The 40 days after you delete
Delete a call recording on Twilio and the audio goes. The record that the recording existed stays for 40 days.That line is in Twilio's own API documentation, and it is the kind of detail no AI receptionist sales page will ever mention.
It isn't a scandal. It's just how the plumbing works. But it tells you something important: the thing you are buying is a stack of other companies' services, and each layer has its own rules about what it keeps, what it charges and what happens when it breaks.
Most buyers evaluate an AI receptionist the way they'd evaluate a new hire on a phone screen. Does it sound nice? Did it get my name right? That's the wrong model. A receptionist product is closer to a lease on a car you can't see under the hood of. You don't judge a lease by the paint. You read the mileage clause, the early exit terms and what happens when it breaks down on the highway.
So this is a checklist of ten questions to put to the salesperson, one at a time. For each I'll tell you why it matters, what a good answer sounds like, which answers should worry you, and how to check the claim yourself instead of taking anyone's word for it, including mine.
I run Frenchy Digital, and we build custom AI receptionists, so I have a stake here. That's why the second half of this article answers all ten questions for us, with the places we fall short stated plainly.
How to use this checklist
This article sits next to two others on this site, and I've kept it from repeating them. The AI receptionist buyer's guide covers the four kinds of product you can buy, a twenty-call test script and compliance basics in depth. The law firm checklist frames ten checks on the ABA rules. This one is narrower on purpose: the question, the worrying answer, and the way to check.
I've put the questions the other guides touch least at the front. Data ownership, what the model provider keeps, the billing unit, write access, exit and outages. Those are the ones that cost real money a year in, when switching is painful.
Ask them in writing if you can. A verbal "yes, of course" on a sales call is worth very little. An email that says the same thing is worth more. A clause in the contract is worth the most.
One more rule before we start. When a vendor answers with a percentage, ask where it came from. The FTC said in its September 2024 Operation AI Comply announcement that there is no AI exemption from the laws on deceptive claims, and it brought five actions that day, including one against DoNotPay that ended in a $193,000 order. Claims about AI still have to be substantiated. You're entitled to ask how.
Questions 1 to 3: your data
Start with the data, because it's the part you can't take back.A bad greeting can be rewritten in five minutes. A year of recorded patient calls sitting in the wrong place can't be un-recorded.
Question 1: Who owns the recordings and transcripts, where are they stored, and how long are they kept?
Why it matters.Recordings and transcripts are the most sensitive thing an AI receptionist produces. They contain names, phone numbers, symptoms, legal problems, addresses and sometimes card numbers read out loud by a caller who didn't know better.
Retention is often longer than you'd guess, because it is set at several layers. The receptionist vendor has its own policy. The telephony carrier underneath has another. Twilio's Recording API documentation says recordings can be deleted through the API, and that recording metadata is kept for 40 days after deletion. The same page reminds customers that they must comply with consent laws "such as California's Invasion of Privacy Act".
What a good answer sounds like. A named storage location. A retention period you can configure. A deletion you can trigger yourself, not by ticket. Redaction of card numbers and Social Security numbers in transcripts. And a contract clause that says the data is yours.
For a sense of what vendors have offered, LawNext reported in July 2022 that Smith.ai kept recordings and transcripts in its dashboard for 90 days by default and redacted personal data such as card and Social Security numbers automatically. That was 2022 and it was the vendor's own description, so check the current terms. But it shows the shape of a good answer: a number, a default, and a redaction rule.
Red flag answers."We keep everything to improve the product." "You can email support to request deletion." "Retention is handled on our side." Each one means you don't control the most sensitive record your business creates.
How to verify.Ask for the data processing agreement or the terms clause, and read the retention and ownership sections. Then, during the trial, make a test call, ask the vendor to delete it, and check that it's gone from the dashboard and the export. If they can't do it in a trial, they won't do it faster when you're a paying customer.
Question 2: Which model provider sits underneath, and does anyone train on my callers?
Why it matters.Most AI receptionists are a product layer on top of someone else's speech and language models. Your caller's voice goes to the receptionist vendor, then to OpenAI, Anthropic, Google or another provider for transcription and reasoning, and back again. Each hop is a place data can be kept.
