1. Status and scope
PENDING PROFESSIONAL REVIEW. This policy describes AnswerWing's current operational practices and is effective as of July 17, 2026. Qualified privacy and healthcare-law review remains a gate before real patient traffic.
This policy covers the AnswerWing website, trial-request form, authenticated client dashboard, post-call webhook service, alert delivery, and weekly reporting. It does not replace a dental or medical practice's own privacy notice and does not describe independent practices by which a voice, hosting, communications, or scheduling provider uses data outside AnswerWing's instructions.
AnswerWing is currently operated by its founder as a sole proprietorship while formation of a separate legal entity is pending.
2. Our role
For account, website, and trial-request data, AnswerWing's founder, operating AnswerWing as a sole proprietorship pending formation of a separate legal entity, determines why and how the data is used. For patient call information processed to provide services to a customer practice, AnswerWing generally acts on that practice's instructions, while the practice remains responsible for its relationship with patients, lawful notices, recording consent, clinical protocols, and data requests.
This description is operational, not a legal conclusion. Counsel must determine the correct privacy and healthcare-law roles for each deployment.
3. Information we collect
Trial and business inquiries
The trial form collects the requester's name, practice name, business email address, and telephone number. It also records structurally non-patient first-touch acquisition identifiers: one of AnswerWing's published landing-page paths; an allowlisted external referrer hostname or “other”; an allowlisted source and medium; and, when present, finite checked-in AnswerWing campaign, content, or term IDs. Invalid or human-readable attribution values are discarded by the page and rejected by the server. The service does not store the referring URL, landing-page query string, or fragment. Contact fields are encrypted; the founder-role account can view the request and acquisition identifiers for follow-up and source measurement.
Practice and account data
We store practice name, time zone, configured appointment value, alert destinations and verification status, approved service settings, user email and its recovery-verification status, password hash, role, session records, and account timestamps. Passwords and password-reset links are not stored in readable form.
Patient call and message data
After a connected voice provider completes a call, AnswerWing may receive a call identifier, caller telephone number and name, start and end times, transcript, recording URL, summary, language, outcome, urgency, transfer result, appointment-channel flags, booking-failure flags, message content, and other structured fields in the documented webhook contract. Transcript and recording fields are optional and depend on voice-provider configuration.
Operational data
We store delivery status, provider message identifiers, retry counts, report calculations, scheduler and worker heartbeat timestamps, and opaque request identifiers. Trial requests are stored with encrypted contact fields, a duplicate-detection fingerprint, and the bounded non-patient acquisition identifiers described above. The application logger is allow-listed and is designed not to log caller names, telephone numbers, transcripts, summaries, recording URLs, request bodies, authentication material, or provider response bodies.
Website and browser data
The current public site does not include an advertising tracker or analytics SDK. It loads fonts from Google Fonts, which receives ordinary request metadata such as IP address and browser information. Public JavaScript is served by AnswerWing from version-pinned application dependencies rather than executed from a third-party CDN. Hosting and network providers may also process standard request metadata. The public site uses browser session storage for presentation state and to retain the bounded first-touch acquisition identifiers until a trial request is submitted; the dashboard uses session storage for its signed-in session.
4. How we use information
- provide and secure the website, dashboard, webhook ingestion, message inbox, call history, and weekly reports;
- route completed-call outcomes and display call information to authorized users;
- send urgent practice alerts, founder lead alerts, calendar-failure alerts, service-health alerts, report emails, and requested account-recovery emails;
- respond to trial requests and perform manual onboarding;
- authenticate users, isolate practice data, prevent duplicate webhooks, investigate abuse, and maintain service reliability;
- comply with valid legal obligations and protect the rights and safety of users, practices, AnswerWing, and others.
The current service does not sell personal information or use patient call information for targeted advertising. Any future materially different use requires an updated notice and, where required, permission.
5. Calls, transcripts, and recording
The rented voice provider—not this repository—places or answers calls and may create audio recordings, transcripts, and analysis according to its configuration. AnswerWing receives post-call information and may store an encrypted recording URL rather than the audio file itself. Accessing that URL may cause the voice or recording provider to process the request.
