Privacy Policy
Version 2026.2 · Last updated July 24, 2026
Overview
Who We Are
RevDesk is operated by Cell Labs, Inc. This policy explains how we collect, use, share, and safeguard information in connection with our conversational AI, omnichannel messaging, and automation platform.
If you have questions about anything here, or want to exercise a privacy right, email privacy@revdesk.com.
Our Two Roles
RevDesk is a business platform, and that makes this policy cover two quite different situations. Most of the confusion people have when reading a policy like this comes from mixing them up, so we separate them up front.
When we act for ourselves (we are the "controller")
This covers the data we decide what to do with: your account and profile, billing records, support conversations, and how people use our marketing website. We determine why and how that data is processed, and this policy governs it directly.
Applies to: RevDesk customers, prospects, and website visitors.
When we act for our customer (we are the "processor")
This covers everything that flows through a customer's workspace: call audio and transcripts, messages, contacts and lead lists, and booking details. We do not decide what happens to that data. The customer does, and we act on their instructions. Our obligations to them are set out in our Data Processing Agreement rather than in this policy.
Applies to: callers, contacts, and anyone a RevDesk customer communicates with.
If a business called you using RevDesk
We are not the business that called you, and we cannot tell you why they did. We host the software they used.
To access, correct, or delete what that business holds about you, contact the business directly, since the data is theirs. If you cannot identify or reach them, email privacy@revdesk.com and we will help route your request to the right customer and support them in answering it.
What We Collect
Categories and Sources
We collect information you give us (account details, business info), call data (recordings, transcripts, caller numbers), and technical data (IP address, browser type, usage patterns).
Information You Provide to Us
- Account information: Name, email address, phone number, company name
- Business information: Industry, business hours, preferences, custom prompts
- Payment information: Processed securely through Stripe (we don't store credit card numbers)
- Communication preferences: Notification settings, language preferences
- Support communications: Messages you send us for customer support
Information Collected Automatically
- Call data: Voice recordings, call transcripts, caller phone numbers, call duration, timestamps
- Usage data: Features accessed, actions taken, time spent in the app
- Device information: IP address, browser type and version, operating system, device type
- Log data: Server logs, error logs, performance metrics
- Analytics data: How you interact with our service (via cookies and similar technologies)
Information from Callers
When someone calls your RevDesk number, we may collect:
- Their phone number (caller ID)
- Voice recordings (only if call recordings are enabled in your settings)
- Conversation transcripts (only if transcription is enabled in your settings)
- Any information they provide during the call (names, messages, appointment details)
You Control Call Recording & Transcription
You have full control over call recording and transcription. You can:
- Enable or disable call recording at any time in your account settings
- Delete individual recordings or transcripts whenever you want
- Set custom retention periods (7 days to 1 year, or disabled entirely)
You own the data from your callers. We process it on your behalf to provide the service. You're responsible for informing callers about recording and obtaining necessary consent (see our Terms of Service for details).
SMS Consent
IMPORTANT NOTICE REGARDING TEXT MESSAGING DATA
Cell Labs, Inc. (“we,” “us,” or “our”) DOES NOT share customer opt-in information, including phone numbers and consent records, with any affiliates or third parties for marketing, promotional, or any other purposes unrelated to providing our direct services. All text messaging originator opt-in data is kept strictly confidential.
When you opt in to receive SMS messages from RevDesk, we collect your mobile phone number and consent preferences. This section explains how we handle your SMS-related data.
How We Collect SMS Consent
We collect SMS consent exclusively through our website opt-in form. During signup, you provide your phone number and check an unchecked SMS consent checkbox that reads: “I agree to get appointment reminders and account alerts via text from RevDesk. Msg frequency varies. Msg & data rates may apply. Reply STOP to unsubscribe. Reply HELP for help.” No messages are sent unless you check this box and submit the form.
Limited Sharing for Service Delivery
We share your mobile phone number only with the following service providers, solely to deliver SMS messages on our behalf:
- Telnyx: Our telephony and SMS gateway provider that transmits messages to your phone. Telnyx is contractually prohibited from using your data for any purpose other than message delivery.
These providers receive only the data necessary to deliver your messages and are bound by strict data protection agreements.
Message Frequency & Costs
Message frequency varies based on your account activity and scheduled appointments. Typical users receive 2–10 messages per month. Standard message and data rates may apply based on your mobile carrier plan.
For full details on our SMS program, including opt-in methods, message types, and carrier information, see our SMS Opt-In & Program Information page.
Managing Your SMS Preferences
You can update your SMS preferences or opt out at any time through your account settings, by replying STOP to any message, or by contacting support@revdesk.com. See our SMS Terms and Conditions for complete opt-out instructions.
Consent records and audit
When you (the workspace operator) capture consent for an outbound channel — voice, SMS, or email — RevDesk persists the consent metadata at the contact level: channel, source, timestamp, sender, and use case. When a contact initiates an inbound call or SMS to your workspace, an inbound-initiated opt-in is recorded automatically. These records are exportable from the Compliance Center on the Outreach page and are available for audit, regulatory inquiry, carrier enforcement, or legal claims.
Voice and Recording
By default, new phone numbers in RevDesk have call recording enabled. Our default outbound greeting template opens with a recording disclosure (“just so you know, this call is being recorded”), localized for 50+ languages, and campaigns use that template unless you replace it.
The disclosure is a default, not an enforcement
We want to be precise about this, because getting it wrong has legal consequences for you. RevDesk does not inject a disclosure into your calls. A sentence bolted onto the front of a greeting sounds robotic, so we ship it as the default greeting text rather than as forced audio.
The practical result: if you write your own greeting, or use surfaces that start from a different opener such as the dialer or a test call, the disclosure is present only if you put it there.
Check your greetings. RevDesk surfaces the recommended disclosure phrasing on every greeting-editing screen, and HIPAA-enabled workspaces have the disclosure requirement locked on.
When you (the workspace operator) place outbound calls to recipients in U.S. states that require all-party consent (CA, CT, DE, FL, IL, MA, MD, MI, MT, NV, NH, OR, PA, WA), the Outreach compose UI surfaces an informational banner reminding you to verify the disclosure is part of your greeting. RevDesk persists per-call disclosure attestation so the Compliance Center can report attestation rates over the prior 30 days and you can surface that evidence in an audit.
Callers and Contacts
Much of the personal data on our systems belongs to people who have never heard of RevDesk: callers, contacts, and leads in our customers' workspaces. We hold that data as a processor for the customer, not for ourselves.
Where it comes from:
- From the person directly, when they call or message one of our customers, or fill in a form
- From our customer, when they upload or sync a contact list from their own systems
- From an enrichment provider, when a customer asks us to enrich a contact record with business-contact details sourced from third parties
If you are a RevDesk customer, the Article 14 duty is yours
Where personal data is not obtained from the individual, GDPR Article 14 generally requires the controller to tell them: what you hold, where it came from, why you have it, and what rights they have. That duty sits with you, since you are the controller. It applies to uploaded lists and to enriched attributes alike.
See the enrichment note on our sub-processor page for detail.
If you are one of these individuals and want to see, correct, or delete what is held about you, contact the business you dealt with, because the data is theirs to act on. If you cannot identify or reach them, write to privacy@revdesk.com with whatever detail you have, such as the number that called you and roughly when. We will identify the customer and require them to respond. We will not ignore you on the grounds that you are not our customer.
How We Use Your Data
Purposes and Legal Bases
We use your data to provide the service (answer calls, schedule appointments), send you updates, provide customer support, and comply with legal requirements:
- Provide and maintain our services: Answer calls, transcribe conversations (if enabled), schedule appointments, sync with your integrations
- Process transactions: Manage subscriptions, process payments, send invoices
- Improve our platform: Use anonymized, aggregated usage metrics (not call content) to improve user experience and product features
- Send service communications: Account notifications, billing updates, service announcements
- Provide customer support: Respond to your requests, troubleshoot issues, provide technical assistance
- Analyze usage patterns: Understand how customers use our service to improve user interface and workflows (anonymized data only)
- Detect and prevent fraud: Monitor for abusive or illegal activity, protect against security threats
- Comply with legal obligations: Respond to legal requests, enforce our Terms of Service
- Send marketing communications: Product updates, new features, tips (you can opt out anytime)
Legal Bases for Processing (GDPR)
For EU users, we process your data based on:
- Contract performance: Processing necessary to provide the services you signed up for
- Legitimate interests: Improving our service, preventing fraud, ensuring security
- Consent: Marketing communications (you can withdraw consent anytime)
- Legal compliance: Complying with laws and regulations
AI Processing
Your call audio is carried by our real-time media layer, which runs inside our carrier's own network. Inbound and outbound calls stay there, so the audio never transits a separate real-time cloud. Only browser-bridged calls, where an operator's browser joins the same session as the phone leg, use LiveKit Cloud.
