Privacy policy
Your data follows the call.
AgentCall is an iPhone voice client. It moves information only through the agent, voice provider, and optional tools you choose. This page separates the permission-lean App Store client from the private Labs build and its optional connected services.
Effective 28 August 2026
App Store client
Three permissions, no developer AI account
The public client asks for microphone access during a call, local speech-recognition access, and camera access only when you choose to scan an Agent Card QR code. Its only background mode is audio during an active call.
It does not expose Calendar, Contacts, Reminders, Health, Location, Focus, NFC, photos, People Memory, private tools, or native action approval to enrolled agents. It includes no advertising or analytics.
Agent credentials stay in iOS Keychain. Your locally transcribed turn goes to the agent or provider endpoint you reviewed and enrolled. That third party's terms and retention choices apply. AgentCall's public deterministic Reference Agent processes each turn only long enough to answer it in real time, writes no user content, and retains nothing after the live request.
Private Labs only
The sections below are not in the App Store client
Google Workspace and the other connected-data routes described below exist only in the separately built private Labs client. The App Store target cannot expose or configure them.
Private Labs 01 · On your iPhone
Permission and refresh token
You choose the Google account. The long-lived refresh token stays in the iOS Keychain.
Private Labs 02 · For one call
Short-lived access
A fresh access token passes through your selected realtime provider to AgentCall's Gmail tool gateway.
Private Labs 03 · Back to the agent
Requested results only
The provider receives the Gmail result needed to answer the request or create the draft you asked for.
Private Labs · Google user data
What AgentCall accesses
When you connect Gmail, AgentCall requests:
- Your Google account identifier and email address, to label and bind the connection.
- Read-only Gmail access, to search threads and read the threads you ask the agent about.
- Gmail compose access, to create drafts you request. AgentCall does not expose a send tool.
The model-visible Gmail tools are limited to thread search, thread read, and draft creation. Sending, deleting, trashing, marking spam, and label mutation are not available.
Private Labs · Use and sharing
Why it moves
Google data is used only to provide the Gmail feature you invoke in an AgentCall conversation. AgentCall does not sell Google user data, use it for advertising, determine creditworthiness, or use it to train a general machine-learning model.
To perform the feature, the selected realtime provider receives a short-lived Google access token and the relevant Gmail tool results. The provider uses AgentCall's Gmail gateway to reach Google's API. The gateway processes the token and results for that request but stores no Google credential. The provider's own terms, privacy policy, retention settings, and account controls also apply to the conversation and tool results it processes.
AgentCall's use of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Private Labs · Storage
What persists
- On the iPhone: Google subject, email address, granted scopes, connection state, and the refresh token. The refresh token is held in the iOS Keychain.
- In memory during a call: the short-lived access token and broker session credential.
- At AgentCall's Gmail gateway: no stored Google credential and no durable mailbox copy.
- At the selected provider: the conversation and Gmail tool results may be retained according to that provider's terms and the settings of your provider account.
AgentCall does not place refresh tokens in CloudKit metadata, logs, diagnostics, Agent Cards, or provider session configuration.
Private Labs · Control and deletion
Disconnect means delete locally
In AgentCall, open the connected agent's Tools screen, choose Google Workspace, and disconnect the account. AgentCall attempts Google's token revocation and then deletes the local refresh token, cached failure state, and connection record even if the network revocation request fails.
You can also revoke AgentCall from your Google Account's third-party connections page. Delete provider-held conversations or tool results using that provider's account controls.
Other call data
The private Labs build adds optional routes
The private Labs build can add Google Workspace and optional iPhone data sources. Those features are not present in the App Store target. In Labs, every source begins disabled and is granted separately per agent. Face templates and enrolled photos remain on the phone.
Credentials are not authority for external actions. AgentCall's access to an account, contact, message, or draft does not itself authorize sending, purchasing, deleting, or contacting anyone.
Contact and changes
Questions belong with the builder
Email agentcall@smartycode.com with privacy or data-deletion questions.
This policy will be updated before AgentCall uses Google user data for a materially different purpose.