OpenReef. / privacy
Privacy Policy
Last updated: July 2026
OpenReef is a voice phone-call agent for AI. Your AI agent — working through ChatGPT (via MCP), Claude, our REST API, or the OpenReef website — asks OpenReef to place a real phone call on your behalf (for example, to make a booking, check a price, or handle a customer-service errand), and OpenReef's server-side voice agent conducts that call. This policy explains what information we collect, how we use it, and who we share it with. It is written to be specific to how OpenReef actually works; we do not sell your personal data.
1. Information we collect
Most data reaches OpenReef because you — or an AI agent acting for you — send it to us to place a phone call. We collect:
Call data (what tool calls send us)
Call requests — the destination phone number, the task you want the call to accomplish, and any names, dates, times, quantities, language, and other details your agent supplies for the call.
Call transcripts and recordings — a transcript of the conversation between OpenReef's voice agent and the person who answered, and any associated audio, used to conduct the call, report the outcome back to you, and improve the service.
Steering instructions — the mid-call guidance you or your agent send while a call is running.
Call metadata — status, duration, outcome, and the credits spent on each call.
Account identity
Your email address, used to create and secure your account and to send transactional email. Authentication is handled by Google Firebase Authentication.
If you sign in with Google, the email address and name associated with your Google account, as provided to us by Google during sign-in.
Payment data
Payments are processed by Stripe. Your card details are entered on and sent directly to Stripe — OpenReef never receives or stores your full card number. We store only what we need to sell call credits: the purchase amount, payment status, and Stripe session, charge, or refund identifiers. Payment always happens on theopenreef.com, never inside ChatGPT or another chat surface.
2. How we use your information
We use the information above to:
Place and conduct the phone calls you or your agent request, and report their transcripts and outcomes back to you.
Process credit purchases through Stripe and meter the credits each call spends.
Send you transactional email about your account and calls (verification, receipts, and account notices).
Operate, maintain, secure, and improve the service, including preventing fraud and abuse.
Comply with legal obligations and enforce our Terms of Service.
3. AI and agent access
OpenReef is designed to be used by AI agents on your behalf. You may authorize an agent — for example, ChatGPT connecting via OAuth, or your own agent using an API key — to act for you. Once authorized, that agent can place and steer phone calls in your name, spending your credits, and its actions are attributed to your account.
You control this authorization. Each API key is scoped to your account, and you can list and revoke keys at any time from the keys page; you can likewise disconnect an OAuth-connected app from that app's settings. Revoking access stops future agent activity but does not retroactively undo calls already placed.
4. Call recording and the people you call
OpenReef places real phone calls and, as described above, records and transcribes them to conduct the call, report the outcome back to you, and improve the service.
Recording-consent laws vary by location. Some places require only one party on a call to consent to its being recorded; others require everyone on the line to consent. Because you decide who OpenReef calls and what each call is for, you are responsible for ensuring that every call you request, and its recording, comply with the laws that apply to you and to the person being called, including obtaining any consent those laws require.
OpenReef's voice agent conducts each call as an automated assistant acting on your behalf; it is not a human. Conducting the call through an automated agent does not by itself satisfy any consent the law requires for recording — that consent remains your responsibility to obtain where it applies.
Do not use OpenReef to place calls that are unlawful where you or the called party are located, including calls that violate recording-consent, robocall, telemarketing, or do-not-call rules. Acceptable use is governed by our Terms of Service.
5. Service providers and subprocessors
We share information with a small set of vendors who process it only as needed to run OpenReef on our behalf. We do not sell your personal data, and we do not share it for third-party advertising.
Google Firebase — account authentication.
Google Cloud Platform — hosting and infrastructure.
Vapi — real-time voice and telephony: placing the call and converting speech to and from text during the conversation, including the call audio and transcript.
Google Gemini — the AI model that powers assistant features.
Stripe — payment processing.
Resend — transactional email delivery.
Cloudflare — content delivery and network security.
Each provider receives only the information necessary for its function and is bound by its own terms and privacy commitments. We may also disclose information where required by law or to protect the rights, safety, and security of OpenReef, our users, and the public.
6. Data retention and your rights
We retain your account data while your account is active, and call and payment records for as long as needed to provide the service, resolve disputes, and meet legal, tax, and accounting requirements.
You may request access to, correction of, or deletion of your personal data by contacting us at support@theopenreef.com. We will respond in accordance with applicable law. Note that some records must be retained even after deletion of an account where required for legal or financial reasons.
7. Security
We use industry-standard measures — including encryption in transit, scoped access credentials, and reputable infrastructure providers — to protect your information. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we work to protect your data and to promptly address issues if they arise.
8. International data transfers
OpenReef and its service providers operate in multiple countries. Your information may be processed and stored in countries other than the one where you live, including the United States. Where we transfer data internationally, we rely on our providers' safeguards and applicable legal protections for such transfers.
9. Children
OpenReef is not intended for anyone under 18 years of age. We do not knowingly collect personal data from children. If you believe a minor has provided us with personal data, please contact us so we can remove it.
10. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you. Your continued use of OpenReef after an update means you accept the revised policy.
11. Contact us
Questions about this policy or your data? Reach us at support@theopenreef.com.
Terms of Service →