01The short version
This policy explains how Receptionists.io (receptionists.io) handles personal information when you visit our website, when you use our AI receptionist platform, and when someone calls or texts a business that uses us.
It applies to receptionists.io, our marketing sites, our dashboard at app.receptionists.io, our APIs, and the voice and messaging agents we operate on behalf of our customers.
02Our two roles
The single most important thing to understand about this policy is that we handle personal information in two very different roles.
As a controller, for our own customers and website visitors
When you sign up, browse our website, request a trial, contact support or pay an invoice, we decide how and why your information is used. For that information we are the controller (or, under United States state privacy laws, the business), and this policy describes what we do with it.
As a processor, for the calls and messages we handle for our customers
When our AI agent answers a call for one of our customers, the caller talks to that business, not to us. The recording, the transcript, the phone number and everything the caller says belongs to that business. For that information we are a processor (or service provider), acting only on our customer’s documented instructions.
If you called a business and want your data deleted, the fastest route is to contact that business directly, because they control it. You can also email us at hello@receptionists.io and we will forward your request to them and help them action it. See section 17.
03Information we collect
Account and business information
- Your name, business name, email address, telephone number, business address and time zone.
- Login credentials. Passwords are stored only as salted one-way hashes; we cannot read them.
- Team member names and email addresses that you invite.
- Your service details, pricing, service area, hours, and the knowledge base content you provide for the agent.
Billing information
- Plan, subscription status, billing period, invoices, and usage totals.
- Billing contact and country. We do not receive or store your full card number — payment details go directly to Paddle, our Merchant of Record. We see only a token, the card brand and the last four digits.
Call and message content (handled for our customers)
- Caller telephone number, call time, duration, direction and outcome.
- Call audio recordings, where the customer has enabled recording.
- Transcripts, AI-generated summaries, lead scores and extracted details such as the caller’s name, address, equipment and the problem they described.
- SMS message content sent and received on the customer’s behalf.
- Appointment details written to a connected calendar, and records written to a connected CRM.
- Voice samples you upload for voice cloning, and the resulting voice model. Where you use a library voice instead, only the identifier of that pre-built voice is stored.
Our customers can enable PII redaction, which masks items such as government identification numbers, payment card numbers, email addresses and full telephone numbers in transcripts before they are stored, and HIPAA mode, which forces redaction on and disables recording entirely.
Usage and technical information
- IP address, browser and device type, operating system, pages viewed, referring page, and timestamps.
- Dashboard actions, feature usage, API requests and audit log entries.
- Error diagnostics and performance traces.
Information we deliberately do not want
Our agents are configured not to solicit payment card numbers, full government identification numbers, or account credentials, and our Terms prohibit using the Service to collect them. Please do not send us sensitive categories of information — such as health, biometric, precise geolocation, financial account, racial or ethnic, religious, or sexual orientation data — through support channels unless we have specifically asked for it.
04Where the information comes from
- Directly from you, when you sign up, configure your agent, request a trial, or contact us.
- From your callers and customers, when they speak or text with an agent you operate.
- Automatically, from your use of our website and dashboard, through cookies and similar technologies.
- From services you connect, such as a calendar or CRM, with your authorisation and only to the scope you approve.
- From our providers, such as billing status from Paddle and delivery status from our telephony carrier.
05How we use information
| Purpose | What that means in practice |
|---|---|
| Providing the Service | Answering calls, transcribing them, generating replies, booking appointments, sending messages, and showing you the results in your dashboard. |
| Accounts and access | Creating your account, authenticating you, managing seats and permissions, and keeping an audit trail. |
| Billing | Metering usage, calculating overage, processing subscription payments through Paddle, and preventing fraud. |
| Support | Answering your questions, reproducing problems you report, and running your onboarding. |
| Security and abuse prevention | Detecting fraud, spam, abuse and unauthorised access; enforcing rate limits; investigating incidents. |
| Reliability and improvement | Diagnosing errors, monitoring performance, and analysing aggregated, de-identified usage to make the product better. |
| Communicating with you | Service notices, usage alerts, billing notices, security notices, and — if you have not opted out — occasional product updates. Service and billing notices are not marketing and cannot be opted out of while you hold an account. |
| Legal and compliance | Meeting tax, accounting and record-keeping obligations, responding to lawful requests, and establishing or defending legal claims. |
We do not sell personal information for money, and we do not use call content, transcripts or your customers’ personal information for our own marketing or advertising.
06Legal bases for processing
Where the General Data Protection Regulation or the UK GDPR applies, we rely on the following legal bases:
- Performance of a contract — to provide the Service to you, manage your account and take payment.
- Legitimate interests — to secure the Service, prevent abuse, improve reliability and communicate about the product, balanced against your rights.
- Consent — for non-essential cookies, marketing communications and voice cloning. You may withdraw consent at any time.
- Legal obligation — for tax, accounting and lawful requests.
Where we act as a processor for our customers, our customer determines the legal basis for their processing.
07AI processing, and our position on model training
Providing the Service necessarily means sending call audio, transcripts and conversation context to third-party artificial intelligence providers so they can be transcribed, understood and answered in real time. Those providers are listed in section 9.
We do not use your calls, transcripts, messages, knowledge base or customer data to train artificial intelligence models — not our own and not anyone else’s.
We contract with our AI providers on terms that prohibit them from using data we send them to train or improve their models, and we prefer providers that offer zero-retention or short-retention processing. Where a provider retains data briefly for abuse monitoring, that retention is limited and governed by our agreement with them.
Automated decision-making. The Service scores and categorises leads to help you prioritise follow-up. These scores are suggestions for a human, not decisions with legal or similarly significant effects, and the Service must not be used to make such decisions about a person — for example about credit, housing, insurance, employment or healthcare. See section 8 of our Terms of Service.
Aggregated and de-identified data. We may derive statistics from use of the Service — for example the average length of a call or the proportion of calls that end in a booking, across all customers — and use them to operate and improve the Service. This data is aggregated and de-identified so that it cannot reasonably be linked back to you, your business or any individual, and we do not attempt to re-identify it.
08Who we share information with
We share personal information only in these situations:
- With service providers and subprocessors who process it on our behalf under written contracts that restrict them to our instructions. They are listed in section 9.
- With services you connect, such as your calendar or CRM, at your direction.
- With our customer, if you called or texted a business that uses us. That business receives the recording, transcript and details of your interaction.
- With professional advisers — accountants, auditors and lawyers — under duties of confidentiality.
- For legal reasons, where we believe in good faith that disclosure is required by law, or is necessary to protect the rights, safety or property of any person. Where we are legally permitted to do so, we will notify the affected customer before disclosing their data, so that they can seek protective relief.
- In a business transfer — if we are involved in a merger, acquisition, financing or sale of assets, information may transfer as part of that transaction. We will notify you, and the recipient will remain bound by commitments at least as protective as these.
We do not sell personal information, and we do not disclose call content, transcripts or customer records to advertisers, data brokers or model trainers.
09Our service providers and subprocessors
These are the third parties that may process personal information on our behalf. This list is current as of the date at the top of this page; we maintain it and will update it here when it changes materially. Customers who would like advance notice of new subprocessors can request it by email.
| Provider | Purpose | Data processed | Primary region |
|---|---|---|---|
| Amazon Web Services | Cloud infrastructure, databases and recording storage | All categories, at rest | United States |
| Vercel | Website and application hosting | Request metadata, IP address | United States / global edge |
| Twilio | Telephony and SMS delivery | Phone numbers, call audio, message content, call metadata | United States |
| Deepgram | Speech-to-text transcription | Call audio, resulting transcripts | United States |
| Cartesia | Text-to-speech voice synthesis and voice cloning | Agent response text, voice samples you upload, voice model | United States |
| Groq | Low-latency inference for the conversational model | Conversation context, knowledge base excerpts | United States |
| OpenAI | Language model processing, summarisation and lead scoring | Transcripts, conversation context | United States |
| Anthropic | Language model processing for agent reasoning | Conversation context, knowledge base excerpts | United States |
| Paddle.com Market Limited | Merchant of Record — payments, invoicing, tax | Billing contact details, payment method (held by Paddle, not by us) | United Kingdom / United States |
| Calendar and workspace integrations you connect | Calendar events and availability, OAuth tokens | United States | |
| Sentry | Error monitoring and diagnostics | Error traces, technical metadata | United States |
| Supabase | Storage for trial signup requests submitted on this website | Name, business, email, phone submitted on the signup form | United States |
| Microsoft Clarity | Website analytics and session replay on our marketing site | Page interactions, device and browser data, IP address | United States |
| Meta Platforms | Advertising measurement on our marketing site | Website events, cookie identifiers | United States |
Which AI providers are used for a given call depends on your configuration and on routing decisions we make for latency and reliability. Not every provider listed is used for every account.
10Cookies, analytics and advertising
In the dashboard
Our application uses only cookies and local storage that are strictly necessary to sign you in, keep you signed in, and remember your preferences. We do not run advertising trackers inside the product.
