Privacy Policy
01Who we are and what this covers
Murusai is an abuse-protection service for AI voice agents, operated by Murusai LLC, a Virginia limited liability company (Murusai, we, us). This policy explains what personal data we collect through murusai.com, app.murusai.com, the Murusai API, and our alerts and emails (the Service), why we collect it, who we share it with, how long we keep it, and the rights you have.
We handle personal data in two roles, and the rest of this policy is organized around them:
- As a controller for the people who use Murusai: account holders, team members, people who fill in a form on our site, and visitors. Sections 2 to 5 cover this.
- As a processor for the call data our customers send us about calls to their voice agents, which includes the phone numbers of people who call those agents. Our customer decides why that data is collected and is the controller. Section 6 covers this.
Two facts shape everything below. Murusai never receives call audio. And the Service is built to work from metadata and timing, not from what was said: our integrations accept transcript lengths and hashes, and we do not store transcript text.
02What we collect about you
Account and team
- Your name, work email, company name, and password. Passwords are stored as salted hashes, never in plain text.
- Your role in the account (owner, admin, or member), invitations you send or accept, and the email addresses you invite.
- If you turn on two-factor authentication: a secret for your authenticator app, stored encrypted, backup codes stored as hashes, and a token for devices you choose to remember for 30 days.
- Email verification and invitation tokens, which expire and are single use.
Billing
- Your plan, subscription status, invoices, and payment history.
- Card details go directly to Stripe, our payment processor. We receive a customer reference, the card brand and last four digits, and payment outcomes. We never see or store full card numbers.
Connections and settings
- Credentials for the telephony and voice platforms you connect (for example API keys and account identifiers). They are encrypted at rest with a key held separately from the database and are used only to read your numbers and calls and, where enabled, to end calls for you.
- The phone numbers you protect, which plan features are on for each, and thresholds you set.
- Where alerts go: webhook URLs and signing secrets, email addresses, and phone numbers for SMS and voice alerts.
Forms and support
- If you use the under-attack form or contact us: your name, email, company, phone number if you give one, what you tell us, and the IP address the form was sent from.
- Emails you send us and our replies.
Automatically
- Server logs: IP address, browser and device information, the pages and API endpoints requested, timestamps, and errors.
- Cookies and browser storage, described in section 5.
We do not collect data about your race, health, religion, politics, sexuality, or other special categories, and we ask you not to send it to us.
03How we use it, and on what basis
We use your data to:
- Provide the Service: run your account, read your calls, score them, send the alerts you configured, end calls where you enabled it, and bill you. Basis: performing our contract with you.
- Keep it secure: verify sign-ins, run two-factor authentication, detect misuse, and investigate incidents. Basis: our legitimate interest in a secure service, and our contract.
- Talk to you: verification, invitations, alerts, billing notices, changes to the Service or these terms, and answers to your questions. Basis: our contract and legitimate interests. Marketing email, if we ever send it, will be opt-in, with an unsubscribe link in every message.
- Improve the Service: understand how features are used and where they fail, in aggregate. Basis: legitimate interests.
- Meet legal obligations: tax, accounting, and responding to lawful requests. Basis: legal obligation.
Where the law requires consent, for example for non-essential cookies, we ask for it and you can withdraw it at any time. We do not make decisions about you with legal or similarly significant effects by automated means. Scores about calls are decisions our customers make about traffic, not decisions we make about you.
06Call data we process for customers
When a customer protects a number, their platform or server sends us events about calls to it. This is the data the Service is built on. Our customer is the controller of it; we process it on their instructions under our terms and, where applicable, a data processing agreement.
What it includes
- Calling and called phone numbers, and the country and carrier information that can be derived from a number.
- Call identifiers, start and end times, duration, and outcome.
- Turn timing during a call: when each side started and stopped speaking, interruptions, and, if the platform provides them, the length in characters or words of what was said and a one-way hash of it. We use the hash to notice repeated identical speech. It cannot be turned back into text.
- Scores, reason codes, alerts, and actions the Service produced.
What it never includes
- Call audio. Murusai is not in the call path and has no way to receive it.
- Transcript text. Integrations that could send text are configured to send lengths and hashes instead, and any text a platform sends anyway is hashed on arrival and the text discarded.
- Names, addresses, or account details of callers. We do not look people up by their phone number.
Network signals
A number that floods one customer's agent is very likely to flood the next. To protect everyone, we derive signals from call data across customers, such as how often a calling number or number pattern appears, how it behaves, and when. These signals are aggregated or de-identified so that they do not reveal which customer the calls were made to, and are used only to score calls. Enterprise customers can opt out of contributing.
