Weyvox documentation
Weyvox is a communication app for iPhone and Android built around an AI voice agent for sole traders and small business. The iPhone app arrives on the App Store on 1 September 2026; the Android app is in development, with release planned for 1 October 2026. Where this document names platform frameworks, it describes the iOS implementation. It combines an agent that answers your line and makes calls for you, writes your invoices and keeps your clients and orders, with real phone numbers, free messaging and HD calls between users. The same agent serves the user's private errands, so one app covers both without mixing them. It is written for businesses where the owner is also the person who answers the phone — removals and transport, restaurants and small shops, hair salons and barbers, sole traders and one-person practices, vet and dental practices, garages, renovation crews, plumbers and electricians, nail and beauty studios, cleaning firms. It is deliberately not built for call centres or support teams: there is no shared team inbox, no seats and no call queue — one account is one business line. This document is the definitive reference: what the product does, and how it works — which parts are built on Apple's system frameworks and which parts are Weyvox's own engineering. For a screen-by-screen map of the app — every page, every setting and what it controls — see the Weyvox app map.
Product overview
Weyvox has four tabs: Contacts (people you can message and call), Messages (chats and call history), Weyvox (the AI agent and its tools), and Settings (profile, phone numbers, balance, tariffs, data, agent configuration).
- Free: all messaging (text, photos, video, files, voice, location) and HD audio calls between Weyvox users, plus the first 5 GB of media storage.
- Paid, from a prepaid in-app balance: calls to regular phone numbers, the AI agent, AI call notes, storage above 5 GB, and real phone numbers. Full prices: weyvox.com/pricing.
Calls & telephony
Weyvox-to-Weyvox calls (free)
Calls between users are high-definition audio calls, transmitted in real time over the internet — no carrier minutes, no roaming. Signaling runs over authenticated WebSocket channels coordinated by a per-call session object; audio flows peer-connected with modern codecs. The incoming-call experience is hybrid: locked phone → the native iPhone call screen; unlocked → the Weyvox call screen.
Calls to regular phone numbers (PSTN)
With a real phone number, users call any phone worldwide. Outbound and inbound legs run through a carrier-grade telephony backbone; Weyvox's own orchestration layer controls each call (dial, answer, bridging, hangup) through the carrier’s verified call-control interface. Costs are computed from the carrier's own post-call cost events — the exact cost of each call, not an estimate (see Billing).
Real phone numbers
- One operator number per account. Numbers are provisioned per country in E.164 format; where regulators require identity verification (KYC), the app collects exactly the documents the carrier lists, submits them, and auto-deletes them within 24 hours of activation (see Privacy Policy).
- Immediate temporary number. When the chosen number needs documents, carrier activation is not instant, so paying provisions a working temporary operator number the same moment — the user can call and receive calls while the main number is under review. That stand-in is usually a number in a different country from the one ordered; it exists to keep the line working, not to preview the future number. Numbers that need no documents are activated directly, with no temporary one.
- Tracked activation with resubmission. The order is reviewed by the carrier; its status streams to an order-tracking page in the app. The carrier never rejects a purchase permanently — it can only ask for corrections, flagging the specific document while the accepted parts stay locked. The user re-uploads only the flagged documents and resubmits under the same order; each resubmission is recorded.
- Automatic switch-over on approval. When the main number is approved it activates automatically and the temporary number is disconnected and removed in the same operation — the account is never left without a number and never billed for two at once. A confirmation (number, activation time, subscription details) is posted to the system chat. Numbers you no longer hold are released with the carrier automatically, so a stalled provisioning cannot leak a paid number.
- 25-day temporary lifetime. If the main number is not approved within 25 days, the temporary number is deactivated and the user is notified; the order stays open and the main number still activates automatically once approved.
- Subscription & cancellation. A monthly subscription engine charges the number's service fee from the balance (the first month is included in the purchase), if the balance is short the number keeps working for 30 days while the charge is retried daily, then outgoing calls from it are blocked for another 30 days, and on day 60 the number is released. Only the user can cancel a purchase; a cancellation releases the numbers and stops the subscription, and the fee already paid is not refunded (balance top-ups follow App Store rules).
Your own business number
A business that already has a number — on its cards, its storefront, its Google listing — does not have to replace it. Weyvox connects that number instead of issuing one: nothing is bought and nothing is ported.
- Incoming = forwarding. The user switches call forwarding on with their own carrier, from the business number to their active Weyvox operator number (main or temporary). Forwarded calls arrive with the original caller's number, and Weyvox can tell they came in on the business line — so the agent answers knowing which line it is on and greets the caller with the business name. Forwarding lives in the user's carrier network: Weyvox can neither switch it on nor read its state, so the app presents it as a method with setup instructions, never as a status it verifies.
- Outgoing = verified caller ID. Ownership is proven with a one-time code (SMS to a mobile line, a voice call to a fixed one), after which outgoing calls can present the business number instead of the Weyvox number. This is a per-account toggle and it applies only to a verified number; if the recipient's network withholds a substituted caller ID, the app warns and the call can fall back to the Weyvox number.
- One-time €5 connection fee. Charged from the balance at the moment the confirmation code is requested — before any code is ordered, so verification can never be triggered for free. Resending the code to the same number is free, and a failed connection is refunded automatically. There is no monthly fee for the connection itself; forwarded minutes are billed by the user's own carrier at the user's own rates. Disconnecting and reconnecting later is charged again.
- Tied to an active Weyvox number. A business number can only be connected while an operator number (main or temporary) is active, and the connection is removed automatically in every path where that receiving number disappears — swap, expiry, cancellation, replacement, deletion for non-payment — with a system-chat notice, because forwarding would otherwise point at a line that no longer exists.