The good news is that the major commercial APIs publish their rules. OpenAI's "Your data" page says data sent to its API has not been used to train its models since March 1, 2023, unless the customer opts in. It also says abuse monitoring logs are kept for up to 30 days by default, and that zero data retention arrangements exist for eligible endpoints, including its realtime and audio endpoints, subject to approval.
Anthropic's API and data retention page says retained data is never used for model training without the customer's express permission, describes a zero data retention arrangement, and says HIPAA readiness requires a signed BAA and applies only to eligible Claude API features.
So the risk usually isn't the model provider's commercial API. It's a vendor running on consumer accounts, or a vendor whose own terms let it reuse your recordings to train its product.
What a good answer sounds like."We use this provider, on its commercial API, under these terms. Here is the retention window. We have or can apply for zero data retention on these endpoints. Our own terms don't let us train on your calls."
Red flag answers."That's proprietary, we can't say which model we use." "Your calls help our AI get smarter over time." A shrug when you ask about the provider's retention.
How to verify.Get the provider named in writing. Read that provider's published data page yourself; it takes ten minutes. Then read the vendor's own terms for any clause about using customer content to improve services.
Question 3: Will you sign a BAA or DPA, on which plan, and are your subprocessors covered?
Why it matters. If you are a HIPAA covered entity (a medical, dental or therapy practice, for instance) and the receptionist handles protected health information for you, HHS guidance says you need a written business associate contract. That contract sets what the vendor may do with the data, requires Security Rule safeguards and requires the vendor to report breaches.
The agreement has to flow down. A BAA with the receptionist vendor helps little if the telephony carrier and the model provider underneath aren't covered too. Twilio's recording documentation, for example, says HIPAA workflows require at least HTTP authentication on recordings. Anthropic's page says its HIPAA readiness depends on a signed BAA. These are real requirements at each layer.
Outside healthcare, the equivalent is a data processing agreement, which matters if you have callers in places with privacy laws that require one.
What a good answer sounds like."Yes. It's available on this plan, at this price. Here is our subprocessor list, and each one handling health data is under a BAA with us."
Red flag answers.A "HIPAA compliant" badge with no agreement behind it. A BAA only on an enterprise tier that wasn't in the quote. No subprocessor list at all.
How to verify.Ask for the BAA as a document before a single patient call goes through, and ask for the subprocessor list. The buyer's guide goes deeper on this; the short version is a signed BAA, not a badge.
Question 4: your bill
The price on the pricing page is the least interesting number in the contract. The unit is what decides your bill.
Question 4: What exactly am I billed for, and what does overage cost?
Why it matters.Vendors bill per call, per minute, per bundle of minutes, per unique customer, or by a unit they define themselves, like a "conversation" or a "credit". The same month of calls can cost very different amounts depending on which one you signed up for.
Think of it like a gym that charges per visit versus one that charges per hour. If your calls are long, per call wins. If they're short, per minute wins. If the unit is a "credit" nobody will define, you can't do the math at all, which is sometimes the point.
Here's a clean example of a unit written down. Smith.ai's AI Receptionist pricing page, checked September 30, 2026, bills per call. The free tier includes 25 calls a month with overage at $3.00 a call. Pro is $150 a month with overage between $1.80 and $2.17 a call depending on the call bundle, and Enterprise starts at $500 a month. The page says known spam is filtered and doesn't count, and customers can remove up to 10 percent of their calls a billing cycle for spam they mark.
I'm not recommending Smith.ai by quoting it. I'm quoting it because it answers the question in public: the unit, the overage and the spam rule are all on one page. That's the standard to hold others to. For the full vendor-by-vendor comparison, the AI receptionist pricing breakdown prices twelve of them.
What a good answer sounds like. The unit defined in writing. The overage price published. Spam and wrong numbers excluded or credited. A cap or an alert when you approach your bundle.
Red flag answers."It depends on usage, we'll show you after onboarding." Overage that appears only in the order form. Transfers billed twice, once as AI minutes and again as carrier minutes. An annual contract with no volume ceiling.
How to verify.Pull last month's call log from your phone provider. Count the calls and total minutes. Multiply by the vendor's written unit and overage. If you can't do that multiplication from what they've given you, ask again until you can.
Questions 5 to 7: its behaviour
These three are about what the thing does when the call stops being routine. Routine calls are easy. The expensive calls are the ones where the caller wants a person, asks something odd, or needs something written into your systems.
Question 5: How does transfer to a human work, and what context goes with the caller?
Why it matters.The handoff is where most of the caller's opinion gets formed. A caller who explained their problem to a machine, got transferred, and then had to explain it all again to a person will remember that more than anything the AI said.
There are two broad kinds. A cold or blind transfer just rings your line. A warm transfer briefs the person first. Vapi's documentation lists five warm transfer modes, including playing a fixed message or a generated summary to the person before the caller is connected, and variants where the operator speaks first and then hears the summary. Retell's call transfer page describes warm transfer with a contextual briefing. Both are vendor descriptions of their own features, but they show what exists.
What a good answer sounds like. Warm transfer with a spoken summary. The transcript posted to your system at the same time. A defined fallback when nobody picks up, such as a message with a callback promise, not a dead line.
Red flag answers."We do blind transfer, your staff can read the transcript later." No answer on what happens after hours. "Callers don't usually ask for a person." (They do.)
How to verify.During the trial, call and demand a human within the first ten seconds. Time how long it takes. Then ask the person who picked up what they heard before the caller was connected. Vapi's own docs say to test transfers through the same phone number and destination you'll use in production, which is good advice for any vendor.
Question 6: What does it do when it doesn't know?
Why it matters.Language models are built to produce a fluent answer. That's great until the fluent answer is a price you don't charge, a service you don't offer, or an opening hour that changed last month.
And voice is harder than text. The τ-Voice benchmark, published by researchers at Sierra and Princeton, tested voice agents from OpenAI, Google and xAI on 278 customer service tasks. In clean audio the voice agents completed 31 to 51 percent of tasks. With realistic noise and accents that fell to 26 to 38 percent. A GPT-5 text agent completed 85 percent of the same tasks.
Two caveats. Sierra sells voice agents itself, so it has an interest in the field. And these are model providers on hard multi-step tasks, not receptionist products on booking calls. But it's the best public evidence we have, and it points one way: a voice agent will get things wrong, so the question is what it does about it.
What a good answer sounds like.Its knowledge is scoped to text you approved. When a question falls outside that, it says it doesn't know and offers a person or a message. Prices and policies are read from a source, not improvised. Transcripts are reviewed on a schedule.
Red flag answers."It never gets anything wrong." "Our accuracy is 99 percent." Ask how that was measured, on whose calls, by whom. If there's no method, it's a slogan.
How to verify.Call and ask about a service you don't offer. Ask for a price that isn't in the approved text. Ask a question with no answer. Then read the transcript. You want to see "I don't have that, let me get someone", not a confident invention.
Question 7: Which systems does it write into, and which does it only read?
Why it matters.Reading your calendar to tell a caller you're open Tuesday is low risk. Writing a booking into your calendar, a lead into your CRM, or a payment into your billing system is where an error costs money or a double-booked chair.
I don't have a neutral study to cite here, so this is practitioner judgment from building these things. The safest design I know has the model decide what the caller wants, and then ordinary code (not the model) checks the slot is free and writes the booking through the system's API. The model never types into a form. Every write is logged.
"Integrates with" is also a slippery phrase. A native integration, a Zapier connection and a CSV export are three different things, and only the first usually writes in real time.
What a good answer sounds like. A list of every write action it can take, which system each goes into, how each is validated before it happens, and where the log lives.
Red flag answers."It integrates with everything." "The AI fills in the booking form." No audit log.
How to verify. On a test call, try to book a slot you know is taken. Try to book outside business hours. Then ask the vendor to show you the log entry for the booking that did go through.
Question 8: the law
I'll keep this one short, because the buyer's guide and the law firm checklist cover it in depth.I'm not a lawyer, and nothing here is legal advice. Confirm your states with counsel.
Question 8: Does it say it is an AI, and how does it handle recording consent?
Why it matters.Two separate rules meet in the first ten seconds of a call: telling people they're talking to a machine, and getting consent to record.
On recording, federal law under 18 U.S.C. 2511 allows recording with one party's consent. Some states require all parties. California Penal Code 632 makes recording a confidential communication without everyone's consent punishable by a fine of up to $2,500 for a first violation and up to $10,000 for later ones. A Justia 50-state survey from January 2018 lists around a dozen states as requiring all parties' consent in some or all circumstances, and it hedges on several. So the count is roughly a dozen, depending on how you read it.
