Legal

Privacy Policy

Last updated: August 28, 2026

Newgensales records, transcribes, and analyzes sales conversations. That means we handle personal data — yours and your meeting participants' — and this page explains exactly what, why, who else touches it, and what rights you have. No legalese where plain language works.

The service is operated by Newgensales LLC, a Wyoming (USA) limited liability company (in formation). Privacy contact: noah@newgensales.ai.

1. Two roles we play

  • For your account (profile, login, billing, our website): we are the data controller — we decide how that data is used.
  • For your meetings and leads (recordings, transcripts, prospect data): we are the data processor — your company is the controller and decides why calls are recorded. You are responsible for informing meeting participants and, where required, obtaining consent; our notetaker joins visibly as a named participant to support that.

2. What we collect

Account & profile — name, email, phone, password (stored as a bcrypt hash), job title, language, timezone, and optional details you add: date of birth, address, location. Business details for team accounts (company name, domain, industry, headquarters).

Meetings — audio recordings of calls the notetaker joins, real-time transcripts with speaker attribution, talk-time analytics, AI coaching messages, and AI-extracted conversation intelligence (pain points, budget and timeline signals, quotes, stakeholders, objections). We do not record video.

Leads & prospects — contact and company details your team enters, imports from a CRM, captures via your referral/capture links, or that our AI extracts from conversations.

Usage & security— login timestamps, IP address and browser info per session, and a security audit log of account events. If location sharing is on, your IP is resolved to a city to place you on your team's Command Tower map.

Billing — subscription status and invoices via Stripe. Your card number never touches our servers.

3. What we use it for

  • Delivering the product: live coaching, transcripts, notes, CRM updates, forecasts, reports.
  • Showing your team what you've allowed them to see (see "Who can see what").
  • Service emails and SMS: verification, security, notifications, reports.
  • Security, abuse prevention, and keeping the pipeline reliable.
  • Billing and partner commission accounting.

We do not sell your data, run ads, embed third-party analytics or tracking scripts, or use your recordings, transcripts, or content to train AI models.

4. AI processing

Transcription is performed by streaming meeting audio to a speech-recognition service (Alibaba Cloud DashScope). Coaching and analysis are performed by sending transcripts and relevant deal context to Anthropic's Claude API, which does not train on API data. Both act as processors for us — they process your data solely to return results to the Service.

5. Who else processes your data (subprocessors)

ServiceWhat it does with your dataRegion
Alibaba Cloud (DashScope)Real-time speech-to-text — meeting audio is streamed for transcriptionSingapore (international endpoint)
Anthropic (Claude)AI coaching and conversation analysis — transcripts and deal contextUSA
Recall.aiMeeting notetaker infrastructure and recording hosting for some meetingsUSA
RunPodRuns our own meeting-bot containers; meeting audio transits these workersUSA/global
StripePayments, subscriptions, partner payouts. Card data goes directly to Stripe — never to our serversUSA/EU
Twilio / SendGridVerification and notification email + SMS; email/SMS you send to leadsUSA
Google / Microsoft / ZoomCalendar and meeting integrations you connect (OAuth)per provider
Salesforce / HubSpot / Pipedrive / ZohoCRM sync — only if you connect your CRMper provider
HetznerServer hosting — application, database, and stored recordingsEU
OpenStreetMap NominatimTurning typed locations (city names) into map coordinatesEU
ipapi.coIP-to-city lookup for the Command Tower map — only if location sharing is enabledUSA

Some of these are outside the EU. Where data leaves the EU we rely on the providers' standard contractual clauses and equivalent safeguards. If you need a signed data processing agreement (DPA), email us.

6. Who can see what, inside your company

  • Every customer's data is isolated per business (enforced at the database level).
  • Reps always see their own calls. Managers and executives can see their reps' calls, transcripts, and coaching — unless a rep turns off "Visible to managers" in privacy settings.
  • Reps can opt out of the team leaderboard and of location sharing (opting out of location also erases previously stored coordinates).

7. How long we keep it

  • Recordings, transcripts, and intelligence: for the life of your account, so your team's history and reports keep working. Deleting a meeting from the app removes its transcript and analysis.
  • Login session records: deleted 30 days after the session expires.
  • Data-export downloads: expire and are deleted after 24 hours.
  • Internal reliability telemetry: 30 days.
  • On account deletion (see below): a 30-day grace window starts, during which your account keeps working and you can change your mind. After it, everything — recordings, transcripts, leads, reports — is automatically and permanently removed, except what we must keep for legal/accounting reasons (e.g. invoices, held at Stripe). We remind you by email 7 days and 1 day before removal.

8. Your rights

Under the GDPR (and similar laws) you can access, correct, export, delete, and object to processing of your personal data:

  • Export: self-service — Account → Privacy → Export Data produces a ZIP of your data, delivered by email link.
  • Correction: edit your profile directly in the app.
  • Deletion: self-service — cancel your subscription, then choose Delete Account in Billing settings. Your data is automatically and permanently removed after a 30-day grace window (cancellable anytime before, with email reminders at 7 days and 1 day). If your subscription has already ended and you can no longer sign in, email noah@newgensales.ai from your account email instead — we delete your account and data within 30 days.
  • If you were a participant in a recorded call run by one of our customers, the customer is the controller of that recording — contact them first; we support their deletion obligations, and you can always reach us at the address above.
  • You can complain to your data-protection authority.

9. Security

  • All traffic is encrypted in transit (TLS).
  • Passwords are bcrypt-hashed; optional two-factor authentication (authenticator app or SMS); account lockout on repeated failed logins.
  • Tenant isolation is enforced at the database level (row-level security per business).
  • Integration credentials (bot accounts) are stored encrypted; access to production systems is restricted to the operator.
  • A security audit log records account events (logins, changes) with IP and device info.

10. Cookies

We set exactly two first-party cookies and load no third-party trackers:

  • session — keeps you signed in while you use the app (strictly necessary).
  • ngs_ref — set for 30 days when you arrive via a partner's referral link, so the partner gets credit if you sign up.

11. Changes

When our data practices change (for example a new subprocessor), we update this page and its date, and notify you of material changes. Questions, requests, complaints: noah@newgensales.ai.