RevDesk
  • Pricing
Product
Features
Voice Agents
Answer and make calls that deliver, 24/7.
Omnichannel Messaging
iMessage, WhatsApp, SMS, and email with shared context.
Augmented Sales
Your team calls with AI coaching what to say in realtime.
Campaigns & Sequences
Multi-touch drips that trigger texts and calls
Tools
Referral Network
Route the matters and patients you can't take
Number Registration
Register any number, and we remediate spam via our API
API & MCP
Connect your agents to RevDesk
Solutions
Industries
Automotive
Work every internet lead like your best BDC
Healthcare
Patient follow-up, recall, and referrals
Law Firms
Intake, conflict screening, booked consults
B2B SaaS
Speed-to-lead, trials, and partner links
Home Services
Book more jobs from every call and get more customers
Logistics
Cover loads and carriers around the clock
Coworkers
Speed-to-Lead
Calls new form leads in seconds
Outbound SDR
Works your lists, warms, books
Customer Care
Reviews, referrals, follow-up care
Re-Engage
Wins back dormant pipeline
ReceptionistIncluded
Answers and routes every call, on every plan
Resources
Blog
Field notes from useful AI
Changelog
What’s new in RevDesk
Docs
Platform documentation
Case studies
Stories from leading customers
Trust Center
SOC 2 Type II and HIPAA
Pricing
Sign InGet Started
Sign InGet Started

Privacy Policy

Version 2026.2 · Last updated July 24, 2026

  • Overview

    • Who We Are
    • Our Two Roles
  • What We Collect

  • How We Use Your Data

  • Sharing and Transfers

  • Security and Retention

  • Your Rights and Regional Laws

  • Cookies and Tracking

  • Updates and Contact

Overview

Who We Are

RevDesk is operated by Cell Labs, Inc. This policy explains how we collect, use, share, and safeguard information in connection with our conversational AI, omnichannel messaging, and automation platform.

If you have questions about anything here, or want to exercise a privacy right, email privacy@revdesk.com.

Our Two Roles

RevDesk is a business platform, and that makes this policy cover two quite different situations. Most of the confusion people have when reading a policy like this comes from mixing them up, so we separate them up front.

When we act for ourselves (we are the "controller")

This covers the data we decide what to do with: your account and profile, billing records, support conversations, and how people use our marketing website. We determine why and how that data is processed, and this policy governs it directly.

Applies to: RevDesk customers, prospects, and website visitors.

When we act for our customer (we are the "processor")

This covers everything that flows through a customer's workspace: call audio and transcripts, messages, contacts and lead lists, and booking details. We do not decide what happens to that data. The customer does, and we act on their instructions. Our obligations to them are set out in our Data Processing Agreement rather than in this policy.

Applies to: callers, contacts, and anyone a RevDesk customer communicates with.

If a business called you using RevDesk

We are not the business that called you, and we cannot tell you why they did. We host the software they used.

To access, correct, or delete what that business holds about you, contact the business directly, since the data is theirs. If you cannot identify or reach them, email privacy@revdesk.com and we will help route your request to the right customer and support them in answering it.

What We Collect

Categories and Sources

We collect information you give us (account details, business info), call data (recordings, transcripts, caller numbers), and technical data (IP address, browser type, usage patterns).

Information You Provide to Us

  • Account information: Name, email address, phone number, company name
  • Business information: Industry, business hours, preferences, custom prompts
  • Payment information: Processed securely through Stripe (we don't store credit card numbers)
  • Communication preferences: Notification settings, language preferences
  • Support communications: Messages you send us for customer support

Information Collected Automatically

  • Call data: Voice recordings, call transcripts, caller phone numbers, call duration, timestamps
  • Usage data: Features accessed, actions taken, time spent in the app
  • Device information: IP address, browser type and version, operating system, device type
  • Log data: Server logs, error logs, performance metrics
  • Analytics data: How you interact with our service (via cookies and similar technologies)

Information from Callers

When someone calls your RevDesk number, we may collect:

  • Their phone number (caller ID)
  • Voice recordings (only if call recordings are enabled in your settings)
  • Conversation transcripts (only if transcription is enabled in your settings)
  • Any information they provide during the call (names, messages, appointment details)

You Control Call Recording & Transcription

You have full control over call recording and transcription. You can:

  • Enable or disable call recording at any time in your account settings
  • Delete individual recordings or transcripts whenever you want
  • Set custom retention periods (7 days to 1 year, or disabled entirely)

You own the data from your callers. We process it on your behalf to provide the service. You're responsible for informing callers about recording and obtaining necessary consent (see our Terms of Service for details).

SMS Consent

IMPORTANT NOTICE REGARDING TEXT MESSAGING DATA

Cell Labs, Inc. (“we,” “us,” or “our”) DOES NOT share customer opt-in information, including phone numbers and consent records, with any affiliates or third parties for marketing, promotional, or any other purposes unrelated to providing our direct services. All text messaging originator opt-in data is kept strictly confidential.

