Privacy Policy
What we collect, what the desktop app captures during a call, where the text goes and is stored, who receives it, and how long it is kept.
On this page
- Scope of this policy
- Key terms
- Information we collect
- How we collect it
- Calls and transcription
- How we use it
- Disclosure to third parties
- Sale and sharing
- Where your data is stored
- Cookies and local storage
- Data retention and deletion
- Security
- Your privacy rights
- Automated processing and AI
- Children
- Third-party links
- Changes to this policy
- Contact and complaints
Scope of this policy
This policy is issued by Thelaywala, the maker of Thelaywala Sales Coach, and covers that product only: the website and web app at salescoach.thelaywala.com, the desktop app for Windows and macOS that sits on a rep’s screen during a call, and the accounts, billing and support that go with them. Our main website, thelaywala.com, has its own privacy policy for visitors, leads and clients of our other services; where the two overlap, this one governs the product.
It is written for two readers: the organisation that signs up and the people it invites, whose accounts and calls we hold; and the people on the other end of those calls, whose words are transcribed. For the people on your calls, we hold and process the text on your organisation’s behalf and on its instructions; for your own account, we decide how it is handled.
Thelaywala · thelaywala.comEmail: info@thelaywala.comPhone or WhatsApp: +1 737-379-5026Address: KDA Apartments, Block A, North Nazimabad Town, Karachi, PakistanKey terms
- The Service: the web app, the desktop app and the web service behind them.
- Organisation: the customer account created at sign-up, which owns everything its members add. Members are the people invited into it; an administrator can add and remove them and manage billing.
- Rep: the member running the desktop app during a call.
- Call participant: anyone else on a call the rep takes, whose speech the desktop app transcribes.
- Transcript: the text of a call as the desktop app produced it, both sides. Summary, next steps, mood and follow-up are what the AI produces from it.
- Knowledge base: the winning-call examples, uploaded documents and website pages an organisation gives the coaching to draw on.
- Credits: the unit in which AI usage is metered; one credit is two thousand tokens. See the Terms of Service.
Information we collect
Account and organisation
Your email address and a password (handled by Supabase, our sign-in provider; we never see the password), the name you show to your team, your organisation’s name and your role in it. If you were invited, the address the invitation went to and who sent it; invitation links expire after seven days.
Billing
You enter payment details with Stripe, on Stripe’s own pages; they never pass through our servers. We keep Stripe’s identifiers for your customer record and subscription, your plan, the number of people billed, the price you agreed to, the billing period and its status, and a record of each billing event Stripe reports. If your organisation buys AI credits, Stripe charges the card it already holds for your subscription, or takes the payment on its own page if it holds none, and we keep that payment’s identifiers, the amount and the number of credits, together with a ledger of credits granted, bought and spent. If an administrator turns on automatic top-up, we keep the setting and a record of each automatic purchase: when, how many credits, the amount, whether it succeeded, the reason if it failed, and the last four digits of the card it used. We read the card’s brand and last four digits from Stripe to show administrators, on the billing page and in credit warnings, which card would be charged.
Your customers
The people your reps call, as your team records them: a name, a business, a phone number, an email address, goals, a status, and the action items and onboarding steps your team adds. The app can also suggest a customer’s name and business from the opening of a call.
Your calls
When a rep saves a call: the transcript as text, the summary, the next steps and the “mood” the AI produced, and which member took the call. Meetings uploaded or entered through the web app are stored the same way, with a score and notes. Follow-up drafts are returned to the rep and are not stored by us.
Your knowledge base
The winning-call examples your team types in or asks the AI to extract from a call; the text of the documents your team uploads (PDF, Word, plain text), split into passages; and the text of the pages of your own website that the setup wizard reads, if you give it the address. Each passage is also stored as a numerical “embedding” so the coaching can find the relevant one.
Usage records
For each AI request: which route made it, which provider and model answered, how many tokens it used, its cost to us, the credits it debited, your organisation and which member made it. We do not keep the text of the request in that record. When a request is refused we keep the route, the status and the reason, not the text.
Technical data
A session cookie that keeps you signed in; the server logs our host keeps for one hour, which record requests with identifiers, counts and sizes, and now and then a short fragment of a suggestion the service discarded, but never the transcript; and, in your browser, two local preferences (your theme and your default phone dialling code). The product sets no advertising, analytics or tracking cookies and includes no analytics or tracking software: we checked the code for this policy and found none.
How we collect it
- From you, when you sign up, invite people, add customers, save calls, upload documents, set up your website in the wizard, and manage billing.
- From the desktop app during a call — the whole of the next section.
- From Stripe, which reports each payment and subscription event to us.
- From your website, if you give the setup wizard its address: our service fetches the pages, respects the site’s robots rules, and identifies itself as the Thelaywala Sales Coach setup wizard.
