Privacy policy
Updated on 11 September 2026
This is the English version, provided for convenience. The Portuguese version is the reference text and prevails in case of any discrepancy between the two.
This policy explains what happens to the data of a call made on digfone. It is specific because the product is specific: a video conversation with translated captions produces personal data derived from voice, and that deserves a straight explanation.
Audio and video never pass through us
Picture and sound travel directly from one browser to the other. Our servers exchange what participants need to find each other (network addresses and the chosen language), issue short-lived credentials and process typed chat messages, as explained below.
When the two networks cannot connect directly (which happens behind certain routers and corporate networks), audio and video go through a third-party relay server, which forwards the packets end-to-end encrypted and cannot open them. It is not ours and it stores nothing. The main point still holds: on neither path is the audio or video available to us.
This is not a promise about our conduct, it is how the system is built. We cannot hand the audio of a conversation to anyone, under any circumstances, because it was never with us.
Captions are produced on your own device
Each participant transcribes their own microphone. The audio goes from your browser straight to a specialised speech recognition service, located in the United States, using a temporary credential issued by us. What comes back is text, and text is all that travels between participants: your original sentence and its translation, so that both sides end up with the conversation in both languages.
Typed messages during the call
When you send a chat message, the text passes through our servers for delivery to the participants present. When translation is needed, we send that text to a language processing service. Each participant receives a translation in their chosen conversation language and can read the original underneath.
Chat is not added to account history, summaries or PDFs. The server keeps a limited temporary copy to recover deliveries on reconnections of up to 30 seconds and deletes it when the room closes. The screen shows up to 200 recent messages during the call. We keep only identifiers and technical usage and cost counters, without message text, to limit the service. Provider processing follows the terms applicable to that service; this digfone memory period is not a statement about the provider's retention.
What we keep, and for how long
- Conversation text, if the host’s plan includes history: 7 days on Free, 90 on Basic, 365 on Pro. Once that period is over the text is deleted, not archived.
- AI summary, when generated, kept for the same period as the text.
- Account: e-mail, name if given, language, time zone and (when you answer during sign-up) the country and what you intend to use the product for.
- Billing: amount, date, status and, in order to issue the Brazilian tax invoice, the Brazilian tax number (CPF/CNPJ) or foreign tax identification number, country, legal name and foreign address. We reuse billing details and request necessary additions in your tax profile. Card details stay with the payment processor; we neither receive nor store them.
- Tax spelling compatibility: names and addresses written in other scripts may be sent to an AI service (Anthropic) for conversion to Latin characters. We retain the original details and the transformation for review. Fields for tax identification numbers, e-mail, card details and payment amounts are excluded from this request. Processing may take place outside Brazil, and provider retention follows the applicable commercial terms; we do not assume zero retention. You can review and correct your tax profile or request review of an already submitted document.
- Tax and accounting archive: documents, receipts, fees, exchange rates, payouts and changes are retained to comply with legal obligations (Brazilian LGPD, articles 7 II and 16 I), including after account deletion. Minimum retention extends through the fifth year following the record and may be longer for legal obligations, inspections or disputes. Authorized administrators, our accounting firm and competent authorities may access these records for their respective purposes.
- Guest e-mail, if they ask to receive the conversation by e-mail at the end of the call. It is tied to that call and is deleted with it, unless that person creates an account, in which case the record becomes the trace of how their account started. The message we send to that address contains no conversation, no summary, no title and no participant name: it only says the conversation exists and carries a link to open it. That link is what confirms the address, and the conversation is only sent afterwards. So an address typed wrong receives an invitation and nothing about anyone. Every such e-mail carries a link that deletes the address in one click, with no account needed. That address is kept for at most 45 days and, during that period, may receive up to two reminders about the product. After that it is deleted on its own, whether or not the person created an account. The conversation itself is still deleted on the retention of the plan of whoever created the call, which is shorter.
- Contact message, if you write through the form on the site: your name, your email, the subject and the text you sent. We use it to reply, and for nothing else. We keep it for 12 months and then delete it, whether or not the conversation ended. If we ask something by email and you would rather stop, just do not reply.
- Usage metering: duration and number of caption sessions, which is what determines the charge.
- Security log: at sign-up, once, the IP address, the browser/device, the country and the page you came from; and, during use, the IP of sensitive account actions (sign-in, plan change, deletion). They serve support and abuse containment, and they go away with the account.
- Error log: when a page fails in the browser of someone visiting us, we keep the error message, the path of the page, the browser and the IP address, including for people who have no account with us, because the failure we most need to see is precisely the one that kept someone from loading the site at all. It serves to fix the defect, and nothing else. The IP is deleted after 7 days and the whole record after 90 days.
- Attack attempt log: the site keeps traps on paths that do not exist (addresses only a scanning program looks for) and refuses access to internal routes. When one of those traps is touched, we keep the IP address, the country reported by the network that delivers the site, the declared browser, the requested path and the time. We never keep the content that was sent: nothing typed into a form, no password, no conversation text. It serves to detect attacks and protect accounts, and nothing else. Everything is deleted after 90 days.
- Technical call quality: during a conversation, your browser measures its own connection and sends us numbers about the network, never the content: round-trip time, packet loss, whether the picture froze, how long captions took, and the device class (for example Chrome · Android, never your browser's full identification). It serves to find out why a call went badly and fix it, and nothing else. No audio, video or text from the conversation is in those numbers, nor your IP address. The minute-by-minute detail is deleted after 30 days; the per-call summary follows the call's own retention.
Whoever receives the link is a data subject too
The person who joins through the link has no account with us, and half of the conversation is their own speech. We recognise that person as a data subject: they may request deletion of the text of any conversation they took part in, by writing to [email protected] with the date and the room code. Their request deletes the conversation for both sides, because there is no such thing as half a transcript.
Turning the record off
There is a control in your account for keeping no transcript at all. It applies to the calls you create: in those, the voice transcript exists only on screen and is not sent to our servers for storage. Typed messages are still processed temporarily for delivery and translation, without permanent chat history. In a call created by someone else, it is that person who decides whether there is a record: it is their account that answers for that transcript, and their plan that sets how long it is kept.
Your rights
You can request access, correction, export or deletion of your data, and withdraw consent, at the e-mail above. We reply within 15 days.
Deleting your account also deletes the conversations you hosted. In our live systems the deletion is immediate and cannot be undone.
One caveat that has to be written down: the database has a backup, which exists only for disaster recovery. Those copies rotate, are not kept indefinitely, and are never used to restore data that someone asked us to delete. The same applies to text purged by the retention period: it leaves the live systems at once, and the copies on the following cycle.
We do not sell any data, and we do not use the content of your conversations to train any model.
International transfer
Part of the processing happens outside Brazil, including in the United States and Germany. Anthropic reports storage in the United States and processing that may also occur in Europe, Asia and Australia. The tax request converts the spelling of details needed for the invoice. Transfers are subject to the grounds and safeguards in article 33 of Brazil’s General Data Protection Law and the terms applicable to each processor.
To find out which processors handle your data, and for what purpose, write to the data protection officer, at the end of this page.
Data protection officer
Requests about personal data: [email protected].
The rules for using the service are in the terms of use.
Colabtec Digital LTDA · CNPJ 65.787.255/0001-91 · São Paulo, Brazil · [email protected]