This Privacy Policy describes how Insito Health, Inc. (“Insito,” “we,” “us,” or “our”) collects, uses, and shares personal information in connection with Resia: the website at resia.ai (the “Site”), the Resia customer portal and APIs (the “Platform”), and the voice and messaging services we provide through them (together, the “Services”).
Resia is a business product. Our customers are organizations that use the Platform to place and receive calls and text messages through AI agents. Because of that, we handle personal information in two different roles:
- Data we collect for ourselves. We decide how to use information about Site visitors, customer accounts, and billing. For this data, we act as the business (the “controller” under some laws), and this Policy governs.
- Data we process for our customers (“Customer Content”). When a customer uses the Platform to communicate with people, we process the resulting data — phone numbers, call recordings, transcripts, and messages — on the customer’s behalf and under the customer’s instructions. For this data, we act as a service provider (a “processor” under some laws). The customer’s agreement with us, including any data processing addendum, governs that data, and the customer — not Insito — decides why it is collected and how it is used.
If you received a call or text from an AI agent powered by Resia, see Section 3.
1. Information We Collect
A. Site visitors
We keep collection on the Site to a minimum:
- Page-view analytics. We measure aggregate page views using Vercel Web Analytics. This measurement sets no cookie and does not identify individual visitors.
- No advertising trackers. The Site sets no cookies and loads no advertising pixels, social-media trackers, or third-party analytics scripts.
- Demo requests. If you book a demo, the name and email address you enter are passed directly to our scheduling provider, Cal.com, to create the booking. We do not store them on the Site. Cal.com’s handling of that information is described in Cal.com’s own privacy policy.
- Server logs. Our hosting providers keep standard technical logs (such as IP address, browser type, and pages requested) to operate and secure the Site.
B. Account and organization data
When you create a Resia account, you sign in with a supported identity provider (currently Google or GitHub). We receive and store your name, email address, and a stable identifier from that provider. We also collect:
- Organization details. The organization name you choose and the email addresses of teammates you invite.
- Credentials and security data. API credential names and hashed secrets, sign-in and access records, and an audit log of account changes.
- Compliance registration details. If you register a brand or messaging campaign for text messaging (for example, US 10DLC registration), the business details you provide — such as legal name, address, tax identifier, and contact information — which we submit to our carrier and the applicable messaging registry.
- Correspondence. Messages you send us for support, sales, or anything else.
C. Billing and usage data
We meter your use of the Services — call minutes, messages sent, phone numbers held, and agent workflow runs — and maintain a ledger of the resulting charges. Payments are processed by Stripe, our payment processor, which receives your payment details; we do not store full payment card numbers ourselves.
D. Customer Content and communications data
When a customer directs the Platform to communicate, we process on the customer’s behalf:
- Recipient information. Telephone numbers of call and message recipients, participant names for multi-party calls, and any information the customer supplies as inputs to an agent (which may include names, appointment details, or other facts about recipients).
- Call data. Call audio recordings (where the customer has enabled recording), transcripts, AI-generated summaries and analysis, and call metadata such as time, duration, and outcome.
- Message data. The content of outbound text messages, delivery status, and opt-out records. We record inbound replies only to the extent needed to honor opt-out and help keywords.
- Agent configurations. The prompts, scripts, knowledge bases, and workflow configurations the customer creates.
The customer is responsible for having a lawful basis to submit this information and to direct these communications, as set out in our Terms of Service.
2. How We Use Information
We use the information described above to:
- Provide, operate, maintain, and support the Services, including routing calls and messages through telecommunications carriers;
- Set up and administer accounts and organizations;
- Meter usage, calculate charges, bill, and collect payment;
- Register brands and campaigns with carriers and messaging registries where required;
- Secure the Services, and detect, investigate, and prevent fraud, abuse, and violations of our Terms of Service;
- Comply with law, regulation, carrier and registry requirements, and legal process, and respond to lawful requests;
- Communicate with you about the Services, including service notices, security alerts, and billing;
- Send marketing communications about our products, which you can opt out of at any time; and
- Create de-identified and aggregate data, as described in our Terms of Service, to operate, evaluate, and improve the Services. Where source data includes personal information, we de-identify it before this use, and we do not attempt to re-identify it.
We do not sell personal information, and we do not share personal information with third parties for cross-context behavioral advertising.
Mobile information. We do not sell mobile information. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent are excluded from every category of sharing described in this Policy; that information is not shared with any third party. We disclose a phone number you give us only to the vendors that carry a message or a call for us, and only so that it can be delivered.
We use Customer Content only to provide the Services to the customer, to secure the Services, to prevent or address fraud, abuse, or legal risk, and as otherwise permitted by our agreement with the customer.
3. If an AI Agent Called or Texted You
Two different things can bring a call or a text from us, and who is answerable for it differs between them. Read whichever paragraph describes yours.
3.a Messages you asked us for
If you asked us for a demo call or for text messages at resia.ai, then Insito Health, Inc. is the sender. We chose the wording, we decided when to send it, and we are answerable for it. No customer of ours is involved.
The two are separate, and asking for one is not asking for the other. Asking for a demo call gets you a phone call and nothing else; we do not text the numbers that form collects. Text messages are asked for in one place only, at resia.ai/sms-opt-in, by ticking a box that starts empty. Ticking it is optional — the form submits either way — and it is never a condition of anything you buy. You may stop the messages at any time by replying STOP. What we send and how to stop it is set out in our Messaging Terms.
When you do tick it we keep a record — your name and number, the exact words shown to you, and when you agreed — because we have to be able to show it. When you leave it empty we record that too, in the same place and in as many words, so that the absence of an agreement is never mistaken for one.