The audio is then processed in one of two ways, depending on how your agent is configured. By default a speech-to-speech model handles the call directly: OpenAI Realtime is our default voice, with Google Gemini selectable as an alternative. These models listen to the audio and answer in speech, so the conversation itself does not pass through a separate transcription or voice-synthesis vendor. Alternatively, our modular voice pipeline uses Deepgram to convert the caller's speech to text, a language model to generate the reply, and a text-to-speech provider — ElevenLabs or Cartesia — to turn that reply back into audio. Audio and transcripts are encrypted in transit (TLS 1.2 or higher) and at rest (AES-256).
Text is still produced, even on the speech-to-speech path. The voice model transcribes the conversation as it goes, and that is where your transcript comes from. On outbound calls we also briefly transcribe whatever answers the phone, which is how the agent tells a person from a voicemail system and avoids talking over someone.
Turning transcripts off means nothing is stored
A voice model has to interpret speech in the moment to hold a conversation at all. That is unavoidable, and it happens inside the model handling your call.
What you control is whether any of it is kept. With transcript saving turned off for your workspace, no transcript is written from any source: not from the voice model, and not from the separate pass we would otherwise run over the recording afterwards. There is nothing to retain, export, or delete, because nothing was stored.
When the Agent Looks Something Up
An agent can do more than talk. When it needs a fact, it calls a tool, and that step is text rather than audio. Depending on what you have enabled, it may check availability, look up or update a contact, retrieve earlier conversation history, search your knowledge base, or search the web.
Knowledge base search is worth describing precisely, because it involves an extra hop. Your knowledge content is split into passages and converted into numeric embeddings using an OpenAI embedding model, and those embeddings are stored in our database. When the agent searches, the search phrase is embedded the same way and matched against your stored passages, and the best matches are handed back to the model as text. If embedding is unavailable, we fall back to a plain text search.
Two things follow. Content you put in a knowledge base, and the phrases the agent searches for, are sent to that embedding provider under the same terms as the rest of our AI processing, which means they are not used to train anyone's models. And if you enable the web search tool, the agent's search phrase leaves our platform to reach a search provider, so treat it as you would any outbound search.
We NEVER Train AI Models with Your Data
RevDesk does NOT use your call recordings, transcripts, or business data to train AI models.
Your conversations and customer data remain completely private. Our AI and voice providers (Google, OpenAI, Anthropic, Deepgram, ElevenLabs, and Cartesia) operate under enterprise API terms that prohibit training on your content. They may retain data temporarily (typically up to 30 days) for abuse monitoring only, then permanently delete it.
Limited exception: We may use anonymized, aggregated analytics (e.g., "average call duration") to improve service quality. This data never contains personally identifiable information or call content.
AI Transparency
RevDesk uses AI to conduct conversations, transcribe and summarize them, and surface suggestions such as which leads look promising. Understanding what that does and does not decide matters.
The AI does not make decisions with legal or similarly significant effects about anyone. It does not determine credit, employment, housing, insurance, healthcare, or access to any service. Its outputs are conversational responses and suggestions to a human operator, who remains the decision-maker. If you have questions about how a suggestion was produced, or want to contest one, contact the business that operates the workspace, or us at privacy@revdesk.com.
Disclosing That the Caller Is AI
A growing number of laws require people to be told they are interacting with an AI rather than a person. California's bot-disclosure law already does. From 2 August 2026, Article 50 of the EU AI Act requires it for AI systems interacting with people in the EU. Several US states have enacted or proposed similar rules.
RevDesk provides localized AI-disclosure phrasing on every greeting-editing screen, so it can be part of how your agent opens a call. As with the recording disclosure, we surface the recommended wording rather than force it into your audio, so deciding whether disclosure is required, and confirming it is actually present in your greeting, is your responsibility.
Security and Retention
Safeguards
We implement industry-standard security measures to protect your data from unauthorized access, disclosure, alteration, or destruction.
