AgentiCall
AgentiCall • For adults 18+

Privacy / 隐私政策

Understand the information behind an AI call. / 了解一通 AI 电话背后的数据处理。

Last updated 19 September 2026 · 更新于 2026 年 9 月 19 日

Privacy policy

AgentiCall is operated by Zhang Liu (刘章). We use information to provide adult AI voice conversations, account access, schedules, time balances, purchase verification and support. Contact zhang3917@gmail.com for privacy questions or requests.

Before an AI call: we ask for your explicit permission to send microphone audio, the role, topic, goal and optional profile (nickname, gender and age group) you provide through our server to Google Gemini. Microphone permission is a separate iOS control. AgentiCall does not save raw call recordings or full conversation transcripts.

Information we process

  • Account access: an account identifier, username and display name; protected credential-verification data for existing password accounts; provider-specific identifiers and authentication credentials for Apple or Google sign-in. Authentication responses may include your name and email. Our account database stores the display name and provider identifier rather than using email to merge accounts.
  • Guest access and trial eligibility: a server-assigned pseudonymous guest identifier, verified Apple app-download transaction information, and minimal hashed eligibility markers for the app-download scope and signed-in identity. We use these with the promotion identifier and claim time to grant trial time once and link unused guest time after you sign in; they are not call recordings.
  • Calls and schedules: the character name, role, topic, goal, language, voice, optional character gender and age group, your optional profile (nickname, gender and age group), schedule and time zone, call status, timestamps and used time. These settings can contain personal information you choose to enter.
  • Purchases: Apple product and transaction identifiers, the associated account identifier, credited and consumed time, and refund adjustments. Apple handles payment details; we do not receive your full card number.
  • Numeric service usage: model-usage counts and modality labels (such as audio or text), model name, receipt time, and account, call and connection identifiers. These records help us monitor service operation and resource costs. They contain numeric token counts, not audio or conversation text, and do not replace the connected-time meter used for your balance.
  • Support and service operation: information you email us and technical information needed to deliver and protect the service, such as request timing, connection information, IP-derived rate-limit keys and errors.

Who processes the information

Our backend is hosted on Tencent Cloud in the United States. Google Gemini processes audio and supplied context to generate replies. Apple and Google process sign-in through their own services, and Apple processes in-app purchases. Processing may occur outside your country. We do not sell your information or use the app for advertising tracking.

Google sign-in

If you choose Google sign-in, Google's sign-in software processes account and device information as well as the identity token sent to AgentiCall. Its data disclosures include name, email address, phone number and approximate location for sign-in functionality; user identifiers for functionality and analytics; device identifiers and other usage information for analytics; and other data for functionality and analytics. These categories are declared as linked to the user. The sign-in software declares no advertising tracking.

Google explains that an IP address can be used to estimate a general location for fraud prevention. Sign-in requests also contain technical details such as the sign-in software version, execution environment and operating-system version. The information processed can vary with the account and sign-in flow; this does not mean AgentiCall asks every user for a phone number or GPS access. Our own Google account record uses the provider identifier and display name.

Apple and Google are the primary sign-in options. Your first successful provider sign-in creates an ordinary AgentiCall account. Existing username/password accounts can use the optional username/password sign-in. Google's sign-in data follows its own privacy and account controls; the Gemini retention periods below are not a retention schedule for Google sign-in. See Google's Privacy Policy, its sign-in disclosure guidance and the data declarations for the sign-in software used by this app.

Google AI processing and retention

Google's published abuse-monitoring policy describes 55-day retention of prompts, contextual information and outputs for safety, enforcement and required disclosures. Flagged information may be reviewed by authorized personnel. This is separate from our own recording policy; it does not mean that every raw audio packet is necessarily retained for 55 days.

AgentiCall uses Live session resumption to recover a brief disconnection. Google states that generating a session handle can retain conversation state, including text and audio, for up to 24 hours. We discard our resumption handle when the call task ends. Discarding our handle does not erase Google's retained state immediately. See Google's Live retention explanation.

Google's use of data also depends on the applicable service terms and project configuration. This policy does not promise that data is never used for model improvement or that the service has zero retention. See the Gemini API terms. Avoid sharing confidential or highly sensitive information.

If previous guest access cannot be confirmed, verification may restore eligible unused trial time while previous guest access, schedules and history are cleared, so a shared App Store account does not expose another guest’s records. Guest records are therefore not guaranteed to survive reinstallation or a device change; sign in to your existing account to recover its purchased balance.