When you opt in to receive SMS messages from RevDesk, we collect your mobile phone number and consent preferences. This section explains how we handle your SMS-related data.

How We Collect SMS Consent

We collect SMS consent exclusively through our website opt-in form. During signup, you provide your phone number and check an unchecked SMS consent checkbox that reads: “I agree to get appointment reminders and account alerts via text from RevDesk. Msg frequency varies. Msg & data rates may apply. Reply STOP to unsubscribe. Reply HELP for help.” No messages are sent unless you check this box and submit the form.

Limited Sharing for Service Delivery

We share your mobile phone number only with the following service providers, solely to deliver SMS messages on our behalf:

  • Telnyx: Our telephony and SMS gateway provider that transmits messages to your phone. Telnyx is contractually prohibited from using your data for any purpose other than message delivery.

These providers receive only the data necessary to deliver your messages and are bound by strict data protection agreements.

Message Frequency & Costs

Message frequency varies based on your account activity and scheduled appointments. Typical users receive 2–10 messages per month. Standard message and data rates may apply based on your mobile carrier plan.

For full details on our SMS program, including opt-in methods, message types, and carrier information, see our SMS Opt-In & Program Information page.

Managing Your SMS Preferences

You can update your SMS preferences or opt out at any time through your account settings, by replying STOP to any message, or by contacting support@revdesk.com. See our SMS Terms and Conditions for complete opt-out instructions.

Consent records and audit

When you (the workspace operator) capture consent for an outbound channel — voice, SMS, or email — RevDesk persists the consent metadata at the contact level: channel, source, timestamp, sender, and use case. When a contact initiates an inbound call or SMS to your workspace, an inbound-initiated opt-in is recorded automatically. These records are exportable from the Compliance Center on the Outreach page and are available for audit, regulatory inquiry, carrier enforcement, or legal claims.

Voice and Recording

By default, new phone numbers in RevDesk have call recording enabled. Our default outbound greeting template opens with a recording disclosure (“just so you know, this call is being recorded”), localized for 50+ languages, and campaigns use that template unless you replace it.

The disclosure is a default, not an enforcement

We want to be precise about this, because getting it wrong has legal consequences for you. RevDesk does not inject a disclosure into your calls. A sentence bolted onto the front of a greeting sounds robotic, so we ship it as the default greeting text rather than as forced audio.

The practical result: if you write your own greeting, or use surfaces that start from a different opener such as the dialer or a test call, the disclosure is present only if you put it there.

Check your greetings. RevDesk surfaces the recommended disclosure phrasing on every greeting-editing screen, and HIPAA-enabled workspaces have the disclosure requirement locked on.

When you (the workspace operator) place outbound calls to recipients in U.S. states that require all-party consent (CA, CT, DE, FL, IL, MA, MD, MI, MT, NV, NH, OR, PA, WA), the Outreach compose UI surfaces an informational banner reminding you to verify the disclosure is part of your greeting. RevDesk persists per-call disclosure attestation so the Compliance Center can report attestation rates over the prior 30 days and you can surface that evidence in an audit.

Callers and Contacts

Much of the personal data on our systems belongs to people who have never heard of RevDesk: callers, contacts, and leads in our customers' workspaces. We hold that data as a processor for the customer, not for ourselves.

Where it comes from:

  • From the person directly, when they call or message one of our customers, or fill in a form
  • From our customer, when they upload or sync a contact list from their own systems
  • From an enrichment provider, when a customer asks us to enrich a contact record with business-contact details sourced from third parties

If you are a RevDesk customer, the Article 14 duty is yours

Where personal data is not obtained from the individual, GDPR Article 14 generally requires the controller to tell them: what you hold, where it came from, why you have it, and what rights they have. That duty sits with you, since you are the controller. It applies to uploaded lists and to enriched attributes alike.

See the enrichment note on our sub-processor page for detail.

If you are one of these individuals and want to see, correct, or delete what is held about you, contact the business you dealt with, because the data is theirs to act on. If you cannot identify or reach them, write to privacy@revdesk.com with whatever detail you have, such as the number that called you and roughly when. We will identify the customer and require them to respond. We will not ignore you on the grounds that you are not our customer.

How We Use Your Data

Purposes and Legal Bases

We use your data to provide the service (answer calls, schedule appointments), send you updates, provide customer support, and comply with legal requirements:

  • Provide and maintain our services: Answer calls, transcribe conversations (if enabled), schedule appointments, sync with your integrations
  • Process transactions: Manage subscriptions, process payments, send invoices
  • Improve our platform: Use anonymized, aggregated usage metrics (not call content) to improve user experience and product features
  • Send service communications: Account notifications, billing updates, service announcements
  • Provide customer support: Respond to your requests, troubleshoot issues, provide technical assistance
  • Analyze usage patterns: Understand how customers use our service to improve user interface and workflows (anonymized data only)
  • Detect and prevent fraud: Monitor for abusive or illegal activity, protect against security threats
  • Comply with legal obligations: Respond to legal requests, enforce our Terms of Service
  • Send marketing communications: Product updates, new features, tips (you can opt out anytime)

