If that ever changes, this section changes with it and a consent banner ships at the same time.
Conversation data — processed for a business
| Category | What is stored | Where |
|---|---|---|
| Chat messages | Role, content and timestamp. No IP address, no user-agent, no page URL | Canada |
| Call records | Caller number, start and end times, duration, turn count, transfer outcome — and the conversation transcript | Canada |
| Live call audio | Not stored. Streamed to a speech-recognition provider and discarded | In transit (US) |
| Voicemail | Recorded and transcribed where a business has enabled after-hours voicemail. The audio is held by our telephony provider | Transcript: Canada · Audio: US |
| Messages, appointments, escalations, leads | Contact details, message text, scheduling details, the transcript attached on handoff, satisfaction responses | Canada |
| Knowledge base | Text crawled from URLs you supply and files you upload, plus the embeddings built from them. If your site or documents contain personal information, that becomes conversation data | Canada; text sent to a US provider during indexing |
| Calendar | Google or Microsoft OAuth tokens, encrypted at rest; events read and written to book appointments | Canada + your calendar provider |
| Outbound notifications | Confirmations, reminders, escalation and satisfaction mail and SMS — sent in your name, with you as the sender | US providers |
AI training. We do not use conversation data to train or fine-tune any model, ours or a vendor's.
Calls, recording and transcription
This is the part most worth reading closely, because it is the part where the law differs most between the places our customers operate.
- A live call is transcribed, not recorded. Audio streams to a speech-recognition provider and is discarded as it is processed. What persists is the text.
- The transcript is retained with the call record, so the business can see what its agent said and what its customer asked.
- Voicemail is different: it is recorded audio. Where a business has set after-hours calls to take a message, callers are told before the recording starts.
- Callers are told they are speaking with an automated assistant at the start of the call, before the agent engages, and told that the conversation is transcribed.
If you are the business using Kresa. Telling the caller is necessary but it is not the whole obligation. Several US states require the consent of every party to a call, not just the business, and Canadian and European regimes have their own notice and purpose requirements. You remain responsible for the notices and consents the law where you operate requires, and for configuring your agent so it does not contradict them.
Automated processing
Large language models decide what the agent says, and whether to transfer a call, book an appointment or escalate to a person. These decisions are operational, not evaluative — we do not score, rank or profile anyone, and we make no decisions about credit, employment, insurance or legal rights.
Kresa always leaves a human route: any caller or visitor can ask for a person, and the agent escalates.
Sub-processors
These are the companies that process data for us. The applies to column matters: a chat-only customer can see at a glance that the telephony and speech vendors never touch their data.
| Sub-processor | Applies to | Data | Location |
|---|---|---|---|
| Google Cloud — Firestore, Cloud Run, Storage, Secret Manager, Tasks, Logging | Both products | All stored data | Canada — Toronto |
| Firebase Authentication | Both | Account email, authentication tokens | US |
| Google Vertex AI | Knowledge search | Knowledge-base text, chat queries | US |
| DeepInfra | Both — AI inference | Prompts, conversation history, retrieved context | US |
| Deepgram | Receptionist only | Live call audio, for speech recognition | US |
| ElevenLabs | Receptionist only | The text to be spoken | US |
| Twilio | Receptionist only | Phone numbers, call metadata and audio, SMS bodies, voicemail recordings | US / global |
| SendGrid | Both — transactional email | Recipients and content, including transcripts in escalation email | US |
| Stripe | Billing | Billing contact and payment method, collected directly by Stripe | US / global |
| Firecrawl (optional) | Knowledge ingestion | URLs you supply and the content retrieved from them | US — a built-in crawler in Canada runs when it is not configured |
We will give at least 30 days' notice before adding or replacing a sub-processor that handles conversation data, by email to workspace owners.
Where data lives, and what leaves Canada
Stored data is in Google Cloud's Toronto region. Processed data leaves Canada: speech, AI, telephony, email and payments are all US providers, and there is currently no Canadian-region option for them that would let the product work as described.