Security Measures
- Encryption: All data encrypted in transit (TLS 1.2 or higher, with TLS 1.3 on our public web surfaces and SRTP on real-time media) and at rest (AES-256)
- Access controls: Multi-factor authentication, role-based permissions, least-privilege access
- Infrastructure: Hosted on Vercel (application plus encrypted Blob storage of recordings and files) and Neon (managed Postgres), both running in US regions on AWS, with physical security, redundancy, and automated encrypted backups
- Network security: Firewalls, intrusion detection, DDoS protection
- Security audits: Regular third-party penetration testing and vulnerability assessments
- Staff training: All employees trained on data protection and privacy best practices
- Incident response: Documented procedures for security incidents and data breaches
- Vendor oversight: Security reviews of all third-party service providers
Compliance Posture
HIPAA: RevDesk supports HIPAA workloads under a signed Business Associate Agreement, and the sub-processors in the call path are BAA-covered. See the HIPAA section for what enabling HIPAA mode actually changes.
SOC 2 Type II: We are actively pursuing SOC 2 Type II certification, with the audit in progress. Our core sub-processors are already SOC 2 Type II certified; each one's certifications are listed on the Sub-processors page.
No Security is Perfect
While we implement strong security measures, no method of transmission or storage is 100% secure. We cannot guarantee absolute security. If you become aware of any security vulnerability, please report it to support@revdesk.com.
How Long We Keep It
Call recordings and transcripts are kept for 90 days by default, and you can configure that from 7 days to 1 year, or turn storage off. Call metadata is kept for as long as your account is open. After account closure we complete deletion within 90 days.
Retention Periods
- Call recordings: 90 days by default. Configurable per phone number from 7 days to 1 year, or disabled entirely. An automated job deletes expired audio and transcripts and writes an entry to our deletion audit log
- Call transcripts: Same period as the recording they belong to
- HIPAA-enabled workspaces: Turning on HIPAA mode applies a minimum-necessary default of 30 days for call recordings across the workspace's numbers, which you can adjust per number afterwards
- Account and workspace data: Retained while the account is open
- Payment records: 7 years, to comply with tax and accounting rules
- Support communications: 3 years
- Aggregated analytics: Retained indefinitely. Contains no call content and no directly identifying information
Call records outlive call content
When a recording reaches the end of its retention period, we delete the audio file and the transcript. We keep the call record itself: who called, when, how long it lasted, and how it was dispositioned.
That record is what your billing, campaign statistics, and historical reporting are built from, so removing it would silently rewrite your past invoices and dashboards. It is retained for as long as your workspace exists, and is deleted when the workspace is. Deleting a call from within the app removes the record along with its content.
What Happens After Deletion
When you close your account, or when we delete data at the end of a retention period:
- Export window: You have 30 days after closure to export your data, and we send reminders during it
- Deletion: After that window we delete your workspace data from our production systems, completing within 90 days of closure. This matches the timeline in our Data Processing Agreement
- Stored files: Recordings, voicemail audio, and uploaded files are deleted from object storage at the point of deletion, not on a later cycle
- Database history: Our managed Postgres keeps a rolling change history that makes point-in-time recovery possible. A deleted row remains theoretically recoverable only inside that window, which is a matter of days and never exceeds 30. Once the window passes the history is discarded permanently. We do not restore it into production to recover deleted customer data
- Service providers: We instruct our sub-processors to delete the corresponding data
- Exceptions: We may retain specific records where the law requires it, or to resolve a dispute or prevent fraud, and we retain only what is needed for that purpose
Breach Notification
If a breach affects your data, we contain it, investigate, and tell you what happened, what was affected, and what we are doing about it. The specific deadline depends on which obligation is engaged, so rather than quote one number for everything, here is each one.
Notification Timelines
- To our customers, as processor: without undue delay, and in any event within 72 hours of becoming aware of a breach affecting data we process on your behalf. This is the commitment in our Data Processing Agreement. Because you are the controller of that data, notifying your own regulators and affected individuals is your call to make, and we give you what you need to make it
- To supervisory authorities, as controller: within 72 hours of becoming aware, where a breach of data we control is likely to result in a risk to individuals, as GDPR Article 33 requires
- To individuals, as controller: without undue delay where a breach is likely to result in a high risk to their rights and freedoms
- Under HIPAA: to affected covered entities within 60 days of discovery, per the Breach Notification Rule
- Under US state breach laws: within the period each applicable statute prescribes
Where an event is still unconfirmed, we notify the security contact on your account during the investigation rather than waiting for it to conclude.
