Privacy Policy

Last updated August 18, 2026

Mobile information and text messaging

We do not share, sell, or provide your mobile phone number or messaging consent data to third parties or affiliates for marketing or promotional purposes.

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing to subcontractors in support services, such as customer service, is permitted. All other use case categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.

Message frequency varies. Message and data rates may apply. Reply STOP to opt out, HELP for help. This is the single, authoritative privacy policy for FrontDesk AI and the messaging program described below.

1. Scope

This policy explains how FrontDesk AI (Ari Berkowitz d/b/a FrontDesk AI — “we”, “us”) handles personal information when businesses use our AI phone receptionist (the “Service”) and when people call a business that uses it. It covers two groups: customers (the businesses with accounts) and callers (people who phone those businesses).

2. Information we collect

From customers: account details (name, email), business information (services, hours, address, phone numbers, website content you ask us to import), calendar connections you authorize, and billing details (handled by Stripe — we never store full card numbers).

From callers: when someone calls a business using the Service, we process the phone number, the audio of the call (which may be recorded), a transcript, and details the caller shares during the conversation — such as their name, callback number, the service they want, preferred times, and messages they leave. The business the caller dialed controls this data; we process it on that business’s behalf.

3. How we use it

We use this information to operate the Service: answering and routing calls, booking appointments, capturing messages, notifying the business, and billing. We also use AI to process call content — generating transcripts and summaries, classifying what the caller wanted, grading how well the AI receptionist performed, and drafting suggested improvements and follow-up messages that a human at the business reviews and approves. We do not sell personal information, and we do not use call content to advertise to callers.

4. Call recording

Calls handled by the Service may be recorded and transcribed. The Service plays a disclosure at the start of calls where the business has enabled it; recording-consent laws vary by jurisdiction, and the business you called is responsible for its disclosure settings. If you are a caller and want a recording deleted, contact the business you called — or contact us and we will refer your request to them.

5. Service providers (subprocessors)

We rely on a small set of providers to run the Service, and share only what each needs: voice and telephony (Retell AI), AI language processing (Anthropic), text messaging (Twilio), email (Resend), payments (Stripe), authentication (Clerk), database and hosting (Neon, Vercel), and calendar scheduling (Google Calendar or Cal.com, when the business connects them). Each acts as our subcontractor in support of delivering the Service, is bound by its own data protection commitments, and may not use the data for its own marketing.

This does not include mobile opt-in data. Text messaging originator opt-in data and consent are never shared with any third party or affiliate, including the subcontractors listed above, for marketing or promotional purposes.

6. Text messaging (SMS) and mobile information

What we collect for messaging: your mobile phone number, the fact that you consented on the call and when, and the appointment details needed to write the message (your name, the service, and the date and time). Nothing else is collected for the messaging program.

How we use it: solely to send you the transactional messages you agreed to — an appointment confirmation, a reminder before the appointment, and any follow-up you specifically asked for. We do not use it for marketing, we do not sell it, and we do not use it to build advertising profiles.

Callers who verbally agree on a call may receive appointment confirmations, reminders, and requested follow-up texts from the business they called. Message frequency varies — typically one to three messages per booking. Message and data rates may apply. Reply STOP to opt out or HELP for help. Consent to receive texts is not a condition of any purchase.

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing to subcontractors in support services, such as customer service, is permitted. All other use case categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.

We do not sell mobile phone numbers or SMS consent data, and we do not use them for our own marketing. How consent is collected on the call is documented in full on our SMS Consent page.

7. Retention

We keep call recordings, transcripts, and business data while the business’s account is active. Once an account closes or is deleted, its remaining records — including call transcripts, leads, and appointment history — are deleted by an automated job after a 90-day grace period. Businesses can delete individual records (leads, knowledge, and so on) from their dashboard at any time; deleted records are removed from active systems promptly and from backups on a rolling basis.

8. Google user data

When a business connects its Google Calendar, the Service accesses calendar data for exactly two purposes: reading free/busy availability so the AI offers callers only genuinely open appointment times, and creating or removing calendar events when an appointment is booked or cancelled. FrontDesk AI’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google calendar data is never sold, never used for advertising, never used to train AI models, and never shared except as needed to provide scheduling for the business that connected it. Disconnecting the calendar in the dashboard revokes our access; stored credentials are deleted.

9. Security

Data is encrypted in transit, access is limited by role and tenant (a business can only ever see its own data), calendar credentials are stored encrypted, and webhooks are signature-verified. No system is perfectly secure; if a breach affects your personal information we will notify affected parties as required by law.

10. Your rights

Depending on where you live (for example under the CCPA or GDPR), you may have rights to access, correct, delete, or export personal information, and to object to certain processing. Customers can exercise these directly in the product or by contacting us. Callers should contact the business they called (the data controller); we support businesses in fulfilling these requests. We do not knowingly collect information from children under 13.

11. Changes and contact

We will post any changes to this policy here and notify customers of material changes by email or in-product. Questions or requests: arigberkowitz@gmail.com.