From eae3b85dcdd7deabe3f91b317fe50fcf17dd8c25 Mon Sep 17 00:00:00 2001 From: Steve Smtih Date: Fri, 25 Sep 2026 10:27:45 -0700 Subject: [PATCH] docs: add Data Retention, Encryption & Access section to Data Flow Customers repeatedly ask (Zendesk/Discord/Ask AI, current week and prior 4 weeks) how long call recordings/transcripts are kept, whether they're encrypted at rest/in transit, who can access them, and how to fully opt out. Data Flow said retention was "configurable" but never linked to the actual per-plan numbers, and Ask AI kept telling customers retention "varies by plan" without a source. This adds a short section linking to the single sources of truth instead of duplicating numbers inline: - Pricing and Success Packages (raw data retention table) - Manage Success Packages and add-ons (extended retention add-on) - GDPR Compliance (encryption in transit/at rest) - SSO (RBAC / who can access artifacts) - Zero Data Retention (full opt-out) Deliberately does not restate specific day counts: PR #1220 (2026-09-14) already moved call-recording.mdx away from hardcoded retention numbers to a link to Pricing and Success Packages, to avoid drift as plans change. This section follows that same pattern rather than reintroducing hardcoded numbers. --- fern/security-and-privacy/data-flow.mdx | 19 +++++++++++++++++++ 1 file changed, 19 insertions(+) diff --git a/fern/security-and-privacy/data-flow.mdx b/fern/security-and-privacy/data-flow.mdx index fc0d6da6e..786ed147e 100644 --- a/fern/security-and-privacy/data-flow.mdx +++ b/fern/security-and-privacy/data-flow.mdx @@ -352,6 +352,21 @@ The **Orchestration Layer** (endpointing, interruption detection, emotion detect --- +## Data Retention, Encryption & Access + +Call recordings, transcripts, and call logs stored on Vapi's infrastructure follow the **raw data retention** window included with your Success Package — this is the "configurable retention" referenced throughout this guide. Retention days, encryption, and access controls live in one place so they don't drift out of sync as plans change: + +- **How long artifacts are kept:** See the raw data retention row in [Pricing and Success Packages](/billing/pricing-and-success-packages#whats-included) for what your plan includes today. To keep artifacts longer than your plan's window, buy the **extended data retention** add-on — see [Manage Success Packages and add-ons](/billing/manage-packages-and-add-ons#buy-compliance-and-data-add-ons) — or configure [custom bucket storage](#custom-storage-data-flow) so you control retention yourself. +- **Encryption:** Vapi encrypts data in transit and at rest as part of its standard security practices. See [GDPR Compliance](/security-and-privacy/GDPR#data-security-measures) for the full list of technical and organizational safeguards. +- **Who can access stored artifacts:** Access to call recordings, transcripts, and call logs is governed by your organization's role-based access control. See [Role-based access control (RBAC)](/security-and-privacy/sso#role-based-access-control-rbac) for what each plan supports. +- **To stop retention entirely:** Enable [Zero Data Retention (ZDR)](/security-and-privacy/zero-data-retention), which stops Vapi from storing recordings, transcripts, messages, summaries, and detailed call logs after a call ends. ZDR is an organization-wide, all-or-nothing setting — for retention control on individual calls instead, use custom storage plus your own deletion policy. + + +Retention days are set at the plan level in [Pricing and Success Packages](/billing/pricing-and-success-packages#whats-included) rather than repeated here, so this page stays accurate as plans change. + + +--- + ## What Data Passes Through Vapi Even with maximum custom configuration, certain data passes through Vapi's orchestration: @@ -381,6 +396,10 @@ Even with maximum custom configuration, certain data passes through Vapi's orche + + Vapi offers an EU region for data residency. For more information, see [EU region and data residency](/security-and-privacy/eu-region). + + - Use **custom bucket storage** in your required region - Use **custom LLM** hosted in-region OR provider with regional endpoints - Use **custom Voice** hosted in-region if needed