Privacy Policy
Last updated: June 10, 2026
Rymi Works Pvt. Ltd. ("Rymi," "we," "us," or "our") operates the Rymi platform, including the website at rymi.live, the web application at studio.rymi.live, and related APIs and services (collectively, the "Service"). This Privacy Policy explains how we collect, use, and protect your information.
1. Information we collect
Information you provide
- Account information: Name, email address, and password when you create an account.
- Payment information: Billing details processed securely through our payment provider. We do not store credit card numbers.
- Agent configuration: The prompts, settings, and instructions you provide to configure your AI agents.
- Phone numbers: Numbers you provide for outbound calling or connect to the platform.
Information generated by the Service
- Call recordings and transcripts: Audio recordings and AI-generated transcripts of calls handled by your agents, stored for your review.
- Call analytics: Summaries, sentiment analysis, and extracted data points generated from calls.
- Usage data: API call volume, feature usage, and performance metrics.
For call recordings and transcripts involving people your agents speak with, you (the account holder) determine the purposes of that processing and Rymi processes the data on your behalf. Callers seeking access to or deletion of their call data should contact the business that operated the agent; we support our customers in fulfilling those requests.
Information collected automatically
- Log data: IP address, browser type, device information, and pages visited.
- Cookies: We use essential cookies for authentication and preferences, and, only with your consent, privacy-friendly PostHog analytics cookies to measure site usage. No third-party advertising cookies. See our Cookie Policy for details.
2. How we use your information
- To provide, maintain, and improve the Service.
- To process calls and generate transcripts, summaries, and analytics.
- To communicate with you about your account, billing, and product updates.
- To detect and prevent fraud, abuse, and security incidents.
- To comply with legal obligations.
We do not sell your personal information. We do not use your call data to train AI models.
Legal bases for processing (GDPR)
Where the GDPR applies, we process your personal data on these legal bases:
- Contract — to provide the Service you signed up for.
- Legitimate interests — to secure and improve the Service and prevent abuse.
- Consent — for optional communications, and for any future analytics cookies.
- Legal obligation — for tax, accounting, and responses to lawful requests.
3. Data retention
- Call recordings and transcripts are retained according to your account settings. You can delete them at any time from your dashboard.
- Account information is retained while your account is active and for 30 days after deletion.
- Usage logs are retained for 90 days.
4. Data sharing
We share your information only in these circumstances:
- Service providers: We use third-party services for hosting, payment processing, and telephony. These providers process data on our behalf under strict agreements.
- Legal requirements: When required by law, regulation, or valid legal process.
- Business transfers: In connection with a merger, acquisition, or sale of assets, with prior notice to you.
We do not share your call data with third parties for their own purposes.
5. Security
We implement industry-standard security measures including:
- Encryption in transit (HTTPS) and at rest, provided by our hosting platform.
- Application-level AES-256-GCM encryption for stored provider credentials and access tokens.
- Row-level security in the database and tenant scoping on every API request.
- Access controls and audit logging of administrative changes.
- Infrastructure hosted on providers holding SOC 2 Type II (Railway, Supabase).
If a data breach affects your personal data, we will notify affected customers within 72 hours of confirming the breach, and notify regulators where required by law. See our Security page for more on how we protect your data.
6. Your rights
Depending on your location, you may have the following rights regarding your personal data:
All users
- Access your personal data.
- Correct inaccurate data.
- Delete your account and associated data.
- Export your call data.
- Opt out of non-essential communications.
GDPR (European Economic Area, UK, Switzerland)
- Access — Request a copy of the personal data we hold about you
- Rectification — Correct inaccurate or incomplete data
- Erasure — Request deletion of your data ("right to be forgotten")
- Restriction — Limit how we process your data
- Portability — Receive your data in a structured, machine-readable format
- Objection — Object to processing based on legitimate interests
- Withdraw consent — Where processing is based on consent, withdraw it at any time
CCPA (California Residents)
- Right to know — What personal information we collect, use, and disclose
- Right to delete — Request deletion of your personal information
- Right to opt-out — We do not sell personal information. If this changes, we will provide a "Do Not Sell" link
- Non-discrimination — We will not discriminate against you for exercising your rights
DPDP Act (India)
If you are in India, the Digital Personal Data Protection Act, 2023 gives you the right to access, correct, and erase your personal data, the right to grievance redressal, and the right to nominate another individual to exercise your rights in the event of death or incapacity. To raise a grievance, contact our Grievance Officer at privacy@rymi.live.
To exercise any of these rights, email privacy@rymi.live (for CCPA requests, use the subject line "CCPA Request"). We respond within 30 days.
7. Children's privacy
The Service is not directed at children. You must be at least 18 years old to create an account, and we do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us personal data, contact privacy@rymi.live and we will delete it.
8. International data transfers
Your data may be processed in countries outside your country of residence. We use appropriate safeguards, including standard contractual clauses, to protect your data during transfers.
9. Subprocessors
We use the following third-party services to operate the platform. Model and voice providers (LLM, speech-to-text, and text-to-speech) receive call data only when your agent configuration selects them.
| Subprocessor |
Purpose |
Location |
| Supabase |
Authentication, database, storage |
US (AWS) |
| Vercel |
Website hosting, CDN, edge functions |
Global |
| Railway |
Application and API hosting |
US |
| Razorpay |
Payment processing |
India |
| LiveKit |
Real-time call audio infrastructure |
US |
| Twilio |
Telephony, phone numbers, SIP |
US |
| Plivo |
Telephony, phone numbers |
US |
| Telnyx |
Telephony, phone numbers |
US |
| Vonage |
Telephony, phone numbers |
US |
| OpenAI |
LLM inference, speech services |
US |
| Anthropic |
LLM inference |
US |
| Google Cloud |
LLM inference (Gemini), speech services |
US / Global |
| Amazon Web Services |
LLM inference (Bedrock), infrastructure |
US / Global |
| Microsoft Azure |
Text-to-speech voice synthesis |
US / Global |
| Deepgram |
Speech-to-text, text-to-speech |
US |
| ElevenLabs |
Text-to-speech voice synthesis |
US |
| MiniMax |
Text-to-speech voice synthesis |
Singapore / China |
| Play.ht |
Text-to-speech voice synthesis |
US |
| Sarvam AI |
Text-to-speech voice synthesis |
India |
| PostHog |
Product analytics (only with your consent) |
US |
We notify customers via email at least 30 days before adding a new subprocessor.
10. Changes to this policy
We may update this policy from time to time. We'll notify you of significant changes via email or an in-app notice. Continued use of the Service after changes constitutes acceptance.
11. Contact us
If you have questions about this Privacy Policy: