Privacy Policy
Last updated 24 September 2026
This describes what Current collects, why, who else sees it, and how to get it back or get rid of it. It is specific on purpose: a privacy policy that could describe any product describes nothing.
What we hold about you
- Your account — your email address, your name and profile picture if you sign in with Google or Microsoft, and a one-way hash of your password if you set one. We never store a password itself.
- Your workspace data — the prospects you import or add, and everything attached to them: companies, contacts, phone numbers, email addresses, notes, activities, follow-ups, and any fields you define yourself.
- Call records — the number dialled, when, how long it lasted, and the outcome you logged.
- Sessions — a signed-in session, stored in our database rather than in a cookie, so signing out on our side genuinely ends it.
Where recordings live
Call recordings are stored by Twilio, on the account the call was placed from — not on Current's servers. When you play one, we fetch it from Twilio and pass it through; we keep only the identifier needed to find it again. Deleting a recording from Twilio deletes it.
If you switch on transcripts, Twilio transcribes the recording on the same account and Current keeps a copy of the text with the call, so it can be read, searched and asked about. It is deleted with the prospect it belongs to.
Call summaries
When a call has a transcript, Current can send it to Anthropic — with the name of the business and when the call was made — so that its Claude models can suggest how the call went, a note and a follow-up. The suggestion is saved with the call, and nothing is added to the prospect until you press Apply. Under Anthropic’s commercial terms, this content is not used to train its models.
Separately, if you connect Claude to Current yourself, Claude reads and changes your workspace only when you ask it to, under the terms of your own Claude account.
What we collect to keep it working
- Failed sign-ins — the email address tried and the network address it came from, so repeated guessing can be slowed. These are deleted after one hour.
- Errors — when a page fails, your browser sends us the error, where it happened and what browser you were using, so we can find out why. We do not send the contents of the page.
- Server logs — ordinary request logs kept by our host, retained for a short period.
There is no advertising in Current, no analytics or tracking scripts, no third-party cookies, and nothing that follows you to other sites.
Who else processes it
We use a small number of services to run Current. Each sees only what its job needs.
- Neon — the database everything is stored in.
- Netlify — hosting and serving the application.
- Twilio — placing calls, and storing recordings if you record.
- Google and Microsoft — only if you sign in with them, and only to confirm who you are.
- SendGrid — sending workspace invitations, if configured.
- Twilio — calls and text messages, sent through the Twilio account you connect yourself.
- Anthropic — reading call transcripts to suggest an outcome, note and follow-up.
We do not sell personal information, and we do not share it for advertising. We disclose it only to these processors, when the law compels us, or to protect someone from harm.
The people in your list
Most of the personal data in Current is not about you — it is about the people and businesses you are contacting. You decided to collect it, so under data protection law you are the controller of it and we are processing it for you. That means you are responsible for having a lawful reason to hold it, for honouring requests from those people, and for not importing lists you should not have.
When someone asks not to be contacted, mark them do-not-contact. That is permanent, it survives re-importing the same list, and it takes them out of every queue.
How long we keep it
Your workspace data stays until you delete it or close your account. Failed sign-in records last an hour. Error reports and logs are kept for a short period and then expire. Closing your account removes your sign-in and any workspace only you belong to; backups containing it expire shortly afterwards.
Getting it back, or getting rid of it
Both are in Settings and neither needs anyone's approval. You can export every prospect, every logged activity and every call as CSV, or the whole workspace as JSON with every field we store — including ones no screen shows. You can close your account from the same page.
Depending on where you live you may also have rights to correct, restrict or object to our use of your personal data. Ask and we will do it.
Security
Traffic is encrypted in transit. Passwords are hashed, never stored. Every query is scoped to the workspace it belongs to. Repeated failed sign-ins are throttled. No system is perfectly secure, and we will tell you promptly if something happens that affects your data.
Children
Current is for business use and is not intended for anyone under 16.
Changes and contact
If this policy changes materially we will say so in the app before it takes effect. For anything at all — a question, a correction, a deletion request — write to hello@obramade.com.