What We'll Tell You
Our breach notification will include:
- Nature of the breach: What happened and how it occurred
- Data affected: What types of personal information were compromised
- Potential impact: Risks to your privacy and security
- Our response: Steps we've taken to contain the breach and prevent future incidents
- Your next steps: Recommended actions you should take (e.g., change passwords, monitor accounts)
- Contact information: How to reach us with questions or concerns
Prevention Measures
We take proactive steps to prevent data breaches:
- Regular security audits and penetration testing
- 24/7 security monitoring and intrusion detection
- Employee security training and access controls
- Incident response plan with defined procedures
- Encryption of all sensitive data
Your Rights and Regional Laws
Universal Rights
You can access, correct, delete, or export your data anytime. You can opt out of marketing emails and request restrictions on data processing. Contact us to exercise these rights.
You have the following rights regarding your personal data:
Universal Rights (All Users)
- Right to access: Request a copy of all personal data we hold about you
- Right to correction: Request correction of inaccurate or incomplete data
- Right to deletion: Request deletion of your personal data (subject to legal obligations)
- Right to data portability: Export your data in a structured, machine-readable format. Call records and transcripts are available as JSON through our API, and recordings as downloadable audio files. For a full workspace export, email us and we will produce one
- Right to opt-out of marketing: Unsubscribe from promotional emails (click "unsubscribe" or email us)
- Right to object: Object to certain data processing activities
How to Exercise Your Rights
To exercise any of these rights:
- Email us at support@revdesk.com
- Include your account email and describe your request
- We'll verify your identity and respond within 30 days
Self-Service Data Management
You can manage your data directly in your account:
- Account settings: Update name, email, phone number, business info
- Recording controls: Enable/disable call recording and transcription
- Retention settings: Configure how long recordings are kept (7 days to 1 year, or off)
- Data export: Download call recordings as audio, and call records and transcripts as JSON through the API
- Data deletion: Delete individual call recordings or transcripts anytime
- Account deletion: Permanently delete your entire account and all associated data
GDPR (EU and UK)
For users in the European Union, we comply with the General Data Protection Regulation (GDPR), which grants you additional rights beyond those available to all users.
Additional GDPR Rights
- Right to data portability: Receive your data in a structured, commonly-used format
- Right to be forgotten: Request complete deletion of your data (with some exceptions)
- Right to restrict processing: Limit how we use your data in certain circumstances
- Right to object to automated decisions: Object to decisions made solely by automated processing (including profiling)
- Right to lodge a complaint: File a complaint with your national data protection authority
GDPR Inquiries
For GDPR-related requests and inquiries, please contact us at support@revdesk.com. We'll respond to all GDPR requests within 30 days.
Data Processing Agreement (DPA)
You do not need to request a DPA, and you do not need to wait for one. A complete Article 28 Data Processing Agreement, pre-filled with your organization's details and ready for counter-signature, downloads directly from Settings → Security → Compliance in the app.
It includes the description of processing, our technical and organizational measures, and the sub-processor terms, and it incorporates the EU Standard Contractual Clauses and the UK International Data Transfer Addendum where a transfer requires them, with RevDesk as data importer. Questions about it go to privacy@revdesk.com.
US State Laws
Most US states now have comprehensive privacy laws, and they grant broadly similar rights under different names. Rather than make you work out which statute applies to you, we extend the following rights to residents of every US state that has enacted a consumer privacy law.
Your Rights
- Know and access: what personal information we have collected, used, and disclosed, the categories of sources and recipients, and our purposes
- Correct inaccurate personal information
- Delete personal information we hold about you, subject to statutory exceptions
- Portability: receive a copy in a portable, machine-readable form
- Opt out of targeted advertising, of the sale of personal information, and of profiling with legal or similarly significant effects. We do none of these, so there is nothing to opt out of
- Limit the use of sensitive personal information. We use sensitive information only to provide the service you asked for, which is already the limit the law permits
- Non-discrimination: we will not degrade your service or charge you more for exercising a right
- Appeal: if we decline a request, you may appeal, and we will respond in writing with our reasoning
We do not sell or share your personal information
RevDesk does not sell personal information, and does not share it for cross-context behavioral advertising. Both terms are used here as California law defines them, which is broader than an everyday reading of "sell" and captures many ad-tech arrangements involving no money.
