Security & privacy
PhonePick answers your phone, so it hears what your customers tell you. This page sets out where that goes, who can see it, and what we will never do with it. It also says what we haven’t done yet, because you should hear that from us.
Questions about your data? Email support@phonepick.ai.
Our promises
Not your data, and not your callers’ names or numbers. Text-message consent is never shared or sold either.
We run no ad tracking of any kind, and nothing behind the sign-in loads analytics.
Not us, and not ElevenLabs or Anthropic, whose AI handles your calls. ElevenLabs’ opt-out has applied since 7 October 2026.
Only the providers named on this page touch it, each for its own job, unless the law requires otherwise.
How it’s protected
Clinics and insurance offices
For a clinic or health practice in Ontario, PhonePick acts as your agent under PHIPA: it handles your callers’ health information only on your behalf, keeps no call audio, puts no patient details in emails or texts, and requires two-step sign-in. We sign a PHIPA agent agreement with you on request. Insurance brokers and agencies get the same safeguards under PIPEDA.
PhonePick is not HIPAA compliant and does not sign a Business Associate Agreement, so a US practice covered by HIPAA must not use it for patient health information.
The full list is in the privacy policy, and your duties and ours are in the terms.
Who else handles it
PhonePick runs on a small number of providers, each doing its own job. Each one is independently audited, and you can check its audits yourself.
| Provider | What it does | Audited for |
|---|---|---|
| Google Cloud (Firebase) | Hosting, sign-in, the database and file storage | SOC 2ISO 27001 Google Cloud compliance |
| Twilio | Carries the phone calls and text messages | SOC 2 Type 2ISO 27001 Twilio Trust Center |
| ElevenLabs | Runs the live voice conversation: hears the caller and speaks the replies | SOC 2 Type 2ISO 27001 ElevenLabs Trust Center |
| Anthropic (Claude) | Understands what callers say and decides what to say back | SOC 2 Type 2ISO 27001 Anthropic Trust Center |
| Stripe | Subscriptions, deposits and invoice payments | PCI DSS Level 1 Security at Stripe |
| Resend | Sends the notification emails | SOC 2 Type 2 Resend SOC 2 |
Clover or Square only if you connect your till. Certifications are each provider’s own, as published on its trust page. What each provider receives is set out in the privacy policy.
Straight answers
No. We’re a small company in Ontario and haven’t had our own SOC 2 audit. Instead we name every company that touches your data, link their audits above, and will walk you through how your data moves.
In the United States. PhonePick and the providers above process and store information there, including what callers in Canada say. It is protected by our contracts with those providers, and it may be accessible to courts and authorities in the United States under the laws there. If your business needs its records kept in Canada, write to us.
No. Callers’ information is not used to train AI models: not by us, and not by ElevenLabs or Anthropic, whose AI handles the calls and chats. ElevenLabs’ opt-out has applied since 7 October 2026.
Access is limited to the people who need it. We handle your callers’ information on your instructions, not for our own ends.
PhonePick is PHIPA compliant for Ontario practices: it acts as your agent under PHIPA, keeps no call audio, puts no patient details in emails or texts, and requires two-step sign-in. We sign a PHIPA agent agreement with you on request. It is not HIPAA compliant: we do not sign a Business Associate Agreement, so US practices should not use it for patient health information. Either way it’s the front desk, not the chart: bookings, hours and callbacks, never symptoms or treatment. The safeguards are above.
Yes. Every call opens by saying it’s an AI and that the call is recorded. Hear it for yourself: call Nina, our own AI receptionist, on (249) 496-5966.
Yes. Your records are yours to export while your account is open. Ask us to delete any recording at any time. Close your account and its data is deleted within 90 days, apart from what we must keep for tax or legal reasons.
No system is perfect. If something goes wrong, we’ll tell the customers affected, promptly. For a clinic or insurance office, we tell you at the first reasonable opportunity and help you notify the people affected and, where the law requires it, Ontario’s Information and Privacy Commissioner.
Last updated 7 October 2026 · Ted Kam Consulting Ltd, Ontario, Canada
If your question isn’t answered here, email us. We’d rather you asked before you sign up than wondered after.