The short answer: do not connect live calls until you know what is recorded, where it is stored, how long it stays there, and who can review it. Then set a clear rule for sensitive or uncertain calls to reach a person.

The privacy conversation is moving beyond a policy page. In its September 1 announcement, Anthropic described Enterprise Frontier Safeguards, which combines zero data retention with automated misuse monitoring and lets customers keep activity data in cloud infrastructure they control. Anthropic says the feature will roll out to customers in phases later this fall. It is an enterprise offering, not proof that a small-business receptionist has the same controls.

OpenAI's Presence overview describes another useful pattern: start with one job, give the agent only the access it needs, test common and high-risk cases, and set rules for escalation. That page also says Presence is available to eligible enterprise customers, not as a self-serve product. The pattern is useful even when the product is not available to your business.

1. Where do recordings and transcripts live?

Ask whether calls are recorded, whether transcripts are created, and which company stores each one. The answer may include your phone provider, receptionist provider, CRM, and automation tools. You need the full path, not only the name on the sales page.

2. How long are they kept?

Find out whether retention is measured in days, months, or forever. Ask what happens to backups and whether you can set a shorter period. A transcript that no longer helps the team should not remain by accident.

3. Is the data used to train a model?

Do not rely on a general statement about privacy. Ask for the provider's current policy for recordings, transcripts, prompts, and connected business data. Anthropic says in its announcement that it has not trained on enterprise data without explicit permission. That is a vendor statement. Compare it with the terms of the product you are considering.

4. Who can see the information?

Ask how access is granted and removed. Look for separate permissions for business owners, staff, support teams, and contractors. An access log is useful because it shows who viewed or changed a call record after the call ended.

5. What gets copied into your CRM?

Send the smallest useful summary. A caller's name, number, reason for calling, and next step may be enough. Do not copy a full transcript into every contact record by default. Our guide to AI receptionist CRM integration shows how to keep the record focused and actionable.

6. What happens when a caller shares sensitive information?

Write the handoff rule before launch. The receptionist can say that a team member will help, stop asking unnecessary questions, and transfer or create a callback. It should not keep probing because it does not know when to stop.

Dental and healthcare offices need extra care around the information they collect. Our guide to AI receptionists for dental offices covers routine booking, sensitive questions, and the point where staff should take over.

7. Can you test changes without risking live callers?

Ask whether you can run test calls, inspect the result, and compare a rule change with the version already in use. Test ordinary questions, unclear requests, a caller asking for a person, and a call that ends before the next step is confirmed.

Our AI receptionist quality checklist gives you a simple test, fix, and retest loop. For calls outside office hours, the after-hours receptionist guide covers fallback rules and clear caller expectations.

A simple privacy boundary for a small team

Start with information your team can explain and use. Hours, location, service area, a callback number, and a short reason for calling are usually easier to control.

Treat detailed health information, payment details, passwords, legal disputes, and urgent situations as a human path unless your workflow has been specifically designed and approved for them. The right boundary will vary by business. It should be written down before the first real call.

What to ask before you buy

Ask for the data flow in plain language. Ask what the service records, what it sends to other systems, how long it keeps information, and how your team can delete or review it. If the answer is vague, the workflow is not ready for customer calls.

Privacy is not a reason to avoid useful automation. It is a design constraint. A smaller call flow with a clear human handoff is often a better first test than a broad receptionist that tries to handle every request.

Want help mapping a safe first call flow? Book a free Leadspa consultation.