We do not run advertising or retargeting pixels on our site or in our product, which is the usual way this obligation gets tripped. We have not sold or shared personal information in the preceding 12 months, and we do not knowingly sell or share the personal information of anyone under 16.
Categories We Collect, and How Long We Keep Them
Collected from you, from your use of the service, and from callers who contact a RevDesk number. Sources and recipients are described in the sections above.
- Identifiers (name, email, phone number, IP address): kept while your account is open
- Commercial information (plan, payment history, usage): 7 years for payment records, per tax rules
- Internet and network activity (usage, device, logs): kept while your account is open
- Audio and electronic information (call recordings, transcripts, messages): 90 days by default, configurable from 7 days to 1 year, or off
- Professional or employment information (company, role, business contact details): kept while your account is open
- Inferences (aggregated usage patterns): retained in aggregate form only
Sensitive personal information. Call recordings and transcripts can contain whatever a caller chooses to say, which may include sensitive details. We do not use that content for any purpose other than providing the service to the customer whose workspace it belongs to, and we never use it to infer characteristics about anyone.
How to Exercise These Rights
- Email privacy@revdesk.com describing your request
- We verify your identity, to keep someone else from exercising your rights
- We respond within 45 days, and may extend once by a further 45 days where needed
Authorized agents may submit a request on your behalf with written permission signed by you, and we may still contact you to confirm. If the data in question belongs to a RevDesk customer's workspace rather than to us, we will route your request to that customer, as described at the top of this policy.
HIPAA
RevDesk supports HIPAA workloads under a signed Business Associate Agreement. Healthcare organizations must execute a BAA with us, and have HIPAA mode enabled on their workspace, before processing Protected Health Information (PHI) through the platform.
A note on the phrase “HIPAA compliant”
No product is certified HIPAA compliant, because no such certification exists. HIPAA compliance is a property of how a covered entity and its business associates operate together. What we can tell you concretely is that we sign BAAs, that our sub-processors in the call path are covered by BAAs, and exactly what the platform does differently once HIPAA mode is on. That is set out below, so you can assess it rather than take a label on trust.
When HIPAA Applies
HIPAA requirements apply when:
- You are a covered entity or business associate under HIPAA
- Callers discuss medical conditions, treatments, prescriptions, or other PHI
- You store, transmit, or process PHI through RevDesk
BAA Required for Healthcare Providers
A signed Business Associate Agreement is required before using RevDesk to handle PHI. The BAA ensures we meet HIPAA security and privacy requirements when processing patient information. We sign BAAs with healthcare customers on request — just email us.
What Turning On HIPAA Mode Does
HIPAA mode is a workspace-level setting that activates once a BAA is signed. It changes platform behavior in specific, checkable ways:
- Restricts AI model routing to providers covered by a BAA. Models that are not BAA-covered become unselectable, and an existing non-eligible selection is switched to a covered default
- Routes Gemini through Google Cloud Vertex AI, so inference happens under the Google Cloud BAA rather than the consumer API terms
- Excludes Anthropic entirely. It is used only for internal tooling and never appears in the live call path
- Blocks installation of integrations that are not BAA-covered
- Locks the call recording disclosure on so it cannot be switched off for the workspace
- Caps recording retention at 30 days across the workspace's numbers as a minimum-necessary default, adjustable per number afterwards, and recording can be disabled entirely
- Emits a compliance audit log of the changes made and by whom
Safeguards
- Encryption of all PHI in transit and at rest (AES-256)
- Role-based access controls, audit logging, and multi-factor authentication
- BAAs with the sub-processors in the call path, covering telephony and messaging, real-time media, speech-to-text, the voice models, and our hosting and data stores. The current set is listed on our Sub-processors page
- Breach notification to affected covered entities within 60 days, per the HIPAA Breach Notification Rule
HIPAA mode is a compliance boundary, not a storage switch
A point that is easy to get wrong: enabling HIPAA mode does not stop recordings or transcripts being stored. It ensures that every provider touching call content is BAA-covered, and it tightens the retention default.
