PhonePick

Security & privacy

Your customers’ calls stay your business.

PhonePick answers your phone, so it hears what your customers tell you. This page sets out where that goes, who can see it, and what we will never do with it. It also says what we haven’t done yet, because you should hear that from us.

Questions about your data? Email support@phonepick.ai.

Our promises

What we never do with it

Sell it

Not your data, and not your callers’ names or numbers. Text-message consent is never shared or sold either.

Use it for advertising

We run no ad tracking of any kind, and nothing behind the sign-in loads analytics.

Train AI on it

Not us, and not ElevenLabs or Anthropic, whose AI handles your calls. ElevenLabs’ opt-out has applied since 7 October 2026.

Share it further

Only the providers named on this page touch it, each for its own job, unless the law requires otherwise.

How it’s protected

Locked down, up front, and yours

Locked down

  • Encrypted in transit and at rest.
  • Walled off by business. Database rules tie every record to its own business’s login, so one account can’t read another’s.
  • Records can’t be forged. Calls, messages and consent records are written by our servers only. Your login can read them, not rewrite them.
  • Two-step sign-in with an authenticator app, on any account. Clinics and insurance offices can’t sign in without it.
  • Card numbers never reach us. Stripe takes every payment, and deposits go straight to your own Stripe account.
  • Till keys are encrypted. A connected Clover or Square key never leaves our servers, and disconnecting deletes it.
  • Access is limited to the people who need it.

Up front with your callers

  • Every call opens by telling the caller it’s an AI and that the call is recorded.
  • “Don’t call me again” puts the number on your do-not-call list on the spot. You can add numbers to it, never remove them.
  • Texting STOP opts a number out at once, until it texts START.
  • Sales calls need consent. PhonePick won’t make one without a consent record on file, and that record can’t be edited afterwards.
  • Callers can ask for a copy, correction or deletion of what they said. If they can’t reach you, we help.

Yours to keep or delete

  • Your call records, transcripts, messages and contacts belong to you. Export them while your account is open.
  • Delete any recording. Ask us, any time.
  • Close your account and its data is deleted within 90 days, apart from what we must keep for tax or legal reasons.
  • No analytics in the app. Google Analytics counts visits to our public pages and never loads once you’re signed in.

Clinics and insurance offices

PHIPA compliant for Ontario practices

For a clinic or health practice in Ontario, PhonePick acts as your agent under PHIPA: it handles your callers’ health information only on your behalf, keeps no call audio, puts no patient details in emails or texts, and requires two-step sign-in. We sign a PHIPA agent agreement with you on request. Insurance brokers and agencies get the same safeguards under PIPEDA.

PhonePick is not HIPAA compliant and does not sign a Business Associate Agreement, so a US practice covered by HIPAA must not use it for patient health information.

The full list is in the privacy policy, and your duties and ours are in the terms.

Who else handles it

Every company that touches your data

PhonePick runs on a small number of providers, each doing its own job. Each one is independently audited, and you can check its audits yourself.

ProviderWhat it doesAudited for
Google Cloud (Firebase)Hosting, sign-in, the database and file storage SOC 2ISO 27001
Google Cloud compliance
TwilioCarries the phone calls and text messages SOC 2 Type 2ISO 27001
Twilio Trust Center
ElevenLabsRuns the live voice conversation: hears the caller and speaks the replies SOC 2 Type 2ISO 27001
ElevenLabs Trust Center
Anthropic (Claude)Understands what callers say and decides what to say back SOC 2 Type 2ISO 27001
Anthropic Trust Center
StripeSubscriptions, deposits and invoice payments PCI DSS Level 1
Security at Stripe
ResendSends the notification emails SOC 2 Type 2
Resend SOC 2

Clover or Square only if you connect your till. Certifications are each provider’s own, as published on its trust page. What each provider receives is set out in the privacy policy.

Straight answers

What people ask us most

Is PhonePick SOC 2 certified?

No. We’re a small company in Ontario and haven’t had our own SOC 2 audit. Instead we name every company that touches your data, link their audits above, and will walk you through how your data moves.

Where is my data stored?

In the United States. PhonePick and the providers above process and store information there, including what callers in Canada say. It is protected by our contracts with those providers, and it may be accessible to courts and authorities in the United States under the laws there. If your business needs its records kept in Canada, write to us.

Does the AI learn from my calls?

No. Callers’ information is not used to train AI models: not by us, and not by ElevenLabs or Anthropic, whose AI handles the calls and chats. ElevenLabs’ opt-out has applied since 7 October 2026.

Who at PhonePick can see my calls?

Access is limited to the people who need it. We handle your callers’ information on your instructions, not for our own ends.

Is it PHIPA compliant? Is it HIPAA compliant?

PhonePick is PHIPA compliant for Ontario practices: it acts as your agent under PHIPA, keeps no call audio, puts no patient details in emails or texts, and requires two-step sign-in. We sign a PHIPA agent agreement with you on request. It is not HIPAA compliant: we do not sign a Business Associate Agreement, so US practices should not use it for patient health information. Either way it’s the front desk, not the chart: bookings, hours and callbacks, never symptoms or treatment. The safeguards are above.

Do callers know they’re talking to an AI?

Yes. Every call opens by saying it’s an AI and that the call is recorded. Hear it for yourself: call Nina, our own AI receptionist, on (249) 496-5966.

Can I get my data out, or have it deleted?

Yes. Your records are yours to export while your account is open. Ask us to delete any recording at any time. Close your account and its data is deleted within 90 days, apart from what we must keep for tax or legal reasons.

What happens if something goes wrong?

No system is perfect. If something goes wrong, we’ll tell the customers affected, promptly. For a clinic or insurance office, we tell you at the first reasonable opportunity and help you notify the people affected and, where the law requires it, Ontario’s Information and Privacy Commissioner.

Last updated 7 October 2026 · Ted Kam Consulting Ltd, Ontario, Canada

Ask us anything.

If your question isn’t answered here, email us. We’d rather you asked before you sign up than wondered after.