The AI agent
The agent is Weyvox's core: a personal AI that actually works the phone for its user. One agent, one user — it shares a single brain, memory and toolset across every surface it appears on (voice calls, the agent chat, in-chat assists, background tasks).
What the agent can do
- Call real numbers on the user's behalf — book a table, ask a business a question, negotiate a price, chase a delivery. Before dialing it shows a confirmation card (users can switch to instant calling); after the call it returns the outcome and a short note into the chat.
- Answer incoming calls — it can pick up for the user, including auto-answering every incoming call after a chosen delay, on both telephonies.
- Take over a live call — during any call, on either telephony, the user hands the agent the "seat": it speaks to the other party in their place while they listen, and can be given silent instructions mid-sentence. See the seat model.
- Navigate phone menus — it recognises IVR menus and presses the right keys (DTMF) to reach a human or the right department; it detects voicemail and dead-ends and finishes gracefully.
- Research on the internet — web search plus full-page reading, so it answers from live sources, not memory alone.
- Find places — "a pharmacy near me", powered by Apple's mapping services and the user's (optional) location.
- Run Business management — the owner's business profile, price list, customers, orders and documents: it reads all of it, quotes prices only from the list, logs developments into existing orders, and records agreed dates with reminders, so "book it and write it down" is one instruction. See Business management.
- Use the address book — "call mum" resolves through the user's own contact names.
- Read the user's chats — a strictly opt-in capability: when enabled, the agent can be opened inside a conversation and look up what was agreed there ("what address did Anna send me?"), including voice messages, photos, files and the full server-side history. See Weyvox inside a personal chat.
- Track phone-number orders — it can report the live status of a number purchase, including which document needs fixing.
- Understand media — photos and files sent in chat are analysed once (text, numbers, links extracted) and their content stays available for the rest of the conversation.
- Run multi-step background tasks — see below.
Every capability is governed by a per-user switch (telephony, business management, contacts, chats, location) — sensitive ones like chat access are off until explicitly enabled, and each switch takes effect immediately across all surfaces.
The agent inside a live call — the seat model
This is the part of Weyvox with no obvious equivalent elsewhere, and it works identically on both telephonies: a free Weyvox-to-Weyvox internet call and a paid call over a real phone number. The user does not learn two behaviours.
The rule is simple: each side of a call has exactly one voice. On the user's side that voice is either the user or their agent — never both. Two people plus two agents all talking into one line is chaos, so Weyvox does not do it. Handing the agent the "seat" is a single button on the call screen.
Handing over, and taking it back
- Bringing the agent in — one tap during any live call. The agent takes the seat by default: it starts speaking to the other party as the user, not as a third participant that joined. The other party hears only the agent.
- The user stays on the line — they hear everything, in real time, for the whole call. They are simply not the voice at that moment.
- "Take the conversation back" — the same button, reversed. The user's microphone returns to the line and the agent goes silent instantly. It keeps listening and keeps taking notes; it just stops speaking.
- Handing it back — the agent resumes mid-conversation, already knowing everything that was said while it was silent. It does not re-introduce itself and does not start over.
- The agent never hangs up. The call belongs to the user; only the user ends it. When the agent has achieved what the call was for, it states the outcome out loud and stops talking.
Whispering to the agent while it is speaking
The user can talk to their own agent, during the call, while the agent is mid-sentence — and the other party hears none of it. This is the capability people ask about most, so it is worth being precise about what it does:
- It does not interrupt. The agent finishes its current sentence rather than cutting itself off. The instruction is folded into what it says next — which is what makes it usable in a real conversation instead of a source of stutter.
- It is an instruction, not a dialogue. "Ask about the price", "agree to Tuesday", "switch to English" — the agent carries it out in what it says to the other party. It never answers the user out loud, because every word it speaks is heard by the other side.
- Silence is a valid response. If a whisper needs nothing new said right now, the agent says nothing at all and simply acts on it. It does not narrate that it heard you.
- How it is possible. The device captures the microphone twice: once for the call itself (muted toward the other party while the agent holds the seat) and once on a separate private path to the agent. On the operator side this second path is what makes whispering work at all — a phone network alone cannot separate "silent to the caller" from "audible to my assistant".
What the mute button means here
Because the seat already keeps the user silent toward the other party, the mute button means something more specific during an agent call: "my agent should not hear me either". Turning it on closes the private channel; the agent is told, and carries on with the conversation alone. It is off by default, so the user can steer from the first second.
The agent knows which way the call went
Inbound and outbound calls are opened in opposite ways, and the agent is told which one it is. On a call the user placed, the business is theirs to raise and the agent states it immediately. On a call someone made to the user, the business belongs to the caller — the agent invites them to say why they are calling instead of announcing an agenda of its own.
What the agent does mid-call, without being asked
- Checks the owner's orders and working hours before agreeing to anything, quotes prices only from the price list, and records the appointment on the matching order once a time is settled — setting the order's dates (with a reminder when wanted) and logging what was agreed — so "book it" is finished, not promised. It may only touch the order this call is about; the owner's other orders are never changed, and it never marks anything paid.
- Looks things up on the web silently when the answer decides what to say next — an address, opening hours, a price — and answers from what it found.
- Keeps the user's memory current as durable facts come up, so the next call already knows them.
It does none of this out loud: no "let me check the schedule", just the outcome — "Tuesday at 18:00 is free, booking it now".
After the call
- An attributed transcript. Weyvox records who said what and when — the user, the other party, and the agent are separate speakers, because each reaches the system on its own stream rather than being guessed apart afterwards. Whispers are marked as a distinct kind of line: they were instructions to the agent, not things the other party heard, and a summary that confused the two would record agreements that never happened.
