privacy, in plain language.

we run AI receptionists for local service businesses. doing that means handling three kinds of information, and we’d rather tell you exactly how than bury it in legalese. last updated august 13, 2026.

what we collect, and why

business facts. hours, services, staff names, escalation rules, approved answers to caller questions — the things a client tells us so their receptionist can answer like their business. we collect these because the receptionist is only allowed to say things the client has confirmed. nothing else.

call recordings and transcripts. calls answered by a receptionist we operate are recorded and transcribed so the business gets a complete message and so we can review quality. every call is disclosed: the greeting states that the caller is speaking with an AI assistant and that the call is recorded, in line with the consent laws of the state involved (in california, that means everyone on the call is told). if you hear the disclosure and keep talking, that’s the recording you’re agreeing to. recordings go to the business you called — we don’t sell them, mine them for advertising, or use them to train foundation models.

credentials and account connections. some clients connect systems — a calendar, a field-service platform — so their receptionist can book real appointments. any key or grant a client gives us is vaulted (encrypted the moment it reaches us, stored separately from the key that decrypts it), scoped (we ask for the minimum access that does the job, read-only where possible), and revocable (rotate the key or withdraw the grant on your side and our access ends — that’s by design, and we’ll never ask for a raw login).

connected google accounts

where a client connects a google service (like google calendar) via oauth, we access only the scopes shown on google’s consent screen, use that data solely to operate the client’s receptionist (checking availability, creating bookings), and never transfer it to anyone else except as needed to provide that service. sixforty’s use of information received from google APIs adheres to the google API services user data policy, including its limited use requirements.

who owns what

the client owns their business facts, their call recordings and transcripts, and their customers’ information. if a client leaves, they get an export and we delete our copies, revoke every grant, and decommission their agent — offboarding is part of the contract, not a favor.

what we don’t do

no selling or renting data, ever. no advertising use. no AI-voice outbound calls. no cold texts. no pretending the receptionist is human. no collecting more than the service needs.

where things live

our infrastructure runs on vercel (hosting), retell (voice), and google workspace (email) — vendors chosen for, among other things, their own security posture. this website itself sets no tracking cookies.

if you called a business we answer for

your message, callback number, and recording went to that business — they’re the ones who decide how it’s used, under their own privacy practices. want something corrected or deleted from our systems? email us and we’ll handle it directly.

questions, corrections, deletions

one email, answered by a person: luke@sixforty.co. if this policy changes in any way that matters, the date at the top changes with it.