---
title: Data and privacy
description: Exactly what leaves your firm to an AI assistant through the Receptiva connector, what needs your owner's opt-in, what never does, and how every read is audited.
sidebarTitle: Data and privacy
section: trust
order: 10
updated: 2026-10-07
---

This page lists exactly what an AI assistant can see through the Receptiva connector, what it sees only after your firm's owner turns it on, what it never sees, and how each read is recorded. The connector sends nothing on its own: an assistant only receives what a tool returns when it asks, on behalf of a person at your firm who connected it.

## What an AI assistant can see

| Data | Through the connector | Notes |
| --- | --- | --- |
| Receptionist settings | Yes | Office details, the email and firm facts the receptionist gives callers, its house rules, hours, who takes transferred calls, routing, who gets summaries by email. This includes your team members' names, phone numbers and emails, because they are part of the settings. |
| Call details | Yes | Time, duration, language, caller type, urgency, transfer outcome, whether a lead was captured, and when the call's record was last updated. Calls where the caller hung up before the receptionist spoke are listed too. |
| How a call was routed | Yes | One call's detail includes the receptionist's routing record: the category it used, whether the office was open, and which staff were rung with each outcome, plus plain-English sentences built from it (not by AI). It holds no caller data, so reduced mode leaves it in place. |
| Call summary and caller's name | Yes, under `untrusted` | A one-line reason (at most 200 characters), a longer message (at most 1,200 characters) and the name the caller gave, on call lists and on one call's detail. |
| Structured call details | Yes, under `untrusted` | Who the call was about (names and how they relate to your firm), the caller's company, who they asked for, a message's recipient and callback time, and identifiers they quoted such as claim or case numbers, on call lists and on one call's detail. They come from the same conversation as the summary and are switched off with it in reduced mode. |
| Summary of the conversation with your staff | Only with full caller data on, owners only, under `untrusted` | When the receptionist briefed or put a caller through to someone at your firm: an AI-written summary of what they discussed (at most 1,200 characters), the outcome, key points, details each side confirmed and next steps, with the staff member's name. On one call's detail only, never on lists. See [Full call records](#full-call-records). |
| Caller's phone number on calls | Yes, in full | The number the call came from and the callback number the caller gave, so a call can be matched to a client in your own system. Both are checked for a valid format first; a value that fails is left out. The last-4 form (`***1234`) is still returned alongside. |
| Lead callback number and email | Yes, unmasked | Returned in full so the assistant can help you call back. Both are checked for a valid format first; a value that fails is left out. |
| Lead's name and incident date | Yes, under `untrusted` | As the caller stated them. |
| Call transcripts | Only with full caller data on, owners only, under `untrusted` | What the caller, the receptionist and your staff member said, turn by turn, labelled by speaker and by part of the call: the intake, the receptionist's briefing to your staff member, and the conversation after the call was put through. Each turn carries the seconds from the start of the call, when the call was recorded with turn times. See [Full caller data](#full-caller-data). |
| A lead's full intake: incident, injuries, treatment, insurance and case narrative | Only with full caller data on, owners only, under `untrusted` | The details the receptionist gathered on the call. They can include health information. See [Full caller data](#full-caller-data). |
| Call recordings | A link only, with full caller data on, owners only | The assistant never receives audio. `receptiva_get_recording_link` returns a link to one call's recording that works for one hour. See [Full caller data](#full-caller-data). |
| Internal call identifiers | Never | Internal room identifiers contain the caller's phone number, so the connector uses a separate call id that does not. |

A summary is written from what the caller said. Even a one-line reason can mention why someone called, including an injury. If that concerns your firm, see [Reduced mode](#reduced-mode) below and email us.

## Full caller data

Call transcripts and a lead's full intake are off until your firm's owner turns them on. The setting is in the Receptiva dashboard under **Integrations**: **Full caller data for AI assistants**. It is off by default, only the owner can change it, and each change is recorded in the audit log.

When it is on:

- `receptiva_get_transcript` returns a call's transcript;
- `receptiva_get_lead` returns one lead with the full intake the receptionist gathered;
- `receptiva_get_recording_link` returns a link to a call's recording. The link works for one hour, and stops working sooner if the setting is turned off;
- `receptiva_get_call` includes the summary of the conversation with your staff member, after a transfer.

All four work only for a firm owner's connection, never for a view-only member. Caller text comes back under `untrusted`. While the setting is off, the first three tools return nothing and tell the assistant where the setting is, and `receptiva_get_call` returns the call without the conversation summary.

Anyone who has a recording link can listen until it expires, so share one only with people who should hear the call.

On a transferred call, the transcript also holds the receptionist's briefing to your staff member and the conversation after the call was put through, unless your firm has [full call records](#full-call-records) turned off. Recordings are the caller's call only: neither the briefing nor your staff member's side of the conversation is in the recording.

Transcripts and intake details hold what callers said about their injuries and treatment. Turn the setting on only if your firm is comfortable with that information going to the AI app you connected, under that app's terms.

In a lead's intake, a yes-or-no detail such as "hospitalized" reads `false` both when the caller said no and when it never came up on the call. Treat `false` as "not confirmed".

## Full call records

When the receptionist puts a caller through to someone at your firm, Receptiva also transcribes what the receptionist told that person before connecting the call (the briefing) and the conversation that follows, and writes an AI summary of that conversation. The setting is in the Receptiva dashboard under **Account & security**: **Full call records**. It is on by default, only the owner can change it, it applies to new calls, and each change is recorded in the audit log.