- A note, written to the user's own instructions. The note follows the same configured style and language as every other Weyvox call note, and lands on the call in the chat with that person.
- Commitments reported separately. If something was actually agreed — a meeting, a call-back, a deadline, an amount — it is posted as its own message — for business calls in the Business management chat, for personal calls in the Weyvox system chat — because after hanging up nobody goes looking inside a note to find out what they now owe. Only firm agreements are reported; if the call was just a conversation, nothing is posted.
- Turning the agent off mid-call erases everything it collected — the transcript is discarded, no note is written, and nothing further is recorded. The same rule as switching off an ordinary call note.
Both people can have an agent
Two Weyvox users can each hand their own agent the seat, and the two agents will hold the conversation with each other while both people listen — either of them can take their side back at any moment. The one-voice-per-side rule is what keeps this coherent rather than a four-way overlap.
The agent always identifies itself as an AI assistant acting for its user at the start of a call — in Weyvox this is a product rule, not a setting, and it matches disclosure requirements for AI voice systems in the jurisdictions Weyvox serves.
Answering incoming calls — auto-answer
The agent can pick up the user's incoming calls automatically, on both telephonies. It is switched on from the agent's settings, where the user also chooses how long the phone rings before the agent steps in — 10, 20, 30 or 40 seconds (30 by default). While it is on, it applies to every incoming call.
- The user always gets first refusal. The phone rings normally for the chosen delay. If the user answers, it is their call as usual — the agent never pre-empts them. Only if the delay elapses unanswered does the agent take the call.
- Dismissing the ring hands it over at once. Declining the incoming call is read as "you take it": the agent answers immediately instead of waiting out the rest of the timer.
- Answered on the server, not on the phone. The agent picks up from Weyvox's backend, so it works even when the user's phone is locked, asleep, out of battery or offline — which is the whole point of having it. For an operator number the routing is arranged in the network only while auto-answer is on; switching it off restores the plain inbound path unchanged.
- It behaves like the agent on any call. It introduces itself as the user's AI assistant, finds out who is calling and why, helps or takes a message, and can act mid-call (check the owner's orders, agree to a time and record it on the order). It is told this is an inbound call and opens accordingly — inviting the caller to say why they are calling rather than raising an agenda of its own.
- The full seat model applies. When the user opens the app, an auto-answered call is a live mini-card: they can listen in, whisper to the agent, or take the conversation over — exactly as on any other call.
- Afterwards the caller gets a note in their chat and any firm commitment is posted — to the Business management chat for business calls, to the system chat for personal ones — the same as a call the agent placed. If the agent never picks up, it is recorded as an ordinary missed call.
When the balance runs out
The agent is a paid feature, so it stands down while the balance is negative (in debt) — but it never leaves a call in a broken state. The behaviour is deliberate and identical on both telephonies:
- Auto-answer stands aside. The agent does not answer. The incoming call rings as a completely ordinary call — the user can still pick it up by hand — and, unanswered, ends as an ordinary missed call. It does not flash on and off or reject the caller.
- A message explains why. At the moment the agent would have answered, Weyvox posts a message in the system chat: the agent could not answer an incoming call because the balance is negative — top up to restore it. It is sent once per call, never once per ring.
- Declining ends the call. If the user dismisses the incoming call while in debt, it simply ends — cleanly, on both the caller's and the user's side — because the agent cannot step in for them.
- Joining a live call is refused visibly. Trying to hand the agent the seat during a call while in debt shows a top-up prompt on the call screen; the agent does not join and the human call carries on unaffected.
- Recovery is automatic. The instant the balance is back to zero or above, everything works again — there is nothing to re-enable.
Realtime voice pipeline & latency
- A streaming pipeline — speech recognition → reasoning model → speech synthesis — runs on every live call, with tuned voice-activity detection and natural interruption handling: when the other person starts speaking, the agent stops and listens.
- Turn-taking latency. The gap between the other party finishing a sentence and the agent beginning to speak is typically a few hundred milliseconds up to about 1.5 seconds. It is dominated by the model's thinking time — which is why calls are pinned to the fastest model rather than left to choice; the network and how much the agent has to say move it as well.
- The brain on calls is fixed: Claude Haiku 4.5. Telephony always runs on it, and there is no setting to change that — on a live call the pause before the agent speaks is felt more sharply than depth of thought, so the lowest-latency model wins. Model choice lives in the agent chat instead, where Claude Fable 5, Claude Opus 5, Claude Sonnet 5 and Claude Haiku 4.5 are all available per thread; a more capable brain answers better and costs more per use.
- Voice — ready-made or your own. Choose the voice the agent speaks with: ready-made male and female voices (each with an audio preview in the chosen language), or clone your own voice — record a short sample and the agent speaks in a voice modelled on yours. A cloned voice is yours alone, used only for your agent, and can be deleted at any time in settings. Even when the agent uses your cloned voice, it still discloses that it is an AI at the start of every call (see AI transparency), so the other party is never misled about speaking to a machine.
- First words at pickup. The opening line is prepared while the phone is still ringing, so the conversation starts naturally the instant the call connects. On an auto-answered operator call the caller hears the agent within roughly 2–3 seconds of the ring ending (carrier routing plus warming the pipeline); on a call the agent places, its first words land about as fast.
- The agent always introduces itself as an AI assistant acting for its user, and speaks the language of the call — 32 languages are supported, chosen per user and separate from the app's interface language.
Memory — how the agent remembers
The agent's memory is a layered, per-user system rather than a single transcript:
- Long-term memory — durable facts the agent saves as it works ("prefers morning appointments", "building door code", "dentist's name"), organised by category. On every turn, the agent retrieves the memories relevant to the current request and injects them into its reasoning — so it uses what matters now instead of re-reading everything it ever learned.
