Back to the AI front desk

Privacy

Privacy for AI front desk calls

This policy explains the call data we process for the AI front desk, why we process it, how long it is kept, and how deletion requests work.

Last updated August 8, 2026

Scope

This policy covers calls handled by Appalytical's AI front desk for a law firm. The law firm decides why the call data is processed and which routing and scheduling fields are enabled. Appalytical processes that data to operate the service for the firm.

This policy does not create an attorney-client relationship and does not mean the firm has agreed to represent a caller.

What we collect on a call

  • Live audio. The service processes the caller's speech so it can respond. The greeting identifies the AI assistant and gives the recording disclosure before the administrative call flow begins.
  • Contact and scheduling details. This can include the caller's name, callback number, safe-to-call instructions, requested consult time, and the provisional booking result.
  • Limited routing details. The service records a short administrative description of what the caller needs and any firm-approved field needed to route the call, such as where a person is being held. It is not configured to collect a detailed matter narrative.
  • Call and compliance metadata. This includes timestamps, call duration, transfer outcome, tool results, and identifiers for the fixed disclosure and routing templates used during the call.

How we use call data

  • Answer and route the call under the firm's written configuration.
  • Place a provisional consult hold and deliver the callback number to the firm.
  • Attempt a transfer when the caller asks for a person or a firm-defined escalation condition occurs.
  • Provide the firm with the call time, short administrative summary, booking result, and callback details.
  • Operate, secure, troubleshoot, and audit the call flow.

We do not sell call data. We do not use call data to advertise to callers. We do not opt in to sharing API data with OpenAI for model training.

Retention

Raw call audio is not stored in Appalytical's systems by default and is not delivered to the firm. The structured call record is kept for the period selected by the firm in its service configuration and agreement. The firm can choose a shorter period and request deletion sooner.

OpenAI's Realtime API does not retain application state for the session. OpenAI may retain API content for up to 30 days in abuse monitoring logs by default, unless a different approved data control applies. OpenAI states that API data is not used to train its models unless the API customer opts in. See OpenAI's data controls documentation.

Telephone carriers retain call routing records and related metadata under their agreements and legal obligations. The current carrier has not been selected because the proof of concept is not complete. Carrier-specific retention terms will be published before any live firm calls are processed.

Deletion requests

A caller can request access or deletion through the law firm that received the call or by emailing . We verify the request and coordinate with the firm because the firm controls the call record.

We delete Appalytical-controlled records within the deletion window in the firm's agreement and send applicable deletion instructions to subprocessors. Some carrier records or abuse-monitoring logs may remain for the provider's stated retention period or when law requires retention.

Who receives call data

The firm's authorized recipients will receive the administrative call record and booking result. The production provider list and DPA links will be published after the proof of concept selects the actual call path and before any live firm calls are processed.

We may disclose information when required by law or when needed to address an immediate safety or security issue.