How long our records remain

  • Account and sign-in records remain while your account exists. Sign-in sessions have a limited lifetime and can be revoked by signing out, changing a password or deleting the account.
  • The call-history list retains up to the latest 200 ended calls within 90 days. Active calls remain until they finish. Active schedules remain until completed or cancelled; completed and cancelled schedule records are cleaned up once 90 days have passed since the last scheduled trigger time stored for that schedule. This is measured from the scheduled time, not the date you cancel it.
  • Recent request records prevent duplicate actions. Any call settings or response snapshots in this cache follow the same call-history pruning; content-free request markers can remain until the bounded cache is replaced or the account is deleted.
  • Minimal hashed trial-claim markers, the offer identifier and claim time may remain after account deletion to prevent the same offer from being claimed again. We keep them while this trial offer is available and arrange for deletion 90 days after the offer ends. These markers do not include call audio, conversation text or a profile, and are separate from purchase and financial records.
  • Pseudonymous purchase and financial ledger records may remain after account deletion for purchase verification, preventing duplicate credits, refunds, disputes and accounting obligations. They do not follow the 90-day call-history schedule.
  • Records needed to preserve unused guest time remain while that time entitlement is outstanding. They are separate from minimal promotion-claim markers and are not removed simply because those markers are cleaned up.
  • Numeric service-usage records are cleared during cleanup after 90 days from receipt, or earlier when their associated call is removed from retained history. Deleting your account removes these usage records as well.
  • Support correspondence and necessary operational records are separate from call history. Contact us about access or deletion of information you sent to support.

Your choices and account deletion

You can end a call, pause or cancel upcoming schedules, and stop using AgentiCall. You can also revoke microphone or notification permission in iOS Settings and clear your optional nickname, gender and age group. Account deletion and requests concerning your personal information are described below.

To delete your account, open My → Account Settings → Delete Account. Confirm your password or reauthenticate with the original Apple/Google method, then confirm deletion. When the request succeeds, we immediately remove the account, sign-in sessions, schedules and call-history content from our active service, end calls and clear remaining time. We revoke the associated Sign in with Apple authorization when applicable. This cannot be undone and does not automatically request an Apple purchase refund. The limited trial-claim markers, financial records and Google's independent retention periods are described above.

You may contact us to request access, correction or deletion of personal information, or exercise rights available where you live. We may need to verify your identity. The in-app deletion flow does not require contacting support.

Adults and changes

AgentiCall is only for people aged 18 or older and is not intended for children. Do not give the app to a child or submit another person's private information without authorization. We update this page when our practices change and show the last-updated date above.

隐私政策

AgentiCall 由刘章(Zhang Liu)运营。我们处理信息以提供面向成年人的 AI 语音交流、账号登录、预约、时长余额、购买验证与客服支持。如有隐私问题或权利请求,请联系 zhang3917@gmail.com。

AI 通话开始前:我们会先征得你的明确同意,将麦克风音频,以及你设定的角色、话题、目标和可选昵称,经我们的服务器发送给 Google Gemini。iOS 麦克风权限是另一项独立控制。AgentiCall 不保存原始通话录音或聊天全文。

我们处理的信息

  • 账号:账号编号、用户名、显示名称;已有用户名账号的受保护凭据验证数据;Apple 或 Google 登录的服务商身份标识和认证凭据。认证响应可能包含姓名和邮箱。账号数据库保存显示名称和服务商身份标识,不按邮箱自动合并账号。
  • 游客访问与试用资格:服务器分配的伪名游客标识、经验证的 Apple App 下载交易资料,以及下载交易范围和登录身份的最少哈希资格标记。我们结合活动编号与领取时间,防止重复发放试用权益,并在登录后关联未用游客时长;这些不是通话录音。
  • 通话和预约:角色名称、角色设定、话题、目标、语言、声音、可选昵称、预约时间和时区,以及通话状态、时间戳和已用时长。你填写的内容可能含有个人信息。
  • 购买:Apple 商品和交易编号、关联账号编号、增加与消耗的时长及退款调整。付款资料由 Apple 处理,我们不会收到完整银行卡号。
  • 数字服务用量:模型用量计数及音频、文字等模态标签、模型名称、接收时间,以及关联的账号、通话和连接标识,用于监测服务运行及资源成本。这些记录包含数字 token 数量,不含音频或对话文字,也不替代按接通时间计算余额的计量方式。
  • 客服和服务运行:你主动发送的邮件内容,以及提供和保护服务所需的技术资料,例如请求时间、连接信息、由 IP 派生的限流标识和错误信息。

处理方与地点

我们的后端位于美国腾讯云服务器。Google Gemini 处理音频和所提供的上下文以生成回复;Apple 和 Google 通过各自服务处理登录,Apple 处理 App 内购买。数据可能在你所在国家或地区以外处理。我们不出售你的信息,也不通过本应用进行广告跟踪。