- Live identity profile — the user's name, age, gender and phone numbers are read fresh from the account on every session, never copied into memory; the agent always addresses and represents the user correctly, and profile changes apply instantly.
- Working context — within a conversation the agent keeps the full thread; long histories are automatically compressed into dense notes that preserve every fact, decision and number, so continuity survives without unbounded cost.
- Task journals — each background task keeps its own journal of findings and decisions (compacted as it grows); when a task finishes, the agent extracts anything durably useful into long-term memory.
- Call follow-up context — after the agent phones somewhere for the user, the call transcript stays available to the chat for 24 hours ("what exactly did they say about Thursday?"), then deletes itself.
- User control — the memory page in the app lists what the agent knows; individual entries can be managed and everything can be wiped with one action. Deleting the account deletes the memory.
Chat agent
In the Weyvox tab the agent works over text with its full tool loop. Replies stream token-by-token with a smoothing renderer; a Stop button keeps the partial answer as the reply; threads are titled automatically; a delegated task appears as a card in the chat with live status. Each one-to-one conversation can also summon a scoped in-chat assistant that sees only that conversation — see Weyvox inside a personal chat.
Weyvox inside a personal chat
Every one-to-one conversation can summon its own scoped assistant: a ✦ button in the chat header opens a mini-chat over the conversation, where the user asks Weyvox about that conversation — "summarise what we agreed", "what address did she send?", "when did he promise to call back?". It is available only while the chat access switch is on, and it keeps the agent's full abilities (calls, tasks, business management, memory) for anything the user explicitly asks.
What the in-chat assistant sees — exactly what the device decrypted for it. The conversation is end-to-end encrypted, so the servers cannot read it; the app itself hands the assistant a recent window of that one conversation, each kind of content in its own way:
- Text messages and shared locations — directly, as a transcript of the recent conversation, decrypted on the phone.
- Calls — with their duration and the user's own AI call note inlined. The other person's private notes are never visible.
- Voice messages — transcribed on demand: when the user's question concerns what was said in a voice note, the device decrypts it and it is transcribed so the assistant answers from the words.
- Photos and files — referenced by number in the transcript; their content (verbatim text on a photo, the text of a PDF) is decrypted by the device and attached only when the user explicitly asks about it. Reviewing or summarising history never silently opens attachments — that keeps answers fast and avoids burning tokens on media nobody asked about.
Read once, remembered on the device. The first read of a voice message, photo or file costs a transcription or vision pass; the result is kept with the conversation on the phone, so every later question about the same attachment is answered from it at no extra cost.
Scope and privacy. The assistant is structurally scoped to the one conversation it was opened in — it receives only what that conversation's screen decrypted and sent, and there is no server-side route from one conversation's assistant to another conversation's data (the servers hold only ciphertext). What it learns from the conversation is used for the answer only — it does not copy the other person's messages into the agent's long-term memory unless the user explicitly asks it to remember something.
Billing. In-chat assistant turns are metered like any agent chat turn (tokens, plus transcription seconds when a voice message is read) and appear on the Balance & usage page as their own line — "Weyvox in a personal chat" — separate from the main agent chat.
Agent tasks (autonomous background work)
Multi-step assignments run in a dedicated task runner: the agent plans, executes tool steps, keeps a compacted work journal, verifies its own steps against the goal, asks the user when a real decision is needed (and waits), survives process restarts by re-seeding from its journal and billing state, streams live progress to the app, and can be stopped at any moment — anything already done is kept and summarised. Each task is billed as a single growing entry.
Documents the agent writes (PDF)
Asked in the chat for an invoice, a statement of completed work, a certificate, a formal letter or a written report, the agent produces a real PDF. It appears in the conversation as a file card; tapping it opens the document, and from there the user forwards, prints or saves it to Files. Beyond the five ready-made kinds it composes any other document on request — a contract, an offer, a receipt, a packing list — right in the chat. Asked for several at once, it returns several files. To change something the user does not edit the file — they say what to change in the chat and the agent rebuilds it.
- Built on the phone, stored nowhere. The agent returns the document's content and the app lays it out. No server generates it, nothing is uploaded, nothing occupies storage — and it works offline. Creating documents costs nothing beyond the agent turn that composed them.
- It never invents the user's real-world data. Company name, address, tax number, bank details, amounts, dates, the recipient — anything it was not told and cannot read from the conversation it asks for first. A plausible but invented invoice is worse than no invoice, because the user may send it to a client.
- Each type is laid out as that type. An invoice carries VAT numbers, bank details and a payment deadline; a statement of work has two signature columns, because both sides sign it; a certificate drops the banking block entirely and can be issued "to whom it may concern" with no recipient at all; a letter has no heading at all — city, date, address block and a subject line, the way a business letter is actually written.
PDF templates. Settings > PDF templates holds one template per document type — invoice, act, certificate, report, letter. A template carries only what is stable and the user's own: who issues it (name, tax number, address, email, phone), the banking block where the type needs one, the numbering series, a note printed on every document of that kind, who signs it, plus a logo, a signature drawn with a finger and a stamp. Everything that changes from document to document — the client, the items, the amounts, the dates, the wording — the agent fills in from the request, which is the whole point of having an agent.
- The fields differ by type, on purpose. An invoice has a VAT number and payment terms; a certificate has neither bank details nor terms but has a place of issue; a report is the shortest of all.
- The signature is drawn, not uploaded. The user signs with a finger on a white sheet in the app; the stroke is kept as a vector, so it prints smoothly at any size, and it lands on every document of that type by itself. A stamp is uploaded separately and must be a PNG or SVG — it sits over the signature, so it needs a transparent background.
