Privacy Policy
Last updated: 1 September 2026
1. Introduction
This Privacy Policy describes what personal data we collect when you use AKITAKI ("the Service"), how we use and disclose it, and the safeguards we apply. We have written it to be as clear and concise as possible. Please read it together with our Terms and Cookie Policy.
This policy may change from time to time; continued use of the Service after a change is deemed acceptance. The date of the last update is at the top of this page.
2. Who We Are
We are the data controller of the personal data described in this policy:
- ANSEKO LLC
- 30 N Gould St Ste N, Sheridan, Wyoming, 82801, United States (registration address; correspondence by email)
- Email: hello@akitaki.com
- Website: https://akitaki.com
3. Data We Collect
We collect only what the Service needs to work:
- Account data — your email address, your password (stored only as a bcrypt hash; we never see it in plaintext), whether your email is verified, your trial credit, and your organization membership.
- Caller ID data — phone numbers you verify for outbound caller ID, their verification status, and which one is your default.
- Call records — for each call: the number you dialed, your caller ID, start/answer/end times, duration, cost, and technical identifiers used to route the call.
- Payment data — voucher purchase records: amount, date, status, and the checkout ID. We do not collect, store, or see your payment card details — Creem, our Merchant of Record, handles those directly.
- Technical data — your IP address, which appears in our server logs and is used for rate limiting and fraud prevention; and, if you consent, anonymized usage statistics collected by our analytics provider.
- Cookies data — see our Cookie Policy.
We do not record or transcribe your calls, and we do not listen to them. We also do not collect any special categories of personal data (health, biometrics, ethnicity, and so on) and do not knowingly collect data about children.
4. How We Use Your Data
- To provide the Service — authenticate you, connect your calls, verify your caller ID numbers, bill your calls, and show your call history and balance.
- To process payments — create checkouts with Creem and record completed purchases so we can credit your organization's balance.
- To send transactional email — email verification, password reset, and purchase receipts. We do not send marketing email to your phone number and do not sell personal data to anyone, ever.
- To prevent fraud — our automated fraud controls (rate caps, premium-destination blocks, concurrency limits, signup restrictions) use account and call data to protect the shared balance of your organization and the Service as a whole.
- To comply with the law — retaining payment records as tax and financial law requires, and responding to lawful requests from authorities.
- To improve the Service — aggregated, anonymized statistics about how the Service is used.
5. Legal Bases (for users in the EEA and UK)
Where the GDPR applies, we process your personal data on these bases: performance of our contract with you (providing and billing the Service); our legitimate interests (fraud prevention, service improvement) where they are not overridden by your rights; compliance with legal obligations (tax and financial record-keeping); and consent, where you have given it (analytics cookies). You may withdraw consent at any time without affecting the lawfulness of earlier processing.
6. Who We Share Data With
We share personal data only with the service providers that operate the Service, and only as far as each needs to do its job. All are bound by contracts requiring them to protect your data.
| Provider | Purpose | Data involved | Location |
|---|---|---|---|
| Hetzner Online GmbH | Hosting (servers and database) | All stored data | Frankfurt, Germany (EEA) |
| Telnyx LLC | Telephony: call routing and caller-ID verification voice calls | Numbers you dial, your caller ID, call metadata | USA |
| Creem Inc. | Payment processing (Merchant of Record) | Your email and purchase details; card details go to Creem directly, we never see them | USA (processes VAT/GST globally) |
| Brevo | Transactional email | Your email address | France (EU) |
| Ahrefs Pte. Ltd. | Web analytics — only if you consent | Anonymized usage statistics | Singapore (processes globally) |
| Google Fonts / unpkg | Delivery of fonts and the htmx script | IP address, as required to deliver the asset | USA / global CDNs |
| Trustpilot | Reviews widget — only if you consent | Interaction with the widget | EU (processes globally) |
We may also disclose data where required by law or to protect the safety and rights of other people.
7. Where Your Data Is Stored and Transfers
Your data is stored on servers operated by Hetzner, located in Frankfurt, Germany, within the European Economic Area (EEA). Some providers listed above process data in the United States or elsewhere. Where we transfer personal data from the EEA or UK to a country without an adequacy decision, we rely on appropriate safeguards, including the providers' standard contractual clauses, and we take reasonable steps to ensure your data stays protected.
8. Security
We protect your data with measures including TLS encryption in transit, bcrypt password hashing, signed session tokens, cryptographic verification of provider webhooks, and access controls limiting data to people who need it. Data transmission over the internet can never be guaranteed completely secure; you are responsible for keeping your password confidential.
9. Retention
We keep your personal data for as long as your account is active. If you close your account or ask us to delete your data, we delete it within 90 days, except where the law requires longer retention — payment and financial records may be kept for up to 7 years. Backups may retain data for a further period under our backup rotation, after which it is securely deleted.
10. Your Rights
If you are in the EEA or UK, you have the right to access, correct, delete, or port your personal data; to restrict or object to processing; and to complain to your local data protection supervisory authority.
Wherever you live, you can correct your account details in the app and request access to or deletion of your personal data by emailing hello@akitaki.com. We respond to requests within 30 days. California residents may have additional rights under the CCPA; contact us to exercise them.
11. Automated Decision-Making
We do not make decisions with legal or similarly significant effects about you solely by automated means. Our automated fraud checks (such as rate caps and destination blocks) may prevent a call from connecting; if you believe a check is wrong, contact us and a human will review it.
12. Children
The Service is not directed at children. We do not knowingly collect personal data from anyone under 18.
13. Changes and Contact
If we change this policy, we will post the changes on this page and, for material changes, may email you. Questions or complaints about privacy: hello@akitaki.com — we would appreciate the chance to address your concern before you contact a supervisory authority.