RevDesk
  • Pricing
Product
Features
Voice Agents
Answer and make calls that deliver, 24/7.
Omnichannel Messaging
iMessage, WhatsApp, SMS, and email with shared context.
Augmented Sales
Your team calls with AI coaching what to say in realtime.
Campaigns & Sequences
Multi-touch drips that trigger texts and calls
Tools
Referral Network
Route the matters and patients you can't take
Number Registration
Register any number, and we remediate spam via our API
API & MCP
Connect your agents to RevDesk
Solutions
Industries
Automotive
Work every internet lead like your best BDC
HealthcareHIPAA
Patient outreach, intake, and follow-through
Law Firms
Intake, conflict screening, booked consults
B2B SaaS
Speed-to-lead, trials, and partner links
Home Services
Book more jobs from every call and get more customers
Logistics
Cover loads and carriers around the clock
AI Coworkers
Speed-to-Lead
Calls new form leads in seconds
Outbound SDR
Works your lists, warms, books
Customer Care
Reviews, referrals, follow-up care
Re-Engage
Wins back dormant pipeline
ReceptionistIncluded
Answers and routes every call, on every plan
Resources
Blog
Field notes from useful AI
Changelog
What’s new in RevDesk
Docs
Platform documentation
Case studies
Stories from leading customers
Trust Center
SOC 2 Type II and HIPAA
Pricing
Sign InGet Started
Sign InGet Started

Privacy Policy

Version 2026.4 · Last updated August 20, 2026

  • Overview

    • The Short Version
    • Who We Are
    • Our Two Roles
  • What We Collect

  • How We Use Your Data

  • Sharing and Transfers

  • Security and Retention

  • Your Rights and Regional Laws

  • Cookies and Tracking

  • Updates and Contact

Overview

The Short Version

Nobody reads privacy policies. So here is ours in eight lines, and the full version below it.

  • We do not sell your data. There are no advertising or retargeting pixels anywhere: not on our website, not in the product.
  • Your workspace's data is yours. Calls, transcripts, messages, and contacts belong to you. We process them on your instructions, under a Data Processing Agreement.
  • Every vendor is named, with the actual data it receives, on our Sub-processors page. No categories-only hand-waving.
  • Nothing trains anyone's models. Our AI providers process your calls and content under enterprise API terms that prohibit training on them.
  • Turning transcripts off means nothing is stored, from any source. Recording is a setting you control, not something we impose.
  • Retention is concrete. Recordings and transcripts keep for 90 days by default, configurable from 7 days to 1 year, or off entirely.
  • If a business called you using RevDesk, the data is theirs, so start with them. If you cannot reach them, we will route your request and make sure it is answered.
  • Questions and rights requests go to privacy@revdesk.com. A person reads that inbox.

Who We Are

RevDesk is operated by Cell Labs, Inc. This policy explains how we collect, use, share, and safeguard information in connection with our conversational AI, omnichannel messaging, and automation platform.

If you have questions about anything here, or want to exercise a privacy right, email privacy@revdesk.com.

Our Two Roles

RevDesk is a business platform, and that makes this policy cover two quite different situations. Most of the confusion people have when reading a policy like this comes from mixing them up, so we separate them up front.

When we act for ourselves (we are the "controller")

This covers the data we decide what to do with: your account and profile, billing records, support conversations, and how people use our marketing website. We determine why and how that data is processed, and this policy governs it directly.

Applies to: RevDesk customers, prospects, and website visitors.

When we act for our customer (we are the "processor")

This covers everything that flows through a customer's workspace: call audio and transcripts, messages, contacts and lead lists, and booking details. We do not decide what happens to that data. The customer does, and we act on their instructions. Our obligations to them are set out in our Data Processing Agreement rather than in this policy.

Applies to: callers, contacts, and anyone a RevDesk customer communicates with.

If a business called you using RevDesk

We are not the business that called you, and we cannot tell you why they did. We host the software they used.

To access, correct, or delete what that business holds about you, contact the business directly, since the data is theirs. If you cannot identify or reach them, email privacy@revdesk.com and we will help route your request to the right customer and support them in answering it.

What We Collect

Categories and Sources

Data reaches us three ways: you give it to us, your use of the product generates it, or the people your workspace talks to provide it. Here is each, concretely.

What you give us

Your name, email, phone number, and company when you sign up. Your business details, hours, preferences, and the prompts you write for your agents. Your billing address and email; the card itself goes to Stripe and is never stored by us. And whatever you send us when you contact support.

What using the product generates

Call records: who was called, when, for how long, and how the call went. Recordings and transcripts, where you have them enabled. Product usage, such as which features you use and which pages you visit, plus the ordinary technical trail of any web application: IP address, browser, device, and server logs.

What callers and contacts provide

When someone calls or messages your RevDesk number, we receive their phone number, the audio of the call if recording is on, a transcript if transcript saving is on, and whatever they choose to say: names, messages, appointment details. This data belongs to you, not to us, and the Our Two Roles section explains what that means in practice.

Recording and transcription are your settings

You can turn call recording on or off at any time, delete individual recordings or transcripts whenever you want, and set retention anywhere from 7 days to 1 year, or disable storage entirely.

Because you own this data, informing callers about recording and collecting any consent the law requires is your responsibility. Our Terms of Service cover what that involves.

SMS Consent

IMPORTANT NOTICE REGARDING TEXT MESSAGING DATA

Cell Labs, Inc. (“we,” “us,” or “our”) DOES NOT share customer opt-in information, including phone numbers and consent records, with any affiliates or third parties for marketing, promotional, or any other purposes unrelated to providing our direct services. All text messaging originator opt-in data is kept strictly confidential.

When you opt in to receive SMS messages from RevDesk, we collect your mobile phone number and consent preferences. This section explains how we handle your SMS-related data.

How We Collect SMS Consent

We collect SMS consent exclusively through our website opt-in form. During signup, you provide your phone number and check an unchecked SMS consent checkbox that reads: “I agree to get appointment reminders and account alerts via text from RevDesk. Msg frequency varies. Msg & data rates may apply. Reply STOP to unsubscribe. Reply HELP for help.” No messages are sent unless you check this box and submit the form.

Limited Sharing for Service Delivery

We share your mobile phone number only with the following service providers, solely to deliver SMS messages on our behalf:

  • Telnyx: Our telephony and SMS gateway provider that transmits messages to your phone. Telnyx is contractually prohibited from using your data for any purpose other than message delivery.

These providers receive only the data necessary to deliver your messages and are bound by strict data protection agreements.

Message Frequency & Costs

Message frequency varies based on your account activity and scheduled appointments. Typical users receive 2–10 messages per month. Standard message and data rates may apply based on your mobile carrier plan.

For full details on our SMS program, including opt-in methods, message types, and carrier information, see our SMS Opt-In & Program Information page.

Managing Your SMS Preferences

You can update your SMS preferences or opt out at any time through your account settings, by replying STOP to any message, or by contacting support@revdesk.com. See our SMS Terms and Conditions for complete opt-out instructions.

Consent records and audit

When you (the workspace operator) capture consent for an outbound channel, whether voice, SMS, or email, RevDesk persists the consent metadata at the contact level: channel, source, timestamp, sender, and use case. When a contact initiates an inbound call or SMS to your workspace, an inbound-initiated opt-in is recorded automatically. These records are exportable from the Compliance Center on the Outreach page and are available for audit, regulatory inquiry, carrier enforcement, or legal claims.

Voice and Recording

By default, new phone numbers in RevDesk have call recording enabled. Our default outbound greeting template opens with a recording disclosure (“just so you know, this call is being recorded”), localized for 50+ languages, and campaigns use that template unless you replace it.

The disclosure is a default, not an enforcement

We want to be precise about this, because getting it wrong has legal consequences for you. RevDesk does not inject a disclosure into your calls. A sentence bolted onto the front of a greeting sounds robotic, so we ship it as the default greeting text rather than as forced audio.

The practical result: if you write your own greeting, or use surfaces that start from a different opener such as the dialer or a test call, the disclosure is present only if you put it there.

Check your greetings. RevDesk surfaces the recommended disclosure phrasing on every greeting-editing screen, and HIPAA-enabled workspaces have the disclosure requirement locked on.

When you (the workspace operator) place outbound calls to recipients in U.S. states that require all-party consent (CA, CT, DE, FL, IL, MA, MD, MI, MT, NV, NH, OR, PA, WA), the Outreach compose UI surfaces an informational banner reminding you to verify the disclosure is part of your greeting. RevDesk persists per-call disclosure attestation so the Compliance Center can report attestation rates over the prior 30 days and you can surface that evidence in an audit.

Callers and Contacts

Much of the personal data on our systems belongs to people who have never heard of RevDesk: callers, contacts, and leads in our customers' workspaces. We hold that data as a processor for the customer, not for ourselves.

Where it comes from:

  • From the person directly, when they call or message one of our customers, or fill in a form
  • From our customer, when they upload or sync a contact list from their own systems
  • From an enrichment provider, when a customer asks us to enrich a contact record with business-contact details sourced from third parties

If you are a RevDesk customer, the Article 14 duty is yours

Where personal data is not obtained from the individual, GDPR Article 14 generally requires the controller to tell them: what you hold, where it came from, why you have it, and what rights they have. That duty sits with you, since you are the controller. It applies to uploaded lists and to enriched attributes alike.

See the enrichment note on our sub-processor page for detail.

If you are one of these individuals and want to see, correct, or delete what is held about you, contact the business you dealt with, because the data is theirs to act on. If you cannot identify or reach them, write to privacy@revdesk.com with whatever detail you have, such as the number that called you and roughly when. We will identify the customer and require them to respond. We will not ignore you on the grounds that you are not our customer.

How We Use Your Data

Purposes and Legal Bases

We use your data to run the service, bill for it, keep it secure, and improve it. Each use has a legal basis under GDPR Article 6, and rather than list uses in one place and bases in another, one table carries both.

What we doWhy we are allowed to
Run the service: answer calls, hold conversations, schedule, sync your integrationsPerformance of our contract with you
Bill you and keep payment recordsContract, and legal obligation for tax records
Send service email: receipts, account notices, security alertsContract
Answer your support requestsContract
Improve the product, using aggregate usage metrics, never call contentLegitimate interests
Detect fraud and abuse, and secure the platformLegitimate interests
Send marketing email about the productConsent, withdrawable at any time
Respond to valid legal processLegal obligation

For the data inside a customer's workspace, the table above does not apply: we process it on the customer's documented instructions under the Data Processing Agreement, and establishing a lawful basis for that processing is the customer's responsibility as controller.

AI Processing

Your call audio is carried by our real-time media layer, LiveKit, which is also where the voice agent itself runs. We operate it in two places, LiveKit Cloud and a LiveKit stack our carrier runs inside its own network, and which one serves a given call is a routing setting we change for reliability. Today inbound and outbound AI calls are served by LiveKit Cloud. Browser-bridged calls, where an operator's browser joins the same session as the phone leg, always are.

The audio is then handled by a single speech-to-speech model: OpenAI Realtime is our default voice, with Google Gemini selectable as an alternative. These models listen to the audio and answer in speech, so the conversation does not pass through a separate transcription or voice-synthesis vendor at all. The pipeline that used to split those steps across separate speech-to-text and text-to-speech providers was retired in August 2026, and with it the vendors that served it. Audio and transcripts are encrypted in transit (TLS 1.2 or higher) and at rest (AES-256).

Text is still produced, even on the speech-to-speech path. The voice model transcribes the conversation as it goes, and that is where your transcript comes from. On outbound calls we also briefly transcribe whatever answers the phone, which is how the agent tells a person from a voicemail system and avoids talking over someone.

Turning transcripts off means nothing is stored

A voice model has to interpret speech in the moment to hold a conversation at all. That is unavoidable, and it happens inside the model handling your call.

What you control is whether any of it is kept. With transcript saving turned off for your workspace, no transcript is written from any source: not from the voice model, and not from the speech-to-text step in the modular pipeline. There is nothing to retain, export, or delete, because nothing was stored.

When the Agent Looks Something Up

An agent can do more than talk. When it needs a fact, it calls a tool, and that step is text rather than audio. Depending on what you have enabled, it may check availability, look up or update a contact, retrieve earlier conversation history, search your knowledge base, or search the web.

Knowledge base search is worth describing precisely, because it involves an extra hop. Your knowledge content is split into passages and converted into numeric embeddings using an OpenAI embedding model, and those embeddings are stored in our database. When the agent searches, the search phrase is embedded the same way and matched against your stored passages, and the best matches are handed back to the model as text. If embedding is unavailable, we fall back to a plain text search.

Two things follow. Content you put in a knowledge base, and the phrases the agent searches for, are sent to that embedding provider under the same terms as the rest of our AI processing, which means they are not used to train anyone's models. And if you enable the web search tool, the agent's search phrase leaves our platform to reach a search provider, so treat it as you would any outbound search.

Your data trains no one's models

We do not use your call recordings, transcripts, or business data to train AI models, and neither may our providers.

OpenAI, Google, and Deepgram process your content under enterprise API terms that prohibit training on it. They may hold it briefly, typically up to 30 days, for abuse monitoring only, and then delete it permanently.

The one thing we keep for ourselves is aggregate analytics such as average call duration, which contains no call content and identifies no one.

AI Transparency

RevDesk uses AI to conduct conversations, transcribe and summarize them, and surface suggestions such as which leads look promising. Understanding what that does and does not decide matters.

The AI does not make decisions with legal or similarly significant effects about anyone. It does not determine credit, employment, housing, insurance, healthcare, or access to any service. Its outputs are conversational responses and suggestions to a human operator, who remains the decision-maker. If you have questions about how a suggestion was produced, or want to contest one, contact the business that operates the workspace, or us at privacy@revdesk.com.

Disclosing That the Caller Is AI

A growing number of laws require people to be told they are interacting with an AI rather than a person. California's bot-disclosure law already does. From 2 August 2026, Article 50 of the EU AI Act requires it for AI systems interacting with people in the EU. Several US states have enacted or proposed similar rules.

RevDesk provides localized AI-disclosure phrasing on every greeting-editing screen, so it can be part of how your agent opens a call. As with the recording disclosure, we surface the recommended wording rather than force it into your audio, so deciding whether disclosure is required, and confirming it is actually present in your greeting, is your responsibility.

Sharing and Transfers

Service Providers

We do not sell your personal information. We share data only with trusted service providers necessary to operate our platform.