Call-recording, wiretap, consent, and automated-assistant disclosure rules vary by jurisdiction. Each customer practice must obtain professional advice, configure legally sufficient notices and consent, and decide whether recording and transcription should be enabled. AnswerWing must not be treated as the practice's legal or clinical advisor.
6. Service providers and disclosures
The current production configuration uses the following categories and providers. Eligible services, data locations, contracts, subprocessors, and any required BAAs must be reviewed before real patient traffic.
- Hosting and database: Railway and managed PostgreSQL host the application and stored records.
- Voice engine: Vapi is the primary provider for calls, transfers, recordings, transcripts, and post-call analysis before it sends an authenticated webhook. Synthflow is retained only as an alternate integration for deliberately configured legacy clients.
- SMS: The application supports Twilio for PHI-minimized alerts, but Twilio is currently disabled in the production email-only configuration and receives no alert data unless the feature is enabled.
- Email: Resend processes alert/report recipient addresses, message content, and delivery status.
- Domain, source, and deployment: Porkbun provides domain registration and DNS. A private GitHub repository stores source code and deployment metadata; application patient records are not intentionally stored there.
- Public-page resources: Google Fonts receives standard browser request metadata when hosted fonts load. AnswerWing self-hosts the public JavaScript libraries used by the site from version-pinned application dependencies.
A customer practice's scheduling software and phone carrier may also process data according to the workflow that practice approves.
Information may also be disclosed when directed by the relevant customer practice, with the person's permission, during a properly structured business transaction, or when reasonably necessary to respond to lawful process or protect rights and safety. This paragraph requires counsel review.
7. Security
Current technical safeguards include HTTPS requirements in production; managed-database transport encryption; AES-256-GCM application encryption for caller phone and name, transcript, recording URL, summary, message body, trial-request contact fields, practice alert contacts, and delivery recipients; hashed passwords and webhook credentials; server-authenticated, single-use password-reset links for operator-verified account emails; short-lived access tokens and one-time rotating refresh credentials; practice-scoped authorization; verified alert contacts; a restrictive content security policy; and PHI-safe application logging.
No safeguard makes a system risk-free. Encryption and access controls are not a legal certification. The production launch remains gated on vendor-contract review, access and retention decisions, incident procedures, backups, restoration testing, and professional privacy/security review.
8. Retention and deletion
Core account, call, message, report, trial-request, and delivery records are retained under the current application behavior. There is no automatic fixed purge or self-service deletion/export workflow. Verified requests are handled case by case, subject to technical dependencies, backups, provider copies, and legal holds.
Authentication credentials expire according to their configured windows. Password-reset links expire after 30 minutes; encrypted recovery-email recipients are scrubbed after terminal delivery, and opaque reset-request metadata is removed after a seven-day cleanup window. Browser session storage is cleared on logout, session failure, inactivity handling, or when the browser session ends, depending on the feature. Backups, voice-provider recordings, and other provider copies follow their configured retention cycles and may persist longer when required for recovery, security, or a legal hold. A professionally approved retention and export schedule remains a gate before real patient traffic.
9. Choices and privacy rights
People may ask about access, correction, deletion, or another applicable privacy right by contacting the address below. When the request concerns a patient call handled for a customer practice, AnswerWing may refer the request to that practice and assist it as contractually and legally required. Identity and authority must be verified before disclosing data.
Service alerts are operational communications, not marketing subscriptions. A practice that no longer wants them must update its verified alert contacts or service configuration without disabling safety-critical routing unintentionally.
Children
The AnswerWing website and business trial form are directed to practice operators, not children. Patient calls may concern minors as part of a practice's services; the practice remains responsible for its notices, authority, and instructions for that data.
10. Contact and policy changes
Privacy questions and requests should be sent to privacy@answerwing.com. AnswerWing is currently operated by its founder as a sole proprietorship while formation of a separate legal entity is pending.
Material changes will be posted on this page with a revised effective date and communicated directly to active customer practices when the change materially affects the service or their data.