Legal

Privacy Policy

Last updated · 2026-07-27

This page is a work in progress and says so. The highlighted items below are unresolved. They are shown rather than filled with plausible-sounding text, because a privacy policy is a document people act on. Nothing here is legal advice, and it has not been through legal review.

Who we are

CallHush is operated by Justas Butkus. It is an AI voice and SMS service used by people who run webinars: it texts and calls the registrants of a client's webinar, on that client's behalf, before and after the session.

[FOUNDER: the registered legal entity name, its registered address, and the contact point for data requests — a company, a sole trader, or a person, and whether a data-protection officer is required]

This policy covers two different things: information collected through callhush.com, and information handled during a client engagement. They are treated separately below because they are not the same relationship.

Information from this website

  • What you send us. If you contact us or book a call, we get whatever you put in that form or email — name, company, email address, and whatever you chose to write.
  • Analytics. Page views, referring source and device type, in aggregate. We set no third-party advertising cookies. [FOUNDER: name the analytics tool actually in use, or confirm there is none, and state whether any cookie banner is required]

We do not sell, rent or trade this information, and we do not pass it to anyone for their own marketing.

Information we handle for a client

During an engagement, the client decides who is on the list and why. We do the texting and calling for them, under their name. What passes through our systems is:

  • Registration records — name, phone number, email address, time zone, and the webinar they registered for.
  • The consent record — the exact text the person agreed to, the timestamp, the IP address, and a snapshot of the version of the form they were served. This is kept because the burden of proving consent falls on the caller, and consent cases are lost on records rather than on checkboxes.
  • Call recordings and transcripts — see below.
  • What the registrant told us — including their own words about why they signed up, which is passed back to the client.
  • Opt-out and do-not-call records — the request, how it arrived, and when it was actioned.

[FOUNDER: the formal characterisation of the two roles — which party is the controller and which is the processor for registrant data — and the contract terms that follow from it. This needs counsel; it is not a wording choice]

Calls are recorded and transcribed

Calls made on a client's behalf are recorded and transcribed. That is not incidental: recordings are how the work gets reviewed, how a client checks what was actually said to their audience, and how any disagreement about whether a call counted gets settled instead of argued.

Recording law is separate from everything else on this page and varies by jurisdiction — several US states require every party on the call to consent to being recorded. Any notice required by the recipient's state is part of what the assistant says at the start of the call.

[FOUNDER: confirm the exact recording-notice wording in the call script, and which states are handled by notice versus excluded from dialling altogether]

Consent belongs to one client at a time

Consent runs to the specific business a person agreed to hear from. Someone who registered for Client A's webinar has not consented to hear from us, and has not consented to hear from Client B. So consent is captured per client, in that client's own name, and it is never pooled, shared or reused across clients. Suppression lists are kept the same way and stay with the client they belong to.

For a registration form to carry consent that actually works, it has to do six things: the box is not pre-checked; the disclosure is clear and conspicuous; it states that consent is not a condition of purchase; it names the specific business; it mentions AI or artificial voice explicitly; and proof of it is retained. A form that misses one of those is where these arrangements usually fail.

Stopping the calls and texts

Anyone contacted can revoke consent by any reasonable means. Since 11 April 2025 the FCC treats these words in a reply text as reasonable by definition:

STOP · QUIT · END · REVOKE · OPT OUT · CANCEL · UNSUBSCRIBE

Those are not the only ways. Saying it on a call counts. Writing to us counts. Nobody may be told there is one official channel and that anything else does not count — designating a single exclusive method of opting out is specifically not allowed. A revocation must be processed within a reasonable time, and in no case more than ten business days. At most one confirmation message may be sent in reply, within five minutes, carrying no promotional content.

One caveat worth stating plainly rather than burying: the rule that would make a single opt-out automatically stop every unrelated future message from the same caller — 47 CFR 64.1200(a)(10), the “revoke-all” provision — is not yet in force. It has been delayed to 31 January 2027. If you want out of everything rather than one campaign, say so and it will be actioned across channels.

To opt out of anything, or to ask what we hold: info@ainora.lt. [FOUNDER: a phone number that accepts do-not-call requests during business hours, which is separately required on calls]

How long things are kept

  • Consent, revocation and do-not-call records — five years. 47 CFR 64.1200(d)(6) does not itself set a retention period: it requires that a do-not-call request be honoured for five years. Keeping the record for at least as long is how that duty is actually met, and it is also what demonstrates an opt-out was honoured if anyone later asks.
  • Call recordings and transcripts. [FOUNDER: the retention period, and whether it differs during an engagement versus after it ends]
  • Registration and contact data. [FOUNDER: the retention period after an engagement ends, and what is handed back to the client at that point]
  • Enquiries that go nowhere. Deleted when they are clearly not going anywhere, and in any case within twelve months.

Deletion, access and correction

You can ask what we hold about you, ask for it to be corrected, and ask for it to be deleted. Deletion is honoured except where a record is one we are legally required to keep — principally the consent and opt-out records above, which exist to protect the person asking as much as anyone else. Where that applies, we say which records are being kept and why, rather than refusing the whole request.

If a client ends an engagement, their registrant data is deleted from our side on request, subject to the same retention obligations.

Requests go to info@ainora.lt. Where the GDPR applies, the response deadline is one month from the request.

Who else touches the data

Delivering a call means other companies are involved. The voice runs on Google's Gemini Live models via Vertex AI, and the calls and texts are carried by Telnyx.

[FOUNDER: the complete sub-processor list — hosting, storage, transcription, email, and anything else — plus where each one stores data. The previous version of this page promised “EU-only data residency by default”, which was removed because nothing supports it. Do not re-add a residency promise that is not true of the actual infrastructure]

Nobody in that list is given data for their own marketing purposes.

Changes to this policy

When this changes, the date at the top changes with it. Material changes affecting how registrant data is handled are told to clients directly rather than left for someone to notice.