Whether call content is recorded and kept at all remains your decision, through your recording and transcript settings. If your minimum-necessary analysis says you should not retain call audio, you must turn recording off yourself.
Requesting a BAA
Email compliance@revdesk.com with subject "HIPAA BAA Request" and your organization name, and we will send our standard BAA for review and execution. Do not send PHI through the platform before the BAA is executed and HIPAA mode is enabled on your workspace.
Consumer Health Data
Washington's My Health My Data Act, Nevada's SB 370, and Connecticut's health-data amendments regulate "consumer health data" far more broadly than HIPAA does. The definition reaches any information that could indicate a person's past, present, or future physical or mental health, including inferences, and it applies to businesses that are not covered entities. Washington's law carries a private right of action.
RevDesk does not collect consumer health data for its own purposes. We do not use it for advertising, we never sell it, and we do not use it to infer anything about anyone. Where such data appears in a customer's call recordings or transcripts, we process it solely as that customer's processor, on their instructions, to provide the service.
If your calls touch on health at all
This catches more businesses than expected. A dental practice confirming an appointment, a veterinary clinic, a gym discussing an injury, or an insurance agency taking a claim can all be handling consumer health data, whether or not HIPAA applies to them.
If that describes you, you likely need a separate consumer-health-data privacy notice and explicit consent from the individual before collecting or sharing that data. Enabling HIPAA mode and signing our BAA is the right starting point, but it does not by itself discharge these state-law obligations.
Voice and Biometrics
RevDesk processes a great deal of recorded speech, so it is fair to ask whether we build voiceprints from it. We do not, and this section states that plainly because several state laws treat voiceprints very differently from ordinary recordings.
We do not create, store, or match voiceprints
We do not use anyone's voice to identify them. Specifically, RevDesk does not:
- Generate a voiceprint, voice template, or other biometric identifier from call audio
- Match a voice against any stored template, on our systems or anyone else's
- Use voice to verify identity, authenticate a caller, or authorize an action
- Infer age, gender, ethnicity, health, or emotional state from voice characteristics
- Sell, lease, trade, or otherwise profit from voice data
We also do not permit our AI and speech sub-processors to use call audio for biometric purposes.
What We Do Instead
Speech is converted to text so the AI can understand and respond. Transcripts carry speaker labels, distinguishing the caller from the agent within that one conversation. Those labels are positional, meaning they mark who spoke when inside a single call. They are not derived from vocal characteristics and cannot be used to recognize the same person on a different call.
Once a call ends, the audio and transcript are stored under your retention settings and deleted when those expire. Nothing persists that could function as a biometric template.
Why This Matters Legally
Illinois' Biometric Information Privacy Act, Texas' CUBI, and Washington's biometric statute impose notice, consent, retention-schedule, and deletion requirements on anyone who collects biometric identifiers, and Illinois provides a private right of action. Because we do not collect biometric identifiers, those obligations are not triggered by the platform. If you intend to build voice identification on top of RevDesk, those obligations become yours, and you should get advice before doing so.
Children's Privacy
RevDesk is not intended for anyone under 18. We don't knowingly collect data from children. If we discover we have, we'll delete it immediately.
Our services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us at support@revdesk.com. We will delete such information immediately.
Note: If callers to your RevDesk number include minors (e.g., parents calling about their children), you are responsible for complying with applicable child privacy laws (COPPA, etc.).
Updates and Contact
Changes
We may update this privacy policy from time to time. We will notify you of any material changes by:
- Sending an email to your registered email address
- Posting a notice within the Services
- Updating the "Last updated" date at the top of this page
Your continued use of the Services after changes become effective constitutes acceptance of the updated Privacy Policy.
Notice period: For material changes that affect your rights, we'll provide at least 30 days' advance notice.
Contact
Questions about privacy? Email privacy@revdesk.com or write to us in New York. We respond within 30 days.
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
- Privacy and data-subject requests
- privacy@revdesk.com
- Compliance, BAAs, and security
- compliance@revdesk.com · security@revdesk.com
- Company
- Cell Labs, Inc.
- Location
- 169 Madison Ave STE 72920
New York, NY 10016 - Response Time
- We aim to respond to all privacy requests within 30 days
Note: For privacy inquiries, GDPR requests, HIPAA BAA requests, or general support, please email us at the address above.