Skip to content
Healthcare

Transcripts, recordings, and privacy

TL;DR — every conversation is transcribed; voice calls are optionally recorded. You and your team see them; nobody outside your account does. PHI redaction is on for healthcare verticals.

Updated May 20, 2026·29 min read
TL;DR. Transcripts: kept for 365 days, visible to your team only, used to improve the agent for you not the global model. Recordings: off by default; if on, 30 days then auto-deleted. PHI redaction: on for healthcare verticals.

What's stored

  • Text transcripts — every SMS and every voice call (auto-transcribed). Stored encrypted at rest in our Postgres + Redis layer.
  • Voice recordings — only if you've enabled them in Settings > Privacy. Off by default.
  • Agent reasoning — the chain of decisions the agent went through. Useful for debugging; visible to you under the "Show agent thinking" toggle.
  • Client metadata — name, phone, email, booking history, deposits paid.

How long it's kept

  • Text transcripts: 365 days, then auto-deleted
  • Voice recordings: 30 days, then auto-deleted
  • Booking + payment records: 7 years (IRS retention requirement)
  • Client profile: until the client requests deletion, or your account is closed

You can shorten any of these in Settings > Privacy > Retention. You cannot lengthen the recording retention beyond 30 days — that's a hard ceiling we won't move.

Who can see what

  • Owner — everything
  • Admin — everything except billing-method details
  • Operator — only their own clients' conversations (e.g. stylists see their own column, not the next chair's)
  • Deskwise staff — engineering can access transcripts only with your written consent (e.g. for a support ticket), and only on a per-incident basis. Logged in our audit trail.

[screenshot: roles table on /settings/team]

What we use your data for

  • Running your account — the obvious one
  • Training your agent's personalization — what worked, what didn't, what to say next time. Your data improves your agent, not the global model.
  • Anonymized, aggregated stats — counts of bookings, average conversation length, etc. Never client-identifiable.

What we never do: sell your data, share with advertisers, use your transcripts to train Anthropic's foundation models, share with anyone outside your account (except as legally required).

PHI redaction (healthcare verticals)

If your account is on a healthcare vertical (dental, vet, med spa, mental health, primary care), PHI-safe mode is on by default:

  • Clinical content (symptoms, diagnoses, medications) is detected by Claude in real-time and either redirected or stored with the PHI field masked
  • The agent never engages with clinical questions — it always redirects to a clinician
  • Transcripts shown to non-clinician staff have PHI redacted (e.g. "patient mentioned [REDACTED_CLINICAL]")
  • No BAA needed — Deskwise stays outside HIPAA scope by never collecting or storing PHI

Details in Healthcare PHI-safe mode.

Client opt-out

Any client can opt out:

  • Texting STOP — opts out of SMS immediately
  • Texting STOP RECORD — opts out of voice recording (for future calls)
  • Emailing contact@deskwise.co — full data deletion (we delete their record from your account; you'll see them disappear from the client list)

We handle all of this automatically — you don't have to manage opt-out lists.

Two-party consent states

In CA, FL, IL, MA, MT, NV, NH, PA, WA, and a few others, recording a call requires both parties' consent. If you're in one of these and you've enabled call recording, the agent discloses at the start of every call: "Just so you know, this call may be recorded." We handle the disclosure automatically; you don't have to remember.

Exporting / deleting your data

  • Export — Settings > Privacy > Export. You get a ZIP with all your transcripts, bookings, and client records in CSV + JSON.
  • Delete account — Settings > Privacy > Delete account. We delete everything within 30 days (the 30-day window is so you can recover if you change your mind).

Related

Frequently asked

Are you HIPAA-compliant?

Deskwise stays outside HIPAA scope rather than inside it: the agent is gated to never collect or store PHI, so we are not a business associate and no BAA is required. We operate to the same technical safeguards regardless — encryption at rest and in transit, audit logging, role-based access, minimum-necessary. If your compliance program requires a BAA-signed scheduler, you want a HIPAA-scoped vendor; email contact@deskwise.co before onboarding and we will tell you straight.

Where are servers located?

US-East and US-West (AWS regions). Data never leaves the US.

Do my clients see a privacy notice?

On the public booking widget, yes — links to /privacy. For SMS / voice, the disclosure happens contextually (the recording disclosure on first call, opt-out at the foot of each marketing-style outbound text).

Related in Healthcare

Didn’t answer your question?

Email contact@deskwise.coand we’ll get back within 4 business hours. Or book a 15-min call.