- Automatically: the session cookie and our host’s server logs.
Calls and transcription: what the desktop app captures, and where it goes
This is the part that matters most, so it is spelled out. It describes the desktop app for Windows and macOS exactly as it is built today.
On the computer
- The app captures two audio sources while it is listening: the default microphone (the rep) and the computer’s own audio output (whoever is on the other end of the call).
- Both streams are transcribed on the computer, by speech-recognition models that ship inside the app. The audio is processed in memory and is never written to disk and never sent to us or to anyone else. The only thing that survives is text.
- The listener keeps the most recent lines of text in memory and hands them to the on-screen panel over a connection that stays on the computer. The panel keeps the full transcript of the current call while the call is running.
- To survive a crash, the panel keeps a draft of the current call — the transcript, the customer’s name and id — in its own local storage on the computer until the call is saved. The app also writes its sign-in token, and technical logs, to its own folder on the computer.
What leaves the computer
- For coaching: while a call runs, the text of the conversation (both sides) is sent to our web service, which sends it on to the AI provider to produce the suggestions the rep sees. Nothing from this is stored by us except the usage record described above.
- To recognise the customer: once enough has been said, the opening of the transcript is sent to our service so the AI can suggest who the customer is.
- When the rep saves the call: the whole transcript is sent to our service, which produces the summary, next steps and mood and stores all of it in your organisation’s account.
- Follow-ups and briefs: on request, the relevant part of the transcript, the customer’s name, and earlier summaries and action items for that customer are sent to our service and to the AI provider; the drafts come back to the rep.
- The app signs in with your email address and password directly with Supabase, keeps a sign-in token on the computer, and checks with our service that your subscription is active and that credits remain. It does not send crash reports, usage analytics or telemetry, and it does not update itself in the background.
Call participants
The other party’s words are transcribed and, if the call is saved, stored as text in your organisation’s account. The app shows no notice to them and asks the rep for no confirmation that they have been told. Telling participants that a call is transcribed, and obtaining any consent the law where you and they are requires, is your organisation’s responsibility; the rules differ by country and, in the United States, by state.
Screen sharing
The panel asks the operating system to exclude its window from screen capture, so it does not appear when the rep shares their screen or records it. That is a per-window setting on the rep’s own computer; it does not hide the panel from a camera pointed at the screen or from a separate recording device, and it changes nothing about the responsibility above.
How we use it
- To run the product: sign you in, coach during calls, summarise saved calls, draft follow-ups and briefs, keep your customers, calls and knowledge base in your organisation’s account, and show your team its own usage and credit balance.
- To bill you: through Stripe, according to your plan, the number of people in your organisation and the credits you buy.
- To keep the service working and secure: usage and failure records per organisation, server logs, and our own administration views, which show totals per organisation and never transcripts.
- To email you about your account: sign-up confirmation, invitations and password resets are sent by Supabase on our behalf. The product sends no marketing email.
Disclosure to third parties
These are the providers that handle data for us, and what each receives. There are no others in the code.
| Who | What they do for us | What they receive |
|---|---|---|
| Supabase | Sign-in, the database and the file store for the installer; sends the sign-up, invitation and password-reset emails | Everything in your account; your email address and password at sign-in |
| Stripe | Payments, credit purchases and the billing portal | Your payment details (entered with Stripe directly), the email address you signed in with, your organisation’s identifier, your plan, seat count and credit purchases |
| OpenAI | Coaching, summaries, follow-ups, briefs, setup | Transcript text, customer names, summaries, knowledge-base passages and website text, as described under Automated processing and AI |
| Embeddings for search | Transcript tails, knowledge-base examples, document and website passages | |
| Vercel | Hosting the website and web service | Every request to the site and the web service, and the server logs described above, which never hold the transcript |
| GoHighLevel | A CRM handoff: the “Save to CRM” button on the Live Coach page, which does nothing until a member presses it | The name and email the member enters, the call outcome and the full transcript, posted to one GoHighLevel webhook address set in the Service’s own configuration (the same address for every organisation, not an account of yours) |
We also disclose information where the law requires it, to professional advisers under confidentiality, and, if the business is sold or reorganised, to the successor under this policy.
Within your organisation
Every member of your organisation can see every member’s customers, saved calls, transcripts, summaries and knowledge base; an administrator can also add and remove people and buy credits. Nothing is visible across organisations. Our own administration tools show us how much each organisation uses the service and its billing state, and are built not to show transcripts or summaries. The people who run the service hold the keys to the database itself.
Sale and sharing of personal information
We do not sell, rent or trade personal information, and we do not share it for anyone else’s advertising. The product contains no advertising technology.