- Numbers are counted by the app. The template keeps the series and the last number issued; the next one is assigned when the document is printed, and the agent is not allowed to invent it. An unbroken sequence is a legal requirement in France and Ukraine.
- Anything can be printed as a blank. The PDF button on a template prints an empty specimen of that document, so the user sees which fields exist and where they land before the first real one is made.
- Own templates. The + in the header creates a template of the user's own — they name it, describe when it applies, and add whatever fields they need in any section. Asking the agent for that document by name builds it from that template. Own templates keep the language they were written in, and the agent can fill and extend them on request — but only the user creates them, so a typo can never spawn a duplicate.
- The templates are independent of each other. Fields sharing a name are not linked, and nothing is copied between them: a person may bill from a sole proprietorship and issue certificates from a company. Filling one leaves the rest exactly as they were, and an empty field stays visibly empty rather than being quietly filled from elsewhere.
- A template holds the user's own data, never a counterparty's. When a document is made for someone else, that party goes into the document's recipient block and the templates are untouched — so a client's name can never end up heading the next invoice.
- The agent maintains them. It reads the templates on every turn and can fill or correct them itself: told something that belongs in a template ("my IBAN is…", "sign my acts as Director"), it saves it into that type's template right away and says so, instead of sending the user to a settings page to retype what they just said. It never writes a value it was not given, and it edits one template per instruction.
Task reports as PDF. The same engine exports any agent task: the task's ••• menu offers Create PDF, either with every work stage — each stage's status, summary and work journal, including what the agent achieved on calls — or with the final report only. A task still running exports whatever is already done, without asking. The document opens in the app rather than jumping straight to a share sheet.
Offline. Templates, tasks and their journals are mirrored on the device, and the PDF is drawn on the phone — so a document can be produced with no connection at all. Edits made offline are queued and reach the server by themselves once there is a network.
Business management — the whole business from the phone
Business management (Settings > Tools > Business management, currently Beta) is where a small-business owner keeps everything the agent needs in order to speak for them. It replaced the older Personal matters CRM in August 2026, when Weyvox was repositioned for business. Five sections.
- Business profile — the agent's system prompt in the shape of a form. Business name and legal name, what you do, who your customers are, contacts, working hours with holiday exceptions, currency and payment methods, prepayment and cancellation terms, delivery, your own FAQ answers word for word, and the persona and limits the agent must respect. Each block says what the agent does with it, because these are not fields for their own sake: the agent speaks from them on every call. A completeness indicator makes the state visible — an empty profile means the agent cannot represent the business at all — and a "Fill in from a conversation" button hands the job to the agent, which asks one question at a time in chat.
- Price list — the only source of prices. Products and services, each with a price or a from–to range, a price note ("per hour", "from"), currency, unit, duration and an active switch. The agent quotes prices only from here: no matching item means "I'll check and call you back", never an improvised number.
- Customers. A searchable base sorted by the latest order; each card carries contacts, tags, a note, how many orders and how much was actually paid, and the full order and call history. The value is not the list but the warm-up of an inbound call: before the agent's first word, the caller's number is matched to a customer and their open orders, so a returning customer is greeted by name and asked about the job already running.
- Customer orders — the pipeline. Four stages (New → In progress → Done, or Cancelled) with payment as a separate axis — unpaid, partly paid or paid, with the amount received. That separation is deliberate: a finished but unpaid order must stay visible as debt instead of vanishing from the pipeline exactly when it matters most. An order holds the customer, line items with prices, an optional date and time, an address, a reminder and an append-only event feed. Dates are optional on purpose — "call back when it is ready" is a valid order — and orders without a date are counted separately, so a period filter can never hide them silently. The list filters by date with a mini calendar that marks days already carrying work.
- Order confirmation and payment. Orders the agent creates — from a call or from the chat — are marked "Unconfirmed" until the owner confirms them in the app; the owner always has the final word on what enters the pipeline. Payment is recorded by the owner on the order card: the status, the amount actually paid and the payment method (cash, card, transfer and so on). The owner can also dictate a payment to the agent, but only in their own private chat with it — on a call with a customer the agent never closes a debt on the caller's word.
- The Business management chat. A separate chat in the chats list where business events arrive: order reminders, order proposals the agent gathered from calls, a reminder when an invoice reaches its due date while the order is still unpaid, and every Monday a digest of debtors — who owes how much, across completed but unpaid orders. Like the system chat it is written by the servers, so it is not end-to-end encrypted.
- Documents. The paperwork of the business: contracts, invoices, tax filings, registration papers, supplier and HR files, licences. Each document is read once on upload — the agent extracts its text and proposes the type, counterparty, number, date, amount and expiry for the owner to confirm — so afterwards any of them can be asked about in plain language, and the agent searches all of them at once. Expiry dates produce a push 30, 7 and 1 day ahead; licences and insurance quietly lapsing is exactly what this archive prevents. Documents count towards the account's storage quota (5 GB free, then 0.10 EUR per GB per month).
- Documents are not end-to-end encrypted — and the app says so on the upload screen. They cannot be: the agent has to read a document in order to answer questions about it, and end-to-end encryption would mean only the device could. The two requirements are mutually exclusive and reading was chosen. For anything too sensitive for that, a per-document switch keeps the file stored and visible while excluding it from everything the agent can see.
- Analytics. Two lenses over one period. The business: revenue received, amount billed, debt, order count, average cheque, new versus returning customers, top price-list items and where orders came from. The agent's own work: calls handled, how many became orders, the call-to-order conversion, minutes spoken, tasks finished and euros spent.
