Privacy policy
Last updated: 30 September 2026
Who we are
TheFrontDesk ("we", "us", "TheFrontDesk"). We are the data controller for account, billing, network-usage, security and support information we use to provide and protect TheFrontDesk and meet our own legal duties.
When a customer uses an assistant, voicemail, fax or Calendar connection to handle information about their callers for that customer's own purposes, the customer normally decides why that content is used and is the controller. We process that content to provide the service on the customer's instructions, while remaining a controller for information we must use for billing, network security, fraud prevention or legal compliance. The exact role can depend on the context.
What data we collect
| Data | Why | How long |
|---|---|---|
| Name and email | Account creation and sign-in | While your account is open |
| Phone number | Verification before buying numbers | While your account is open |
| Payment data | Processing website card payments (Stripe) or app credit purchases (Apple) | Card details stay with the payment provider. We retain transaction references and accounting records for 6 years. |
| Call records | Billing, usage reporting, dispute resolution | 6 years (tax requirements) |
| Assistant conversations | Answering calls, taking caller details and showing summaries and transcripts in your account | 90 days |
| Assistant call audio | Playback only when you switch on call recording | 90 days when enabled; deleted when recording is off |
| Fax documents | Delivery to you and your inbox | 30 days, then automatically deleted |
| Voicemail recordings | Playback in the portal | 30 days |
| Translated call metadata | Billing (duration, languages) | 6 years |
| Connected Google or Microsoft 365 Calendar | Checking free/busy times and creating appointments you enable | While the calendar is connected or until your account closes |
| IP address | Security, fraud prevention, rate limiting | 90 days |
What we DON'T collect
- Transcripts of translated calls — we never store what was said during Language Bridge calls
- Card numbers — website payments are processed by Stripe and iOS purchases by Apple; we never see or store full card details
- Browsing history — we don't track you across other websites
How information reaches us
You provide account details, assistant instructions, uploaded greetings, business notes and any documents or website addresses you attach. Callers provide speech and contact details during calls. Our telephone systems create call and usage records. Connected sign-in, Calendar and payment providers return the identifiers and results needed for the feature you choose. We do not read your address book, photo library or unrelated files.
Your choice before AI processing
Before an app or portal action sends your information to an AI service, we show the data, named recipients and purpose and ask you to choose Allow AI data sharing. Choosing Not now cancels that action without sending your draft. Signing in, opening an editor or buying credit does not grant this permission.
Choose whether SimplyAnswered may send the information below to these AI services to provide the features you use.
ElevenLabs
Assistant speech, voice greetings and call transcription.
Assistant instructions, business details, attached website pages or documents, voice or practice-call audio, transcripts and caller details. Voice previews also contact ElevenLabs.
Google (Gemini)
Assistant answers, fax summaries and, when enabled, live call translation.
Assistant instructions, relevant business knowledge, conversation text and caller details, including details needed for bookings or messages. Fax summaries use text from received fax documents. Translation includes spoken text and your phrase book.
OpenRouter, OpenAI and Anthropic
Optional writing help when you choose Build from my website, Describe my business, Shape the brief or Suggest changes.
Your website address and the public text we read from it, or the business notes you submit, any personal details in them, and a pseudonymous account reference. OpenRouter routes this writing request only to OpenAI (GPT) and Anthropic (Claude) models on endpoints declared to keep no data and not train on it, run by OpenAI, Anthropic or their cloud hosts (Microsoft Azure, Amazon Web Services or Google Cloud). OpenRouter also routes fax and live translation text to Google.
Allowing this is optional. You can still use numbers, ordinary call forwarding, voicemail, call history and credit without it. Nothing you have typed is sent to an AI service just by opening this notice.
Read the privacy policyWe record the notice version, your account and user identifiers, decision time and app or website source. We keep the current permission record while your login exists, and security audit evidence for investigating misuse. Request deletion in Account or contact [email protected]; legal retention of billing records is separate.
AI providers act under data-protection terms requiring confidentiality, appropriate security and assistance with data rights. We require them and their subprocessors to provide protection at least equivalent to the protections described in this policy. These requirements include restricted processing purposes and safeguards for international transfers. See the ElevenLabs data-processing terms and OpenRouter data-processing terms. This does not mean that every provider has identical retention periods or that no provider ever retains data for security or legal duties.
For writing help we restrict OpenRouter requests to OpenAI (GPT) and Anthropic (Claude) models on endpoints declared to use no retention or training, run by OpenAI, Anthropic or their cloud hosts (Microsoft Azure, Amazon Web Services or Google Cloud). When you choose Build from my website, we read a few public pages of the address you enter at that moment and send their text for writing help; we don’t keep a copy. Please do not include passwords, payment card details, medical records or other sensitive personal information in business notes or documents. Generated suggestions can be inaccurate: review them before saving.
AI assistant calls
When you use a TheFrontDesk assistant, the call is processed to understand and respond to the caller. We keep the transcript, summary and details the caller gives the assistant — such as their name, contact details, reason for calling and agreed next step — for 90 days so you can review the conversation and follow it up.
Call audio is kept for 90 days only when you switch on Keep call recordings. When recording is off, the provider is instructed to delete the audio while the transcript, summary and captured caller details remain available for 90 days. You are responsible for giving callers any notice and obtaining any permission required for recording or other use of their information.
How we use your data
- Providing the services you've signed up for
- Processing payments and managing your credit balance
- Sending service emails (fax notifications, low balance alerts, renewal reminders)
- Preventing fraud and abuse
- Meeting legal obligations (tax records, law enforcement requests)
Customer push notifications are not offered. The apps do not register devices for push delivery. Service emails, including voicemail, low-balance and renewal messages, continue according to your account settings.