On disclosure, Utah's SB 226 from 2025 requires a business using generative AI with consumers to disclose it when the person clearly asks, and requires up-front disclosure in regulated occupations during high-risk interactions. California's bot disclosure statute (Business and Professions Code 17940 and following) is written for online platforms with at least 10 million monthly US users, so whether it reaches a phone line is doubtful. Colorado's SB 26-189, signed in May 2026, sets requirements from January 1, 2027 for automated decisions that are consequential, which a receptionist booking a haircut rarely makes.
If it makes outbound calls (reminders, callbacks), the FCC's 2024 declaratory ruling FCC 24-17 treats AI-generated voices as artificial voices under the Telephone Consumer Protection Act, so those calls need consent.
What a good answer sounds like."The greeting says it's an AI assistant and that the call is recorded, on every call, in every state. Outbound calling is off unless you set up consent."
Red flag answers."Callers can't tell, that's the point." "Recording consent is your responsibility, we don't touch the greeting."
How to verify. Listen to the first ten seconds of a real call. Both the AI disclosure and the recording notice should be there.
Questions 9 and 10: leaving and failing
Nobody asks about the breakup on the first date. You should. These last two questions are about the day you want to leave and the day it stops working.
Question 9: Can I export my data and leave, and do I keep my phone number?
Why it matters. Your phone number is on your truck, your website, your Google profile and your business cards. If the vendor owns it, the vendor owns a piece of your business.
The FCC's consumer guide on porting says you can generally keep your number when you change providers in the same area, that simple ports are usually processed within one business day, that companies may charge a porting fee, and that your existing contract terms still apply. So porting is a right, but a contract can still make leaving expensive.
There's a simpler protection, and it's practice, not law: keep the number with your own carrier and forward calls to the receptionist. Then leaving is a settings change, not a porting project.
Data is the other half. Transcripts, recordings, call logs and the configuration you spent weeks tuning (the prompts, the answers, the transfer rules) should come with you.
What a good answer sounds like. Bulk export in standard formats. The number is yours or portable. Your configuration can be exported as text. No fee to get your own data.
Red flag answers."The number stays with us." "Exports are available on request" (for a fee, it turns out). A configuration that lives only inside a proprietary builder with no export.
How to verify. Ask for a sample export file during the trial and open it. Read the termination and porting clauses before you sign, not after.
Question 10: What happens when it or the model provider goes down, and how do we test before go-live?
Why it matters.An AI receptionist depends on the vendor, a telephony carrier and at least one model provider. Each has its own outages. OpenAI's public status page shows uptime and incident history per component, including its realtime and voice services, which is a reminder that the layers underneath a receptionist go down too. I won't print a percentage from it because it changes daily.
When a human receptionist is sick, the phone rings through to someone else. When the AI leg fails, the phone does whatever the vendor built it to do. Sometimes that's voicemail. Sometimes it's silence.
What a good answer sounds like. A published status page. A written SLA with service credits. Automatic failover to your staff line or voicemail when the AI leg fails. A pre-launch test plan, and a named person who reviews transcripts every week after launch.
Red flag answers."We're 99.99 percent up" with no SLA document. No status page. No fallback route. "Just forward your number and you're live."
How to verify.Read the SLA. Ask exactly where a call goes when the AI doesn't answer within a few rings. For testing, the buyer's guide has a twenty-call script; add a weekly transcript review with an owner's name next to it.
The printable one-page table
Print this, take it into the demo, and write the vendor's answer in the margin. If an answer matches the red flag column, circle it.
