This is an English convenience translation, provided for your information. The legally binding version is the German original; in the event of discrepancies, the German version prevails.
Privacy Policy
Last updated: 24 August 2026
This policy applies jointly to the website coolblack.gmbh and the Coolblack app (Coolblack phone agent for iPhone, iPad and Mac). We explain in plain language what data Coolblack processes — and what we do not do. Coolblack is a hybrid app: much happens directly on your Apple device, some things require our servers in Germany and selected services in the EU. We show every step openly.
1. Who is responsible
Coolblack GmbH
Südfeldwiese 14
32107 Bad Salzuflen
Germany
Managing director: Dirk Nesner
Email: info@coolblack.gmbh
Phone: +49 (0) 5222 917 90 917
If you have questions about data protection, simply write to the same email address. We have not appointed a data protection officer, as there is no legal obligation to do so — enquiries are answered personally by the management.
2. Use of this website (coolblack.gmbh)
The website is deliberately built to be data-minimising:
- No trackers, no analytics, no advertising cookies. We use no Google Analytics, no Facebook pixel and no comparable services. No cookies are set for analytics or advertising purposes.
- Server logs (hosting). When the website is accessed, the web server processes technically necessary access data (including IP address, date/time, page accessed, browser type). This serves the secure operation of the site and the defence against attacks, and the data is deleted after 14 days at the latest. Legal basis: legitimate interest (Art. 6(1)(f) GDPR). Hosted by Hetzner Online GmbH (see section 8.7).
- Contact. The website contains no contact form. If you write to us by email (mailto link), we process your details only to answer your enquiry. Legal basis: legitimate interest or steps prior to entering into a contract (Art. 6(1)(f)/(b) GDPR).
- Value calculator. The calculation runs entirely in your browser; no input is transmitted to us.
3. Using the app: no account, no advertising IDs
Coolblack requires no registration, no password, no email address. The app can be used immediately after download.
So that your credit (see section 7) can be allocated to your device, the app generates a random device ID (UUID) and stores it in your device's keychain. This ID contains no name and no contact details — it identifies the device, not you.
We use no advertising IDs, no analytics SDKs (no Firebase, no Adjust, no Facebook SDK) and no cookies on the app side.
4. What stays local on your device
The following data does not leave your device:
- Your agent configurations (name, greeting, voice, mode)
- Your knowledge base (FAQ, prices, imported website content)
- Call logs (except call documentation that you expressly attach to a support report — see section 6)
- SIP credentials for your telephony provider (in the keychain)
- Local language models and local voices ("Local" tier)
- Access to contacts / calendar / reminders — only if you grant the respective permission, and exclusively to create appointments or contacts for the current caller
Legal basis for local processing: performance of the contract (Art. 6(1)(b) GDPR).
5. Speech recognition (what Apple processes)
Coolblack uses the Apple Speech framework for speech recognition. Apple may transfer audio excerpts to its own servers for recognition — depending on the device model, the operating-system version and the selected language. We at Coolblack do not receive the audio and do not store it. What goes to Apple is governed by Apple's privacy policy (apple.com/legal/privacy). On newer devices (with Apple Intelligence capability), recognition in many cases takes place directly on the device.
6. What is transmitted to our server (app.coolblack.gmbh)
Our server is located in Germany and handles only what cannot be done locally. It is not the agent's brain — prompts, knowledge-base search and tool calls run on your device. The following goes to our server:
- Device ID + device secret for authentication with the server.
- Call usage (minutes consumed and mode "online" / "offline") — for credit billing. No content. Website import and repeated setup are free of charge and generate no usage record.
- App Store purchases (transaction ID, product ID) — so that your credit can be topped up.
- Your device's push token + the caller's phone number for incoming calls — so that the device wakes up and CallKit can display the call (Apple Push Notification service as transport).
