Privacy Policy
Last updated: July 30, 2026
Arnova (“Arnova”, “we”, “us”) is building an AI phone receptionist service for local businesses. This policy explains what personal information we collect, why we collect it, how we protect it, and the choices you have. It applies to our website (arnova.app), our product (app.arnova.app), and the receptionist service itself.
Who is responsible for your information
Arnova is operated by its founder as a sole trader, currently from British Columbia, Canada. Arnova is not yet incorporated. A company is to be registered in Australia before commercial launch, and this policy will be updated with the registered company name, registration number, and registered address at that time. Until then, the person accountable for the information described here is Arnova's founder, reachable at the address in “Privacy contact” below.
Current status — what is actually collected today
The receptionist service is pre-launch and not yet commercially available. Today, the only personal information collected through this website is what you give us on the waitlist form: your name, email address, business type, and city, together with a record of your consent to receive launch updates and the date you gave it. We use it to contact you about Arnova's launch, and for nothing else.
The sections below describe how the service handles information when it is live, so you can see what you would be agreeing to before you sign up. They are written in advance on purpose, so the terms are visible before anyone commits to anything.
Who this covers
Two groups of people: our clients (the businesses that subscribe to Arnova) and their callers (the people who phone a business whose calls Arnova answers). If you called a business and spoke with its AI receptionist, the section “Callers” below is about you.
Information we collect — clients
When you sign up we collect your name, email address, business name and details (trade, hours, services, service area, business phone number), and billing information. Payments are processed by Stripe — we never see or store your full card number. If you connect a Google Calendar, we store a secure token that lets the service create appointments; the token is encrypted at rest and we access your calendar only to check availability and create bookings.
Information we collect — callers
When Arnova answers a call on a client's behalf, we collect what a human receptionist would: the caller's name, phone number, the reason for the call, and — where relevant to the job — a service address and preferred appointment times. Calls are recorded and transcribed so the business receives an accurate record; the AI receptionist identifies itself as an AI and discloses that the call may be recorded at the start of each call. Call recordings, transcripts, and captured details are made available to the business you called and to Arnova for operating and improving the service.
How we use personal information
To deliver the receptionist service (answer calls, capture leads, book appointments, notify the business by text and email); to bill our clients; to provide support; to monitor quality and troubleshoot; and to meet legal obligations. We do not sell or rent personal information, and we do not use caller data for advertising.
Automated processing and AI
Arnova is an AI service, so automated processing is central to how it works: speech is transcribed automatically, and large language models generate the receptionist's side of a conversation, summarise calls, and draft follow-up emails about enquiries. A person is not listening to your call as it happens. No automated decision is made that has a legal effect on you — the output is a message and a record handed to the business you contacted, which decides what to do next.
Service providers and where data is stored
We use a small number of specialised providers to run the service, most of which store or process data in the United States:
- Vapi — voice-call orchestration; Deepgram — speech-to-text; Cartesia — text-to-speech
- Anthropic — the AI models that draft replies, summaries, and call notes from enquiry details
- Telnyx — phone numbers and SMS; Resend — email delivery
- Stripe — payments; Clerk — client sign-in and account security
- Google — calendar booking and business lookup, where used
- Cloudflare, Vercel, Neon — hosting, application, and database infrastructure; Trigger.dev — background processing
- Sentry — error monitoring, configured to exclude caller phone numbers and business data from error reports
- Notion — internal client account records
This means personal information may be stored or accessed outside the country you are in, and may be subject to the laws of those jurisdictions. Each provider is bound by its own contractual and security obligations, and we share only what each needs to perform its function.
How long we keep it
Client account records are kept for the life of the subscription and for up to 7 years afterwards where required for tax and accounting. Call recordings, transcripts, and lead details are kept while the client's account is active so the business can review its own call history, and are deleted or anonymised within 90 days of a client's account closing. Records of marketing consent are kept for a minimum of 3 years, as required by Canada's Anti-Spam Legislation (CASL) for consents given while we operate from Canada, and under the Spam Act 2003 (Cth) for consents given once we operate from Australia. We delete personal information sooner on valid request (see “Your rights”).
How we protect it
Data is encrypted in transit; access is limited to what is needed to operate the service; calendar credentials are encrypted at rest; and payment details are handled entirely by Stripe. No system is perfectly secure, but if we ever become aware of a breach that creates a real risk of serious harm, we will notify affected people and the appropriate authority.
Your rights
You may request access to the personal information we hold about you, ask us to correct it, or ask us to delete it. We respond to requests within 30 days. Callers may make requests directly to us or to the business they called — where the business controls the data, we will assist it in responding. To stop receiving any marketing email, use the unsubscribe link in the email or contact us.
Cookies and analytics
Our website uses privacy-friendly, cookieless analytics to count page visits. We do not use advertising cookies or cross-site tracking. If that ever changes, this policy will be updated first.
Privacy contact
Privacy questions, access requests, deletion requests, and complaints can be sent to hello@arnova.app, which reaches Arnova's founder directly.
If you are not satisfied with our response: while Arnova operates from Canada you may contact the Office of the Information and Privacy Commissioner for British Columbia (oipc.bc.ca); once Arnova operates from Australia you may contact the Office of the Australian Information Commissioner (oaic.gov.au).
Changes to this policy
If we make material changes, we will update this page and the “last updated” date, and notify active clients and waitlist subscribers by email. Registering the Australian company will be a material change and will be published here.