Trust and safety
Data and privacy
What AnswerStack stores about a caller, who can see it, how long it is kept and how it is separated.
A sales call to a senior living community is personal. It often contains a family member's name, their health, their finances and their address. This page says what happens to that.
Info
This describes how the product works. It is not legal advice and it is not your privacy policy. Your own counsel decides what you must tell callers and what agreements you need.
What is stored about a call#
| Stored | Detail |
|---|---|
| The call record | When it started and ended, how long it lasted, the number dialled, the caller's number, the community, the outcome |
| The playbook version | Exactly which version answered, so a transcript always traces to the content that produced it |
| The answers collected | Each answer by its short name, with the ones you marked sensitive masked in the app |
| The booking facts | The details the booking rules saw, the rule that fired and what it did |
| The transcript | Turn by turn, with the assistant's actions |
| The recording | Where recording is switched on and the caller did not object |
| The summary | A three-line summary written after the call |
| Timings | How fast the assistant responded, for quality |
| Usage events | Minutes, whether the call was answered, whether it booked |
What is not stored#
- Card numbers, passwords and government ID numbers. The assistant refuses them on the call, and any digits a caller volunteers are redacted from the transcript.
- Transcript text, caller details or collected answers in our application logs, traces or error reports. Logs carry identifiers, never call content.
- Anything about a caller whose record did not match: an unrecognised caller is simply a new caller.
Who can see it#
| Who | Sees |
|---|---|
| Your team | Calls for the communities their role allows. A group manager sees only their own communities' calls. |
| Your CRM users | Whatever your CRM shows them: the prospect, the logged call with its summary, the booked tour. |
| AnswerStack staff | Only with an explicit support reason, and every access is written to an audit log. |
| Other AnswerStack accounts | Nothing. Ever. |
Account separation is enforced in the database itself, not only in the application, so a mistake in one screen cannot expose another organisation's calls.
Sensitive answers#
Mark a question Sensitive: health or care details and its answer is masked on the call record behind a Show button. Revealing it is written to your audit log. Sensitive answers are also left out of notification emails: those carry a link to the call, never the details.
Tip
Mark every question about somebody's health, care needs or money as sensitive. It costs nothing and it means the detail is not sitting on a screen in a shared office.
How long it is kept#
Set per playbook on the Advanced tab:
| Setting | Default |
|---|---|
| Keep recordings for | 90 days |
| Keep transcripts for | 90 days |
A scheduled job deletes recordings and transcripts once they are past their date. The call record itself — when, how long, the outcome — is kept for your history, your analytics and your billing.
Shorten the period whenever you like; the next run applies the new setting to everything already past it.
How it is protected#
| Measure | What it means |
|---|---|
| Encryption | In transit and at rest. |
| Private storage | Recordings and uploaded documents live in private buckets, never on a public URL. Links are signed and expire in minutes. |
| Credentials | Your CRM token is encrypted in a secrets vault and is never shown again, not even to an owner. |
| Access control | Five roles, community scoping for group managers, and the same checks enforced again in the database. |
| Audit log | Sign-ins, role changes, publishes, connection changes, and each time somebody reveals a sensitive answer. |
| Notifications | Carry a link, not the details. |
What leaves AnswerStack#
| Goes to | What |
|---|---|
| Your CRM | The prospect, the call activity with its summary and collected answers, and the tour. Exactly what a person taking the call would type in. |
| Your webhook, if you set one up | The events described in Generic webhook. |
| The people you named for callbacks | An email with the caller's name, number, reason and a link to the call. |
| Voice and language vendors | Call audio and text, during the call, to hear and speak. |
| Tool servers you approved | Only what each tool is set up to send in the playbook, such as an answer the caller gave. See Use tools on calls. |
| AI apps and API tokens you allow | Only what their permissions cover, and never more than the member or service identity behind them may see. See Connect AI apps. |
Every vendor sits behind an interface, so the set can be changed per account without redesigning anything.
A caller's rights#
AnswerStack gives you the tools; the relationship with the caller is yours.
| A caller asks to | What you do |
|---|---|
| Not be recorded | Nothing. They say it on the call and recording and transcript storage stop immediately for that call. |
| See what you hold | Open the call in the admin app, and their record in your CRM. |
| Be deleted | Delete them in your CRM as you normally would, and ask us to remove the AnswerStack call records. Shortening your retention period removes transcripts and recordings on the next run. |
| Not be called back | The do-not-call flag on your CRM record is read and honoured, and the assistant never dials out in any case. |
Where it runs#
AnswerStack runs in the United States. If your organisation needs a specific region, dedicated infrastructure, or an agreement about how data is handled, talk to us before you go live rather than after.
See also HIPAA status, which is deliberately blunt about what is not offered today.