diff --git a/fern/security-and-privacy/data-flow.mdx b/fern/security-and-privacy/data-flow.mdx index 9b9bddbac..786ed147e 100644 --- a/fern/security-and-privacy/data-flow.mdx +++ b/fern/security-and-privacy/data-flow.mdx @@ -352,6 +352,21 @@ The **Orchestration Layer** (endpointing, interruption detection, emotion detect --- +## Data Retention, Encryption & Access + +Call recordings, transcripts, and call logs stored on Vapi's infrastructure follow the **raw data retention** window included with your Success Package — this is the "configurable retention" referenced throughout this guide. Retention days, encryption, and access controls live in one place so they don't drift out of sync as plans change: + +- **How long artifacts are kept:** See the raw data retention row in [Pricing and Success Packages](/billing/pricing-and-success-packages#whats-included) for what your plan includes today. To keep artifacts longer than your plan's window, buy the **extended data retention** add-on — see [Manage Success Packages and add-ons](/billing/manage-packages-and-add-ons#buy-compliance-and-data-add-ons) — or configure [custom bucket storage](#custom-storage-data-flow) so you control retention yourself. +- **Encryption:** Vapi encrypts data in transit and at rest as part of its standard security practices. See [GDPR Compliance](/security-and-privacy/GDPR#data-security-measures) for the full list of technical and organizational safeguards. +- **Who can access stored artifacts:** Access to call recordings, transcripts, and call logs is governed by your organization's role-based access control. See [Role-based access control (RBAC)](/security-and-privacy/sso#role-based-access-control-rbac) for what each plan supports. +- **To stop retention entirely:** Enable [Zero Data Retention (ZDR)](/security-and-privacy/zero-data-retention), which stops Vapi from storing recordings, transcripts, messages, summaries, and detailed call logs after a call ends. ZDR is an organization-wide, all-or-nothing setting — for retention control on individual calls instead, use custom storage plus your own deletion policy. + + +Retention days are set at the plan level in [Pricing and Success Packages](/billing/pricing-and-success-packages#whats-included) rather than repeated here, so this page stays accurate as plans change. + + +--- + ## What Data Passes Through Vapi Even with maximum custom configuration, certain data passes through Vapi's orchestration: