Skip to content

Effective: 2 September 2026

Privacy Policy

This policy covers the public 4word website and the current personal and business pilots. It explains the data the systems are designed to process, the reasons for processing it, retention, service providers, and your choices.

The short version

4word processes voice and text to answer calls, show captions, and provide standalone transcription. Calls are not recorded as audio - audio is processed in real time only, and what is kept is the transcript and summary. In standalone transcription, audio is streamed in real time and never stored as a file by 4word. Text and summaries remain until deletion, and calls, transcripts, and the account can be deleted in the app.

Two products, two relationships

4word operates two pilot-stage products: a personal app for accessible call handling, including standalone live transcription, and a business answering and follow-up product. This policy covers the public site and both pilots. Some features and integrations may be available only to selected accounts.

4word is the controller of information collected directly from site and app users. You can contact us and submit a privacy request at support@4word.io or through the contact form on the site. Providing information is voluntary; without required details and approvals, an account cannot be created and the requested service cannot be supplied.

What we collect

When you submit a waitlist, pilot, or contact form, we process the fields shown in that form - for example name, email, phone number, business details, and your message - plus basic request information used for security and duplicate prevention. Google sign-in to the business product supplies only basic identity data: account identifier, name, email address, and profile image. Required and optional fields are marked in the interface.

The public website does not listen to phone calls or collect call audio. A participant who enters the closed beta also creates a versioned consent record that may include contact details, time, IP address, browser information, an on-page action trail, and a cryptographic fingerprint of the exact consent text. The personal product records acceptance after the user's phone number has been verified, while the business product records it after the Google identity has been verified. These records include document versions, acceptance time, and basic device or browser information.

In the personal product, when the app registers for notifications we also store a minimal set of technical data for support, security and troubleshooting: the app version and build number, the operating-system version, and the device model (a product type such as SM-S711B, not a personal identifier). We do not collect persistent hardware identifiers - no IMEI, serial number, Android ID or advertising ID - and we do not track you across apps. This technical data is deleted together with the account.

Contacts on your device stay on your device. Your contact list is never sent to us and is not stored by us; identification happens on the device itself, and when a caller is one you have saved, only that single saved name is sent to us, for that one call, so the assistant can address the caller by name. The name is held briefly in memory and is never written to the database. When a caller is not saved, identification comes from your own history, and if the external business-lookup service is enabled the caller's phone number may be sent to an external business-lookup service, with the result cached for a limited period.

How we use it

We use form data to respond, operate enrollment, prevent abuse, and communicate about the pilot. Service data is used to deliver calls, show live captions, relay user decisions, prepare summaries, support users, maintain security, and improve reliability. We do not sell personal information or use call content for advertising.

The pilot service: calls, transcripts, and audio

The personal product processes telephone numbers, call status and timing, live speech content, transcripts, the user’s in-call replies, and generated summaries. 4word identifies itself as an AI assistant at the beginning of calls it handles. Authorized team access may occur for support, quality review, security, and debugging during the pilot.

Telephone calls are not recorded as audio. Audio is processed and streamed in real time to operate the assistant, captions, and transcription, and is not stored; text transcription is what live captions, assistance, and summaries rely on. If we ever enable recording, we will announce it in advance and ask for separate consent.

Standalone live transcription

Standalone transcription uses the microphone to transcribe and translate, in real time, a conversation in which the user participates. 4word does not store an audio file of the transcription. Voice is streamed to the transcription provider for transcription and translation and is therefore processed by that provider during the conversation. 4word stores text, speaker labels, language, usage timing, and display preferences. Text may be sent to the AI-model provider to generate a title and summary.

A separate, feature-specific consent appears before first use. The user declares that they are a party to the conversation and will not use the feature to transcribe other people's conversations, commit an offence, cause harm, or unlawfully expose intimate matters. The declaration version, acceptance time, and wording fingerprint are stored. Other participants' speech will also be transcribed; the user's acceptance does not constitute consent on their behalf and does not replace any additional notice or permission that may apply.

The business product: who is responsible for which data

For information a business owner provides directly, 4word acts as controller (contact details, the business knowledge base, system settings). Toward the customers who call or message the business, we process their information (name, phone number, reason, transcript and summary) on the business's behalf and per its instructions; informing its customers and establishing a lawful basis is the business owner's responsibility, and we provide the tools for it - including the AI disclosure spoken on every call.

The business knowledge base is built from sources the owner explicitly provides: their website address and their public pages (Instagram, Facebook, Google Maps). We read only the public information on those pages, and the owner approves every draft before it is used.

Processing by artificial intelligence

The products use AI for speech transcription, conversation handling, summarisation, and structured detail extraction. This means call content may be sent to external telephony, speech, and model providers to produce the service. 4word identifies itself as an AI assistant at the start of calls it handles. AI output can be wrong and should not be treated as a guaranteed record of what happened.

