Callio
Trust & Security

How we handle your practice data

This page is maintained by Callio to answer common security and privacy questions about our AI receptionist for dental practices. It describes current, app-visible controls — it is not an independent audit or certification.

Last updated: June 2026

Access & authentication

Access to the Callio dashboard requires an account with email and password, or a supported social sign-in provider. Sessions are managed by our authentication provider and protected with industry-standard token handling.

Administrative areas (such as viewing demo leads) are gated by a server-enforced role check — client-side flags alone cannot grant access.

Platform & hosting

The Callio app runs on managed cloud infrastructure. Application data is stored in a managed Postgres database with row-level security policies that scope reads and writes to the correct user or role.

Data is transmitted over TLS between your browser and our servers.

Data we collect

When you book a demo we collect the details you submit (name, practice name, email, phone, message, how you heard about us). We also capture standard marketing attribution like UTM parameters and the referring URL.

When you create an account we store your email and authentication metadata. Operational logs may include request metadata needed to run and debug the service.

Subprocessors & integrations

Callio relies on a small set of vendors to operate, including our cloud database and authentication provider, and AI model providers used to power conversation features. We share only the data needed for each vendor to perform its function.

For an up-to-date list of subprocessors, contact us at the address below.

Retention & deletion

Demo lead submissions and account data are retained while your relationship with Callio is active. You can request deletion of your personal data by contacting us.

When voice answering ships, specific retention periods for transcripts, recordings, and call metadata will be agreed in your service contract.

Shared responsibility

Callio is responsible for securing the application, its infrastructure, and the controls described on this page. Your practice remains responsible for managing who has access to your Callio account, keeping credentials secure, and ensuring the information you submit complies with the laws applicable to your practice.

Reporting a security concern

If you believe you've found a security or privacy issue, please email hello@calliotech.net with details so we can investigate. Please do not include real patient information in your report.

Contact

For privacy requests, data export, deletion, or any other question about how Callio handles your data, reach us at hello@calliotech.net.

This page is editable content maintained by Callio and is provided for informational purposes only. It is not a certification, legal advice, or a contractual commitment. For binding terms, refer to your signed agreement with Callio.