If you called a Murusai-protected agent
The business you called decides how your call data is used and is the right place for any request about it. We hold that data for them. If you contact us at support@murusai.com we will help you reach the right business, and where the law gives you rights directly against us we will honor them.
07How long we keep it
We keep data only as long as it is needed for the purpose we collected it for, then delete or de-identify it. Our standard periods:
| Data | Kept for |
|---|---|
| Account, team, and settings | Life of the account, then deleted within [30] days of closure |
| Billing records and invoices | [7] years, for tax and accounting law |
| Platform credentials | Until you disconnect the platform or close the account, then deleted at once |
| Call events and turn timing | [90] days, then reduced to daily and hourly aggregates |
| Aggregated call statistics per number | [13] months, for baselines and the health charts |
| Reputation of calling numbers (counts and a fading score per number, never tied to a customer once they leave) | Kept while the number keeps calling; a number not seen for 12 months has no weight left and is dropped |
| Alerts and incident reports | Life of the account |
| Under-attack and contact form submissions | [24] months |
| Server logs | [30] days |
We may keep data longer where we need it to resolve a dispute, enforce our terms, or comply with a legal obligation, and we keep backups for up to [30] days after the live copy is deleted.
08How we protect it
- Data moves over TLS. Platform credentials, two-factor secrets, and webhook signing secrets are encrypted at rest with a key kept apart from the database.
- Passwords and backup codes are stored as salted hashes. Sign-in attempts and second-factor attempts are rate limited and locked after repeated failures.
- Access to production systems is limited to people who need it and is protected by two-factor authentication.
- Webhooks we send to you are signed so you can verify they came from us.
- If we learn of a breach affecting your personal data, we will notify you without undue delay, and within 72 hours where the law requires it, with what we know and what we are doing.
No service can promise perfect security. Keep your credentials safe, turn on two-factor authentication, and tell us at support@murusai.com if you suspect a problem.
09Where it is stored
Murusai is operated from the United States and our providers store data there. If you use the Service from the European Economic Area, the United Kingdom, Switzerland, or another place with data transfer rules, your data will be transferred to and processed in the United States. Where required, we rely on the European Commission's Standard Contractual Clauses and the UK Addendum, or another lawful mechanism, and our Data Processing Agreement includes them. You can ask for a copy at support@murusai.com.
10Your rights and choices
Depending on where you live, you may have the right to:
- access the personal data we hold about you, and receive a copy in a portable format;
- correct data that is inaccurate or incomplete;
- delete your data, subject to the retention we are required or entitled to keep;
- restrict or object to certain processing, including any processing based on legitimate interests;
- withdraw consent where processing is based on it, without affecting what was done before;
- complain to a supervisory authority. In the EEA that is the authority in your country; in the UK it is the Information Commissioner's Office.
Much of this you can do yourself in the dashboard: update your name and company, change your email, manage team members, disconnect platforms, and close the account. For anything else, email support@murusai.com. We will verify that the request comes from you and respond within 30 days, or tell you why we need longer. We will not treat you differently for exercising a right.
California
If you are a California resident, the California Consumer Privacy Act gives you the rights above, including the right to know the categories of personal information we collect (identifiers, commercial information, internet activity, and professional information, as described in section 2), the purposes (section 3), and the categories of third parties we share it with (section 4). We do not sell personal information or share it for cross-context behavioral advertising, and we have not done so in the past 12 months. We do not use or disclose sensitive personal information for purposes that require a right to limit. You may use an authorized agent to make a request; we will ask for proof of authorization.
Do Not Track and Global Privacy Control
Because we do not track you across sites or sell data, there is nothing for these signals to switch off, and we treat every visitor as if they were sent.
11Children
The Service is for businesses and is not directed at children. We do not knowingly collect personal data from anyone under 18 as a user. If you believe a child has created an account, email support@murusai.com and we will delete it.
12Changes to this policy
We will update this policy as the Service and the law change. The effective date at the top tells you when it last changed. For material changes we will email account holders or show a notice in the dashboard at least 30 days before the change takes effect. Earlier versions are available on request.
13Contact
Questions, requests, and complaints about privacy:
- Email: support@murusai.com
- Security reports: support@murusai.com
- Mail: Murusai LLC, 8401 Mayland Dr #11633, Richmond, VA 23294
- EU or UK representative: none appointed. The Service is offered in the United States and Canada only.