Privacy
What CallProof stores
Last updated: 28 August 2026.
Controller
Karim, trading as Engilane, karim@engilane.com. This notice covers callproof.engilane.com only. The umbrella notice atengilane.com/privacy covers shared brand pages.
What runs on this site
CallProof is a signed-in workspace for auditing AI receptionist calls. There is no third-party analytics, advertising, or embedded fonts. Pages and APIs are served from Cloudflare Workers on callproof.engilane.com. Cloudflare sees IP address, path, User-Agent, and timestamps as part of hosting, the same as any reverse proxy.
Cookies
After email verification, CallProof sets one HttpOnly session cookie (cp_session) scoped to this site. It holds an opaque session token; we store only a peppered hash of that token in D1. The cookie is necessary for authentication and expires after 30 days unless you sign out sooner.
Links through /go?ref= set an HttpOnly attribution cookie (cp_ref) for up to 30 days. If that visit creates a new workspace, we retain the allowlisted source label (for example, agency or linkedin) with the organization. It contains no cross-site identifier and is not shared with an analytics provider.
Email delivery
Login codes, critical call alerts, and optional weekly digests are sent through Brevo when configured. Brevo receives the recipient address and message content. We do not use Brevo for marketing lists on this product.
Workspace data
For each organization we store: workspace name, membership roles, agent names, webhook secret hashes (never plaintext after creation), rubric configuration, call metadata, transcripts, structured evaluation results, and acknowledgement/resolution timestamps. Every query is scoped by organization id.
Vapi end-of-call reports are posted to your agent webhook URL. We verify a bearer secret, then store the payload fields needed for evaluation. Seeretention for how long transcripts remain.
AI evaluation
Structured model evaluation uses Cloudflare Workers AI when available. Transcript excerpts and rubric context are sent to that binding for the evaluation request. Deterministic checks run locally in the worker without an external model call. If the model fails or returns invalid JSON, the call is marked for review rather than silently passed.
Billing
Paid plans (Single agent: 49 EUR/month; Agency:149 EUR/month) are sold through Gumroad as merchant of record when checkout is enabled. Gumroad processes payment and account data; this site never sees card numbers or billing addresses.
After purchase you receive a licence key from Gumroad. To attach it to your workspace, an owner submits the key through the dashboard billing panel. We verify it against Gumroad’s licence API and store only a peppered hash of the key, the product id, plan name, and verification timestamps. Plaintext licence keys are not logged or written to D1.
Access is not removed automatically because a verification timestamp is old. Re-checks happen when an owner submits the key again. See terms for plan limits.
Your choices
Owners can delete individual calls or wipe the entire workspace from the dashboard. A daily retention job purges expired transcript fields. You can request export or deletion of account data by email; workspace deletion is immediate when initiated in the product.
No legal guarantee
CallProof helps agencies review call quality and catch likely failures. It is not legal advice, compliance certification, or a substitute for listening to client calls or contract terms with your end customers.
Subprocessor summary: data processing. Security contact:security.