- In online mode: conversation texts as requests to our LLM and TTS proxies — these pass them on to Google, and for existing agents with a phased-out premium voice additionally to Cartesia (see section 8). In the premium tier the conversation runs as speech-to-speech directly via Google (section 8.1). We do not store the content on our server — it only passes through.
- During the setup assistant: your company's website URL, optionally supplemented by a Google Maps URL — our server loads these pages and uses Google Vertex AI to create a knowledge-base summary. The URL and the result are not stored persistently in the server logs.
- Optionally in a support report: call documentation — only if you expressly enable the switch "Include latest call documentation" for that report when sending it. No automatic transcript upload takes place (data protection by default, Art. 25 GDPR).
What does not go to the server: audio streams, your local knowledge base, your contacts/appointments, your SIP password (with a direct SIP connection).
Legal basis: performance of the contract (Art. 6(1)(b) GDPR) for server operation and credit; legitimate interest (Art. 6(1)(f) GDPR) for security logs (max. 14 days); consent (Art. 6(1)(a) GDPR) for call documentation optionally attached to a support report.
7. Credit and in-app purchases
Purchases run via Apple StoreKit 2. We receive no payment data (credit card, IBAN, name) — Apple handles payment processing entirely. On our server we store per device: the anonymous device ID, the current credit balance, a usage log (date, minutes, mode — no content) and purchase receipts (transaction ID, product ID).
8. External service providers (processors)
In online mode and during the setup assistant we integrate the following services. A data processing agreement (DPA) pursuant to Art. 28 GDPR is in place with all of them. Which service providers are used is determined by you through the voice tier you select per agent:
- Premium tier (Live voices): a true speech-to-speech conversation entirely by Google Cloud in the EU (section 8.1) — the AI listens and answers directly, without separate speech synthesis.
- Former premium voices (Cartesia, existing agents only): speech synthesis by Cartesia (section 8.2), AI responses by Google Cloud (section 8.1). These voices are being phased out in favour of the new Live voices.
- Standard tier (Google voices, Chirp 3 HD): speech synthesis and AI responses entirely by Google Cloud in the EU (section 8.1).
- Local tier: the language model and speech synthesis run entirely on your device — conversation content is not transmitted to any of the AI service providers named in sections 8.1 and 8.2. The technical infrastructure in sections 8.3–8.7 (push, telephony, hosting) remains unaffected.
8.1 Google Cloud (Vertex AI & Text-to-Speech)
- Recipient: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
- Purpose: AI responses (LLM), website summaries, speech synthesis of the response (standard voices, Chirp 3 HD) and — in the premium tier only — the speech-to-speech conversation (Gemini Live: the AI hears the caller and answers directly with its voice)
- Task agent: if you give your agent a task ("call there and make a reservation"), we additionally process your spoken task description and — if you do not provide the phone number yourself — an internet search for the target (Google Search via Vertex AI, EU). During the resulting call, your agent identifies itself as an AI acting on your behalf within the first second; the call is not recorded as audio, only a text log is created for you.
- Data: in the standard and local tiers call content (text), response text for speech output and website content from setup — no caller audio. In the premium tier the conversation audio is additionally processed in real time (required for the speech-to-speech conversation); it is not stored and not used for training
- Place of processing: exclusively in the EU (LLM in europe-west1, Belgium; speech-to-speech in europe-west4, Netherlands; speech synthesis via the EU endpoint)
- Retention: at most 30 days per Google's standard; no training of AI models with your data
- DPA: Cloud Data Processing Addendum — cloud.google.com/terms/data-processing-addendum
8.2 Cartesia (former premium voices — existing agents only)
- Recipient: Cartesia AI Inc., 548 Market St, San Francisco, CA 94104, USA
- Purpose: real-time speech synthesis of the response — only active for existing agents that chose a Cartesia voice before the switch to the Live voices
- Data: exclusively the response text generated by the agent (no caller audio)
- Place of processing: EU cluster (Frankfurt region). Cartesia contractually guarantees that API calls are not processed outside the EU — including failover scenarios
- Third-country safeguards: EU standard contractual clauses (Module 2, Implementing Decision (EU) 2021/914), certification under the EU-US Data Privacy Framework and a data processing agreement between Coolblack GmbH and Cartesia AI, Inc.
