SaraDesk Privacy Policy
Last updated: July 18, 2026
SaraDesk ("we", "us", "SaraDesk") provides an AI voice receptionist service for property managers. This policy describes what data we collect, how we use it, and your choices.
1. What data we collect
- Account information you provide when calling our sales line or signing up: your name, your company name, business email, business phone number, billing details.
- Property and operational information you provide for setup: property addresses, rental terms, calendar availability, receptionist policies, maintenance routing preferences, escalation contacts.
- Call recordings and transcripts from interactions with our AI receptionist (Sara) or our AI sales agent (Sam). Calls are recorded and transcribed for service delivery, quality assurance, and to provide you with call history in your dashboard.
- Technical data from your use of our services: phone numbers used to call us, timestamps, API request logs, and similar service-operation metadata.
2. How we use it
- To provide the receptionist service to you and your tenants/prospects.
- To send you account-related SMS such as billing setup links (Stripe), calendar OAuth connection links, subscription-activation confirmations, booking notifications, and maintenance ticket forwards.
- To process billing through Stripe and maintain your subscription.
- To improve service quality, debug issues, and prevent abuse.
3. Mobile information sharing
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All other categories of personal information exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
- We do not sell your information to third parties under any circumstances.
- We do not share your information, including mobile phone numbers and SMS opt-in records, with third parties or affiliates for marketing or promotional purposes.
- We share information only with the service providers required to operate our service: Twilio (telephony + SMS delivery), Vapi (AI voice orchestration), OpenAI (large language model powering Sara's conversation, invoked through Vapi), Deepgram (speech-to-text transcription, invoked through Vapi), ElevenLabs (text-to-speech voice synthesis, invoked through Vapi), Google (Google Calendar integration for customers who connect a Google account — event data, availability, and attendee emails), Microsoft (Outlook / Microsoft 365 Calendar integration for customers who connect a Microsoft account — same scope as Google), Apple (Apple Calendar via CalDAV for customers who connect an app-specific password — same scope), Stripe (billing and payment card handling), Resend (transactional email delivery), and Cloudflare (hosting, key-value storage, and DNS). These providers act as data processors or sub-processors and are contractually restricted from using your data for their own marketing.
4. SMS messaging program
Program name: SaraDesk Transactional Messages.
Program description: SaraDesk sends transactional SMS messages to customers about their account, including: billing setup links (Stripe checkout), calendar OAuth connection links, signup confirmations, booking confirmations sent by your AI receptionist Sara, day-before booking reminders sent to your prospects, maintenance ticket forwards from your tenants, and dashboard access links.
How customers opt in: Customers opt in by either (a) signing up through our public web form at https://saradesk.com/signup, which collects their mobile number explicitly for transactional SMS, or (b) calling our sales line and verbally providing their mobile number to our agent for the same purpose. By providing your mobile number through either method, you expressly consent to receive transactional SMS messages from SaraDesk at that number.
Message frequency: Recurring messages. Approximately 5–50 messages per month per active account, depending on call and booking volume.
Message and data rates: Message and data rates may apply per your carrier's plan.
Opt-out: Reply STOP to any SaraDesk SMS at any time to immediately unsubscribe from all SaraDesk text messages. Confirmation of opt-out will be sent.
Help: Reply HELP to any SaraDesk SMS for assistance, or email support@saradesk.com.
Carriers: Carriers are not liable for delayed or undelivered messages.
5. Service providers and sub-processors
We use the following providers to operate SaraDesk. Each has their own privacy practices; we share only what is operationally necessary for the specific function.
- Twilio — SMS and voice telephony (call routing, SMS delivery, phone number provisioning).
- Vapi — AI voice assistant orchestration. Vapi in turn uses OpenAI, Deepgram, and ElevenLabs as sub-processors for language modeling, speech-to-text, and text-to-speech respectively; call audio and transcripts pass through these providers.
- OpenAI — large language model powering Sara's conversation. Invoked via Vapi. Conversation transcripts are sent to OpenAI for the duration of each call.
- Deepgram — real-time speech-to-text for inbound audio. Invoked via Vapi.
- ElevenLabs — text-to-speech for Sara's voice. Invoked via Vapi.
- Google — Google Calendar and Google OAuth for customers who connect a Google account. We receive an OAuth refresh token and use it to read availability + create/update/delete calendar events + include attendee emails. We do not read or write any other Google surface (Gmail, Drive, Contacts, etc.).
- Microsoft — Microsoft Graph and Microsoft OAuth for customers who connect an Outlook / Microsoft 365 account. Same scope as Google.
- Apple — Apple Calendar (CalDAV) for customers who provide an app-specific password. Same scope as Google and Microsoft.
- Stripe — payment processing, subscription management, invoicing. Card details are handled directly by Stripe; we never see raw card data.
- Resend — transactional email delivery (welcome emails, booking confirmations, reminders, ops alerts).
- Cloudflare — application hosting (Cloudflare Workers), key-value storage (Cloudflare KV), and DNS.
6. Google Workspace API Limited Use compliance
SaraDesk's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, we affirm that data received from Google Workspace APIs (Google Calendar in particular) is handled as follows:
- User-facing features only. Google Workspace data is used solely to power the calendar-integration features that customers explicitly enabled by connecting their Google account: reading availability for showing bookings, creating and updating calendar events for confirmed showings, and reading attendee emails on booking-related events. All of these are prominent, user-facing features of the SaraDesk product.
- Not used to train AI/ML models. SaraDesk uses AI/ML services (including Anthropic Claude for conversational reasoning and Deepgram for speech-to-text) to power the Sara receptionist. We do not use, transfer, or share raw or derived Google Workspace user data to train, retrain, fine-tune, or improve any AI/ML model — whether foundational, generalized, or specialized. Google user data flows to Anthropic Claude only during the immediate, in-conversation processing of a live call (e.g., for Sara to decide whether a proposed showing time is available), and Anthropic operates under a zero-retention agreement for API traffic. No Google user data is used for model training by SaraDesk, Anthropic, or any downstream provider.
- Not used for personalized advertising. SaraDesk does not serve advertising of any kind, and never uses Google Workspace data for ad targeting, personalization, or ad measurement.
- Not sold or transferred to data brokers. We do not sell, rent, or license Google Workspace data to any third party. We do not transfer it to data brokers, information resellers, or any organization that redistributes personal data.
- Not used for creditworthiness or lending. Google Workspace data is never used to determine creditworthiness, for lending decisions, or for any similar financial-eligibility purpose.
- Human access is limited to essential operations. SaraDesk personnel access Google Workspace data only for the following purposes: (a) with the customer's explicit consent, (b) to comply with applicable law, (c) to investigate a specific abuse or security incident, or (d) for internal operations where the data has been aggregated and anonymized (such as counting total showings booked across all customers for cost reporting).
- Scoped access. When a customer connects Google Calendar, we request only the minimum OAuth scopes required for the receptionist feature to work: read calendar availability, create/update/delete calendar events, and manage attendees on those events. We do not request or use any other Google surface (Gmail, Drive, Contacts, Photos, Meet metadata, etc.).
7. Data retention
Call recordings, transcripts, and account data are retained while your account is active. On cancellation, we retain billing records for the period required by applicable tax and accounting law and delete operational data within 30 days.
8. Your choices
You can request data export or deletion by emailing support@saradesk.com. You can opt out of SMS at any time by replying STOP. You can cancel your subscription from your dashboard. You can revoke Google Calendar access at any time from your Google Account permissions page (myaccount.google.com/permissions) or from the SaraDesk customer dashboard.
9. Contact
SaraDesk LLC — Phoenix, Arizona, USA — support@saradesk.com