Legal Bases for Processing (GDPR)

For EU users, we process your data based on:

  • Contract performance: Processing necessary to provide the services you signed up for
  • Legitimate interests: Improving our service, preventing fraud, ensuring security
  • Consent: Marketing communications (you can withdraw consent anytime)
  • Legal compliance: Complying with laws and regulations

AI Processing

Your call audio is carried by our real-time media layer, which runs inside our carrier's own network. Inbound and outbound calls stay there, so the audio never transits a separate real-time cloud. Only browser-bridged calls, where an operator's browser joins the same session as the phone leg, use LiveKit Cloud.

The audio is then processed in one of two ways, depending on how your agent is configured. By default a speech-to-speech model handles the call directly: OpenAI Realtime is our default voice, with Google Gemini selectable as an alternative. These models listen to the audio and answer in speech, so the conversation itself does not pass through a separate transcription or voice-synthesis vendor. Alternatively, our modular voice pipeline uses Deepgram to convert the caller's speech to text, a language model to generate the reply, and a text-to-speech provider — ElevenLabs or Cartesia — to turn that reply back into audio. Audio and transcripts are encrypted in transit (TLS 1.2 or higher) and at rest (AES-256).

Text is still produced, even on the speech-to-speech path. The voice model transcribes the conversation as it goes, and that is where your transcript comes from. On outbound calls we also briefly transcribe whatever answers the phone, which is how the agent tells a person from a voicemail system and avoids talking over someone.

Turning transcripts off means nothing is stored

A voice model has to interpret speech in the moment to hold a conversation at all. That is unavoidable, and it happens inside the model handling your call.

What you control is whether any of it is kept. With transcript saving turned off for your workspace, no transcript is written from any source: not from the voice model, and not from the separate pass we would otherwise run over the recording afterwards. There is nothing to retain, export, or delete, because nothing was stored.

When the Agent Looks Something Up

An agent can do more than talk. When it needs a fact, it calls a tool, and that step is text rather than audio. Depending on what you have enabled, it may check availability, look up or update a contact, retrieve earlier conversation history, search your knowledge base, or search the web.

Knowledge base search is worth describing precisely, because it involves an extra hop. Your knowledge content is split into passages and converted into numeric embeddings using an OpenAI embedding model, and those embeddings are stored in our database. When the agent searches, the search phrase is embedded the same way and matched against your stored passages, and the best matches are handed back to the model as text. If embedding is unavailable, we fall back to a plain text search.

Two things follow. Content you put in a knowledge base, and the phrases the agent searches for, are sent to that embedding provider under the same terms as the rest of our AI processing, which means they are not used to train anyone's models. And if you enable the web search tool, the agent's search phrase leaves our platform to reach a search provider, so treat it as you would any outbound search.

We NEVER Train AI Models with Your Data

RevDesk does NOT use your call recordings, transcripts, or business data to train AI models.

Your conversations and customer data remain completely private. Our AI and voice providers (Google, OpenAI, Anthropic, Deepgram, ElevenLabs, and Cartesia) operate under enterprise API terms that prohibit training on your content. They may retain data temporarily (typically up to 30 days) for abuse monitoring only, then permanently delete it.

Limited exception: We may use anonymized, aggregated analytics (e.g., "average call duration") to improve service quality. This data never contains personally identifiable information or call content.

AI Transparency

RevDesk uses AI to conduct conversations, transcribe and summarize them, and surface suggestions such as which leads look promising. Understanding what that does and does not decide matters.

The AI does not make decisions with legal or similarly significant effects about anyone. It does not determine credit, employment, housing, insurance, healthcare, or access to any service. Its outputs are conversational responses and suggestions to a human operator, who remains the decision-maker. If you have questions about how a suggestion was produced, or want to contest one, contact the business that operates the workspace, or us at privacy@revdesk.com.

Disclosing That the Caller Is AI

A growing number of laws require people to be told they are interacting with an AI rather than a person. California's bot-disclosure law already does. From 2 August 2026, Article 50 of the EU AI Act requires it for AI systems interacting with people in the EU. Several US states have enacted or proposed similar rules.

RevDesk provides localized AI-disclosure phrasing on every greeting-editing screen, so it can be part of how your agent opens a call. As with the recording disclosure, we surface the recommended wording rather than force it into your audio, so deciding whether disclosure is required, and confirming it is actually present in your greeting, is your responsibility.

Sharing and Transfers

Service Providers

We do not sell your personal information. We share data only with trusted service providers necessary to operate our platform.

Service Providers (Data Processors)

We engage third-party providers to operate the platform, spanning telephony and messaging, real-time media, AI models and voice synthesis, hosting and storage, payments, email, and product analytics. Each receives only the data it needs for its function, under a written contract imposing data-protection obligations no less protective than those we owe you, and we remain responsible to you for their performance.