- Retention: zero data retention (ZDR) enabled on our account — transmitted texts and generated audio are not stored; no training, no logging
- Privacy policy: cartesia.ai/privacy
8.3 Apple Push Notification service
- Recipient: Apple Inc., Cupertino, USA
- Purpose: waking the device for incoming calls (CallKit)
- Data: anonymous push token, caller's phone number
- Third-country transfer: USA, safeguarded by EU standard contractual clauses (Art. 46 GDPR) and Apple's certification under the EU-US Data Privacy Framework
8.4 Apple Speech framework
- Recipient: Apple Inc., Cupertino, USA — purpose: speech recognition (see section 5)
- Data: short audio excerpts for transcription
- Third-country transfer: USA, safeguarded by EU standard contractual clauses and Apple's certification under the EU-US Data Privacy Framework. On newer devices, processing in many cases takes place directly on the device — in that case no transfer occurs
8.5 Your own API keys (BYOK, optional — disabled by default)
This feature remains inactive unless you activate it yourself. Only if you deliberately store your own API key for OpenAI, Anthropic or Cartesia in the settings do requests go directly to that provider. Your key is stored exclusively in your device's keychain and is never transmitted to our server. The privacy policy of the respective provider then applies in addition; without a stored key, no such transfer takes place.
8.6 Your SIP provider
The actual telephony connection (audio stream) runs directly between your device and the SIP provider you have chosen (e.g. easybell, sipgate, Telekom). We do not see the audio stream. Your SIP provider's privacy terms apply in addition.
Coolblack phone number (optional): If you book a Coolblack phone number through the app, it is provided via our telephony carrier easybell GmbH (Brückenstraße 5a, 10179 Berlin, Germany). Incoming calls to this number technically pass through easybell and are put through to your device via our server in Germany. Connection data arises in the process (the caller's number, time, duration); place of processing exclusively Germany. A data processing agreement is in place with easybell; their privacy policy applies in addition.
8.7 Hetzner Online GmbH (server hosting)
- Recipient: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany
- Purpose: hosting of our servers and of this website (coolblack.gmbh, app.coolblack.gmbh, push.coolblack.gmbh)
- Data: the data processed server-side pursuant to sections 2 and 6
- Place of processing: Germany — contract: DPA pursuant to Art. 28 GDPR
9. Retention periods
- Locally on your device: until you delete the app or remove data manually
- Server logs (security, website and app): at most 14 days
- Processing at Google Vertex AI: at most 30 days per Google's standard
- Processing at Cartesia: no storage (zero retention)
- Credit and purchase data: for statutory retention obligations (German Commercial Code / Fiscal Code) up to 10 years, then deletion
- Support reports and optionally attached call documentation: until you withdraw consent, at most 90 days
- SIP passwords in the push gateway: only in memory during registration; no storage on disk
10. Your rights
Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), objection (Art. 21) and withdrawal of consent you have given (Art. 7(3)) — e.g. for call documentation attached to a support report — at any time by email to info@coolblack.gmbh.
You can also lodge a complaint with a data protection supervisory authority at any time — the authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (ldi.nrw.de).
11. Data security
- TLS encryption for all server connections (Let's Encrypt certificates)
- Authentication via per-device secrets (in the keychain)
- Third-party API keys are kept only on our server, never in the app
- Hardened servers (firewall, automatic security updates, fail2ban)
- Daily backups, restrictive file permissions
12. Changes to this policy
We update this policy when the app, the website or our service providers change. The current version is always available at coolblack.gmbh/en/datenschutz. We communicate material changes via an in-app notice.