AI annex

Some 4word features use automated models for speech recognition, transcription, translation, speech generation, conversation handling, summarising and reply suggestions. To do that, the system may pass the active provider audio, text, conversation context, information the user or the business provided, and earlier outputs - only to the extent the feature requires.

AI output may be wrong, partial, out of date or unsuited to its context. It must not be relied on as medical, legal or financial advice, as an emergency instruction, or as an authoritative record. The user or the business is responsible for checking material information before acting on it.

4word does not use call content to train a model of its own and does not ask its providers to use it for training. A provider may process or retain information for a limited period in order to provide the service, for security, for abuse prevention or to meet a legal requirement, according to its agreement and the account settings. The providers are listed on the subprocessors page.

Where it is possible, you can avoid an optional feature that sends information to an AI provider. Avoiding the core conversation-handling or transcription feature may make it impossible to provide the service itself. The assistant identifies itself as an AI assistant at the start of calls it handles, and that disclosure cannot be switched off.

Sub-processors and data transfers

Provider categories include telephony, speech and transcription, AI model processing, cloud hosting and databases, operational email, and app push notifications. The business pilot may also use a messaging provider when that integration is enabled. The full list of providers, with what each one receives and where it processes it, is on the subprocessors page. Provider identity and configuration can change during the pilot; a material change is reflected there.

Personal data is never sold, rented, or shared with advertisers. Service providers that help us operate receive only the minimum access their role requires: telephony and verification, voice processing, transcription, and AI, email delivery, app push notifications, and storage and hosting.

Where it's stored

4word uses managed cloud infrastructure and restricts operational access by role. Some providers process data outside Israel. Security and international-transfer obligations depend on the provider, configuration, and applicable law; we review these arrangements as the pilot evolves rather than claiming that every environment is automatically compliant.

Retention and deletion

The table below is the single source of truth for retention periods: it is generated from one file that this site and the servers share, so the policy and the code cannot drift apart. In short: full call transcripts and diagnostic events are deleted after 30 days; call records and summaries are kept until you delete them or your account; in the business product call content is cleared after 30 days and the call row stays until the business deletes it; website forms are kept for 24 months (waitlist and business-pilot signups) and 12 months (contact messages). Encrypted backups are kept for up to 7 days, so a deletion you make does not reach an offline backup copy inside that window. Deletion controls do not override limited information that must or may be kept for law, security, accounting, or legal defence. The usage history that is not linked to your identity is kept indefinitely, as described in the Usage history section. When device storage is enabled for standalone transcription, the transcript text is kept encrypted on that device only and is not sent to 4word's servers; in that mode it will not be available from another device or after a reinstall.

Retention and deletion
What is keptWhereHow longWhat that means
Full phone-call transcriptsThe service (the app and the business product)30 daysDeleted automatically 30 days later, with nothing for you to do.
Call diagnostic eventsThe service (the app and the business product)30 daysDeleted automatically 30 days later, with nothing for you to do.
Questions and decisions waiting for you during a callThe service (the app and the business product)30 daysDeleted automatically 30 days later, with nothing for you to do.
Standalone live-transcription sessionsThe service (the app and the business product)30 daysDeleted automatically 30 days later, with nothing for you to do.
The identification result for a caller you have not savedThe service (the app and the business product)30 daysDeleted automatically 30 days later, with nothing for you to do.
Caller signals and spam reputationThe service (the app and the business product)180 daysDeleted automatically 180 days later, with nothing for you to do.
Operational alerts to the teamThe service (the app and the business product)365 daysDeleted automatically 365 days later, with nothing for you to do.
Audit log of authorised staff accessThe service (the app and the business product)730 daysDeleted automatically 730 days later, with nothing for you to do.
Business records on the outreach listThe service (the app and the business product)90 daysDeleted automatically 90 days later, with nothing for you to do.
Outreach calls placed to businessesThe service (the app and the business product)90 daysDeleted automatically 90 days later, with nothing for you to do.
Business call content: transcript, summary and leadThe service (the app and the business product)30 daysThe transcript, the summary and the lead are cleared after 30 days. The call row and the caller's number stay in the CRM until the business deletes the call.
Log of the website sync runsThe service (the app and the business product)90 daysCleared by a periodic sweep 90 days later.
Log of the changes detected on the websiteThe service (the app and the business product)90 daysCleared by a periodic sweep 90 days later.
A copy of the business website's page content, used to answer callersThe service (the app and the business product)Until you delete itKept for as long as the website is connected, and deleted when the website is disconnected or the business account is deleted. It is a copy of content the business itself published publicly, used by the assistant to answer callers.
Call records and summaries in the personal productThe service (the app and the business product)Until you delete itKept until you delete the call or your account.
Usage history that is not linked to your identityThe service (the app and the business product)No time limitKept with no time limit, and with no name, number, identifier or call content.
Website waitlist signupsThe public website730 daysDeleted automatically 730 days later, with nothing for you to do.
Website business-pilot enrolmentsThe public website730 daysDeleted automatically 730 days later, with nothing for you to do.
Contact-form messagesThe public website365 daysDeleted automatically 365 days later, with nothing for you to do.
Beta consent recordsThe public websiteKept as evidenceAn append-only record kept as evidence of consent, including after the account is closed.
Encrypted database backupsOperations and infrastructureUp to 7 daysKept encrypted for up to 7 days and then deleted. A deletion you make does not reach an offline backup copy inside that window.