The full list lives on its own page

Every provider, what each one receives, where it processes data, and its certifications are published at revdesk.com/subprocessors.

We keep it there rather than in this policy on purpose. The list is versioned and dated, so you can tell exactly which providers were engaged at any point in time, and we can give you the 30 days' advance notice of a change that our Data Processing Agreement requires without amending this policy each time. You may object to a new sub-processor on reasonable data-protection grounds during that window.

Other Sharing Scenarios

We may also share your data:

  • With your consent: When you explicitly agree to share your data (e.g., enabling CRM integrations)
  • For legal compliance: When required by law, court order, subpoena, or government request
  • In business transfers: If we're acquired or merge with another company, your data may transfer to the new entity
  • To protect rights and safety: To enforce our Terms, protect against fraud, or ensure user safety

Google Account Permissions

When you sign in with Google or connect a Google integration, RevDesk requests only the OAuth scopes needed for the feature you're enabling. RevDesk's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Your Google data is used only to provide the user-facing feature you authorized, never sold, and never used to train AI models.

Scopes We Request

  • userinfo.profile and userinfo.email: Required for Google sign-in. We use your name, email, and profile picture to identify your account.
  • calendar.events and calendar.readonly: Requested only if you connect Google Calendar as an individual user. Used to read your availability and create, update, or cancel events for bookings made through RevDesk. Google Meet links are generated automatically through the Calendar API and do not require an additional scope.
  • calendar (full): Requested only when a Google Workspace administrator enables domain-wide delegation for their organization. Used by RevDesk's service account to read availability and manage bookings on behalf of users in the Workspace, exactly as the administrator authorizes in their Google Workspace Admin Console. Individual users connecting their own Calendar do not grant this scope.
  • drive.file: Requested only if you connect the Google Sheets integration. Grants per-file access to the specific spreadsheets you select via the Google Picker, which we use to read and write call data. We do not list, browse, or read any other files in your Drive.

Scopes We Do NOT Request

RevDesk does not request any of the following:

  • Gmail (read, send, or modify)
  • Google Drive write or full-Drive access
  • Google Workspace Admin Directory (user lists, customer info)
  • Contacts, Photos, YouTube, or any other Google service

Token Storage and Revocation

OAuth refresh tokens are encrypted at rest and used only to maintain the connection you authorized. You can revoke RevDesk's access at any time from your Google Account permissions page or by disconnecting the integration in your RevDesk settings. Disconnecting removes the stored token immediately.

Data Flow

Each step below shows where your data goes during a call — from the caller, through our carrier and real-time media layer, to the voice model, then into encrypted storage. This is the default speech-to-speech path; if your agent is configured to use the modular pipeline instead, a transcription step and a text-to-speech step are added, as described above. All data is encrypted in transit (TLS 1.2 or higher, and TLS 1.3 on our public web surfaces) and at rest (AES-256).

Caller

Customer places a call to your number

Telnyx

Routes the PSTN call and provides telephony infrastructure

Real-time media

Streams the call audio to the AI agent, on the stack our carrier runs inside its own network. Only browser-bridged calls use LiveKit Cloud.

Voice model

OpenAI Realtime (default) or Google Gemini listens to the audio and answers in speech, with no separate transcription or synthesis step

Storage

Call recordings, transcripts, and metadata stored securely

Data Protection

  • ✓All data encrypted in transit (TLS 1.3) and at rest (AES-256)
  • ✓Third-party processors are SOC 2 Type II certified
  • ✓Regular security audits and penetration testing
  • ✓GDPR and CCPA compliant data handling procedures

International Transfers

Your data may be processed in the United States and other countries where our service providers operate. We ensure appropriate safeguards are in place for international transfers (Standard Contractual Clauses, etc.).

Your information may be transferred to and processed in countries other than your country of residence, including the United States.

Where Your Data is Processed

  • United States: Our primary infrastructure (Vercel and Neon, US regions on AWS)
  • Service providers: primarily US-based. Each provider's processing location is listed on our Sub-processors page
  • Backup storage: Geographically distributed for redundancy

Data residency: By default, recordings, transcripts, and call metadata are stored in U.S. regions. EU or other regional data residency, and dedicated data-handling arrangements, are available to Enterprise customers on a case-by-case, contractual basis. If your contract requires a specific region, contact support@revdesk.com.

Safeguards for International Transfers

We ensure appropriate safeguards are in place:

  • Standard Contractual Clauses. We rely on the European Commission's SCCs (Decision 2021/914), incorporated into our Data Processing Agreement with RevDesk as data importer, together with the UK International Data Transfer Addendum and the Swiss annex where those apply
  • Transfer impact assessment. Available to customers on request, alongside our record of the supplementary measures we apply
  • Back-to-back terms with sub-processors, so the protections travel with the data rather than stopping at us

EU and UK representatives. Cell Labs, Inc. is established in the United States. If you are in the EEA or the UK and wish to raise a matter with a local representative under GDPR Article 27, contact privacy@revdesk.com and we will put you in touch with the appointed representative for your region. You retain the right to lodge a complaint with your national supervisory authority at any time.