Our lawful bases
- Contract — to create your account and provide, bill and support the services you ask for
- Legal obligation — for tax, accounting, regulatory and lawful disclosure duties
- Legitimate interests — to secure the service, prevent fraud and abuse, diagnose faults and resolve complaints, where those interests are not overridden by your rights
- Consent — where we specifically ask for it, such as optional marketing or app AI data sharing; you can withdraw it at any time
Google Calendar data
When Calendar bookings are available and you choose to connect Google Calendar, we use your Google account email and encrypted OAuth tokens to check whether your primary calendar is busy and to create an appointment only after the caller confirms it. The booking sent to Google contains the agreed time and the caller details needed for the appointment and invitation.
When enabled, the booking feature does not show existing event titles or details to callers and does not change or cancel existing events. You can stop new bookings in the assistant. You can withdraw TheFrontDesk's Google access at any time from your Google Account's connected-app settings; Google then prevents the stored connection from being used again. You can also ask us to remove the connection by emailing [email protected].
We use Google user data only to provide the Calendar feature you enabled. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Microsoft sign-in
If you choose Microsoft sign-in, we verify your work or school account and retain its organisation and account identifiers so you can sign in again. Microsoft may also provide a suggested name and email address. We ask new customers to confirm their contact details and verify their email separately. We do not merge accounts just because their email addresses match. Sign-in tokens are used on our server for verification and are not retained. Signing in does not connect your calendar.
Microsoft 365 Calendar data
If you connect a Microsoft 365 work or school account, TheFrontDesk uses your mailbox address and encrypted OAuth access and refresh tokens to check availability and create caller-confirmed appointments in your primary calendar. Microsoft receives the agreed appointment time and the caller details needed for the booking and invitation. Existing event details are not passed to callers, and the assistant cannot edit or cancel existing appointments.
Microsoft Calendar access is separate from CallPlatform connections and your TheFrontDesk sign-in. Disconnect it in the assistant's Bookings settings to remove the stored tokens and stop new bookings. Existing appointments remain in Microsoft. You can also revoke the app's permissions through your Microsoft account or ask your organisation's administrator to do so. We retain a booking receipt containing identifiers, hashes and status to prevent duplicate appointments; it contains no event body or caller contact details.
Third-party processors
| Processor | What they do | Data they see |
|---|---|---|
| Apple | Sign in with Apple and iOS credit purchases | Sign-in authorization and purchase transactions; we receive a verified account identifier, permitted contact details and purchase/refund records, not your Apple password or card number |
| Stripe | Card payments | Card details, payment amount, billing email |
| Amazon Web Services | Hosting and storage | Account data, call records, assistant conversation data and encrypted fax documents |
| ElevenLabs and Google (Gemini) | Building and running AI assistants | Live call audio, assistant instructions, transcripts, caller details and any website pages or documents you attach as business knowledge |
| TheSMSWorks | SMS notifications | Your phone number, message content |
| Amazon SES | Email delivery | Your email address, email content |
| OpenRouter, OpenAI, Anthropic and Google (Gemini) | Optional assistant writing help (OpenAI and Anthropic models), fax summaries and live translation (Google) | Submitted business notes, or the public text of the website you ask us to read, and a pseudonymous account reference for writing help; received fax text for summaries; spoken text, selected languages and phrase book for translation |
| Google / Apple | Sign-in and, if you enable it, Google Calendar bookings | Your sign-in name and email; for Calendar, authorization tokens, free/busy results and appointment details |
| Microsoft | Sign-in and, separately, Microsoft 365 Calendar bookings if you connect a calendar | Sign-in identifiers and suggested name/email; for Calendar, mailbox identity, authorization tokens, availability requests and confirmed appointment details |
Your rights (UK GDPR)
You have the right to:
- Access — request a copy of your personal data
- Rectification — correct inaccurate data
- Erasure — request deletion (we may need to retain billing records for tax purposes)
- Restriction — ask us to limit how we use your data in certain circumstances
- Portability — receive your data in a machine-readable format
- Object — object to certain processing
- Withdraw consent — for optional marketing or app AI sharing at any time; manage AI sharing in Account → AI data permissions
To exercise any of these rights, email [email protected].
Data security
We take security seriously:
- Connections between your browser and our public portal are encrypted (HTTPS/TLS)
- Fax documents are stored in encrypted private cloud storage
- Access to documents uses short-lived signed links that expire after 5 minutes
- Passwords are hashed (bcrypt) — we can't see them
- API keys are hashed — we can't retrieve them after creation
- Google OAuth access and refresh tokens are encrypted at rest and are never sent to your browser
- We use rate limiting and fraud detection
International transfers
Your TheFrontDesk account and service data is primarily stored in the UK (London). Some processors, including Google, Apple, Stripe, ElevenLabs and its AI model providers, may process data outside the UK under appropriate safeguards such as UK adequacy decisions or Standard Contractual Clauses.
Cookies
We use only essential cookies for sign-in sessions and security tokens. We don't use advertising or analytics cookies.
Data retention summary
| Data type | Retention period |
|---|---|
| Account details | While account is open + 6 years (tax) |
| Fax documents | 30 days |
| Voicemail recordings | 30 days |
| Assistant transcripts, summaries and caller details | 90 days |
| Assistant call audio | 90 days when recording is enabled; otherwise deleted |
| Call records | 6 years (tax) |
| Payment records | 6 years (tax) |
| Google Calendar connection | While connected or until account closure |
| Security logs | 90 days |
| API request logs | 30 days |
Complaints
If you believe we've mishandled your data, contact us first at [email protected]. If you're not satisfied, you can complain to the Information Commissioner's Office at ico.org.uk or 0303 123 1113.
