ResponseLab answers phone calls on behalf of small businesses. That means we handle recordings and transcripts of real conversations between a business and its customers. This page explains exactly what we keep, who else sees it, and how to get it removed. It is written to be read, not to be impenetrable.
Two roles, and the difference matters. When you visit this website, ResponseLab decides what happens to your data — we are the controller. When our receptionist answers calls for a business that hired us, that business decides, and we act on their instructions — we are the processor. If you called a business and want your data removed, the fastest route is to ask that business; we will act on their request. You can also contact us directly and we will pass it to them.
We do not ask for and do not want payment card numbers, government identifiers, or medical records. Our receptionist is instructed to refuse to record them. If you volunteer something sensitive anyway, it may appear in the transcript — tell the business and it can be removed.
We use a small number of providers. Each sees only what it needs to do its job.
| Provider | What it handles |
|---|---|
| OpenAI | Generates the receptionist's replies. Call text is sent to produce a response. |
| ElevenLabs | Speech: turns your voice into text and the reply into speech. |
| Railway | Hosting. Your data is stored on servers they operate. |
| Calendar (only if the business connected one, and only that calendar), Workspace email, and Firebase login for business owners. | |
| Cloudflare | Serves this website. |
We do not sell your data. We do not share it with advertisers. We do not use call recordings or transcripts to train our own models.
Each business's data is stored in a separate database, isolated from every other business.
We keep customer facts for as long as the business remains our customer, because remembering callers between calls is the point of the product. When a business leaves, its data is deleted within 30 days unless they ask for it sooner.
An honest note about deletion. Our memory system is built to be auditable: when a fact changes or is retracted, we mark it as no longer true rather than erasing the row, so a business can always show where an answer came from. A retracted fact stops being used and stops being visible to the receptionist. If you want a genuine hard erasure rather than a retraction, say so explicitly in your request and we will remove the underlying records. This is currently a manual process handled by a person, not a button — we would rather tell you that than imply an automation that does not exist.
Depending on where you live, you may have the right to ask for a copy of your data, correct it, delete it, or object to how it is used. We honour these requests regardless of where you live.
To make a request, email jonathan@responsetlab.com with the phone number you called from and the business you called. We will respond within 30 days. We may ask you to confirm you control that phone number before we release anything — otherwise anyone could request your file.
If you called a business we work for, we will forward your request to them, since it is their data and their decision.
Calls answered by ResponseLab are transcribed, and the business that hired us can read the transcript. Recording and notification laws differ by state and country; the business is responsible for any notice or consent its own callers require. If you do not want a call handled this way, ask to be called back by a person, or contact the business another way.
If we email you about ResponseLab, every message includes our postal address and a way to opt out. Reply "stop" to any message and we will not email you again. We honour that permanently, not for 30 days.
ResponseLab is a tool for businesses and is not directed at children. We do not knowingly collect data from anyone under 13. If a child's information reaches us through a call, contact us and we will remove it.
Data is encrypted in transit. Each business's records live in a separate database, so one business can never read another's. Access to production is limited to the founder. We are a very small operation and we would rather be plain about that than imply a security department that does not exist. No system is perfectly secure; if we ever discover a breach affecting your data, we will tell you and the affected business promptly.
If we change this policy in a way that materially affects you, we will update the date at the top and, for customers, email you.
ResponseLab
jonathan@responsetlab.com
[Postal address — see note below]
To the site owner: replace the postal address above with a real one before sending any commercial email. US law (CAN-SPAM) requires a valid physical postal address in every commercial message, and a privacy policy that lists no address undercuts the same trust it is meant to build. A street address, a USPS-registered PO box, or a virtual mailbox all qualify.