Service Providers (Data Processors)

We engage third-party providers to operate the platform, spanning telephony and messaging, real-time media, AI models and voice synthesis, hosting and storage, payments, email, and product analytics. Each receives only the data it needs for its function, under a written contract imposing data-protection obligations no less protective than those we owe you, and we remain responsible to you for their performance.

The full list lives on its own page

Every provider, what each one receives, where it processes data, and its certifications are published at revdesk.com/subprocessors.

We keep it there rather than in this policy on purpose. The list is versioned and dated, so you can tell exactly which providers were engaged at any point in time, and we can give you the 30 days' advance notice of a change that our Data Processing Agreement requires without amending this policy each time. You may object to a new sub-processor on reasonable data-protection grounds during that window.

Apps You Connect Are Different

When you connect a calendar, a CRM, a spreadsheet, or a webhook to your workspace, that is your instruction and your data flow, not a vendor we chose. Those products are not our sub-processors: they operate under their own terms and privacy policies, data reaches them because you asked it to, and you can disconnect them at any time. Disconnecting stops future data exchange, though it does not retrieve what was already sent.

The Remaining Cases

Beyond service providers and the apps you connect, data leaves us in exactly three situations:

  • Legal process: where a law, court order, or subpoena requires it. We disclose the minimum required, and where we are permitted to tell you first, we do
  • A change of ownership: if we are acquired or merge, your data transfers to the successor under this same policy, and we notify you before the transfer takes effect
  • Protecting people and the platform: to enforce our Terms, investigate fraud, or respond to a threat to someone's safety

Google Account Permissions

When you sign in with Google or connect a Google integration, RevDesk requests only the OAuth scopes needed for the feature you're enabling. RevDesk's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Your Google data is used only to provide the user-facing feature you authorized, never sold, and never used to train AI models.

Scopes We Request

  • userinfo.profile and userinfo.email: Required for Google sign-in. We use your name, email, and profile picture to identify your account.
  • calendar.events and calendar.readonly: Requested only if you connect Google Calendar as an individual user. Used to read your availability and create, update, or cancel events for bookings made through RevDesk. Google Meet links are generated automatically through the Calendar API and do not require an additional scope.
  • calendar (full): Requested only when a Google Workspace administrator enables domain-wide delegation for their organization. Used by RevDesk's service account to read availability and manage bookings on behalf of users in the Workspace, exactly as the administrator authorizes in their Google Workspace Admin Console. Individual users connecting their own Calendar do not grant this scope.
  • drive.file: Requested only if you connect the Google Sheets integration. Grants per-file access to the specific spreadsheets you select via the Google Picker, which we use to read and write call data. We do not list, browse, or read any other files in your Drive.

Scopes We Do NOT Request

RevDesk does not request any of the following:

  • Gmail (read, send, or modify)
  • Google Drive write or full-Drive access
  • Google Workspace Admin Directory (user lists, customer info)
  • Contacts, Photos, YouTube, or any other Google service

Token Storage and Revocation

OAuth refresh tokens are encrypted at rest and used only to maintain the connection you authorized. You can revoke RevDesk's access at any time from your Google Account permissions page or by disconnecting the integration in your RevDesk settings. Disconnecting removes the stored token immediately.

Data Flow

Each step below shows where your data goes during a call: from the caller, through our carrier and real-time media layer, to the voice model, then into encrypted storage. This is the default speech-to-speech path; if your agent is configured to use the modular pipeline instead, a transcription step and a text-to-speech step are added, as described above. All data is encrypted in transit (TLS 1.2 or higher, and TLS 1.3 on our public web surfaces) and at rest (AES-256).

  1. 1

    Caller

    A customer places a call to your number, or your agent places one to them.

  2. 2

    Telnyx

    Our carrier routes the call on the public telephone network.

  3. 3

    Real-time media

    LiveKit streams the call audio to the AI agent. LiveKit Cloud serves calls today; a LiveKit stack our carrier operates inside its own network remains configured, and which one is live is a routing setting.

  4. 4

    Voice model

    OpenAI Realtime (our default) or Google Gemini listens to the audio and answers in speech, with no separate transcription or synthesis vendor in the path.

  5. 5

    Storage

    Recordings, transcripts, and call metadata are stored encrypted, under the retention settings you control.

At every step

  • Data is encrypted in transit (TLS 1.2 or higher) and at rest (AES-256)
  • Every processor in the path is SOC 2 Type II certified
  • No step trains an AI model on your content

International Transfers

We are a US company and your data is processed in the United States, which for readers outside the US means an international transfer. This section says where the data sits and what legal protections travel with it.

Where Your Data is Processed

  • United States: Our primary infrastructure (Vercel and Neon, US regions on AWS)
  • Service providers: primarily US-based. Each provider's processing location is listed on our Sub-processors page
  • Backup storage: Geographically distributed for redundancy

Data residency: By default, recordings, transcripts, and call metadata are stored in U.S. regions. EU or other regional data residency, and dedicated data-handling arrangements, are available to Enterprise customers on a case-by-case, contractual basis. If your contract requires a specific region, contact support@revdesk.com.

Safeguards for International Transfers

We ensure appropriate safeguards are in place:

  • Standard Contractual Clauses. We rely on the European Commission's SCCs (Decision 2021/914), incorporated into our Data Processing Agreement with RevDesk as data importer, together with the UK International Data Transfer Addendum and the Swiss annex where those apply
  • Transfer impact assessment. Available to customers on request, alongside our record of the supplementary measures we apply
  • Back-to-back terms with sub-processors, so the protections travel with the data rather than stopping at us

EU and UK representatives. Cell Labs, Inc. is established in the United States. If you are in the EEA or the UK and wish to raise a matter with a local representative under GDPR Article 27, contact privacy@revdesk.com and we will put you in touch with the appointed representative for your region. You retain the right to lodge a complaint with your national supervisory authority at any time.

Security and Retention

Safeguards

Rather than promise "industry-standard security" and leave you to guess what that means, here is what we actually do.

  • Encryption everywhere: TLS 1.2 or higher in transit, TLS 1.3 on our public web surfaces, SRTP on real-time media, and AES-256 at rest
  • Access controls: multi-factor authentication, role-based permissions, and least-privilege access for our own staff
  • Infrastructure: the application runs on Vercel, with recordings and files in encrypted Blob storage; the database is managed Postgres on Neon. Both run in US regions on AWS with redundancy and automated encrypted backups
  • Edge protection: a web application firewall, bot detection, and DDoS mitigation in front of every public surface
  • Testing: periodic internal penetration testing, ongoing vulnerability assessment, and a coordinated disclosure program
  • Process: a documented incident response plan, and security review of every vendor before it touches customer data

Compliance Posture

HIPAA: RevDesk supports HIPAA workloads under a signed Business Associate Agreement, and the sub-processors in the call path are BAA-covered. See the HIPAA section for what enabling HIPAA mode actually changes.

SOC 2 Type II: We are actively pursuing SOC 2 Type II certification, with the audit in progress. Our core sub-processors are already SOC 2 Type II certified; each one's certifications are listed on the Sub-processors page.

No security is perfect

No method of transmission or storage is completely secure, and anyone who guarantees otherwise is selling something. If you find a vulnerability, report it to security@revdesk.com and we will take it seriously.

How Long We Keep It

Call recordings and transcripts are kept for 90 days by default, and you can configure that from 7 days to 1 year, or turn storage off. Call metadata is kept for as long as your account is open. After account closure we complete deletion within 90 days.

Retention Periods

  • Call recordings: 90 days by default. Configurable per phone number from 7 days to 1 year, or disabled entirely. An automated job deletes expired audio and transcripts and writes an entry to our deletion audit log
  • Call transcripts: Same period as the recording they belong to
  • HIPAA-enabled workspaces: Turning on HIPAA mode applies a minimum-necessary default of 30 days for call recordings across the workspace's numbers, which you can adjust per number afterwards
  • Account and workspace data: Retained while the account is open
  • Payment records: 7 years, to comply with tax and accounting rules
  • Support communications: 3 years
  • Aggregated analytics: Retained indefinitely. Contains no call content and no directly identifying information

Call records outlive call content

When a recording reaches the end of its retention period, we delete the audio file and the transcript. We keep the call record itself: who called, when, how long it lasted, and how it was dispositioned.

That record is what your billing, campaign statistics, and historical reporting are built from, so removing it would silently rewrite your past invoices and dashboards. It is retained for as long as your workspace exists, and is deleted when the workspace is. Deleting a call from within the app removes the record along with its content.

What Happens After Deletion

When you close your account, or when we delete data at the end of a retention period:

  • Export window: You have 30 days after closure to export your data, and we send reminders during it
  • Deletion: After that window we delete your workspace data from our production systems, completing within 90 days of closure. This matches the timeline in our Data Processing Agreement
  • Stored files: Recordings, voicemail audio, and uploaded files are deleted from object storage at the point of deletion, not on a later cycle
  • Database history: Our managed Postgres keeps a rolling change history that makes point-in-time recovery possible. A deleted row remains theoretically recoverable only inside that window, which is a matter of days and never exceeds 30. Once the window passes the history is discarded permanently. We do not restore it into production to recover deleted customer data
  • Service providers: We instruct our sub-processors to delete the corresponding data
  • Exceptions: We may retain specific records where the law requires it, or to resolve a dispute or prevent fraud, and we retain only what is needed for that purpose

Breach Notification

If a breach affects your data, we contain it, investigate, and tell you what happened, what was affected, and what we are doing about it. The specific deadline depends on which obligation is engaged, so rather than quote one number for everything, here is each one.