The table is generated from a single file (2026-09-04) that this site and the servers share, so the policy and the code cannot drift apart. A period shown here is the period the system actually enforces.

Usage history

When you register, the account is assigned a random identifier. It is not derived from your phone number, your email or any other detail about you, and it cannot be computed from them. Alongside it we keep a usage history: when the account was opened, which setup steps were completed and when, the mobile carrier chosen, when the first and last call happened, how many calls and minutes were delivered each month and what they cost, which capabilities were used, which languages calls were held in, and quality counts such as how many calls ended in an error. The history contains no call content, transcripts, summaries, names, addresses or phone numbers.

The user record is the only link between that random identifier and a person, and deleting the account deletes it. From that point the history is not linked to your identity, and we keep it indefinitely in order to know how the service performs, where it fails and what it costs. Registering again creates a new account with a new random identifier; it is not linked to the previous account and the two cannot be joined.

Deactivation, termination, and deletion by us

You can also deactivate your account from within the app, which stops the service without deleting anything; reactivation is done by contacting us. When an account is deactivated or suspended, its data is kept under the normal retention periods until deleted and is not processed to answer calls; when the account is terminated or deleted, the deletion process described in this policy runs. The dedicated number assigned to you may be assigned to another user after the account is closed, and a caller who dials it afterwards reaches the new user.

When the personal caller-ID feature is turned off by you or revoked by us, your personal number is deleted from the telephony provider's verified list; the verification-attempt count is kept briefly to enforce the attempt limit. We may also delete data for security, legal, or provider reasons or because of a technical failure, and we do not undertake to back up, restore, or keep data for any period. Deletion at sub-processors and in backup copies is carried out on a best-effort basis and may take time.

What is special about a pilot

To improve the product, a small team of ours may review transcripts and summaries for quality control and debugging, under confidentiality. We want you to know this in advance - and it is one reason the pilot service is not yet suitable for especially sensitive information.

Cookies and browser storage

This site uses no tracking, advertising, analytics, or third-party cookies, and does not track you across sites. Your language is chosen from the page address, not from a cookie. The only thing saved in your browser is data essential to running the site: the accessibility preferences you choose (text size, contrast, link highlighting, spacing, and so on) and a small note that remembers you dismissed this notice. This data stays on your device only, is never sent to us, and is never shared with anyone.

Because this is essential data only, no prior consent is needed - we simply let you know. You can remove it at any time: turn the settings off in the accessibility tool (or reset them) and clear this site's data in your browser. As with any website, your browser may also temporarily cache static files (images, fonts, and code) so pages load faster; these contain no personal information.

How to delete

In the personal app you can deactivate your account or delete it, and these are two different actions. Deactivation stops the service and deletes nothing: the account, the calls and the transcripts stay as they are, and reactivation is done by contacting us. Account deletion removes the account and associated calls, transcripts, decisions, profile facts, blocked numbers, device tokens and related product records, and releases the dedicated number. Deletion may wait while a call is active. After deletion four categories remain: a usage history and account journey that are not linked to your identity, as described in the Usage history section; accounting rows for AI-provider requests with the user identifier detached; a deletion record that contains no phone number and no user identifier; and a Terms acceptance record with the phone number and identifiers removed, where needed to prove the relationship, handle a dispute, or comply with law.

You may also contact us to request access, correction, or deletion. We may need to verify your identity and may retain limited information where required for security, legal, or accounting purposes.

Privacy requests: access, correction, a copy and deletion

You can ask to see the information kept about you, correct it, receive a copy of it, delete it, or object to a particular processing. 4word handles these requests: write to support@4word.io or use the contact form. To protect your information we will ask you to verify your identity, usually from the number or the email address on the account, and we will not disclose information on an unverified request.

We acknowledge a request within two business days and complete it within 30 days; if more time is needed we will say so and explain why. Two actions are available directly in the app without contacting us: deleting a single call or transcript, and deleting the whole account. Limited information may be kept even after a deletion request where the law requires or permits it, as set out in the retention and deletion section.

Minors

The service is intended for people aged 18 or older. We do not knowingly collect information about anyone under 18, and the signup forms on this site accept an age of 18 or over only. If we learn that such information has been collected, we will delete it. If you know that a minor has given us information, write to support@4word.io and we will handle it. An incoming call can come from anyone, including a minor; in that case the call content is subject to the same retention periods and the same deletion controls as any other call.

Contact

Questions, objections, or rights requests - reach 4word by email at support@4word.io or through the contact form.