If you have questions or concerns about international data transfers, contact support@revdesk.com.

Security and Retention

Safeguards

We implement industry-standard security measures to protect your data from unauthorized access, disclosure, alteration, or destruction.

Security Measures

  • Encryption: All data encrypted in transit (TLS 1.2 or higher, with TLS 1.3 on our public web surfaces and SRTP on real-time media) and at rest (AES-256)
  • Access controls: Multi-factor authentication, role-based permissions, least-privilege access
  • Infrastructure: Hosted on Vercel (application plus encrypted Blob storage of recordings and files) and Neon (managed Postgres), both running in US regions on AWS, with physical security, redundancy, and automated encrypted backups
  • Network security: Firewalls, intrusion detection, DDoS protection
  • Security audits: Regular third-party penetration testing and vulnerability assessments
  • Staff training: All employees trained on data protection and privacy best practices
  • Incident response: Documented procedures for security incidents and data breaches
  • Vendor oversight: Security reviews of all third-party service providers

Compliance Posture

HIPAA: RevDesk supports HIPAA workloads under a signed Business Associate Agreement, and the sub-processors in the call path are BAA-covered. See the HIPAA section for what enabling HIPAA mode actually changes.

SOC 2 Type II: We are actively pursuing SOC 2 Type II certification, with the audit in progress. Our core sub-processors are already SOC 2 Type II certified; each one's certifications are listed on the Sub-processors page.

No Security is Perfect

While we implement strong security measures, no method of transmission or storage is 100% secure. We cannot guarantee absolute security. If you become aware of any security vulnerability, please report it to support@revdesk.com.

How Long We Keep It

Call recordings and transcripts are kept for 90 days by default, and you can configure that from 7 days to 1 year, or turn storage off. Call metadata is kept for as long as your account is open. After account closure we complete deletion within 90 days.

Retention Periods

  • Call recordings: 90 days by default. Configurable per phone number from 7 days to 1 year, or disabled entirely. An automated job deletes expired audio and transcripts and writes an entry to our deletion audit log
  • Call transcripts: Same period as the recording they belong to
  • HIPAA-enabled workspaces: Turning on HIPAA mode applies a minimum-necessary default of 30 days for call recordings across the workspace's numbers, which you can adjust per number afterwards
  • Account and workspace data: Retained while the account is open
  • Payment records: 7 years, to comply with tax and accounting rules
  • Support communications: 3 years
  • Aggregated analytics: Retained indefinitely. Contains no call content and no directly identifying information

Call records outlive call content

When a recording reaches the end of its retention period, we delete the audio file and the transcript. We keep the call record itself: who called, when, how long it lasted, and how it was dispositioned.

That record is what your billing, campaign statistics, and historical reporting are built from, so removing it would silently rewrite your past invoices and dashboards. It is retained for as long as your workspace exists, and is deleted when the workspace is. Deleting a call from within the app removes the record along with its content.

What Happens After Deletion

When you close your account, or when we delete data at the end of a retention period:

  • Export window: You have 30 days after closure to export your data, and we send reminders during it
  • Deletion: After that window we delete your workspace data from our production systems, completing within 90 days of closure. This matches the timeline in our Data Processing Agreement
  • Stored files: Recordings, voicemail audio, and uploaded files are deleted from object storage at the point of deletion, not on a later cycle
  • Database history: Our managed Postgres keeps a rolling change history that makes point-in-time recovery possible. A deleted row remains theoretically recoverable only inside that window, which is a matter of days and never exceeds 30. Once the window passes the history is discarded permanently. We do not restore it into production to recover deleted customer data
  • Service providers: We instruct our sub-processors to delete the corresponding data
  • Exceptions: We may retain specific records where the law requires it, or to resolve a dispute or prevent fraud, and we retain only what is needed for that purpose

Breach Notification

If a breach affects your data, we contain it, investigate, and tell you what happened, what was affected, and what we are doing about it. The specific deadline depends on which obligation is engaged, so rather than quote one number for everything, here is each one.

Notification Timelines

  • To our customers, as processor: without undue delay, and in any event within 72 hours of becoming aware of a breach affecting data we process on your behalf. This is the commitment in our Data Processing Agreement. Because you are the controller of that data, notifying your own regulators and affected individuals is your call to make, and we give you what you need to make it
  • To supervisory authorities, as controller: within 72 hours of becoming aware, where a breach of data we control is likely to result in a risk to individuals, as GDPR Article 33 requires
  • To individuals, as controller: without undue delay where a breach is likely to result in a high risk to their rights and freedoms
  • Under HIPAA: to affected covered entities within 60 days of discovery, per the Breach Notification Rule
  • Under US state breach laws: within the period each applicable statute prescribes

Where an event is still unconfirmed, we notify the security contact on your account during the investigation rather than waiting for it to conclude.