Google 登录

选择 Google 登录时,除了发送给 AgentiCall 的身份令牌,Google 登录软件还会处理账号和设备信息。其数据披露包括:用于登录功能的姓名、邮箱、电话号码和粗略位置;用于功能与分析的用户标识;用于分析的设备标识和其他使用数据;以及用于功能与分析的其他数据。这些类别均声明为与用户关联。该登录软件声明不用于广告跟踪。

Google 说明,IP 地址可用于估算设备大致位置以防范欺诈。登录请求还包含登录软件版本、运行环境及操作系统版本等技术信息。实际处理内容会因账号和登录流程而异,这不表示 AgentiCall 要求每位用户填写电话号码或授予 GPS 权限。我们自己的 Google 账号记录使用服务商身份标识和显示名称。

主要登录方式为 Apple 和 Google;首次成功登录会自动创建普通 AgentiCall 账号。已有用户名密码账号可使用可选的「用户名密码登录」。Google 登录数据适用其自身的隐私及账号控制;下方 Gemini 的保留期限不是 Google 登录数据的保留期限。详见 Google 隐私政策、登录披露说明及本应用所用登录软件的数据声明。

Google AI 的处理与保留

Google 的滥用监控政策说明,提示、上下文和输出会为安全、政策执行和必要披露保留 55 天,被标记的内容可能由获授权人员审查。这与本应用不保存录音是不同的规则,也不表示每个原始音频包一定保留 55 天。

AgentiCall 使用 Live 会话恢复功能处理短暂断线。Google 说明,生成恢复句柄后,包括文字、音频在内的会话状态可保留最多 24 小时。通话任务结束后,我们会丢弃自己持有的恢复句柄,但这不等于立即删除 Google 已保留的状态。详见 Google 的 Live 保留说明。

Google 对数据的使用还取决于适用的服务条款和项目配置。本政策不承诺数据绝不用于模型改进,也不承诺零保留。详见 Gemini API 条款。请避免分享保密或高度敏感的信息。

如果无法确认原有游客访问身份,核验后可恢复符合资格的未用试用时长,同时清除旧游客访问、预约与历史,避免共享 App Store 账号暴露其他游客的记录。因此,游客记录不保证在重装或换设备后恢复;已有账号的购买余额仍可通过登录原账号恢复访问。

我们保留记录的时间

  • 账号和登录资料在账号存在期间保留。登录会话有有限有效期,可通过退出登录、更改密码或删除账号撤销。
  • 可查看的通话历史最多保留90 天内最近 200 条已结束通话。进行中的通话保留至结束;有效预约保留至完成或取消,已完成或取消的预约记录,从该预约最后保存的计划触发时间起满 90 天后清理,而不是从点击取消的日期起算。
  • 近期请求记录用于防止重复操作。其中的通话设置和响应快照会随上述通话历史一起清理;不含通话内容的请求标记可保留至有限缓存被替换或账号删除。
  • 为防止重复领取同一试用优惠,最少哈希领取标记、活动编号与领取时间可能在删号后继续保留,在该试用优惠提供期间保留,并在优惠停止满 90 天后安排清理。这些标记不含通话音频、对话文字或个人资料档案,与购买和财务流水分开处理。
  • 与伪名账号标识关联的购买和财务流水,可能在删号后继续保留,用于购买核验、防止重复入账、退款、争议及账务义务,不适用通话历史的 90 天清理规则。
  • 为继续保留未用游客时长所必需的权益关联记录,会在该时长权益尚未处理完毕期间保留;它们独立于最少促销领取标记,不会仅因清理领取标记而被一并删除。
  • 数字服务用量记录在接收满 90 天后的清理任务中删除;关联通话先从保留历史中移除时,用量记录也会相应提前清理。删除账号也会移除这些用量记录。
  • 客服邮件与必要运行记录独立于通话历史。如需访问或删除主动发给客服的信息,请联系我们。

选择与删除账号

你可以结束通话、暂停或取消未来预约,并停止使用 AgentiCall。也可以在 iOS 设置中关闭麦克风或通知权限,并清空可选昵称。删除账号及提出个人信息相关请求的方式见下文。

删除路径为我的 → 账号设置 → 删除账号。输入当前密码,或使用原来的 Apple/Google 方式重新验证身份,再确认删除。请求成功后,我们会立即从运行中的服务移除账号、登录会话、预约和通话历史,结束通话并清除剩余时长;适用时会撤销关联的 Sign in with Apple 授权。操作无法撤销,且不会自动向 Apple 申请退款。最少试用领取标记、财务记录和 Google 独立保留规则见上文。

你可以联系我们请求访问、更正、删除个人信息,或行使所在地适用的权利。我们可能需要核实身份。使用 App 内删除功能不需要先联系客服。

成年人及政策更新

AgentiCall 仅供年满 18 岁的人使用,不面向儿童。请勿交给未成年人使用,或未经授权提交他人的私人资料。处理方式变更时,我们会更新本页及上方日期。