| # | Ask the vendor | Red flag answer | How to verify |
|---|---|---|---|
| 1 | Who owns recordings and transcripts, where are they stored, how long are they kept? | "We keep everything to improve the product"; no deletion path | Get the clause; delete a test call and watch it disappear |
| 2 | Which model provider do you use, under which terms, and does anyone train on my calls? | "We can't say which model"; "your data makes our AI smarter" | Ask for the provider name and the API data policy it runs under |
| 3 | Will you sign a BAA or DPA, on which plan, and are your subprocessors covered? | A HIPAA badge with no agreement; BAA only on an unpriced tier | Request the signed document and the subprocessor list before any live call |
| 4 | What exact unit am I billed for, and what does overage cost? | Undefined "credits"; overage only in the contract | Price your own call log against the written unit |
| 5 | How does transfer to a human work, and what context goes with it? | Blind transfer only; "read the transcript later" | Demand a person on a test call; ask the receiver what they heard |
| 6 | What does it do when it doesn't know? | "It never gets anything wrong"; a 99% with no method | Ask it something outside scope and read the transcript |
| 7 | Which systems does it write into, and which does it only read? | "It integrates with everything"; no audit log | Book a slot that is taken; ask for the write log |
| 8 | How does it disclose the AI and announce recording? | "Callers can't tell, that's the point" | Listen to the first ten seconds of a live call |
| 9 | Can I export everything and keep my number if I leave? | Number owned by the vendor; export for a fee | Ask for a sample export file and the porting terms |
| 10 | What happens when it or its model provider goes down, and how do we test? | No status page; "just turn it on" | Read the SLA; ask where calls go when the AI leg fails |
Three circles and I'd walk. One circle can be fine if the vendor fixes it in writing before you sign.
Red flags that end the call
Some answers are worse than others.These are the ones where I'd thank the salesperson and hang up, whatever the price.
- A statistic with no method: An accuracy, answer or booking rate that can't be traced to who measured it, on which calls. Vendor rates are marketing until proven otherwise.
- An unnamed model: Refusing to tell you which AI provider processes your callers' voices.
- Compliance by badge: A HIPAA or security claim with no signed agreement and no report you can read.
- An undefined unit: Credits, conversations or tasks that no document defines.
- Blind transfer only: The caller repeats everything to a human, every time.
- A number you can't take: The vendor owns your line and won't port it.
- Signing before testing: An annual contract before you've heard it take your own calls.
And one missed-call warning. You'll be shown dramatic statistics about how many callers never call back. I've traced several of the popular ones and couldn't find a study behind them, so I don't repeat them. Your own call log is better evidence than any of them.
Our answers for Frenchy Digital
Disclosure first: Frenchy Digital builds custom AI receptionists, so this section is us grading ourselves. I've used the same ten questions and marked where we fall short. Our AI Receptionist product page has the details.
1. Recordings and transcripts.You get full source code and IP ownership. Because you hold the telephony and model accounts yourself and pay the providers directly, recordings live in your accounts and follow your retention settings there. The gap: we don't publish a standard retention policy or a DPA template on the product page. We set retention with you during the build.
2. Model provider.The API accounts are yours, at provider rates, so commercial API terms apply rather than consumer ones. We choose the model per build and tell you which. The gap: the page doesn't name a default provider or promise zero data retention, which depends on the provider approving your account.
3. BAA.We sign a BAA with every healthcare client. The gap, and it's a real one: we hold no SOC 2, ISO 27001 or HITRUST certification. If your compliance team requires one of those from every vendor, we don't pass.
4. Billing.$5,000 for the agent plus $5,000 one-time setup, so $10,000 to start, rising with complexity and the number of integrations. After launch, $2,500 a month. Usage (model tokens, telephony, third-party APIs) is billed to you directly by the providers at their rates, with no per-call markup from us. So year one is $40,000 plus usage, and later years are $30,000 plus usage. The arithmetic: $10,000 plus 12 times $2,500 is $40,000. It's all published. The downside is obvious: against a $150 a month subscription ($1,800 a year), that's roughly 22 times more in year one, and it only makes sense if ownership and a fitted integration are worth that to you.
5. Transfer.Anything it can't answer is handed to a person with the conversation so far attached. The gap: the product page doesn't spell out warm versus cold transfer mechanics. We design that in discovery, and you should ask us to put it in the proposal.
6. When it doesn't know. It says so and hands over. Handover rules are written in discovery, and out-of-scope questions escalate by default. I have no independent accuracy data to show you, because nobody publishes that for any receptionist product, including us.
7. Writes.It books against a live calendar, and the booking is written by deterministic code rather than produced as text by a language model, so it can't offer a slot that isn't free. It can integrate with any system that has an API. The gap: we're a custom build, not an off-the-shelf product, so there's no library of prebuilt certified integrations and no marketplace listing. Each integration is built and tested for you, which takes time and money.
