Security, privacy and data handling
Last reviewed: . Written so your IT or legal team can answer most of a questionnaire without emailing us. Anything they still need, ask at hello@yappa.com.au.
Where your data lives
Your account data, leads, call records and transcripts sit in Sydney, Australia: the application runs on Fly.io in Sydney and the database is Neon in Sydney. Call recordings are stored in Cloudflare R2 in the Asia Pacific region.
Two parts are not in Australia, and we would rather say so than let you discover it in an audit. The voice platform that carries the audio and turns speech into text, and the language model that decides what the AI says, both run in the United States. Audio and the words spoken on a call pass through those services while the call is happening. If in-country processing end to end is a hard requirement for you, tell us before you sign rather than after.
Encryption and access
- Traffic is TLS everywhere, browser to us and us to every provider.
- Personal details are encrypted at rest with a key derived per workspace, not one key for the platform. Names, phone numbers and email addresses are stored encrypted; lists and search results show only the last four digits of a number.
- Card numbers are never handled by Yappa. When a call takes a payment, the AI sends a Stripe pay-by-link and never hears or stores card details.
- Card numbers, Medicare numbers, tax file numbers and dates of birth that a caller reads out are removed from the transcript before it is stored, so they never reach the database, an export, or the AI scoring pass.
- Recording links are never handed out as public URLs. Audio is streamed through the application, so hearing a call always requires a signed-in session with access to that account.
Keeping accounts apart
Yappa is multi-tenant, and separation is enforced by the database itself. Every table carrying customer data has a row-level security policy that scopes reads and writes to the owning account, so a query that forgot to filter returns nothing rather than someone else's leads. Each account also gets its own telephony sub-account, which keeps numbers, caller reputation and billing separate.
Actions taken by the Yappa team inside an account are written to an internal audit log.
What happens before every call
Every outbound call passes one compliance gate before it is placed. There is no override flag, and the gate fails closed: if it cannot confirm something is allowed, the call does not happen.
- Do Not Call Register, checked against a mirror that refuses to run if it is stale.
- Your own internal do-not-call list, and anyone who has opted out by SMS.
- Consent on file, including whether it has been revoked or has expired.
- Legal calling hours in the lead's own state, and that state's public holidays.
- Attempt caps: at most eight calls to a number in thirty days, one automatic attempt a day.
- Spending caps, so a runaway campaign stops itself.
Every decision, allowed or refused, is written to an append-only audit trail with the reason. Nobody, including us, can edit or delete it, and you can read and export it yourself from the Compliance tab in your dashboard.
Calls also carry disclosure by design. The recording notice is checked at dial time and a call will not be placed without it, and the AI never denies being an AI if a person asks.
Retention and erasure
- Recordings are kept for five years by default. Each recording carries its own retention stamp taken when it was archived, so shortening the setting later cannot retrospectively delete audio kept under a longer promise.
- Transcripts are the durable record of a call. Audio held by our voice provider before it reaches our own storage expires on their schedule.
- If someone asks you to delete their data, an account owner can erase them from the dashboard. That removes the recordings we hold, destroys the transcripts, blanks their messages and overwrites their name, number and email.
- Two things deliberately survive an erasure. The call records stay, without any personal detail, because they are billing history and deleting them would change a past invoice. The one-way hash of the phone number stays, with the person marked do-not-call, because that is what stops the same number being dialled again if it turns up in a future upload. An erasure that causes the next unwanted call would not be much of an erasure.
Sub-processors
| Provider | What for | Where |
|---|---|---|
| Vapi | Voice orchestration and speech to text | United States |
| Twilio | Phone numbers, calls and SMS | Australia and United States |
| Anthropic | The language model on the call, and call scoring where enabled | United States |
| Neon | Application database | Sydney, Australia |
| Fly.io | Application servers | Sydney, Australia |
| Cloudflare R2 | Call recording storage | Asia Pacific |
| Vercel | Dashboard and website hosting | Global edge |
| Resend | Transactional and notification email | United States |
| Stripe | Payments and subscriptions | Australia and United States |
| Clerk | Dashboard sign-in | United States |
What we do not have
Yappa is a small Australian company and does not hold ISO 27001, SOC 2, PCI DSS certification or IRAP assessment. Those are real, expensive programmes and claiming them loosely would be worse than not having them. If your procurement requires one, say so early: we will tell you honestly whether it is something we can commit to for your timeline rather than let it surface at contract stage.
What we do have is the list above, all of it verifiable in the product: the compliance audit trail you can export yourself, recordings you can play and delete, and an erasure that is a button rather than a support ticket.
Reporting a security problem
Email hello@yappa.com.au with the word SECURITY in the subject. Tell us what you found and how to reproduce it. We will confirm we have it, keep you posted while we fix it, and we will not pursue anyone who reports a genuine problem in good faith.
