Security and data handling

Clear controls around every live clinic.

AnswerOtter limits live service to the clinic facts, call paths, delivery destinations, and fallback behavior that have been configured and tested. We do not turn a generic demo into a customer deployment.

AI + recording noticeThe opening identifies the AI assistant and says the call may be recorded.
Verified delivery pathsPrimary and backup staff destinations are tested before live service.
Stripe-hosted card handlingAnswerOtter does not receive full card numbers or security codes.
Operational controls

Designed to fail visibly and safely.

These controls describe the managed service. They are not a claim of a third-party security certification.

01

Clinic-specific authority

Live call handling is bound to an approved clinic configuration, phone route, service period, and tested staff-delivery paths.

02

Signed webhook checks

Provider events are authenticated before call records can enter the delivery path, and retries are reconciled instead of treated as new calls.

03

Primary and backup delivery

Appointment, refill, general, and urgent messages use the destinations and backup behavior approved for that clinic.

04

Visible failure handling

Delivery problems and provider outages must be visible to AnswerOtter. A transcript existing at a provider is not treated as proof that clinic staff received a message.

05

Restricted access

Clinic and caller information is used only to configure, deliver, secure, support, and improve the service as described in the agreement and privacy policy.

06

Reversible forwarding

The clinic's forwarding mode and reversal procedure are tested before live service, with a pre-approved fallback for new calls.

Data lifecycle

Know what is collected and why.

Clinic setup information

We collect the facts, routing instructions, delivery contacts, access details, and approvals needed to configure and support the service. Carrier passwords should not be sent through ordinary email or public forms.

Call information

When enabled, the service may process recordings, transcripts, caller contact details, appointment and refill requests, and operational notes. Retention and deletion requirements are documented with the clinic before setup.

Demo-line calls

The demo line asks callers to use made-up details. It may process the caller number, recording, transcript, and extracted test details and is currently configured for 30-day provider retention.

Payments

Stripe hosts the private, clinic-bound Checkout and resulting payment records. AnswerOtter receives Stripe identifiers and payment status, not the full card number or security code. Public Payment Links, the Customer Portal, and automated billing lifecycle actions remain deferred.

Report a security concern.Email pat@answerotter.com with a concise description and a safe way to contact you. Do not include passwords, payment-card data, or unrelated caller information.

Need a data-handling answer?

Ask before setup. Clinic-specific retention, routing, disclosure, or access requirements must be agreed in writing before live service.