Sensitive Data Handling
How each type of sensitive data is detected and handled during AI phone calls.
| Data Type | Detection | Action | Status |
|---|---|---|---|
| Credit card numbers (PCI) | Pattern detection | Not collected. AI redirects to secure channel | Active |
| Social Security numbers | Pattern detection | Not collected. AI redirects to human | Active |
| Phone numbers | Captured intentionally | Stored as contact info in CRM | By design |
| Email addresses | Captured intentionally | Stored as contact info in CRM | By design |
| Medical information (PHI) | Not auto-detected | Recommend human handoff for PHI | Guidance |
Recommended Architecture for Payment Data
Best practices for ensuring payment and financial data never enters call transcripts.
Don't Collect Payment Info by Phone
Configure your AI receptionist to redirect payment conversations to a secure channel (payment portal link via SMS, or transfer to a human agent). This prevents PCI data from entering transcripts entirely.
Escalation & Handoff
Set up escalation rules so that when a caller mentions payment, credit card, or billing, the AI transfers to a human agent or sends a secure payment link via SMS. No sensitive financial data is processed by the AI.
CRM Sync Controls
Granular controls over what transcript and call data is pushed to your CRM integrations.
| Control | Available | Details |
|---|---|---|
| Send call summary to CRM | Yes | Push AI-generated summary to Salesforce, HubSpot, etc. |
| Send full transcript to CRM | Yes | Configurable: on/off per integration |
| Send link only (no text) | Yes | CRM receives a link to the transcript rather than the full text |
| Suppress transcript from CRM | Yes | Send only metadata (caller, duration, outcome) with no transcript |
| Field-level suppression | Roadmap | Coming soon: suppress specific fields from CRM sync |
Selective Sync Philosophy
My AI Front Desk gives you control over what data flows to external integrations, by default, CRM integrations receive a call summary and metadata. Full transcript sync is opt-in. You can choose to send only a link to the transcript (so the CRM has no raw text), or suppress transcripts entirely and send only metadata. This minimizes data sprawl across systems and keeps sensitive information centralized.
Frequently Asked Questions
Do you redact credit card numbers from transcripts?
Can I push only summary (not transcript) to CRM?
Does My AI Front Desk detect PII automatically?
Can an office manager see transcripts but not send them to CRM?
What about HIPAA compliance?