Privacy Policy
Last updated August 11, 2026
This policy describes what data Ringpost collects, how it's used, and who else it passes through. If anything here is unclear, email hello@ringpost.io and you'll get a direct answer.
What we collect
- Account info: your name and email, plus either a password (hashed, never stored in plain text) or, if you sign in with Google, your Google account's ID and verified email instead.
- Organization and team data: your team members, roles, and departments.
- Your Twilio Account SID and Auth Token, which you provide to connect your own Twilio account.
- Contacts, calls, and text messages that pass through your connected Twilio numbers.
- Call recordings, transcripts, and AI-generated summaries, where you have those features enabled.
How your Twilio credentials are protected
Your Auth Token is encrypted at rest with AES-256-GCM before it's stored. It's only decrypted server-side, at the moment it's needed to place a call, send a text, or manage your numbers through your own Twilio account. It is never sold, shared, or used for anything other than operating your account.
Third parties your data passes through
Ringpost is built on top of a small number of infrastructure providers. Each one only sees the data it needs to do its job:
- Twilio: your calls and texts. You connect and pay Twilio directly; Ringpost never sees or marks up your Twilio bill.
- Google: if you use "Continue with Google," Google verifies your identity and shares your Google account ID, name, and verified email with us to create or sign in to your account. We never see your Google password.
- Amazon Web Services (S3): stores call recordings.
- OpenAI: generates call transcripts and summaries, where enabled.
- Resend: sends account and notification emails.
- Upstash: short-lived rate-limiting data, not your calls or messages.
- PostHog: product analytics. Once you're logged in, this is tied to your account (your user ID and email), so we can see how the product is actually used.
- Google Analytics: aggregate site traffic on the marketing pages, not tied to your account.
- Your account and application data is stored in a Postgres database.
Cookies
We use one essential cookie to keep you signed in. PostHog and Google Analytics also set their own cookies to track usage, as described above. You can block these in your browser, though signing in requires the essential cookie to work.
How long we keep your data
We keep your account, contacts, calls, and messages for as long as your account is active. If you delete your account, we delete this data within 30 days, except where we're required to keep it longer (for example, fraud prevention or a legal obligation).
What we don't do
We don't sell your data. We don't mark up or resell your Twilio usage. We don't share your calls, texts, or contacts with anyone outside the providers listed above.
Your rights
You can request an export or deletion of your account data at any time by emailing hello@ringpost.io. Deleting your account does not delete data held directly by Twilio under your own Twilio account; that's managed through Twilio.
Changes to this policy
If this policy changes in a way that affects how your data is handled, the "Last updated" date at the top of this page will change, and material changes will be emailed to active accounts.