3.b Messages from a business that uses Resia
Resia provides communications technology to businesses. If an AI agent called or texted you, a business — our customer — chose to contact you, decided what the agent would say, and controls the resulting data. Insito processes that data as the business’s service provider.
- Who to contact. Requests about the communication or your data — including access, deletion, and questions about why you were contacted — should go to the business that contacted you. If you contact us instead, we will refer your request to that business and support its response as our agreement with it requires.
- Stopping text messages. Reply STOP to any text message to opt out of further messages from that sender. Reply HELP for help. We maintain opt-out records so that further messages to your number from that sender are blocked.
- Recording. Calls may be recorded, transcribed, or monitored where the business that placed or received the call has enabled those features. The business is responsible for providing any legally required notice and obtaining any legally required consent.
- Voice data. We do not use call audio to identify individual speakers, and we do not create voiceprints or other biometric identifiers from call audio.
4. How We Share Information
We share personal information only as described here:
- Service providers and subprocessors. We use third-party providers to deliver the Services, bound by contract to use the information only to provide services to us. These include cloud infrastructure (Google Cloud, in United States regions), website hosting and analytics (Vercel), demo scheduling (Cal.com), payment processing (Stripe), speech-recognition providers, speech-synthesis providers, and large language model providers (including Anthropic, OpenAI, and Google). Some AI models run on infrastructure we operate ourselves.
- Telecommunications carriers and registries. To route calls and deliver messages, we share communications data — including phone numbers, call audio in transit, and message content — with telecommunications carriers (including Telnyx) and messaging registries. Carriers process some of this data as independent controllers for their own legal obligations, such as billing and fraud prevention, under their own privacy policies.
- At the customer’s direction. We disclose Customer Content as the responsible customer instructs.
- Legal compliance and protection. We may disclose information when we believe in good faith that the law requires it, or that disclosure is necessary to comply with legal process, enforce our agreements, or protect the rights, property, or safety of Insito, our customers, call and message recipients, or the public.
- Business transfers. If Insito is involved in a merger, acquisition, financing, or sale of assets, personal information may be disclosed and transferred as part of that transaction. We will require the receiving party to honor the commitments in this Policy or give you notice as required by law.
- De-identified and aggregate data. We may share data that does not identify you and cannot reasonably be used to identify you.
- With your consent. We share for any other purpose you consent to.
5. Data Retention
- Site analytics. Aggregate only; we hold no per-visitor analytics record.
- Demo requests. Not stored by the Site; held by Cal.com under its policy.
- Account and organization data. Kept for the life of the account, and afterward as needed for legal, billing, audit, and dispute purposes.
- Billing and usage ledgers. Kept as required for tax, accounting, and audit purposes.
- Call recordings. Deleted no later than twelve (12) months after the call.
- Transcripts and other communications data. Retained for as long as reasonably necessary to provide the Services, unless the responsible customer requests deletion of specified data or a signed agreement with the customer sets a different retention period. We may retain data as required for legal, regulatory, audit, or dispute-resolution purposes.
- Opt-out records. Kept for as long as needed to honor the opt-out.
- Backups. Encrypted backups persist for a limited period after deletion from live systems.
- De-identified data. May be retained indefinitely.
Customers may request deletion of specified Customer Content at any time, as described in our Terms of Service.
6. Security
We maintain an information security program with administrative, technical, and physical safeguards appropriate to the Services, including encryption of Customer Content in transit and at rest, role-based access controls, logging, and personnel screening and training. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. We will notify affected customers without undue delay after confirming a security incident affecting Customer Content.
7. Health Information and Other Regulated Data
The Services as offered under our standard Terms of Service are not intended for protected health information subject to HIPAA or other data subject to sector-specific legal protection, unless we have signed a separate written agreement covering it — such as a Business Associate Agreement. Where such an agreement exists, its terms govern that data to the extent of any conflict with this Policy.
8. Your Rights and Choices
- Marketing. You may opt out of marketing emails using the unsubscribe link in any marketing message or by contacting us at privacy@resia.ai. We will still send service and billing communications tied to your account.
- Account information. Customers can review and update organization and member information in the portal, or by contacting us.
- State privacy rights. Depending on where you live, you may have rights to know, access, correct, delete, or receive a portable copy of personal information we hold about you as a business, and the right not to be discriminated against for exercising those rights. Because we do not sell personal information or share it for cross-context behavioral advertising, there is no sale or sharing to opt out of; we honor recognized opt-out preference signals such as Global Privacy Control where they apply.
- How to exercise rights. Email privacy@resia.ai or write to the address in Section 12. We will verify your identity before acting, respond within the time applicable law requires, and explain any denial. You may appeal a denial by replying to our response, and you may also contact your state attorney general or supervisory authority.
- Requests about Customer Content. If your request concerns data a customer controls — for example, a call a business placed to you — we will refer the request to that customer, as Section 3 describes.
9. Children
The Services are for business use and are not directed to individuals under 18. We do not knowingly collect personal information from children under 13 through the Site or the Platform. If you believe a child has provided us personal information, contact us at privacy@resia.ai and we will delete it.
10. Processing in the United States
We are based in the United States and process personal information in the United States. If you access the Services from outside the United States, you understand that your information will be transferred to and processed in the United States, where data protection laws may differ from those of your jurisdiction. Where applicable law requires a transfer mechanism for international transfers, we will implement one; contact us at privacy@resia.ai for details.
11. Changes to This Policy
We may update this Policy from time to time. When we do, we will revise the “Last updated” date above, and for material changes we will provide notice on the Site, through the Services, or by email before the changes take effect. Your continued use of the Services after the effective date constitutes acceptance of the updated Policy.
12. Contact Us
Insito Health, Inc.
56 Broad Street, STE 14277
Boston, Massachusetts 02109
Email: privacy@resia.ai



