Privacy Policy
Last updated: September 18, 2026 · Effective: September 21, 2026
1. Who we are and what this covers
PILOTLAB LLC dba VM HUNTER ("VM Hunter", "we", "us") operates the answering machine detection service, the website at vmhunter.com and the customer portal (together, the "Service"). This policy explains what personal data we handle, why, who we share it with and the choices you have.
We handle personal data in two different roles, and the difference matters:
- As a controller for data about our own customers and website visitors: account details, billing records, sign-in logs, support messages and website analytics.
- As a processor for call data our customers send us. When a customer's dialer streams the first seconds of a call to us, that customer decides why and how the data is used; we process it only to return a detection result and to show the customer their own logs. See GDPR & Data Processing.
2. Data we collect
| Category | What it includes | Where it comes from |
|---|---|---|
| Account | Name, email address, company, postal address, phone number, password (stored only as a salted bcrypt hash), API key. | You, when you register or edit your profile. |
| Billing | Plan, billing period, invoices, payment status, Stripe customer and subscription identifiers. We never see or store your full card number. | You and our payment processor. |
| Sign-in and security logs | Date and time, IP address, browser and operating system (user agent), language header, referring page, the event (sign-up, sign-in, failed sign-in, sign-out, password reset, email verification) and the email address used. | Your browser, automatically. |
| Call data (processed for customers) | The first seconds of far-end call audio streamed by the customer's dialer (normally 2 to 3.5 seconds), the transcript of that audio, the detection result and reason, the call or lead identifier the customer chooses to send, timing metrics, and, where the customer's setup supplies them, the dialed number and the dialer's unique call ID. | Our customer's telephony system. |
| Support and contact | Messages you send us and the contact details in them. | You. |
| Website usage | Pages viewed, approximate location derived from IP address, device and browser type, referring site. Collected by Google Analytics only if you accept analytics cookies. | Your browser, with your consent. |
| Notification preferences | Which account, usage and marketing emails you have switched on or off. | You. |
3. How we use data and our legal bases
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Create and run your account, authenticate API requests, return detection results, show call logs and usage. | Performance of our contract with you. |
| Charge for the Service, keep accounting and tax records. | Contract; legal obligation. |
| Send service emails: verification, password reset, payment problems, plan changes, usage and limit alerts, warnings about calls arriving without audio. | Contract; legitimate interest in keeping your integration working. You can switch most of these off in Settings. |
| Keep sign-in and security logs; detect abuse, fraud and unauthorised access; enforce plan limits. | Legitimate interest in securing the Service and your account. |
| Improve detection accuracy by reviewing results, transcripts and audio samples in aggregate or for specific support cases. | Legitimate interest; for customer call data, on the customer's documented instructions. |
| Website analytics. | Your consent, which you can withdraw at any time in Cookie settings. |
| Product news and marketing email. | Your consent (opt-in). Every message has an unsubscribe link. |
| Respond to lawful requests and defend legal claims. | Legal obligation; legitimate interest. |
We do not sell personal data, and we do not use call data for advertising.
4. Call audio, transcripts and recordings
The Service works by analysing the first seconds of audio after a call is answered. For each call we keep a short audio sample, its transcript and the result, so that you can review and audit detections in your portal. Recordings are available only to the account that made the call and to our authorised staff, through authenticated or signed, expiring links.
You control this data from your portal:
- Delete a recording from the call log, or delete all recordings from Settings. Deleted audio cannot be recovered.
- Turn recording storage off in Settings. Calls are still analysed in real time, but no audio sample is written to disk; the transcript and result are kept so your logs and usage remain accurate.
Your responsibilities as our customer. You control which calls are sent to us. You are responsible for having a lawful basis to place those calls and to have the opening seconds analysed and recorded, for giving any notice or obtaining any consent that call-recording, wiretapping, telemarketing or privacy law requires in the places you call, and for honouring do-not-call rules. See our Acceptable Use Policy.
5. How long we keep data
| Data | Retention |
|---|---|
| Account and profile | While your account is open, then deleted or anonymised within 30 days of closure, except records we must keep by law. |
| Billing and tax records | As long as tax and accounting law requires, typically 7 years. |
| Call audio samples | Deleted automatically 30 days after the call. You can delete individual recordings, or all of them, sooner from your portal, or switch recording storage off entirely. |
| Transcripts, results and call metadata | Kept while your account is open and deleted within 30 days of closure or on request. We may keep aggregated statistics that do not identify anyone. |
| Sign-in and security logs | 12 months, then deleted. |
| Support correspondence | Up to 24 months after the conversation ends. |
| Analytics data | Up to 14 months, according to our Google Analytics retention setting. |
7. International transfers
We operate from, and store data in, the United States, and some of our providers process data in other countries. Where personal data from the EEA, the UK or Switzerland is transferred to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where relevant) or another lawful transfer mechanism.
8. Security
We protect data with measures appropriate to the risk, including:
- TLS encryption for the website, the customer portal and all account and billing traffic.
- Passwords stored only as salted bcrypt hashes; session cookies that are HTTP-only and sent only over HTTPS.
- Per-account API keys that can be deactivated at any time, and plan-level rate limits.
- Call recordings served only to the owning account or through signed links that expire.
- Access to production systems restricted to authorised personnel, and logs of sign-ins and administrative actions.
Audio is streamed from your dialer to our detection endpoint over a WebSocket connection. If your security policy requires transport encryption or a private network path for the audio stream, contact us before sending production traffic so that we can agree a suitable setup.
No system is perfectly secure. If we become aware of a personal data breach affecting you, we will notify you and the competent authorities as the law requires.
9. Your rights
Depending on where you live, you may have the right to access, correct, delete or export your personal data, to restrict or object to certain processing, and to withdraw consent at any time without affecting processing that already took place. Residents of the EEA, UK and Switzerland can find the detail in GDPR & Data Processing.
California residents: you have the right to know what personal information we collect and how we use and disclose it, to request deletion and correction, and not to be discriminated against for exercising these rights. We do not sell or share personal information for cross-context behavioural advertising.
To exercise any right, email support@vmhunter.com from the address on your account. We respond within 30 days. If a request concerns call data that one of our customers sent us, we will refer you to that customer, who decides how that data is used.
11. Children
The Service is for businesses. It is not directed at children, and we do not knowingly collect data from anyone under 16.
12. Changes to this policy
We will post any changes on this page and update the date at the top. If a change materially affects how we use your data, we will notify account holders by email before it takes effect.
13. Contact
Questions, requests or complaints about privacy:
PILOTLAB LLC dba VM HUNTER
1309 Coffeen Ave Ste 1200, Sheridan, WY 82801, United States
Email: support@vmhunter.com
Website: vmhunter.com