On our marketing website
This site uses the following, in addition to necessary cookies:
- Microsoft Clarity — analytics and session replay, which records how visitors interact with pages (clicks, scrolling, mouse movement) to help us improve the site. Clarity masks text input by default. You can opt out at clarity.microsoft.com/terms.
- Meta Pixel — measures whether visitors who arrive from an advertisement go on to request a trial, and enables advertising measurement and audiences on Meta platforms.
Being straight with you about “sharing”: we do not sell personal information for money. However, advertising cookies like the Meta Pixel can amount to “sharing” for cross-context behavioural advertising under California law, and to “targeted advertising” under other United States state privacy laws. You have the right to opt out. To do so, enable a Global Privacy Control signal in your browser, use your browser’s tracking protection, or email us at hello@receptionists.io and we will action it. We honour Global Privacy Control signals where we detect them.
This applies to our marketing website only. Call recordings, transcripts and your customers’ information are never shared with advertising platforms.
Most browsers also let you block or delete cookies. Blocking necessary cookies will stop the dashboard from working.
11How long we keep information
| Category | Retention |
|---|---|
| Account and configuration | For as long as your account is open, then deleted or de-identified within 30 days of closure. |
| Call recordings and transcripts | Retained for the analytics window of your plan — 30 days on Starter, 90 days on Growth, 365 days on Scale — unless you set a shorter period or delete individual records sooner. You can delete any recording or transcript at any time. |
| Messages and contact records | For as long as your account is open, or until you delete them. |
| Voice clones and the samples used to create them | Until you delete the clone or close your account. Deleting a clone deletes the underlying sample with it. |
| Do-not-contact entries | Kept indefinitely, on purpose. Deleting an opt-out record would mean contacting someone who asked not to be contacted. |
| Billing and tax records | Up to 7 years, as required by tax and accounting law. |
| Security and audit logs | Typically 12 months. |
| Backups | Encrypted backups roll off within 35 days. Data you delete disappears from live systems immediately and from backups as they expire. |
We may retain information for longer where we are required to by law, or where it is needed to establish, exercise or defend a legal claim.
12How we protect information
- Encryption in transit (TLS) and at rest for stored data and recordings.
- Passwords stored as salted one-way hashes; API keys stored hashed and shown once.
- Strict tenant isolation, so one customer’s data is not reachable from another customer’s account.
- Role-based access control and per-organisation audit logging.
- Least-privilege internal access. Our people access customer content only when needed to operate the Service or to help you with a support request, and that access is logged.
- Automated error monitoring, rate limiting and abuse detection.
No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your personal information, we will notify you and any regulator required, without undue delay and within the timeframes the applicable law requires.
If you believe you have found a security vulnerability, please report it to hello@receptionists.io. We will not pursue action against researchers who report in good faith, act in proportion, and do not access or destroy other people’s data.
13Your privacy rights
Whoever you are and wherever you live, you can ask us to do the following, and we will honour it to the extent the law that applies to you allows:
- Access — get a copy of the personal information we hold about you.
- Correct — fix information that is inaccurate or incomplete.
- Delete — have your information erased.
- Port — receive your data in a common machine-readable format.
- Object or restrict — object to certain processing or ask us to pause it.
- Withdraw consent — where processing is based on consent.
- Opt out of marketing — unsubscribe from any marketing email, instantly.
- Be free from retaliation — we will never degrade the Service or charge you differently for exercising a privacy right.
Account holders can do most of this without asking: export and deletion tools are built into the dashboard. For anything else, email hello@receptionists.io. We respond within 30 days, and will tell you if we need an extension the law permits. We may need to verify your identity first, and we will only ask for what is necessary to do that. You may use an authorised agent where the law allows; we will ask for proof of authority.
14United States state privacy rights
If you are a resident of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana or another state with a comprehensive privacy law, you have the rights listed in section 13, plus the right to opt out of the sale of personal information, of sharing for cross-context behavioural advertising or targeted advertising, and of profiling that produces legal or similarly significant effects.
- We do not sell personal information, and we have not sold personal information in the preceding 12 months.
- We do not profile individuals in a way that produces legal or similarly significant effects.
- We do use advertising cookies on our marketing website, which may count as sharing or targeted advertising. Section 10 explains how to opt out, and we honour Global Privacy Control signals.
- We do not knowingly process the personal information of anyone under 16 for advertising purposes.
