Sintaya / Security
Your calls, and who gets to hear them.
Answering a business's phone means holding its customers' names, numbers, addresses and voices. This page says exactly what happens to that information — including the parts we haven't finished.
Last updated 23 September 2026
01 The short version
Disclosed on every call
Before anything else happens, every caller hears that they're speaking with an AI. If call recording is ever switched on, they're told that first too — today it's off.
Never a dead line
If anything on our side fails, the call falls back to ringing your own phone, whether or not our servers are up.
Calendar: busy times only
We see which time blocks are taken. We never receive event titles, descriptions, attendees, locations or attachments.
Not sold, not ours to train on
We don't sell caller information, and we don't use recordings, transcripts or caller details to train AI models.
Still being changed
Our voice platform's current terms let it use recordings to improve its own models. We're changing that arrangement.
No BAA, no SOC 2 audit
We can't currently sign a Business Associate Agreement, which a medical or dental practice needs before using us. We haven't been audited for SOC 2 either.
Where the information lives
- Audio recordings are stored by our voice AI platform, which runs the live conversation.
- Transcripts, caller details and bookings are stored in our own database: what was said, the caller's name and callback number, the address and problem they gave, and any appointment that was made.
- Text alerts go through our SMS provider to the numbers you choose, and nowhere else.
Each of these providers is bound by contract to use the information only to deliver its part of the service.
Who can see it
- You. Every call reaches you as a text, and you get a password-protected page listing your recent calls, leads and bookings.
- Us, when we're setting up your assistant, checking its work, or fixing something that went wrong on a call.
- Nobody else. We don't share mobile numbers or caller details with anyone for their own marketing.
Your calendar
When we connect Google Calendar or Microsoft 365, we ask only for what's needed to find free time and add an appointment. From your calendar we learn which blocks are busy, and nothing else. The open times it works out do reach the AI and the voice that reads them out — it has to say “I have Thursday at 9 AM” — and that is the only calendar-derived information any provider sees.
How long we keep it
We delete on a schedule now, and it runs every week without anyone remembering to. Call audio goes at 14 days — that's our voice platform's window, not a number we picked. Transcripts, summaries and the conversation log go at 12 months. Demo-line records go at 90 days. Your caller details and bookings stay while you're a customer and are deleted within 30 days of your account ending. Database backups roll over on a six-hour window, so when something is deleted it's gone everywhere within six hours.
This page used to say we kept everything and deleted nothing on a schedule, because that was true and we'd rather have said it than implied otherwise. It isn't true any more.
When you leave, or whenever you ask, we delete your data from our systems and have our providers delete theirs, recordings included. We check each recording was actually erased rather than assuming it was. A caller who wants their own information removed can ask you or us, and we'll respond within 30 days.
AI training
We don't use your calls to train AI models. Our voice platform's own terms currently allow it to use recordings and transcripts to improve its models; we're in the process of changing that, and our privacy policy will say so the day it's done.
What we don't have yet
There is no such thing as HIPAA certification. No government body certifies anyone, and any vendor claiming it is describing something they bought rather than something official. The question that actually matters is whether we can sign a Business Associate Agreement — and today we can't.
That matters more than it sounds for a medical or dental practice. If our assistant answers your phone, callers tell it why they are ringing a dentist, and that is protected health information. Handling it makes us your business associate, and you need a signed BAA with us before sharing it. Without one, the exposure is yours as much as ours. So if you run a practice, tell us before anything else and we will say plainly where we are — which today means we are not yet the right choice for you.
We also haven't been audited for SOC 2. If your business runs a security review before approving a vendor, that review is part of our Enterprise plan, and the honest answer will be what we can show you rather than a certificate.
Questions
Email contact@sintaya.com or call (904) 943-3365. The legal detail is in our privacy policy and terms of service.