Privacy Policy

Last updated: September 18, 2026 · Effective: September 21, 2026

1. Who we are and what this covers

PILOTLAB LLC dba VM HUNTER ("VM Hunter", "we", "us") operates the answering machine detection service, the website at vmhunter.com and the customer portal (together, the "Service"). This policy explains what personal data we handle, why, who we share it with and the choices you have.

We handle personal data in two different roles, and the difference matters:

  • As a controller for data about our own customers and website visitors: account details, billing records, sign-in logs, support messages and website analytics.
  • As a processor for call data our customers send us. When a customer's dialer streams the first seconds of a call to us, that customer decides why and how the data is used; we process it only to return a detection result and to show the customer their own logs. See GDPR & Data Processing.

2. Data we collect

CategoryWhat it includesWhere it comes from
AccountName, email address, company, postal address, phone number, password (stored only as a salted bcrypt hash), API key.You, when you register or edit your profile.
BillingPlan, billing period, invoices, payment status, Stripe customer and subscription identifiers. We never see or store your full card number.You and our payment processor.
Sign-in and security logsDate and time, IP address, browser and operating system (user agent), language header, referring page, the event (sign-up, sign-in, failed sign-in, sign-out, password reset, email verification) and the email address used.Your browser, automatically.
Call data (processed for customers)The first seconds of far-end call audio streamed by the customer's dialer (normally 2 to 3.5 seconds), the transcript of that audio, the detection result and reason, the call or lead identifier the customer chooses to send, timing metrics, and, where the customer's setup supplies them, the dialed number and the dialer's unique call ID.Our customer's telephony system.
Support and contactMessages you send us and the contact details in them.You.
Website usagePages viewed, approximate location derived from IP address, device and browser type, referring site. Collected by Google Analytics only if you accept analytics cookies.Your browser, with your consent.
Notification preferencesWhich account, usage and marketing emails you have switched on or off.You.

3. How we use data and our legal bases

PurposeLegal basis (GDPR Art. 6)
Create and run your account, authenticate API requests, return detection results, show call logs and usage.Performance of our contract with you.
Charge for the Service, keep accounting and tax records.Contract; legal obligation.
Send service emails: verification, password reset, payment problems, plan changes, usage and limit alerts, warnings about calls arriving without audio.Contract; legitimate interest in keeping your integration working. You can switch most of these off in Settings.
Keep sign-in and security logs; detect abuse, fraud and unauthorised access; enforce plan limits.Legitimate interest in securing the Service and your account.
Improve detection accuracy by reviewing results, transcripts and audio samples in aggregate or for specific support cases.Legitimate interest; for customer call data, on the customer's documented instructions.
Website analytics.Your consent, which you can withdraw at any time in Cookie settings.
Product news and marketing email.Your consent (opt-in). Every message has an unsubscribe link.
Respond to lawful requests and defend legal claims.Legal obligation; legitimate interest.

We do not sell personal data, and we do not use call data for advertising.

4. Call audio, transcripts and recordings

The Service works by analysing the first seconds of audio after a call is answered. For each call we keep a short audio sample, its transcript and the result, so that you can review and audit detections in your portal. Recordings are available only to the account that made the call and to our authorised staff, through authenticated or signed, expiring links.

You control this data from your portal:

  • Delete a recording from the call log, or delete all recordings from Settings. Deleted audio cannot be recovered.
  • Turn recording storage off in Settings. Calls are still analysed in real time, but no audio sample is written to disk; the transcript and result are kept so your logs and usage remain accurate.

Your responsibilities as our customer. You control which calls are sent to us. You are responsible for having a lawful basis to place those calls and to have the opening seconds analysed and recorded, for giving any notice or obtaining any consent that call-recording, wiretapping, telemarketing or privacy law requires in the places you call, and for honouring do-not-call rules. See our Acceptable Use Policy.

5. How long we keep data

DataRetention
Account and profileWhile your account is open, then deleted or anonymised within 30 days of closure, except records we must keep by law.
Billing and tax recordsAs long as tax and accounting law requires, typically 7 years.
Call audio samplesDeleted automatically 30 days after the call. You can delete individual recordings, or all of them, sooner from your portal, or switch recording storage off entirely.
Transcripts, results and call metadataKept while your account is open and deleted within 30 days of closure or on request. We may keep aggregated statistics that do not identify anyone.
Sign-in and security logs12 months, then deleted.
Support correspondenceUp to 24 months after the conversation ends.
Analytics dataUp to 14 months, according to our Google Analytics retention setting.

6. Who we share data with

We share personal data only with providers that help us run the Service, under contracts that limit what they may do with it:

  • Payment processing: Stripe, for subscriptions, invoices and card payments.
  • Speech recognition infrastructure: a cloud speech-processing provider that converts the audio sample to text in real time on our behalf.
  • Transactional email delivery: an email service provider, for account, usage and security messages.
  • Hosting and data centre: the provider of the servers the Service runs on, located in the United States.
  • Analytics: Google Analytics, only if you consent to analytics cookies.

We may also disclose data where the law requires it, to protect our rights or the safety of others, or to a successor in a merger, acquisition or sale of assets, subject to this policy. A current list of sub-processors for customer call data is available to customers on request.

7. International transfers

We operate from, and store data in, the United States, and some of our providers process data in other countries. Where personal data from the EEA, the UK or Switzerland is transferred to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where relevant) or another lawful transfer mechanism.

8. Security

We protect data with measures appropriate to the risk, including:

  • TLS encryption for the website, the customer portal and all account and billing traffic.
  • Passwords stored only as salted bcrypt hashes; session cookies that are HTTP-only and sent only over HTTPS.
  • Per-account API keys that can be deactivated at any time, and plan-level rate limits.
  • Call recordings served only to the owning account or through signed links that expire.
  • Access to production systems restricted to authorised personnel, and logs of sign-ins and administrative actions.

Audio is streamed from your dialer to our detection endpoint over a WebSocket connection. If your security policy requires transport encryption or a private network path for the audio stream, contact us before sending production traffic so that we can agree a suitable setup.

No system is perfectly secure. If we become aware of a personal data breach affecting you, we will notify you and the competent authorities as the law requires.

9. Your rights

Depending on where you live, you may have the right to access, correct, delete or export your personal data, to restrict or object to certain processing, and to withdraw consent at any time without affecting processing that already took place. Residents of the EEA, UK and Switzerland can find the detail in GDPR & Data Processing.

California residents: you have the right to know what personal information we collect and how we use and disclose it, to request deletion and correction, and not to be discriminated against for exercising these rights. We do not sell or share personal information for cross-context behavioural advertising.

To exercise any right, email support@vmhunter.com from the address on your account. We respond within 30 days. If a request concerns call data that one of our customers sent us, we will refer you to that customer, who decides how that data is used.

10. Cookies

We use a small number of essential cookies to keep you signed in and remember your choices, and analytics cookies only with your consent. The full list and your controls are in our Cookie Policy.

11. Children

The Service is for businesses. It is not directed at children, and we do not knowingly collect data from anyone under 16.

12. Changes to this policy

We will post any changes on this page and update the date at the top. If a change materially affects how we use your data, we will notify account holders by email before it takes effect.

13. Contact

Questions, requests or complaints about privacy:

PILOTLAB LLC dba VM HUNTER

1309 Coffeen Ave Ste 1200, Sheridan, WY 82801, United States

Email: support@vmhunter.com

Website: vmhunter.com