Transfers out of the EEA and UK rely on Standard Contractual Clauses and the UK Addendum, together with our sub-processors' own transfer mechanisms.
Cookies and local storage
| Name | Purpose |
|---|---|
__session | Authentication session, HttpOnly, 14 days |
NEXT_LOCALE | Your language preference |
kresa_current_business | Which business you last viewed |
pie_stealth | Access gate for private, pre-launch environments |
The embedded chat widget sets no cookies. It keeps a conversation id in sessionStorage, which the browser clears when the tab closes. There is no cross-site tracking.
We set no non-essential cookies, so we show no consent banner. If we ever add analytics, a compliant banner ships with it.
How long we keep things
What we have not built yet. We do not yet run automated deletion on a retention schedule. Conversation data, call records and transcripts are kept for the life of your account unless you ask us to delete them. We would rather say that than publish a schedule we are not yet enforcing.
Retention limits and self-serve deletion are being built. When they ship we will publish the schedule here and give notice before it starts running against existing data.
Two things do have firm periods today:
- Billing records are kept for seven years, because tax and corporate law requires it.
- Records of accepting these documents are kept indefinitely and survive account deletion — they are the proof of what you agreed to and when.
Your rights
If you are a Kresa customer
Email hello@kresa.ai to access, correct, export or delete your data. We verify your identity first and respond within 30 days — we apply the strictest deadline we are subject to, globally, rather than varying it by where you are.
Handled by hand, for now. Export and account deletion are manual requests today, not dashboard buttons. Ask us and we will do it and confirm when it is complete. The self-serve versions are being built; until they exist we will not pretend otherwise.
If you called or chatted with a business that uses Kresa
Contact that business first. They decide what happens to your data; we hold it for them and act on their instructions. If you contact us we will identify the business and help it respond, but we cannot delete or disclose its records on our own initiative.
Rights by region
Canada (PIPEDA). Access, correction, withdrawal of consent subject to legal and contractual limits, an explanation of our purposes, and the right to challenge our compliance. Complaints go to the Office of the Privacy Commissioner of Canada.
Québec (Law 25). Additionally: information about automated decisions and the right to have a person review them, data portability in a structured technological format, de-indexing in defined circumstances, and notice when information is communicated outside Québec. Complaints go to the Commission d'accès à l'information.
EEA and United Kingdom (GDPR). Access, rectification, erasure, restriction, portability, objection — including to processing based on legitimate interests — and the right not to be subject to solely automated decisions with legal or similarly significant effect. Complaints go to your national supervisory authority or the UK ICO.
California (CCPA/CPRA). The right to know, delete and correct, and to opt out of sale or sharing. We do not sell or share personal information as those terms are defined, and have not in the preceding 12 months. Where we act for a business we are a service provider and process only on that business's documented instructions. We will not discriminate against you for exercising these rights.
Security
TLS 1.2 or better in transit, AES-256 at rest. Every read and write is scoped to a single tenant. API keys are stored only as SHA-256 hashes; widget keys are locked to specific origins; secrets live in Google Secret Manager rather than in configuration.
Kresa staff can access your workspace only under a grant you issue, in a scoped session, with every request written to an audit log you can read. You can end a session at any time.
If something goes wrong
We notify affected customers without undue delay, and regulators as required — the Office of the Privacy Commissioner where a breach creates a real risk of significant harm, the Commission d'accès à l'information for Québec, and EU or UK authorities within 72 hours where the GDPR applies.
We keep a register of confidentiality incidents — including those we assess as not reportable, and why — for five years.
Children
Kresa is sold to businesses and is not directed at children. If a child's information reaches us through a customer's phone line or chat widget, that customer is responsible for it under applicable law and should tell us so we can help delete it.
Changes to this policy
We post changes here with a new version and effective date, and keep prior versions available. If a change materially affects how we handle conversation data we will email workspace owners at least 30 days before it takes effect — a silent "last updated" bump is not sufficient notice and we do not treat it as one.
Kresa is a product of Prism Cloud Consulting Inc., a Canadian software studio. Questions about this page? Reach us at hello@kresa.ai.