Privacy Policy
Last updated: October 3, 2026
Ello lets a person reach a business by calling a handle from a browser or our app, over the internet, with no phone number and without using the public telephone network. A business can be answered by its owner or by a voice AI assistant that takes orders, answers questions and books meetings. This policy explains what we collect, why, who we share it with, how long we keep it, and the choices you have.
The short version: we do not sell your data, we do not use it for advertising, we do not record call audio, your delivery address goes only to the business filling your order, and your phone number is never given to a business unless you say yes on that call.
Who we are
Ello operates this service and is the data controller for the information described here. You can reach us about anything in this policy at [email protected].
What we collect
- Google account information. When you sign in with Google we receive your name, email address, Google account identifier and profile picture. We request only sign-in scopes (openid, email and profile). We do not request access to your Gmail, Drive, contacts or any other Google data in order to sign you in.
- Customer profile. Your phone number and delivery address, if you choose to add them. Both are optional, and the app works without either.
- Business profile. Business name, handle, description, website, category, opening hours, answering mode, and the registration certificate you upload so a person can check the business is real.
- Call records. Who called which business, when, how long, and how the call ended. Where you use the voice assistant we also keep a written summary of what was asked and agreed. We do not record or store call audio.
- Messages. The text of chats between a customer and a business, including replies written by the assistant.
- Orders, bookings and payments. Items, quantities and prices on an order; the reason for a meeting and its time; and the record of a payment. Card details are entered on our payment provider’s own page and never reach our servers.
- Connected accounts. If a business connects a calendar or a spreadsheet, we store the access tokens for that connection on our servers so bookings and stock can be kept in step. Those tokens are never sent to a browser or a phone.
- Technical data. Browser and device information needed to place a call, IP address, and diagnostic logs. On your device we store only what is needed to keep you signed in and to remember small preferences such as your theme.
How we use it
- To connect calls and chats between a customer and a business.
- To run the voice assistant a business has chosen to switch on.
- To take orders, book meetings and move money to a business.
- To check a business is real before it is listed as verified.
- To send notifications about a call, a message or an order.
- To keep the service secure, to fix faults, and to answer you.
- To meet our legal and accounting obligations.
We do not use your information to train our own models, and we do not sell it or use it for advertising.
How we handle Google user data
Ello’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
This policy covers the Ello web app at ello.africa and the Ello mobile apps for Android and iOS.
- We use the name, email address and profile picture we receive from Google only to create your account, to show you who is signed in, and to contact you about the service.
- Where a business connects Google Calendar or Google Sheets, we use that access only to create and read the bookings or the stock list that business asked us to manage.
- We do not transfer Google user data to anyone except as needed to provide the service, to comply with the law, or as part of a merger or acquisition, and we do not use it for advertising.
- No human reads your Google data except with your explicit permission, to resolve a fault you have reported, for security reasons, or where the law requires it.
- How we protect it. Google user data is encrypted in transit, OAuth tokens are held on our servers and never sent to a browser or a phone, and access by our staff is limited to the people who need it.
- How long we keep it, and deleting it. We keep the Google account information behind your sign-in while your account is open, and a connected calendar or spreadsheet only until you disconnect it. Delete your account and the Google user data we hold goes with it.
- You can withdraw our access at any time at myaccount.google.com/permissions, and you can disconnect a calendar or spreadsheet inside Ello.
What we never do with Google user data
We affirm that Ello does not, and will not:
- Use Google user data for serving targeted advertising.
- Sell or transfer Google user data to data brokers or information resellers.
- Use Google Workspace APIs, or any Google user data obtained through them, to develop, improve or train generalised or non-personalized AI or machine learning models. The voice assistant uses only the business’s own records to answer a call, and nothing it handles is used to train a model.
- Allow a human to read Google user data, except with your explicit permission, to resolve a fault you reported, for security reasons, or where the law requires it.
When we share information
We share personal information only in these cases:
- With your consent. A business receives your phone number only when you have agreed on that call. We ask first, every time, and the answer is stored with the call.
- To fill an order. Your delivery address goes to the business filling your order and to nobody else.
- With the people who run the service for us. They act on our instructions and receive only what they need.
- Where the law requires it. Only to the extent required, and we tell you where we are allowed to.
- If the business changes hands. If Ello is merged or acquired, information moves with it, under this policy until it is replaced.
Who processes data for us
We keep this list short on purpose, and we update it when it changes.
- Supabase. Sign-in and the main database.
- Fly.io. Hosting for our servers.
- Netlify. Hosting for this website.
- LiveKit. Carrying call audio between people.
- OpenAI. The speech model behind the voice assistant. Audio is processed to answer the call and is not used to train its models.
- Composio. Connections to Google Calendar, Google Sheets and Cal.com.
- Paystack. Taking payments and paying businesses out.
- Google and Apple. Delivering push notifications to phones.
Where your information is held
Our providers operate in Nigeria, the European Union and the United States, so your information may be processed outside the country you are in. Where it leaves Nigeria or the European Economic Area we rely on the safeguards those providers offer, including standard contractual clauses.
How we protect it
Calls and web traffic are encrypted in transit. Tokens that admit a person to a call are issued only by our servers and expire within minutes. Secrets, including OAuth tokens for connected accounts, are held on our servers and never reach a browser or a phone. Who may see what is enforced by the database itself and not only by the screens: a delivery address cannot be read by anyone but the ordering customer and the business filling that order. Access by our staff is limited to the people who need it. If a breach puts your rights at risk we will tell you and the relevant regulator without undue delay.
How long we keep it
- Your profile: while your account is open.
- Calls, chats, orders and bookings: up to 24 months after they end, so you can look up what happened.
- Payment and ledger records: 7 years, because tax and accounting law requires it.
- Verification documents: up to 24 months after a business closes its account.
- Diagnostic logs: up to 90 days.
When you delete your account we remove what we no longer need, and keep only what the law obliges us to hold.
Your choices and rights
- Consent. You decide whether a business may be given your phone number, and you can change your mind.
- Access, correction and a copy. You can see and edit your profile in the app, and ask us for a copy of your information.
- Deletion. You can delete your account at ello.africa/delete-account or by emailing us.
- Objection and restriction. You can ask us to stop or limit a particular use of your information.
- Complaint. You can complain to your data protection authority. In Nigeria that is the Nigeria Data Protection Commission.
- Where the law gives you stronger rights, including the Nigeria Data Protection Act 2023, the GDPR and the CCPA, we honour them.
Children
Ello is not for children under 16. If you think a child has given us personal information, write to us and we will delete it.
Changes
We may update this policy as the service changes. If a change matters to you we will update the date above and, where we can, tell you in the app. If we ever change how Ello accesses, uses, stores or shares Google user data, we will tell you here and in the app before the change takes effect, and ask again for your consent where one is needed.
Contact
Questions, requests or complaints? Email [email protected]. We answer within a few business days.