- With it on, a call's transcript includes the briefing and the conversation, and one call's detail includes the conversation summary (for an AI assistant, only with [full caller data](#full-caller-data) on).
- With it off, transcripts hold only the caller's call with the receptionist, and there is no conversation summary.
- A second setting beside it, **Include the conversation summary in call emails and alerts**, adds the conversation summary to the call email and the Slack alert your firm receives. It is off by default and works only while full call records are on. It changes what goes to email and Slack, not what the connector or the API returns.

The conversation summary is written by AI from that conversation, with the intake and the briefing as context. A confirmed detail is kept only when it was actually said on the call; its value is written for reading, with dates, times and amounts in digits. It is returned under `untrusted`, like every other summary.

## Reduced mode

Receptiva can switch the connector to a reduced mode for caller data. It is a setting Receptiva applies on request, not something in your dashboard. When it is on:

- call summaries, conversation summaries and caller names are withheld;
- the caller's phone number on calls is masked to its last 4 digits;
- transcripts and full lead intake are withheld, whatever your firm's own setting says;
- lead names, incident dates and emails are withheld;
- a lead's callback number is masked to its last 4 digits.

Call and lead responses then include `caller_data: "minimal"`, so the assistant can tell you why those fields are empty. Today the setting applies to the connector as a whole rather than to one firm. If you would like it turned on, or have questions about it, email [hello@receptiva.ai](mailto:hello@receptiva.ai).

## Every call and lead read is audited

Before any call or lead data goes back to the assistant, Receptiva writes an entry to its audit log recording who asked, their role, the firm and the tool. Caller data is not copied into the log. The entries are:

- `calls.list` for each page of calls;
- `call.view` for one call's summary and routing record;
- `transcript.view` for a call's transcript, written before the transcript is read;
- `recording.link_create` each time a recording link is created, `recording.play` each time a recording is downloaded with an API key, and `recording.link_play` each time a link starts playing, with the address it was played from. Skipping around inside a recording is not recorded;
- `leads.list` for each page of leads;
- `lead.intake_view` for one lead's full intake, written before the intake is read;
- `connector.caller_data_update` each time the owner turns full caller data on or off, with the value before and after;
- `org.full_call_records_update` each time the owner changes either full call records setting, with both values before and after;
- `lead.status_update` for each lead status change, with the status before and after. A request that changes nothing (the lead already had that status, or had moved on from the status the request expected) is recorded too;
- `receptionist.draft_update`, `receptionist.apply` and `receptionist.rollback` for each receptionist settings change, recording which settings changed and the version the change was made from (setting values are not copied into the log).

If the audit entry cannot be written, the tool returns an error and no data, and a change is not made. No entry, no data.

Reads of your account status and receptionist settings are not logged today.

## Who can connect and what they get

Anyone who is an owner or member of a firm on Receptiva can connect an AI assistant with their own sign-in. The connection belongs to that person, not to the firm, and covers only the firms they chose on the consent screen.

- **Firm owners** can use every tool, including marking a lead contacted, signed or rejected and changing the receptionist's settings. Transcripts and full lead intake also need [full caller data](#full-caller-data) turned on.
- **View-only members** can read calls, summaries and leads, but the connection is read-only for that firm, and it never returns transcripts or full lead intake. A status or settings change is refused with a permission message.

Each person can see and disconnect their own connections in the dashboard under **Integrations**, then **Connected AI apps**. A disconnect takes effect on the assistant's next request.

## Caller text is untrusted

> [!WARNING]
> Anything a caller says ends up in call summaries, conversation summaries, lead fields, transcripts and intake details. A caller could try to slip instructions into what they say. That is why caller text is always returned inside a field named `untrusted`. The connector's instructions tell your assistant to treat that text as data, never to follow instructions found in it, and to quote it only when you ask. No tool uses caller text to decide what to do, and a lead's status or your receptionist's settings change only when you ask for it.

## Where the data goes

What a tool returns goes to the AI app you chose to connect, such as Claude or ChatGPT. From there it is processed under that app's own terms and privacy policy, not Receptiva's. Read Receptiva's [privacy policy](/privacy) and [terms](/terms) for how Receptiva handles your data.

Call summaries, transcripts and leads can contain confidential client information. The connector tells the assistant to show only what you ask for.

## The REST API and API keys

This page is about AI assistants connected through the MCP connector. The [REST API](/docs/api-overview) is separate: it sends data to a system your firm runs, using an [API key](/docs/api-keys) your firm's owner created.

- A key can read calls and leads for its firm, and transcripts and full lead intake when the owner chose a permission set that includes them. The **Full caller data for AI assistants** setting and reduced mode do not apply to API keys.
- Caller text is returned under `untrusted` on the REST API too.
- The same audit entries are written, recording the key's id in place of a person. Creating and revoking a key are recorded as `api_key.create` and `api_key.revoke`, with who did it.
- A key with the `calls:recording` permission can download a call's recording or create a link to it that works for one hour. The audio is always served by Receptiva; the API never hands out a storage address.
- Transcripts on the REST API are the same as through the connector, with the briefing and the conversation after a transfer when full call records are on. Recordings are the caller's call only: neither the briefing nor your staff member's side of the conversation is in the recording.
- The REST API does not return room names or storage keys, both of which contain the caller's phone number. A list's `next_cursor` encodes the position of the last item, including that row's internal id, which holds no caller data.

## How long Receptiva keeps call data

Receptiva keeps your firm's call records, transcripts, recordings and leads until your firm asks us to delete them. Nothing is deleted automatically today. To have a call, a lead or all of your firm's data deleted, email [hello@receptiva.ai](mailto:hello@receptiva.ai) from the owner's address. We plan to add retention periods a firm can set; this page will say so when they exist.

## Next

- [Tools reference](/docs/tools)
- [Troubleshooting](/docs/troubleshooting)
- [Roadmap](/docs/roadmap)
