Poof
← Legal Center

Privacy Policy

Effective
August 12, 2026
Last updated
August 12, 2026
Version
v0.1 (working draft)

This policy explains what information Poof collects, why we process it, who we share it with, and how you can control it. Poof does not record or store call audio or video by default.

“Download as PDF” opens your print dialog — choose “Save as PDF”.

Contents

  1. 01Account and profile information
  2. 02Provider profile and business information
  3. 03Booking and transaction data
  4. 04Call metadata
  5. 05Device, security, and diagnostic data
  6. 06Payment information
  7. 07Cookies and analytics
  8. 08Why we process each category
  9. 09Service providers and subprocessors
  10. 10Data retention
  11. 11Account deletion
  12. 12Data security
  13. 13Health information and HIPAA
  14. 14Your privacy rights
  15. 15International data transfers
  16. 16Children's privacy
  17. 17Changes to this policy
  18. 18Contact

01Account and profile information

When you create an account we collect your name, email address, and authentication details. If you sign in with Google, we receive your basic profile and email from that provider; we never receive your password.

You may add optional profile details such as a photo, time zone, and display preferences.

02Provider profile and business information

Providers additionally give us a public profile (display name, headline, bio, avatar, booking slug), service configuration (call lengths, availability, access rules, credit rules), and, where selling is enabled, the business and identity details Stripe requires for payouts.

03Booking and transaction data

We store bookings, their status, the Provider and Client involved, any topic or note you provide, and the credit ledger that records when a Poof was issued, reserved, consumed, returned, or expired. This is what lets balances and history stay accurate.

04Call metadata

For each call we may process technical metadata: who the participants were, the start time, the end time, the duration, how the call ended, and basic connection quality signals.

Poof does not record or store call audio or video by default and does not transcribe calls. Live audio and video pass between participants for the length of the call.

05Device, security, and diagnostic data

We process IP address, browser and device type, operating system, approximate location derived from IP, timestamps, and error or diagnostic logs. We use this to keep accounts secure, prevent abuse, and fix problems.

06Payment information

Stripe processes payment credentials. Card numbers and bank details go directly to Stripe and are not stored on Poof's systems. We keep limited records such as the amount, currency, status, last four digits, and Stripe identifiers so we can show receipts and support your account.

07Cookies and analytics

Poof uses essential cookies and local browser storage for sign-in and for remembering local preferences. See the Cookie Policy for the current list and for how to control optional cookies.

08Why we process each category

  • Account and profile data — to create your account, authenticate you, and show you to the people you book with.
  • Provider and business data — to publish profiles, run booking rules, and enable payouts.
  • Booking, credit, and transaction data — to deliver the service you paid for or were granted, and to keep balances correct.
  • Call metadata — to run and end calls on time, show history, and troubleshoot quality issues.
  • Device, security, and diagnostic data — to protect accounts, detect abuse, and maintain the platform.
  • Payment data — to take payment, issue refunds, and meet financial record-keeping duties.

09Service providers and subprocessors

We share data with vendors who help us run Poof, under contracts that limit what they can do with it. Current categories:

  • Cloud hosting and application delivery.
  • Database, authentication, and file storage (Supabase infrastructure operated through Lovable Cloud).
  • Payment processing (Stripe).
  • Email delivery for transactional messages.
  • Real-time audio and video transport for the call room.

Current subprocessor list: [SUBPROCESSOR LIST PLACEHOLDER]. We do not sell personal information.

10Data retention

We keep account and booking records for as long as your account is active and afterwards only as long as needed for legal, tax, accounting, dispute, and security purposes. Diagnostic logs are kept for a short period. Specific retention periods: [RETENTION SCHEDULE PLACEHOLDER].

11Account deletion

You can ask us to delete your account by writing to legal@poofcall.com. We will delete or anonymize your personal data except where we must keep records — for example financial transactions — and except for the aggregated data that no longer identifies you. Deleting an account forfeits any remaining Poofs.

12Data security

We use encryption in transit, row-level access controls on our database, scoped credentials, and least-privilege server access. No system can be guaranteed completely secure, so we do not promise absolute security. Tell us immediately if you suspect a problem with your account.

13Health information and HIPAA

Poof is not currently represented as HIPAA compliant.

Do not submit protected health information through Poof and do not use Poof for HIPAA-regulated care unless Poof has expressly entered into the required written agreements with you, including a business associate agreement.

14Your privacy rights

Depending on where you live, you may have the right to access, correct, delete, port, or restrict the processing of your personal data, and to object to certain processing.

To exercise a right, email legal@poofcall.com. We may need to verify your identity first. You also have the right to complain to your local data-protection authority.

15International data transfers

Poof and its vendors may process data in countries other than your own. Transfer mechanism and safeguards: [INTERNATIONAL TRANSFER MECHANISM PLACEHOLDER].

16Children's privacy

Poof is for adults aged 18 and over. We do not knowingly collect personal information from children. If you believe a child has given us data, contact legal@poofcall.com and we will remove it.

17Changes to this policy

We may update this policy. We will change the “last updated” date and give notice in the product for material changes.

18Contact

Privacy questions and requests: legal@poofcall.com. Data controller: [CONTROLLER ENTITY PLACEHOLDER].

Contact

Questions about this document? Email legal@poofcall.com.

Other documents

  • Terms of Service
  • Payments, Poofs, Cancellations & Refunds
  • Acceptable Use Policy
  • Provider Agreement
  • Cookie Policy
  • Legal Center
Powered by Every call ends when the timer does.
TermsPrivacyPayments & PoofsAcceptable UseLegal Center© 2026 POOF