- How the agent works with all this. Reading is free — the profile, prices, customers, orders and documents are all available whenever relevant. Logging is autonomous: after a related call, a finished background task or news told in chat, it appends one short factual entry to the right order. It creates an order when a customer actually agrees to buy or book something, taking prices from the list. Two things it never does: quote a price that is not in the price list, and mark an order paid on a customer's word — payment is recorded by the owner on the order card, or dictated by the owner in their own private chat with the agent.
- Access control. The agent's access to Business management is a single switch in the agent's settings (on by default). Off, the agent can neither read nor write any of it — the pages themselves keep working for the owner.
Isolation
Isolation is enforced by design, not by policy: every agent request is bound to a single user, and the agent can only reach the data of the user it belongs to. There is no shared memory between users and no way for one user's agent to read another user's anything.
AI call notes
An AI note is a short factual summary (typically 2–4 sentences) produced after a call. The pipeline:
- Capture — for Weyvox-to-Weyvox calls, each device records its own microphone track (two clean mono tracks — no crosstalk); for operator calls, the carrier produces the recording. An audible notice is played to the other party on operator calls.
- Transient processing — audio is transcribed per track and merged into a timeline; the audio file is deleted the moment transcription picks it up, and the transcript is deleted immediately after the note is written.
- One transcript per call. Everything spoken accumulates into a single transcript that belongs to that one call and to the one user the note is for. Nothing from any other call, and nothing belonging to any other person, is ever part of it.
- Generation — that single transcript is sent to the AI together with your own note instructions to write the note. The instructions come from your account and yours alone; each note is produced in its own isolated request built from exactly one call's transcript and one user's instructions.
- Delivery — the note lands in the related chat with the call record; users can steer what notes should focus on, or disable them entirely.
How your note instructions are scoped
Weyvox lets you tell the agent what your notes should focus on (and what to leave out). It is worth being precise about how far those instructions can reach, because it is a deliberate boundary of the design — not a promise we simply ask you to trust:
- Your instructions only ever shape your own calls' notes. Every note is generated on its own: one call's transcript plus the instructions stored on that account, in a request that contains nothing else. Your instructions are never combined with anyone else's transcript, and they never take part in generating another person's note.
- Rewriting them changes nothing outside your own notes. Because the boundary is structural — each note sees exactly one transcript and one account's instructions — there is no wording you could put in your instructions that would reach a different call or a different user's note. The isolation does not depend on what the instructions say.
- Where the processing happens. Producing a note is not end-to-end private: the recording is transcribed by our speech-to-text sub-processor, and the transcript plus your instructions are sent to our AI sub-processor to write the summary. Both act only to produce your note for your call. If you switch AI notes off, none of this runs for that call.
Messenger
- End-to-end encrypted: texts, media, voice messages, albums, captions and locations are encrypted on the sender's phone and decrypted on the recipient's — see Encryption for the full model, the metadata that stays visible, and the one-phone / QR-transfer rule.
- Realtime model: the WebSocket layer carries signals only; clients fetch deltas from the API and keep everything in an on-device cache (itself encrypted with a device-held key) — chats open instantly cold, bandwidth stays minimal, and history survives offline.
- Message types: text, photos, video, files, voice messages, locations, multi-photo albums; replies with quotes, forwarding, emoji reactions, edit and delete; read state via debounced read cursors.
- Edit & delete — the 60-minute rule: a sent message can be edited (an “edited” mark is shown to both sides) or deleted for everyone within 60 minutes of sending; the limit is enforced server-side. After that, the message can only be deleted for yourself — which is available for any message at any time.
- Media pipeline: media lives in object storage with ownership semantics — deleting a shared file passes ownership to whoever still keeps it; files nobody keeps are physically erased by a nightly job. Custom wallpapers ride the same pipeline.
- Storage metering: only real media files count toward the 5 GB free allowance; usage is shown by category with instant-effect deletion.
Push & incoming calls
- Messages arrive as push notifications, with per-chat mute windows and three preview levels (full text / sender only / silent).
- Incoming calls use a dedicated call push: it wakes the app, the phone rings immediately with the native call screen, and audio is pre-connected during the ring so answering is instant — including cold starts right after reboot, thanks to securely cached credentials.
The billing engine
Billing is Weyvox's most heavily engineered subsystem. Design principles: server-authoritative (the app can never invent a price), metered as it happens, safe against duplicates (retries can never double-charge), and transparent (every cent visible to the user).
- Prepaid wallet. Top-ups are Apple in-app purchases; each purchase is verified with Apple and credited exactly once, and refunds handled by Apple are reflected in your balance automatically.
- Welcome credit. Every new account is credited €5 on first registration — applied automatically and exactly once per user, with a welcome message in the system chat.
- Per-second call metering. A live agent call is charged minute-by-minute while it runs and settled to the exact second at hangup — as one entry per call that grows as the call goes on, so your history shows one clean line per call, not dozens of fragments.
- Exact telephony costs. Operator-call charges are driven by the carrier's own cost event emitted at hangup — the user pays a rate derived from the real cost of that exact call, applied seconds after it ends.
- Token metering, mirrored 1:1. AI usage is metered in the same five token categories the AI provider bills: base input, cache writes (5-minute and 1-hour tiers), cache reads, and output — per model family, so a task that mixes a fast model and a deep model prices each at its own rate. What the pricing page shows is exactly what you are charged.
- Safe to resume. If a background task restarts, it picks up its usage where it left off, so a resume can never refund or double-charge you.
- Subscription engine. Phone-number fees auto-charge monthly; if the balance is short the number keeps working for 30 days, then outgoing calls are blocked for 30 more, and it is released on day 60.
- Storage billing. A monthly job charges only full gigabytes above the free 5 GB.
- Negative-balance settlement. Post-rated charges may take the balance below zero; the debt settles from the next top-up while free features keep working.
