# Cal.ai privacy rating

AI phone agent from Cal.com that makes scheduling calls to book meetings, confirm appointments, send reminders and follow up on no-shows, triggered from Cal.com workflows.

## Summary

Cal.ai scores 38 out of 100 (grade F) on the scheduling criteria. It meets 3 of 8 criteria: no ads or data sales, TLS configuration and security headers. It partly meets independent audit. It does not meet open source, no trackers or telemetry, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.

- Website: https://cal.com/ai
- Jurisdiction: United States. Five Eyes member. Subject to the US CLOUD Act.
- Platforms: Web
- Home page trackers: Google Fonts (not scored), Google Tag Manager, PostHog, Trustpilot (not scored), X (Twitter) Pixel, YouTube embed (not scored)
- Category: [Scheduling](https://privacyratings.com/scheduling/)
- Also rated: [Cal.com](https://privacyratings.com/scheduling/cal-com/) (Scheduling)
- Grade: F (38/100)

## Criteria

| Criterion | Answer | Note | Evidence |
| --- | --- | --- | --- |
| Open source | No | Closed source. Cal.ai is part of the Cal.com production codebase, which moved to a private repository. | https://cal.com/blog/cal-com-goes-closed-source-why |
| No trackers or telemetry | No | The marketing site runs analytics and ad measurement, loading Google Tag Manager, PostHog and LinkedIn scripts, and the product uses opt-out product analytics. | https://cal.com/privacy |
| No ads or data sales | Yes | Funded by paid usage. The privacy policy states personal data is never sold and booking data is not used for advertising profiles. | https://cal.com/privacy |
| Independent audit | Partial | Cal.com lists SOC 2 Type II and ISO 27001 certification and third-party penetration tests, but the reports are not public. | https://cal.com/security |
| Transparency report | No | No transparency report or government request policy is published. |  |
| Tells users about requests | No | No published policy on notifying users about data requests. |  |
| TLS configuration | Yes | Grade A+ | https://www.ssllabs.com/ssltest/analyze.html?d=app.cal.com&hideResults=on |
| Security headers | Yes | Grade A+ (125/100+) | https://developer.mozilla.org/en-US/observatory/analyze?host=app.cal.com |
| Modern web standards | Not tested yet | Not tested yet. |  |

Source: https://privacyratings.com/scheduling/cal-ai/
Edit: https://github.com/privacyratings/privacyratings.com/edit/main/ratings/scheduling/cal-ai.md
