Call rules
what the code enforces.
You, the operator, are responsible for the calls your install places. This page describes what the code enforces and why. It is not legal advice: rules for calls to third parties in your markets are not verified by MIKODES.
01The three call rings
| Ring | When | What the callee hears | Status |
|---|---|---|---|
self | a call to the user's own verified number | the assistant directly | Ships |
third_party | any other number | the AI disclosure first, then anything else | Ships only with the disclosure |
cold | campaign or cold dialling | nothing: RING_FORBIDDEN, before any network access | Never |
The ring is derived, not declared. self applies only when the dialled number is exactly the verified own number; a typo, a placeholder or a number found in an e-mail is third_party. The media server recomputes the ring from the saved call plan when the stream connects and never takes it from the network. Uncertainty always falls towards the disclosure.
Third-party callers get no tools: nothing a stranger says becomes an action. The rings are the same for every SaaS customer; a plan may forbid third-party calls (403 PLAN_FORBIDS_THIRD), never the disclosure.
02The AI disclosure is not configurable
Every third_party call begins with, verbatim:
- en: "Hello. I am an automated AI voice assistant. This call is conducted by artificial intelligence."
- sk: "Dobrý deň, volám vám ako automatický hlasový asistent. Tento hovor vedie umelá inteligencia."
- The callee is muted and barge-in is off while it plays; the model does not speak until it has finished.
- "Finished" is measured on audio actually sent (at least 0.25 s per word), not on time.
- An error before the end, or no finish within 20 s (adjustable 8–30 s), hangs up the call.
- Neither the text nor the minimum length is a setting: not in the console, a file, a variable, a plan or the branding.
- A call is only placed in a language for which a disclosure exists.
A code path that disables the disclosure is a bug. Report it and do not use it. Open risk: if ElevenLabs does not mark the end of the disclosure audio on a live line, every third-party call would hang up after the disclosure (safe, but unusable). Not verified live.
03Why so strict
- EU AI Act, article 50 (from 2 August 2026): a person must be told, audibly and at the start, that they are talking to AI. Fines reach €15 million or 3 % of worldwide turnover.
- US TCPA: since the FCC declaratory ruling of February 2024, AI-generated voices are "artificial" under the TCPA: statutory damages of $500–1,500 per call, with no aggregate cap. California AB 2905 adds an AI disclosure duty for autodialled calls.
Calling users on their own verified number with their consent is the product; anything else is your legal responsibility.
04No cold calls, ever
Campaign or cold dialling is not implemented and never will be. --ring cold ends with RING_FORBIDDEN and exit code 2 before the network is touched. There is no bulk dialler, no list import and no function that takes a list of recipients. SMS and WhatsApp go only to the user's own verified number. Automated calls are limited to 3 per hour, texts to 6 per hour and 30 per day.
05GDPR: export and delete
| Who | Export | Delete |
|---|---|---|
| Single-user | Console → Data: a zip without keys, tokens or call secrets | Console → Data, confirmed by typing DELETE EVERYTHING; single facts, calls or all inferred facts individually |
| SaaS customer | The same export in their console | Account view: password plus the phrase DELETE ACCOUNT |
| SaaS operator | Panel → customer → export (owner role, audited) | Panel → customer → delete, confirmed with DELETE <email> (owner role, audited); cancels the Stripe subscription when a key is set |
Deletion is refused during a live call or a running job. Deleted is deleted: there is no backup unless you make one.
06NLTK punkt_tab needs legal review
pipecat splits the model's text into sentences with NLTK's punkt_tab data; without it the bot is silent after the disclosure. VOX downloads it on your machine (python -m voice setup-nltk, zip pinned by SHA-256); it is not in the package. The nltk_data repository is Apache-2.0 at repository level, but punkt_tab has no licence statement of its own and its English model was trained on Wall Street Journal text from the Penn Treebank (LDC), a corpus under its own licence. Whether that model may be used commercially is not established: have it reviewed before you sell a service built on it. A Docker image you build contains it.
07LGPL components installed by pip
All direct dependencies are MIT, BSD or Apache-2.0, and no GPL or AGPL code is part of VOX. Three transitive components are LGPL-2.1: soxr and num2words (required by pipecat) and libsndfile (inside the soundfile wheel). pip installs them on your machine; they are not in the package. If you distribute a built image, the LGPL notices must travel with it.