- Retention. Per-operation usage detail is kept 90 days, then whole days are physically deleted; payment records are kept for statutory accounting periods.
AI transparency & regulatory compliance
Weyvox's voice agent interacts directly with people on the phone, so it falls under the transparency rules of the EU AI Act (Regulation (EU) 2024/1689), Article 50, which apply from 2 August 2026. How Weyvox is built to meet them:
- AI disclosure — Art. 50(1) and 50(5). The agent always identifies itself as an AI assistant acting for its user at the start of every call — on outbound calls, on auto-answered incoming calls, and when it takes the seat in a live call, on both telephonies. This is a built-in product rule the user cannot switch off, delivered clearly at the first moment of the interaction — exactly what Art. 50 requires: natural persons must be informed that they are interacting with an AI system, at the latest at the time of the first interaction.
- A synthesised (and optionally cloned) voice. The agent speaks in an AI-generated voice. A user may have it speak in a clone of their own voice; because the agent still gives the spoken AI disclosure at the start of the call, the other party is never misled into thinking a human is speaking. The clone is only ever the user's own voice — recorded by them, for their own agent — and is never used to impersonate a third party, so it is not a deceptive "deep fake" of the kind Art. 50(4) targets. The spoken disclosure is the human-facing transparency measure for the synthetic voice.
- Recording and consent. AI call notes need a recording; on operator calls Weyvox plays an audible notice to the other party, and the user is responsible for only recording where they are permitted to. See the Privacy Policy and Terms of Use.
- Voice data under the GDPR. A cloned voice is the user's personal data, processed only to produce their own agent's voice on the basis of their explicit consent, and deletable at any time — detailed in the Privacy Policy.
- Human accountability — GDPR Art. 22. The agent acts only on the user's instructions and within the capabilities they enable; Weyvox makes no automated decisions producing legal or similarly significant effects, and a human is always reachable at the support address.
Encryption, and where each kind of data lives
Weyvox states plainly what is protected and how, including where the protection stops. A messaging app that overstates its encryption is worse than one that explains it.
Personal chats are end-to-end encrypted
- What is encrypted: message texts, photos, videos, files, voice messages, albums, captions and shared locations. Encryption and decryption happen on the participants' phones; the servers relay and store only ciphertext they cannot read.
- How, concretely. Each account generates a Curve25519 identity key pair inside the phone's secure Keychain; the private half never leaves the device. The key belongs to the account rather than to the handset, so two accounts used on the same phone hold two unrelated keys and publish two unrelated public keys — nothing links them to one another. The two devices of a conversation independently derive the same conversation key (X25519 key agreement + HKDF-SHA256) — there is no key server and no key escrow. Messages are sealed with ChaCha20-Poly1305 authenticated encryption, cryptographically bound to the exact message and conversation, so ciphertext cannot be replayed into another chat. Every media file carries its own random 256-bit key that travels only inside the encrypted envelope. The cryptography is Apple's own (CryptoKit), running on the device.
- What stays visible to the servers — deliberately: the delivery metadata a messenger cannot work without — conversation and ordering identifiers, sender and timestamps, the message type, reply/forward references as identifiers, reactions, read cursors, and the size and generic content type of encrypted files. That metadata is protected by TLS in transit, disk-level encryption at rest, and per-user access policies enforced in the database itself; media ciphertext is reachable only through short-lived signed URLs, never a public link.
- What this means concretely: Weyvox cannot read your conversations, cannot serve their content to anyone, and could not be compelled to disclose it — a lawful order can reach only ciphertext and metadata. There is no backdoor and no recovery path.
- One phone, QR key transfer. An account is active on exactly one phone, and the keys exist only there — marked this-device-only, excluded from iCloud and device backups. Changing phones is a two-QR-code handshake directly between the devices (Settings → Account → Move to a new device); the key never touches the servers, and the old phone signs out after the transfer. If the phone is lost before the keys were transferred, the encrypted history is permanently unreadable — for the user, for Weyvox, for anyone. The account itself (number, balance, the agent's data) survives a re-login on a new phone.
- Signing out and back in, on the same phone. Signing out ends the session and clears the local copy of the data; it does not delete the account's key, which stays in that phone's Keychain on purpose. Signing back in is the ordinary flow — phone number plus a confirmation code — after which the history is downloaded from the servers and decrypted again on the device. Deleting the account is the opposite: it destroys that account's key, and only that one, leaving any other account on the same phone untouched.
- Several accounts on one phone. Supported, and each is sealed off from the others: its own identity key, its own history, its own local data. The one-phone rule applies per account, not per handset — one account is active on one phone at a time, while different accounts may share a phone freely. Signing in to the same account from a second phone is what triggers the transfer screen: the server sees a different device and the app offers the QR handshake, or the deliberate choice to continue without it. Without the transfer the account itself works normally on the new phone, but the earlier encrypted history stays unreadable there — the key that could open it never left the old device. A key change is never announced to anyone: the people you chat with are not notified about it.
- Not end-to-end encrypted, stated honestly: SMS and calls to regular phone numbers (the telephone network cannot be end-to-end encrypted), the Weyvox system chat (written by the servers), the Business management chat (also written by the servers), the agent chat (below), and any call with an AI note enabled — the note lifts end-to-end protection for that one call, because the audio is processed server-side to write it. App-to-app calls are end-to-end encrypted in transit.
The agent and encrypted chats
The agent's chat access is device access, not server access. When the user opens the assistant inside a personal conversation (a per-capability switch, off by default), their own phone decrypts the recent messages — and, when the question concerns them, specific attachments — and hands them to the agent with the request. The servers cannot read the conversation on their own, and no server-side path exists by which the agent could search or fetch chat history. Switching the capability off removes even that device-mediated access.