Notification Timelines

  • To our customers, as processor: without undue delay, and in any event within 72 hours of becoming aware of a breach affecting data we process on your behalf. This is the commitment in our Data Processing Agreement. Because you are the controller of that data, notifying your own regulators and affected individuals is your call to make, and we give you what you need to make it
  • To supervisory authorities, as controller: within 72 hours of becoming aware, where a breach of data we control is likely to result in a risk to individuals, as GDPR Article 33 requires
  • To individuals, as controller: without undue delay where a breach is likely to result in a high risk to their rights and freedoms
  • Under HIPAA: to affected covered entities within 60 days of discovery, per the Breach Notification Rule
  • Under US state breach laws: within the period each applicable statute prescribes

Where an event is still unconfirmed, we notify the security contact on your account during the investigation rather than waiting for it to conclude.

What the Notice Contains

A notification from us tells you what happened, what data was affected, what the realistic risk to you is, what we have done to contain it, what you should do next, and who to contact with questions. We write it to be acted on, not to minimize.

Your Rights and Regional Laws

Universal Rights

These rights apply to everyone, everywhere. We do not make you work out which statute covers you before honoring the basics.

What You Can Ask Of Us

  • Right to access: Request a copy of all personal data we hold about you
  • Right to correction: Request correction of inaccurate or incomplete data
  • Right to deletion: Request deletion of your personal data (subject to legal obligations)
  • Right to data portability: Export your data in a structured, machine-readable format. Call records and transcripts are available as JSON through our API, and recordings as downloadable audio files. For a full workspace export, email us and we will produce one
  • Right to opt-out of marketing: Unsubscribe from promotional emails (click "unsubscribe" or email us)
  • Right to object: Object to certain data processing activities

How to Exercise Them

Email privacy@revdesk.com from your account address, or include it, and describe what you want. We verify your identity, which protects you from someone else exercising your rights, and respond within 30 days.

Self-Service Data Management

You can manage your data directly in your account:

  • Account settings: Update name, email, phone number, business info
  • Recording controls: Enable/disable call recording and transcription
  • Retention settings: Configure how long recordings are kept (7 days to 1 year, or off)
  • Data export: Download call recordings as audio, and call records and transcripts as JSON through the API
  • Data deletion: Delete individual call recordings or transcripts anytime
  • Account deletion: Permanently delete your entire account and all associated data

GDPR (EU and UK)

For users in the European Union, we comply with the General Data Protection Regulation (GDPR), which grants you additional rights beyond those available to all users.

Additional GDPR Rights

  • Right to data portability: Receive your data in a structured, commonly-used format
  • Right to be forgotten: Request complete deletion of your data (with some exceptions)
  • Right to restrict processing: Limit how we use your data in certain circumstances
  • Right to object to automated decisions: Object to decisions made solely by automated processing (including profiling)
  • Right to lodge a complaint: File a complaint with your national data protection authority

GDPR Inquiries

GDPR requests go to privacy@revdesk.com. We respond within 30 days.

Data Processing Agreement (DPA)

You do not need to request a DPA, and you do not need to wait for one. A complete Article 28 Data Processing Agreement, pre-filled with your organization's details and ready for counter-signature, downloads directly from Settings → Security → Compliance in the app.

It includes the description of processing, our technical and organizational measures, and the sub-processor terms, and it incorporates the EU Standard Contractual Clauses and the UK International Data Transfer Addendum where a transfer requires them, with RevDesk as data importer. Questions about it go to privacy@revdesk.com.

US State Laws

Most US states now have comprehensive privacy laws, and they grant broadly similar rights under different names. Rather than make you work out which statute applies to you, we extend the following rights to residents of every US state that has enacted a consumer privacy law.

Your Rights

  • Know and access: what personal information we have collected, used, and disclosed, the categories of sources and recipients, and our purposes
  • Correct inaccurate personal information
  • Delete personal information we hold about you, subject to statutory exceptions
  • Portability: receive a copy in a portable, machine-readable form
  • Opt out of targeted advertising, of the sale of personal information, and of profiling with legal or similarly significant effects. We do none of these, so there is nothing to opt out of
  • Limit the use of sensitive personal information. We use sensitive information only to provide the service you asked for, which is already the limit the law permits
  • Non-discrimination: we will not degrade your service or charge you more for exercising a right
  • Appeal: if we decline a request, you may appeal, and we will respond in writing with our reasoning

We do not sell or share your personal information

RevDesk does not sell personal information, and does not share it for cross-context behavioral advertising. Both terms are used here as California law defines them, which is broader than an everyday reading of "sell" and captures many ad-tech arrangements involving no money.

We do not run advertising or retargeting pixels on our site or in our product, which is the usual way this obligation gets tripped. We have not sold or shared personal information in the preceding 12 months, and we do not knowingly sell or share the personal information of anyone under 16.

Categories We Collect, and How Long We Keep Them

Collected from you, from your use of the service, and from callers who contact a RevDesk number. Sources and recipients are described in the sections above.

  • Identifiers (name, email, phone number, IP address): kept while your account is open
  • Commercial information (plan, payment history, usage): 7 years for payment records, per tax rules
  • Internet and network activity (usage, device, logs): kept while your account is open
  • Audio and electronic information (call recordings, transcripts, messages): 90 days by default, configurable from 7 days to 1 year, or off
  • Professional or employment information (company, role, business contact details): kept while your account is open
  • Inferences (aggregated usage patterns): retained in aggregate form only

Sensitive personal information. Call recordings and transcripts can contain whatever a caller chooses to say, which may include sensitive details. We do not use that content for any purpose other than providing the service to the customer whose workspace it belongs to, and we never use it to infer characteristics about anyone.

How to Exercise These Rights

  1. Email privacy@revdesk.com describing your request
  2. We verify your identity, to keep someone else from exercising your rights
  3. We respond within 45 days, and may extend once by a further 45 days where needed

Authorized agents may submit a request on your behalf with written permission signed by you, and we may still contact you to confirm. If the data in question belongs to a RevDesk customer's workspace rather than to us, we will route your request to that customer, as described at the top of this policy.

HIPAA

RevDesk supports HIPAA workloads under a signed Business Associate Agreement. Healthcare organizations must execute a BAA with us, and have HIPAA mode enabled on their workspace, before processing Protected Health Information (PHI) through the platform.

A note on the phrase “HIPAA compliant”

No product is certified HIPAA compliant, because no such certification exists. HIPAA compliance is a property of how a covered entity and its business associates operate together. What we can tell you concretely is that we sign BAAs, that our sub-processors in the call path are covered by BAAs, and exactly what the platform does differently once HIPAA mode is on. That is set out below, so you can assess it rather than take a label on trust.

When HIPAA Applies

HIPAA requirements apply when:

  • You are a covered entity or business associate under HIPAA
  • Callers discuss medical conditions, treatments, prescriptions, or other PHI
  • You store, transmit, or process PHI through RevDesk

BAA Required for Healthcare Providers

A signed Business Associate Agreement is required before using RevDesk to handle PHI. The BAA ensures we meet HIPAA security and privacy requirements when processing patient information. We sign BAAs with healthcare customers on request; just email us.

What Turning On HIPAA Mode Does

HIPAA mode is a workspace-level setting that activates once a BAA is signed. It changes platform behavior in specific, checkable ways:

  • Restricts AI model routing to providers covered by a BAA. Models that are not BAA-covered become unselectable, and an existing non-eligible selection is switched to a covered default
  • Routes Gemini through Google Cloud Vertex AI, so inference happens under the Google Cloud BAA rather than the consumer API terms
  • Keeps call content off external egress. Recordings and transcripts are stripped from outbound webhooks and the public API, so PHI stays inside the covered boundary
  • Defaults recording retention to 30 days across the workspace's numbers as a minimum-necessary starting point, adjustable per number afterwards, and recording can be disabled entirely
  • Emits a compliance audit log of the changes made and by whom

What it does not do is narrow the sub-processors that sit outside the call path. Product analytics, error monitoring, and contact enrichment are not BAA-covered, and HIPAA mode does not disable them. We never send call audio, transcripts, or message content to any of them, but the data you choose to put there is yours to keep within your minimum-necessary analysis. In particular, do not run contact enrichment against a record that is PHI.

Safeguards

  • Encryption of all PHI in transit and at rest (AES-256)
  • Role-based access controls, audit logging, and multi-factor authentication
  • BAAs with the sub-processors in the call path, covering telephony and messaging, real-time media, speech-to-text, the voice models, and our hosting and data stores. The current set is listed on our Sub-processors page
  • Breach notification to affected covered entities within 60 days, per the HIPAA Breach Notification Rule

HIPAA mode is a compliance boundary, not a storage switch

A point that is easy to get wrong: enabling HIPAA mode does not stop recordings or transcripts being stored. It ensures that every provider touching call content is BAA-covered, and it tightens the retention default.

Whether call content is recorded and kept at all remains your decision, through your recording and transcript settings. If your minimum-necessary analysis says you should not retain call audio, you must turn recording off yourself.

Requesting a BAA

Email compliance@revdesk.com with subject "HIPAA BAA Request" and your organization name, and we will send our standard BAA for review and execution. Do not send PHI through the platform before the BAA is executed and HIPAA mode is enabled on your workspace.

Consumer Health Data

Washington's My Health My Data Act, Nevada's SB 370, and Connecticut's health-data amendments regulate "consumer health data" far more broadly than HIPAA does. The definition reaches any information that could indicate a person's past, present, or future physical or mental health, including inferences, and it applies to businesses that are not covered entities. Washington's law carries a private right of action.

RevDesk does not collect consumer health data for its own purposes. We do not use it for advertising, we never sell it, and we do not use it to infer anything about anyone. Where such data appears in a customer's call recordings or transcripts, we process it solely as that customer's processor, on their instructions, to provide the service.

If your calls touch on health at all

This catches more businesses than expected. A dental practice confirming an appointment, a veterinary clinic, a gym discussing an injury, or an insurance agency taking a claim can all be handling consumer health data, whether or not HIPAA applies to them.

If that describes you, you likely need a separate consumer-health-data privacy notice and explicit consent from the individual before collecting or sharing that data. Enabling HIPAA mode and signing our BAA is the right starting point, but it does not by itself discharge these state-law obligations.

Voice and Biometrics

RevDesk processes a great deal of recorded speech, so it is fair to ask whether we build voiceprints from it. We do not, and this section states that plainly because several state laws treat voiceprints very differently from ordinary recordings.

We do not create, store, or match voiceprints

We do not use anyone's voice to identify them. Specifically, RevDesk does not:

  • Generate a voiceprint, voice template, or other biometric identifier from call audio
  • Match a voice against any stored template, on our systems or anyone else's
  • Use voice to verify identity, authenticate a caller, or authorize an action
  • Infer age, gender, ethnicity, health, or emotional state from voice characteristics
  • Sell, lease, trade, or otherwise profit from voice data

We also do not permit our AI and speech sub-processors to use call audio for biometric purposes.

What We Do Instead

Speech is converted to text so the AI can understand and respond. Transcripts carry speaker labels, distinguishing the caller from the agent within that one conversation. Those labels are positional, meaning they mark who spoke when inside a single call. They are not derived from vocal characteristics and cannot be used to recognize the same person on a different call.

Once a call ends, the audio and transcript are stored under your retention settings and deleted when those expire. Nothing persists that could function as a biometric template.

Why This Matters Legally

Illinois' Biometric Information Privacy Act, Texas' CUBI, and Washington's biometric statute impose notice, consent, retention-schedule, and deletion requirements on anyone who collects biometric identifiers, and Illinois provides a private right of action. Because we do not collect biometric identifiers, those obligations are not triggered by the platform. If you intend to build voice identification on top of RevDesk, those obligations become yours, and you should get advice before doing so.

Children's Privacy

RevDesk is a business tool, not intended for anyone under 18, and we do not knowingly collect personal information from children. If you are a parent or guardian and believe a child has given us personal information, email privacy@revdesk.com and we will delete it.

One caveat for our customers: minors may call your number, for example a teenager confirming a family appointment. Complying with child-privacy laws such as COPPA for the data in your workspace is your responsibility as its controller.

Cookies and Tracking

We use cookies to keep you signed in, to remember your preferences, and to understand how the product is used. We do not run advertising or retargeting cookies of any kind.

What We Actually Set

  • Essential cookies. Authentication, session management, and security, including protection against cross-site request forgery and automated abuse. The product cannot function without these, so they cannot be turned off.
  • Preference cookies. Your settings, such as light or dark appearance and language.
  • Product analytics, via PostHog. Which pages and features are used, plus browser, device, and an approximate location derived from IP. This tells us what to fix and what to build. No call audio, transcript, or message content is ever sent to PostHog.
  • Affiliate attribution. If you arrive through an affiliate referral link, a cookie records that referral for 90 days so commission can be attributed correctly. See the Affiliate Terms.

What we do not use

  • No advertising, retargeting, or conversion-tracking pixels
  • No Google Analytics, and no Meta, LinkedIn, or other ad-network tags
  • No session-replay or screen-recording tools
  • No sale or sharing of any of this for cross-context behavioral advertising

How to Control Cookies

Most browsers let you refuse or delete cookies through their settings, and doing so is the most direct control available today. Blocking essential cookies will stop parts of RevDesk working.

To opt out of product analytics specifically, or to ask what we hold from it, email privacy@revdesk.com and we will apply the opt-out to your account.

Updates and Contact

Changes

When we change this policy in a way that matters, we email you and post a notice in the product at least 30 days before the change takes effect, so you can read it, ask us about it, or leave before it applies to you. Minor edits, such as clarified wording or a corrected link, just update the version and date at the top of this page.

The version number is there so you can cite exactly which policy was in effect at a given time. Using the service after a change's effective date means the new version governs.

Contact

Questions, concerns, or a rights request: email privacy@revdesk.com. We respond within 30 days, usually much sooner.

Privacy and data-subject requests
privacy@revdesk.com
Compliance and BAAs · Security reports
compliance@revdesk.com · security@revdesk.com
Mail
Cell Labs, Inc.
169 Madison Ave STE 72920
New York, NY 10016
RevDesk
Product
Voice AgentsChat AgentsAugmented SalesNumber RegistrationIntegrationsPricingBook a Demo
Solutions
For AutomotiveFor HealthcareFor Law FirmsFor B2B SaaSFor Home ServicesFor Logistics
Resources
BlogDocumentationChangelogRoadmapSMS SubscribeCase StudiesAffiliate
Company
AboutCareersPartnersBrandContactSecurityTrustStatus

Ask your AI assistant about RevDesk

revdesk.com/llms.txt
© RevDesk™ 2026 · Cell Labs, Inc.Privacy Policy·Terms of Service·Acceptable Use·Sub-processorsRevDesk™ is a trademark of Cell Labs, Inc. All other marks are property of their respective owners.