Legal

Privacy policy

What we collect, why we collect it, who processes it on our behalf, and how long we keep it. Written against what the platform actually stores rather than against a template.

Last updated 1 August 2026

1. Who this covers

Talqing is a platform for building and running AI voice, video and text agents. It is operated by Oggnai Technologies Private Limited, 293 S/F, Western Marg, Saidulajab, New Delhi, Delhi 110030, India (“Talqing”, “we”, “us”). This policy covers talqing.com, the Talqing dashboard, and the Talqing API.

Two different groups of people appear in this policy and they are not treated the same way:

  • Customers — the people and organisations who hold a Talqing account and build agents. For their data we are the controller, and this policy is the full description of what we do.
  • End users — the people who call, message or talk to an agent that a customer has built and published. For their data we are a processor acting on that customer’s instructions. The customer decides what is collected and why, and their own privacy notice governs it. If you spoke to an agent and want your data removed, contact the business that operates it; if you cannot reach them, write to us at hello@talqing.com and we will route the request.

2. What we collect

Account data. Sign-in is Google OAuth only — there is no password to store. We keep your email address, your Google account identifier, your role in your organisation, and the email domain your organisation is keyed on. We do not store your name or your Google profile picture.

Session records. For every agent run we store which agent and published version handled it, the channel (voice, video or text), start and end times, duration, outcome, latency and usage metrics, and the computed cost. For calls placed over the telephone network this includes the calling and called numbers in E.164 form.

Conversation content. We store the transcript of each session as text — what the end user said, what the agent replied, which tools the agent invoked and what those tools returned, and any files or attachments sent through a messaging channel.

We do not record or store call audio or video. Speech is transcribed in memory as the call runs and the audio is discarded. There is no recording to download, produce or leak, and no configuration that turns one on.

Credentials you give us. Provider API keys you bring, OAuth tokens for apps you connect (such as Google Calendar, HubSpot, Asana, Jira, Cal.com or Calendly), telephony account credentials, and any secrets you store for your tools. These are encrypted at rest and are never returned to the dashboard or the API after you save them.

Knowledge base content. When you point a knowledge base at a URL we fetch those pages and store their text so your agent can use it. We fetch only what you ask us to.

Technical data. Our servers log IP addresses, request paths, timestamps and error traces. This is operational data used to run and debug the service.

3. What we use it for

  • Running the service — authenticating you, executing your agents, connecting calls, and calling the AI providers your agent is configured to use.
  • Showing you your own data — transcripts, call history, usage and cost in the dashboard.
  • Billing — metering usage and computing what you owe.
  • Security and debugging — investigating errors, abuse and outages.
  • Service email — changes that affect your account, your agents or this policy.

We do not sell your data, and we do not use your conversations or your knowledge bases to train any model of ours. We do not run advertising, and there is no advertising or analytics tracker on the dashboard.

4. Who processes it on our behalf

Running an agent means sending its conversation to the AI providers it is configured to use, and connecting a phone call means routing it through a carrier. Which providers see a given conversation depends entirely on how that agent is configured — an agent with no telephone number never touches a carrier, and an agent using your own API key sends that traffic under your account with that provider rather than ours.

CategoryProviders
Language modelsOpenAI, Google (Gemini), xAI (Grok), Sarvam AI
Speech to text and text to speechDeepgram, ElevenLabs, Sarvam AI, OpenAI, Google
Video avatarsAnam
Telephony carriersExotel, Plivo, Twilio, Vobiz
Messaging channelsTelegram
Hosting and infrastructureDigitalOcean (Bengaluru, India)
CDN and DNSCloudflare
Sign-inGoogle

We disclose data outside this list only when the law requires it, or to protect the rights and safety of our users — and we will tell you unless we are legally barred from doing so.

5. Where your data lives

Our servers and databases are in Bengaluru, India. Several of the providers in the table above process data in the United States and the European Union, so running an agent generally means an international transfer. Where that transfer is from a region that requires a legal basis, we rely on the provider’s standard contractual clauses.

6. How long we keep it

DataRetention
Account and organisation recordsUntil you delete the account
Transcripts and session recordsUntil you delete them, or the account is closed
Stored credentials and OAuth tokensUntil you remove the connection or the account is closed
Knowledge base contentUntil you delete the knowledge base
Billing and usage recordsAs long as tax and accounting law requires
Server logsRolling, short-lived, overwritten as they rotate

Deleting an account removes its data from our live systems. Backups age out on their own cycle and are not selectively edited.

7. How it is protected

  • Traffic between your browser, our API and our infrastructure is encrypted with TLS.
  • Provider keys, OAuth tokens and stored secrets are encrypted at rest with a key held outside the database.
  • Every organization's data is isolated and every query is scoped to the organization making it.
  • Databases, queues and caches are not reachable from the public internet.
  • One honest exception: the leg of a phone call that crosses the public telephone network is carried by the carrier in the clear, as PSTN telephony everywhere is. It is not encrypted end to end and we do not claim it is.

No system is perfectly secure. If we discover a breach affecting your data we will tell you and the relevant regulator as the law requires.

8. Your rights

Depending on where you live you may have the right to access your data, correct it, delete it, export it, object to processing, or withdraw consent. Most of these you can exercise yourself in the dashboard — transcripts, agents, knowledge bases and connections are all deletable there.

For anything else, write to hello@talqing.com. We will respond within 30 days. If you are unhappy with our response you may complain to your data protection authority.

9. Cookies

We set exactly one cookie: a session cookie that keeps you signed in after you authenticate with Google. It is strictly necessary, it is not used for tracking, and there is no analytics, advertising or third-party cookie on this site. That is why there is no cookie banner.

10. Children

Talqing is a business product and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a child has given us data, write to hello@talqing.com and we will delete it.

11. Changes to this policy

We will update this page when what we do changes, and revise the date at the top. If a change materially affects how we handle your data we will email account holders before it takes effect.

12. Contact

Oggnai Technologies Private Limited
293 S/F, Western Marg, Saidulajab, New Delhi, Delhi 110030, India
hello@talqing.com
+91 99101 80529