Conversations with the AI agent
- Stored on the phone, with a server-side backup. The Weyvox agent chat history lives in a local database on the device — that is what the app reads and displays. A server-side copy exists for one purpose: restoring the history when the user changes or loses their phone. It is never shown to anyone else, never used to train any model, and is deleted with the account. The agent chat is not part of the end-to-end-encrypted personal chats, because the agent's replies are produced server-side.
- Transmitted only to be answered. To generate each reply, the message is sent to the AI provider whose model produces the answer, and is processed there under a data-processing agreement. Weyvox does not retain it there.
- What the agent does keep, server-side, on purpose: its long-term memory (facts the user asked it to remember, or that it learned while helping — all viewable and erasable in Settings), background tasks it is running, and transcripts of calls it made, held for 24 hours so the user can ask follow-up questions about a call.
Protecting the account: PIN and app lock
Weyvox offers two protections that are commonly mistaken for one another. They defend against different threats, and relying on the second alone leaves the first gap wide open. Both live on one screen — Settings → Account → Security — precisely so the difference is visible at a glance.
The PIN protects the account
Signing in to Weyvox normally means a phone number and the confirmation code sent by SMS. That is convenient, but it leaves the SMS as the only thing standing between an account and whoever manages to read it — through a swapped SIM, an intercepted message, or a glance at a lock screen. A PIN closes that gap. Once set, signing in from a different phone asks for a six-digit code that the user chose and that is never transmitted anywhere, so a confirmation code on its own no longer opens the account. It is optional and off by default; enabling it takes a minute and is the single most effective step a user can take for account safety.
- Any six digits — which combination to choose is the user’s decision. The app does not second-guess it.
- Recovery codes — setting a PIN issues ten one-time codes, displayed once and copyable in a single tap. They should be kept away from the phone, on paper or in a password manager: each one can stand in for the PIN exactly once.
- The set is stable — changing the PIN does not replace the codes: they are bound to the account, not to the current PIN, so a list written down months ago keeps working. Exactly two actions replace or remove it, and both warn first: reissuing the codes on purpose, and deleting the PIN (which deletes the codes with it, since without a PIN there is nothing for them to stand in for).
- Guessing is not a route — repeated wrong PIN attempts suspend entry for a period that grows with each series. Recovery codes carry their own allowance of ten attempts — as many as there are codes, so trying them one after another is normal use rather than something to be punished — and once it is spent, signing in from a new device is blocked for seven days.
- Forgotten PIN, no codes left — the account is still recoverable. A reset request is accepted and the account opens seven days later. The delay is deliberate: it gives the rightful owner time to see the request on their own phone and cancel it by entering their PIN, while making the same route useless to anyone in a hurry.
- Nobody will ever ask for it — not by email, not in the app, not through the AI assistant, not in support correspondence. There is no circumstance in which anyone but the account owner needs a PIN or a recovery code.
The app lock protects the phone
With the lock enabled, opening Weyvox on that handset requires the phone's own biometrics, with the device passcode as the fallback. It guards against a realistic and common risk: an unlocked phone left on a desk, borrowed, or taken.
The switch is labelled with whatever the handset actually supports, because Face ID is not universal: iPhone SE (2nd and 3rd generation) and iPhone 8 use Touch ID, and Android devices mostly use a fingerprint reader. The app reads the device's capability and names it accordingly rather than assuming.
It is worth being precise about the lock's limits, because assuming it also protects the account is a costly mistake. Biometrics are matched against the template enrolled in that specific handset — a template that never leaves the device and is never handed to any app. On a stranger's phone the check would therefore simply pass for them. Guarding the account against a sign-in from another phone is the PIN's job, not the lock's.
The setting belongs to that one phone and is stored only there. It requires biometrics to be configured in the phone's own settings first; until then the switch stays unavailable. The two features are complementary, and most users will want both: the lock for the phone in their pocket, the PIN for the account behind it.
Security & data engineering
- Per-user isolation by design — access to every record is bound to its owner, the agent is bound to one user per request, and each user has their own telephony identity; no cross-user data path exists.
- Verified channels — every incoming call event is signature-verified before it is acted on.
- Secrets on device — credentials live in the phone’s secure storage and are cleared on sign-out.
- Short-lived sensitive data — call audio for notes is deleted right after transcription; transcripts right after the note; KYC documents within 24 hours of activation; the full retention table is in the Privacy Policy.
- No ads, no trackers — the app contains no third-party advertising or analytics SDKs. What we do measure is our own and aggregate: how much the service earned and cost, and how many accounts are active. It is counted from billing records and never touches the content of your calls, chats or documents, and it is never shared with anyone.
Using the app (quick reference)
- Sign-up: phone number + one-time SMS code (no email), then profile (first name, last name, date of birth, gender; photo optional). Editable later in Settings → Account → Personal information.
- Messaging: free and unlimited between users; Saved messages is a personal notepad chat; blocking, notification and wallpaper controls per chat.
- Agent: talk to it in the Weyvox tab; ask it to call ("call and find out…"), give it background tasks, review its memory, choose its voice and — for chat — its model. Calls always run on Claude Haiku 4.5.
- Numbers: buy in Settings; some require KYC documents shown during purchase; the subscription starts on activation day.
- Balance: top up via the App Store; every charge is itemised in Settings → Balance & usage; prices in Settings → Account → Tariffs and on the pricing page.
- Data: manage storage by category in Settings → Account → Data & storage; delete the account (irreversibly) in Settings → Account → Delete account.
More question-style answers: the FAQ (60 questions). Availability: iPhone (iOS), on the App Store from 1 September 2026; the Android app is in development, planned for 1 October 2026; no web client. Support: support@weyvox.com.