Where your data is stored
We are based in Pakistan. Your data is not stored there; it is stored and processed in the places below, which may be outside the country you are in.
- Your account, your customers, your saved calls and transcripts, your knowledge base, your usage records and the credit ledger are stored in our database at Supabase, which runs in Amazon Web Services’ Singapore region (ap-southeast-1). The installer file store is in the same place.
- The web service that serves the site and answers the desktop app runs on Vercel in the United States (its Washington, D.C. region, iad1), which is also where it keeps its one hour of server logs. The site’s static files are served from Vercel’s edge network worldwide.
- Your payment details and Stripe’s billing records are held by Stripe; the text sent for coaching, summaries and embeddings is processed by OpenAI and Google. Each does so on its own infrastructure, in the countries where it operates and under its own terms; we do not choose a region with them.
- The transcript of a running call, the unsaved draft and the sign-in token live on the rep’s own computer, wherever that is.
Data retention and deletion
We keep your organisation’s data — its account, customers, saved calls, knowledge base and usage records — for six months after its subscription or trial ends, and then delete it. Billing and credit records are kept for the same six months; Stripe keeps its own records of your payments under its terms.
Sooner than that, on your side: your team can delete documents, knowledge-base examples and meetings in the app, archive customers and saved calls (which hides them from the app), and remove members, which ends their access at once while their saved calls stay with the organisation. On ours: email info@thelaywala.com with the subject “Privacy Request” and we will delete your organisation’s data, or part of it, earlier.
When a trial or subscription ends, the service stops answering, and the data stays as it is until the six months are up or you ask sooner. On the rep’s computer, the app’s own folder keeps its logs and sign-in token until the app is uninstalled or the person signs out; the draft of an unsaved call stays until the call is saved.
Security
We use reasonable administrative, technical and organisational measures. Every connection to the Service and to our providers is encrypted in transit. Every request to our service is checked against the sign-in it carries, and the database holds its own rules that keep each organisation’s records to that organisation’s members. Payment details never reach us. Audio never leaves the rep’s computer. Invitation links are stored only as a hash and expire after seven days. Installer downloads are issued as links that expire after five minutes and only to an organisation with an active trial or subscription.
No system is perfectly secure. If a breach affects your information we will notify you, and the authorities where the law requires it, as soon as we reasonably can.
Your privacy rights
You can see and edit your organisation’s customers, calls and knowledge base in the app, change your display name, and manage your team, billing and credits. For anything the app does not let you do yourself — a copy of your data, correction, deletion, or a question about how we handle it — email info@thelaywala.com with the subject “Privacy Request”. We will verify that you are who you say you are before acting, we will not treat you differently for asking, and we will answer within the time the law where you are allows.
Depending on where you live, the law may give you the right to access, correct, delete or receive a copy of your information, to object to or restrict how it is used, and to complain to a data-protection authority. A person on a call who is not our customer can write to the same address about their transcript; because the transcript belongs to a customer organisation’s account, we will refer the request to that organisation and act on its instructions.
Automated processing and AI
Two providers do the AI work. OpenAI (the gpt-4o-mini model, over its API) receives the text that needs an answer: transcript excerpts during a call, whole transcripts when a call is saved or a meeting is scored, the customer’s name and earlier summaries for follow-ups and briefs, the winning-call examples and document passages retrieved to ground a suggestion, and the text of your website during setup. Google (the Gemini embedding model, over its API) receives the text that needs an embedding: the tail of the live transcript used to look up relevant examples, your knowledge-base examples, and passages of your documents and website. Each processes it to answer our requests, under its own terms.
Suggestions, summaries and drafts are shown to a person, who decides what to do with them; nothing is said or sent to a customer automatically, and the Service makes no decision with legal or similarly significant effects about anyone. We do not train AI models on your content, and nothing from one organisation is used to answer another.
Children’s privacy
The Service is for businesses and the people who work in them. It is not directed at children, and we do not knowingly collect information from anyone under 16.
Third-party links
The Service links to Stripe’s checkout and billing portal, to thelaywala.com, and to the privacy policies of the providers named above. Those sites have their own policies, which we do not control.
Changes to this policy
When this policy changes, the date at the top changes with it, and we announce the change in the app’s dashboard.
Contact and complaints
Questions about this policy or about your data, and privacy requests (subject line “Privacy Request”):
Thelaywala · thelaywala.comEmail: info@thelaywala.comPhone or WhatsApp: +1 737-379-5026Address: KDA Apartments, Block A, North Nazimabad Town, Karachi, PakistanIf you are not satisfied with our answer, you may complain to the data-protection authority where you live.
Questions, or the other half
Write to info@thelaywala.com or message +1 737-379-5026 on WhatsApp. The Terms of Service cover accounts, plans, credits, billing and what each side agrees to.