- Sensitive personal information. We do not use or disclose sensitive personal information for purposes beyond those permitted without an opt-out under California law.
California residents may also request the categories of personal information we collected, the sources, our business purpose, and the categories of third parties to whom we disclosed it — all of which are set out in sections 3, 4, 5, 8 and 9 above. If we deny a request, you may appeal by replying to our decision; we will respond to an appeal within 45 days and explain our reasoning.
Where we handle call content on behalf of a business customer, we act as that customer’s service provider and process it only for the business purpose of providing the Service, as required by California law.
15Canadian privacy rights
We handle personal information of individuals in Canada in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial legislation, including Quebec’s Law 25, Alberta’s PIPA and British Columbia’s PIPA.
- Consent. We collect, use and disclose personal information with consent, which may be express or implied depending on the sensitivity of the information and the reasonable expectations of the individual. You may withdraw consent, subject to legal and contractual restrictions and reasonable notice.
- Access and correction. You may request access to your personal information and ask us to correct it. We respond within 30 days.
- Transfers outside Canada. Our providers are located primarily in the United States and our operations are based in Tunisia, so personal information is stored, processed and accessed outside Canada and may be accessible to foreign courts, law enforcement and national security authorities under the laws of those countries. We use contractual and technical safeguards to protect it, and we remain accountable for it while it is with a provider.
- Quebec residents. You additionally have the right to data portability, the right to be informed about automated decision-making, and the right to request that we cease disseminating your information or de-index it where the law provides. Our privacy officer can be reached at the address in section 21.
- CASL.Commercial electronic messages we send comply with Canada’s Anti-Spam Legislation, identify us, and include a working unsubscribe mechanism.
16European and United Kingdom rights
If you are in the European Economic Area, the United Kingdom or Switzerland, you have the rights in section 13, and in addition the right to lodge a complaint with your supervisory authority. Where we transfer personal data out of those regions, we rely on the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism, together with supplementary technical measures such as encryption.
Business customers who need a Data Processing Agreement incorporating Standard Contractual Clauses can request one from hello@receptionists.io and we will provide and sign it at no charge.
17Notice to people who call or text our customers
This section is for you if you telephoned or texted a business and an AI receptionist answered.
- Who you were dealing with. The business you called is responsible for your information. We operate the phone system on their behalf. Where the business has enabled it, an announcement tells you at the start of the call that you are speaking with an automated assistant, and whether the call is being recorded.
- What is kept.Depending on that business’s settings: your phone number, a recording of the call, a transcript, a summary, and any details you gave, such as your name, address and the problem you described.
- Why. So the business can call you back, book your job, confirm your appointment and keep a record of the conversation.
- Texts. Reply STOP to any message and you will be added to the do-not-contact list immediately and permanently. Reply HELP for help.
- Your rights. You can ask for a copy of your information, ask for it to be corrected, or ask for it to be deleted. Contact the business directly for the fastest result. You can also email us at hello@receptionists.io; because we act on that business’s instructions, we will pass your request to them promptly and help them carry it out, and we will confirm to you when we have done so.
18International data transfers
Where we are. The business is operated from Tunisia. Our infrastructure and the providers listed in section 9 are located primarily in the United States, which is where call recordings, transcripts and account data are stored and processed.
This means personal information is transferred across borders in the ordinary course of providing the Service: from the caller’s country to our United States infrastructure, and accessible to our personnel in Tunisia for support, operations and security purposes. Those countries have data protection laws that differ from one another and may differ from those of your country.
We protect that information with the safeguards described in section 12, and with the contractual mechanisms described in sections 15 and 16 — including Standard Contractual Clauses where personal data leaves the European Economic Area or the United Kingdom. Access by our personnel is least-privilege and logged.
19Children
The Service is for businesses and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, contact us and we will delete it promptly.
20Changes to this policy
We will update this policy as the Service and the law evolve. The “Last updated” date at the top always reflects the current version. If we make a material change — for example, a new purpose for using your information — we will notify account holders by email or in the dashboard at least 30 days before it takes effect. We keep prior versions and will provide one on request.
21How to contact us or complain
Privacy questions and requests go to a real person, and we answer every one:
Receptionists.io
Attention: Privacy Officer
Rue de Mateur, Sousse 2100, Tunisia
hello@receptionists.io
If you are not satisfied with our response, you may complain to your data protection authority: the Office of the Privacy Commissioner of Canada or your provincial commissioner in Canada, your state attorney general in the United States, or your supervisory authority in the European Economic Area or the United Kingdom. We would appreciate the chance to put it right first.