What We'll Tell You

Our breach notification will include:

  • Nature of the breach: What happened and how it occurred
  • Data affected: What types of personal information were compromised
  • Potential impact: Risks to your privacy and security
  • Our response: Steps we've taken to contain the breach and prevent future incidents
  • Your next steps: Recommended actions you should take (e.g., change passwords, monitor accounts)
  • Contact information: How to reach us with questions or concerns

Prevention Measures

We take proactive steps to prevent data breaches:

  • Regular security audits and penetration testing
  • 24/7 security monitoring and intrusion detection
  • Employee security training and access controls
  • Incident response plan with defined procedures
  • Encryption of all sensitive data

Your Rights and Regional Laws

Universal Rights

You can access, correct, delete, or export your data anytime. You can opt out of marketing emails and request restrictions on data processing. Contact us to exercise these rights.

You have the following rights regarding your personal data:

Universal Rights (All Users)

  • Right to access: Request a copy of all personal data we hold about you
  • Right to correction: Request correction of inaccurate or incomplete data
  • Right to deletion: Request deletion of your personal data (subject to legal obligations)
  • Right to data portability: Export your data in a structured, machine-readable format. Call records and transcripts are available as JSON through our API, and recordings as downloadable audio files. For a full workspace export, email us and we will produce one
  • Right to opt-out of marketing: Unsubscribe from promotional emails (click "unsubscribe" or email us)
  • Right to object: Object to certain data processing activities

How to Exercise Your Rights

To exercise any of these rights:

  1. Email us at support@revdesk.com
  2. Include your account email and describe your request
  3. We'll verify your identity and respond within 30 days

Self-Service Data Management

You can manage your data directly in your account:

  • Account settings: Update name, email, phone number, business info
  • Recording controls: Enable/disable call recording and transcription
  • Retention settings: Configure how long recordings are kept (7 days to 1 year, or off)
  • Data export: Download call recordings as audio, and call records and transcripts as JSON through the API
  • Data deletion: Delete individual call recordings or transcripts anytime
  • Account deletion: Permanently delete your entire account and all associated data

GDPR (EU and UK)

For users in the European Union, we comply with the General Data Protection Regulation (GDPR), which grants you additional rights beyond those available to all users.

Additional GDPR Rights

  • Right to data portability: Receive your data in a structured, commonly-used format
  • Right to be forgotten: Request complete deletion of your data (with some exceptions)
  • Right to restrict processing: Limit how we use your data in certain circumstances
  • Right to object to automated decisions: Object to decisions made solely by automated processing (including profiling)
  • Right to lodge a complaint: File a complaint with your national data protection authority

GDPR Inquiries

For GDPR-related requests and inquiries, please contact us at support@revdesk.com. We'll respond to all GDPR requests within 30 days.

Data Processing Agreement (DPA)

You do not need to request a DPA, and you do not need to wait for one. A complete Article 28 Data Processing Agreement, pre-filled with your organization's details and ready for counter-signature, downloads directly from Settings → Security → Compliance in the app.

It includes the description of processing, our technical and organizational measures, and the sub-processor terms, and it incorporates the EU Standard Contractual Clauses and the UK International Data Transfer Addendum where a transfer requires them, with RevDesk as data importer. Questions about it go to privacy@revdesk.com.

US State Laws

Most US states now have comprehensive privacy laws, and they grant broadly similar rights under different names. Rather than make you work out which statute applies to you, we extend the following rights to residents of every US state that has enacted a consumer privacy law.

Your Rights

  • Know and access: what personal information we have collected, used, and disclosed, the categories of sources and recipients, and our purposes
  • Correct inaccurate personal information
  • Delete personal information we hold about you, subject to statutory exceptions
  • Portability: receive a copy in a portable, machine-readable form
  • Opt out of targeted advertising, of the sale of personal information, and of profiling with legal or similarly significant effects. We do none of these, so there is nothing to opt out of
  • Limit the use of sensitive personal information. We use sensitive information only to provide the service you asked for, which is already the limit the law permits
  • Non-discrimination: we will not degrade your service or charge you more for exercising a right
  • Appeal: if we decline a request, you may appeal, and we will respond in writing with our reasoning

We do not sell or share your personal information

RevDesk does not sell personal information, and does not share it for cross-context behavioral advertising. Both terms are used here as California law defines them, which is broader than an everyday reading of "sell" and captures many ad-tech arrangements involving no money.

We do not run advertising or retargeting pixels on our site or in our product, which is the usual way this obligation gets tripped. We have not sold or shared personal information in the preceding 12 months, and we do not knowingly sell or share the personal information of anyone under 16.

Categories We Collect, and How Long We Keep Them

Collected from you, from your use of the service, and from callers who contact a RevDesk number. Sources and recipients are described in the sections above.

