Privacy Policy
Last updated: September 17, 2026
This Privacy Policy describes how Infinium Cloud ("PrankPortal," "we," "us," or "our") collects, uses, stores, and shares information when you use the PrankPortal service at prankportal.com (the "Service").
By using the Service, you agree to the collection and use of information as described in this Privacy Policy. This policy is incorporated into and subject to our Terms and Conditions.
1. Information We Collect
1.1 Account Information (via Google Sign-In)
When you sign in using Google OAuth, we receive and store:
- Name — your Google account display name
- Email address — your Google account email
- Profile photo URL — your Google avatar
- Google account ID — a unique identifier for your Google account
We do not receive or store your Google password. Authentication is handled entirely by Google's OAuth 2.0 flow.
1.2 Phone Number (Your Own)
After signing in, we ask you to provide your own phone number. This is stored in our database in E.164 format and is used to identify you as the call initiator. We do not verify this number via OTP in the current version of the Service.
1.3 Recipient Phone Numbers
When you initiate a prank call, you provide the recipient's phone number. We store this number in our database for:
- Abuse detection and prevention (e.g., identifying repeated calls to the same number)
- Rate limiting
- Legal compliance
- Service operations and support
The phone number is also transmitted to our telephony provider to place the call.
1.4 Prank Call Data
For each call you initiate, we collect and store:
- Scenario selection — which template you chose, or your custom scenario text
- Recipient name — the name you entered for the recipient (optional)
- Context — any additional context you provided to personalize the prank
- Call audio recording — audio of calls may be recorded and stored by our telephony provider for transcript generation, quality assurance, and safety monitoring
- Call transcript — a text-based transcript generated from speech-to-text processing of the call audio
- Call metadata — status, duration, timestamp, ended reason, and cost
1.5 Automatically Collected Data
When you use the Service, we automatically collect:
- IP address — for rate limiting, abuse prevention, and security
- Usage timestamps — when you access the Service and initiate calls
- Browser and device information — via standard HTTP headers (user agent, language preference)
We log application events (including errors and security events) to a database table for operational monitoring. These logs may include your user ID and IP address.
2. How We Use Your Information
We use the information we collect to:
- Provide the Service — authenticate you, place AI prank calls, generate and display transcripts, and manage your call history
- Enforce usage limits — track daily call counts per user and per IP address
- Prevent abuse — detect harassment, repeated unwanted calls, and other violations of our Terms and Conditions
- Ensure security — protect against unauthorized access, fraud, and technical attacks
- Improve the Service — analyze usage patterns and errors to fix bugs and enhance features
- Comply with legal obligations — respond to lawful requests from law enforcement or regulatory authorities
We do not use your data for advertising, sell it to third parties, or use it for purposes unrelated to providing and improving the Service.
3. How We Share Your Information
We share your information only with the third-party service providers necessary to operate the Service:
| Category | Data Shared | Purpose |
|---|---|---|
| Authentication provider | OAuth tokens | User sign-in and identity verification |
| Telephony provider | Recipient phone number, scenario instructions, voice selection | Placing and managing AI voice calls |
| AI language model provider | Scenario prompts and conversation context | Powering the AI agent's conversational logic |
| Voice synthesis provider | Text to be spoken during calls | AI voice generation |
Each provider operates under its own privacy policy and terms. We encourage you to review the privacy policies of these providers, which are available on their respective websites.
We may also share information:
- To comply with law — in response to valid legal process (subpoenas, court orders, or government requests)
- To protect rights and safety — when we believe disclosure is necessary to protect our rights, your safety, or the safety of others
- In a business transfer — if PrankPortal is acquired, merged, or transfers assets, your data may be transferred to the successor entity
4. Data Retention
- Account data (name, email, avatar, phone number) — retained for the lifetime of your account. When you request account deletion, all personal identifiers are permanently removed from your profile (anonymized). Your account cannot be recovered after this process.
- Call recordings, transcripts, and metadata — retained for up to 90 days after the call, after which they may be automatically deleted. We may retain de-identified call metadata and transcripts longer if required for abuse prevention, legal compliance, or an ongoing investigation. These records are not linked to any personal identity after account deletion.
- Recipient phone numbers — retained for abuse prevention, legal compliance, and service operations. Stored in hashed form where applicable.
- Application logs (IP addresses, event logs) — retained for up to 30 days for operational purposes, unless a longer retention is required for security investigation.
- Financial records — payment and transaction records may be retained as required by applicable tax and financial regulations.
5. Data Security
We implement reasonable technical and organizational measures to protect your information, including:
- Recipient phone numbers hidden from all user-facing interfaces and API responses
- Encrypted connections (HTTPS/TLS) for all data in transit
- CSRF token protection on all authenticated requests
- Rate limiting to prevent automated abuse
- Webhook signature verification for incoming data from third-party services
No method of electronic storage or transmission is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
6. Cookies and Local Storage
We use:
- Session cookies — essential cookies to maintain your authenticated session. These are strictly necessary for the Service to function and cannot be disabled.
- CSRF tokens — security cookies to prevent cross-site request forgery.
- Local storage — we temporarily store prank setup data (scenario selection, recipient details) in your browser's local storage to preserve your progress during the sign-in flow. This data is cleared after use or after 30 minutes.
We do not use analytics cookies, advertising cookies, or tracking pixels.
7. Children's Privacy
PrankPortal is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected information from a person under 18, we will take steps to delete that information promptly. If you believe a child has provided us with personal data, please contact us at [email protected].
8. Your Rights
Depending on your location, you may have certain rights regarding your personal data:
8.1 All Users
- Access — request a copy of the personal data we hold about you
- Correction — request that we correct inaccurate data
- Deletion — request that we delete your account and associated personal data. Upon approval, all personal identifiers are permanently removed. We may retain de-identified records as permitted by law for abuse prevention and legal compliance.
- Data portability — request your data in a machine-readable format
- Do Not Call opt-out — if you have received a prank call and do not wish to receive any further calls through PrankPortal, you may add your phone number to our Do Not Call list. Phone numbers on this list are stored as irreversible hashes and cannot be used to identify you.
8.2 California Residents (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act and the California Privacy Rights Act, including:
- The right to know what personal information we collect, use, and disclose
- The right to request deletion of your personal information
- The right to opt out of the "sale" or "sharing" of personal information — we do not sell or share your personal information as defined by CCPA/CPRA
- The right to non-discrimination for exercising your rights
8.3 European Economic Area (EEA) Residents
If you are in the EEA, you may have rights under the General Data Protection Regulation (GDPR), including:
- Right of access, rectification, erasure, and restriction of processing
- Right to data portability
- Right to object to processing
- Right to withdraw consent at any time
- Right to lodge a complaint with your local data protection authority
Our legal basis for processing your data is: (a) performance of a contract (providing the Service), (b) legitimate interest (security, abuse prevention), and (c) your consent (where applicable).
8.4 Canadian Residents (PIPEDA)
If you are a Canadian resident, you have rights under the Personal Information Protection and Electronic Documents Act, including the right to access, correct, and withdraw consent for the collection and use of your personal information.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days (or the period required by applicable law).
9. International Data Transfers
Your data may be processed and stored in the United States and other countries where our service providers operate. By using the Service, you consent to the transfer of your information to countries that may have different data protection laws than your country of residence.
10. Do Not Track Signals
Our Service does not track users across third-party websites and therefore does not respond to Do Not Track (DNT) signals. We do not use third-party analytics or advertising trackers.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page. We encourage you to review this page periodically. Your continued use of the Service after changes become effective constitutes your acceptance of the updated policy.
12. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at:
Infinium Cloud
Email: [email protected]