8. Disclosure.Callers are told they're speaking to an AI assistant. The gap: the product page says nothing about recording announcements. We treat the recording notice as a build requirement, but it isn't a published promise.
9. Exit.You own the code and the provider accounts, so if you leave us, the system stays with you. The gap: number porting isn't addressed on the page. My advice is the same as above: keep your number with your carrier and forward.
10. Uptime and testing.Builds run about 2 to 4 weeks from discovery to launch, the setup fee covers tuning after launch and guardrail work, and there's a 30-day post-launch warranty. The gap: no published SLA and no status page. If you need contractual uptime credits, a larger vendor may suit you better.
To be clear, I have no receptionist client outcome to show you. Our published case studies are website and app work, and I won't dress them up as receptionist results. We're a senior-led, Black-owned agency in Los Angeles, operating since 2016 in France and with a US entity since 2019, reachable at +1 (424) 272-5601.
Limitations
This is a checklist built from published documents, and it has limits.
I didn't test any vendor's call quality, transfer or retention in practice for this article. The vendor examples (Smith.ai, Vapi, Retell) are their own descriptions of their own features, used to show what a good answer can look like, not endorsements.
The Smith.ai retention and redaction details come from a 2022 news report and may have changed. Its pricing was checked September 30, 2026; a fact sheet from earlier the same week showed different overage ranges, which tells you how fast these pages move.
I found no independent accuracy benchmark for commercial receptionist products. τ-Voice tests model providers on customer service tasks and comes partly from a voice-agent vendor. I refused several accuracy figures from vendor blogs and a "report" hosted on a receptionist vendor's site builder because I couldn't trace their method.
The HHS and FCC pages blocked automated fetching; I confirmed their content through search results. The Justia recording survey dates from 2018. Anthropic's specific log retention window appeared only in secondary sources, so I haven't printed one. Whether any disclosure law covers your phone line is a question for your counsel.
Three things this week
You don't need to book a demo to start. You need the table and your call log.
- 1.Print the one-page table above and email the ten questions to every vendor on your shortlist. Ask for written answers. How fast and how specifically they reply is itself an answer.
- 2.Pull last month's call log from your phone carrier. Count calls and minutes, and price them against each vendor's written unit and overage. Confirm your number stays with your carrier.
- 3.On one free trial, make three test calls: demand a person, ask about something you don't offer, and try to book a slot that's taken. Read the transcripts the same day.
Whoever answers all ten in writing, with evidence, earns your trial. Time to get to work.
Want Straight Answers to All Ten?
Book a free discovery call with Frenchy Digital, a senior-led Black-owned LA agency. We'll answer these ten questions in writing for a custom receptionist, gaps included, and send a fixed-price phased proposal within 5 business days. Call +1 (424) 272-5601.
Want Straight Answers to All Ten?
Book a free discovery call. We'll answer these ten questions for a custom receptionist in writing, including where we fall short, and send a fixed-price phased proposal within 5 business days.
1517 S Bentley Ave Apt 204, Los Angeles CA 90025
Frequently Asked Questions
Sources & References
- 1Twilio, Recording resource (Voice API documentation)↗
- 2LawNext, Smith.ai adds automatic call recording and transcription (July 2022)↗
- 3OpenAI, Your data (API documentation)↗
- 4Anthropic, API and data retention↗
- 5HHS, Business Associates guidance↗
- 6HHS, Sample Business Associate Agreement Provisions↗
- 7Smith.ai, AI Receptionist pricing↗
- 8Vapi, Warm transfer documentation↗
- 9Retell AI, Call transfer feature page↗
- 10Ray et al., τ-Voice benchmark, arXiv 2603.13686↗
- 11FTC, Operation AI Comply announcement, September 2024↗
- 12California Penal Code 632↗
- 1318 U.S.C. 2511 (Cornell LII)↗
- 14Justia, 50-state survey on recording calls and conversations (PDF, January 2018)↗
- 15California Business and Professions Code 17940 to 17943 (bot disclosure)↗
- 16Utah SB 226 (2025), enrolled bill↗
- 17FCC Declaratory Ruling FCC 24-17 on AI-generated voices under the TCPA↗
- 18Colorado SB 26-189, Automated Decision-Making Technology↗
- 19FCC, Porting: Keeping Your Phone Number When You Change Providers↗
- 20OpenAI status page↗