  • Identifiers (name, email, phone number, IP address): kept while your account is open
  • Commercial information (plan, payment history, usage): 7 years for payment records, per tax rules
  • Internet and network activity (usage, device, logs): kept while your account is open
  • Audio and electronic information (call recordings, transcripts, messages): 90 days by default, configurable from 7 days to 1 year, or off
  • Professional or employment information (company, role, business contact details): kept while your account is open
  • Inferences (aggregated usage patterns): retained in aggregate form only

Sensitive personal information. Call recordings and transcripts can contain whatever a caller chooses to say, which may include sensitive details. We do not use that content for any purpose other than providing the service to the customer whose workspace it belongs to, and we never use it to infer characteristics about anyone.

How to Exercise These Rights

  1. Email privacy@revdesk.com describing your request
  2. We verify your identity, to keep someone else from exercising your rights
  3. We respond within 45 days, and may extend once by a further 45 days where needed

Authorized agents may submit a request on your behalf with written permission signed by you, and we may still contact you to confirm. If the data in question belongs to a RevDesk customer's workspace rather than to us, we will route your request to that customer, as described at the top of this policy.

HIPAA

RevDesk supports HIPAA workloads under a signed Business Associate Agreement. Healthcare organizations must execute a BAA with us, and have HIPAA mode enabled on their workspace, before processing Protected Health Information (PHI) through the platform.

A note on the phrase “HIPAA compliant”

No product is certified HIPAA compliant, because no such certification exists. HIPAA compliance is a property of how a covered entity and its business associates operate together. What we can tell you concretely is that we sign BAAs, that our sub-processors in the call path are covered by BAAs, and exactly what the platform does differently once HIPAA mode is on. That is set out below, so you can assess it rather than take a label on trust.

When HIPAA Applies

HIPAA requirements apply when:

  • You are a covered entity or business associate under HIPAA
  • Callers discuss medical conditions, treatments, prescriptions, or other PHI
  • You store, transmit, or process PHI through RevDesk

BAA Required for Healthcare Providers

A signed Business Associate Agreement is required before using RevDesk to handle PHI. The BAA ensures we meet HIPAA security and privacy requirements when processing patient information. We sign BAAs with healthcare customers on request — just email us.

What Turning On HIPAA Mode Does

HIPAA mode is a workspace-level setting that activates once a BAA is signed. It changes platform behavior in specific, checkable ways:

  • Restricts AI model routing to providers covered by a BAA. Models that are not BAA-covered become unselectable, and an existing non-eligible selection is switched to a covered default
  • Routes Gemini through Google Cloud Vertex AI, so inference happens under the Google Cloud BAA rather than the consumer API terms
  • Excludes Anthropic entirely. It is used only for internal tooling and never appears in the live call path
  • Blocks installation of integrations that are not BAA-covered
  • Locks the call recording disclosure on so it cannot be switched off for the workspace
  • Caps recording retention at 30 days across the workspace's numbers as a minimum-necessary default, adjustable per number afterwards, and recording can be disabled entirely
  • Emits a compliance audit log of the changes made and by whom

Safeguards

  • Encryption of all PHI in transit and at rest (AES-256)
  • Role-based access controls, audit logging, and multi-factor authentication
  • BAAs with the sub-processors in the call path, covering telephony and messaging, real-time media, speech-to-text, the voice models, and our hosting and data stores. The current set is listed on our Sub-processors page
  • Breach notification to affected covered entities within 60 days, per the HIPAA Breach Notification Rule

HIPAA mode is a compliance boundary, not a storage switch

A point that is easy to get wrong: enabling HIPAA mode does not stop recordings or transcripts being stored. It ensures that every provider touching call content is BAA-covered, and it tightens the retention default.

Whether call content is recorded and kept at all remains your decision, through your recording and transcript settings. If your minimum-necessary analysis says you should not retain call audio, you must turn recording off yourself.

Requesting a BAA

Email compliance@revdesk.com with subject "HIPAA BAA Request" and your organization name, and we will send our standard BAA for review and execution. Do not send PHI through the platform before the BAA is executed and HIPAA mode is enabled on your workspace.

Consumer Health Data

Washington's My Health My Data Act, Nevada's SB 370, and Connecticut's health-data amendments regulate "consumer health data" far more broadly than HIPAA does. The definition reaches any information that could indicate a person's past, present, or future physical or mental health, including inferences, and it applies to businesses that are not covered entities. Washington's law carries a private right of action.

RevDesk does not collect consumer health data for its own purposes. We do not use it for advertising, we never sell it, and we do not use it to infer anything about anyone. Where such data appears in a customer's call recordings or transcripts, we process it solely as that customer's processor, on their instructions, to provide the service.

If your calls touch on health at all

This catches more businesses than expected. A dental practice confirming an appointment, a veterinary clinic, a gym discussing an injury, or an insurance agency taking a claim can all be handling consumer health data, whether or not HIPAA applies to them.

If that describes you, you likely need a separate consumer-health-data privacy notice and explicit consent from the individual before collecting or sharing that data. Enabling HIPAA mode and signing our BAA is the right starting point, but it does not by itself discharge these state-law obligations.

Voice and Biometrics

RevDesk processes a great deal of recorded speech, so it is fair to ask whether we build voiceprints from it. We do not, and this section states that plainly because several state laws treat voiceprints very differently from ordinary recordings.

We do not create, store, or match voiceprints

We do not use anyone's voice to identify them. Specifically, RevDesk does not:

  • Generate a voiceprint, voice template, or other biometric identifier from call audio
  • Match a voice against any stored template, on our systems or anyone else's
  • Use voice to verify identity, authenticate a caller, or authorize an action
  • Infer age, gender, ethnicity, health, or emotional state from voice characteristics
  • Sell, lease, trade, or otherwise profit from voice data

We also do not permit our AI and speech sub-processors to use call audio for biometric purposes.

What We Do Instead

Speech is converted to text so the AI can understand and respond. Transcripts carry speaker labels, distinguishing the caller from the agent within that one conversation. Those labels are positional, meaning they mark who spoke when inside a single call. They are not derived from vocal characteristics and cannot be used to recognize the same person on a different call.

Once a call ends, the audio and transcript are stored under your retention settings and deleted when those expire. Nothing persists that could function as a biometric template.

Why This Matters Legally

Illinois' Biometric Information Privacy Act, Texas' CUBI, and Washington's biometric statute impose notice, consent, retention-schedule, and deletion requirements on anyone who collects biometric identifiers, and Illinois provides a private right of action. Because we do not collect biometric identifiers, those obligations are not triggered by the platform. If you intend to build voice identification on top of RevDesk, those obligations become yours, and you should get advice before doing so.

Children's Privacy

RevDesk is not intended for anyone under 18. We don't knowingly collect data from children. If we discover we have, we'll delete it immediately.

Our services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children.

If you are a parent or guardian and believe your child has provided us with personal information, please contact us at support@revdesk.com. We will delete such information immediately.

Note: If callers to your RevDesk number include minors (e.g., parents calling about their children), you are responsible for complying with applicable child privacy laws (COPPA, etc.).

Cookies and Tracking

We use cookies to keep you signed in, to remember your preferences, and to understand how the product is used. We do not run advertising or retargeting cookies of any kind.

What We Actually Set

  • Essential cookies. Authentication, session management, and security, including protection against cross-site request forgery and automated abuse. The product cannot function without these, so they cannot be turned off.
  • Preference cookies. Your settings, such as light or dark appearance and language.
  • Product analytics, via PostHog. Which pages and features are used, plus browser, device, and an approximate location derived from IP. This tells us what to fix and what to build. No call audio, transcript, or message content is ever sent to PostHog.
  • Affiliate attribution. If you arrive through an affiliate referral link, a cookie records that referral for 90 days so commission can be attributed correctly. See the Affiliate Terms.

What we do not use

  • No advertising, retargeting, or conversion-tracking pixels
  • No Google Analytics, and no Meta, LinkedIn, or other ad-network tags
  • No session-replay or screen-recording tools
  • No sale or sharing of any of this for cross-context behavioral advertising

How to Control Cookies

Most browsers let you refuse or delete cookies through their settings, and doing so is the most direct control available today. Blocking essential cookies will stop parts of RevDesk working.

To opt out of product analytics specifically, or to ask what we hold from it, email privacy@revdesk.com and we will apply the opt-out to your account.

Updates and Contact

Changes

We may update this privacy policy from time to time. We will notify you of any material changes by:

  • Sending an email to your registered email address
  • Posting a notice within the Services
  • Updating the "Last updated" date at the top of this page

Your continued use of the Services after changes become effective constitutes acceptance of the updated Privacy Policy.

Notice period: For material changes that affect your rights, we'll provide at least 30 days' advance notice.

Contact

Questions about privacy? Email privacy@revdesk.com or write to us in New York. We respond within 30 days.

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Privacy and data-subject requests
privacy@revdesk.com
Compliance, BAAs, and security
compliance@revdesk.com · security@revdesk.com
Company
Cell Labs, Inc.
Location
169 Madison Ave STE 72920
New York, NY 10016
Response Time
We aim to respond to all privacy requests within 30 days

Note: For privacy inquiries, GDPR requests, HIPAA BAA requests, or general support, please email us at the address above.

RevDesk
Product
Voice AgentsChat AgentsAugmented SalesNumber RegistrationIntegrationsPricingBook a Demo
Solutions
For AutomotiveFor HealthcareFor Law FirmsFor B2B SaaSFor Home ServicesFor Logistics
Resources
BlogDocumentationChangelogRoadmapSMS SubscribeCase StudiesAffiliate
Company
AboutCareersPartnersBrandContactSecurityTrustStatus

Ask your AI assistant about RevDesk

revdesk.com/llms.txt
© RevDesk™ 2026 · Cell Labs, Inc.Privacy Policy·Terms of Service·Acceptable Use·Sub-processorsRevDesk™ is a trademark of Cell Labs, Inc. All other marks are property of their respective owners.