Privacy Policy

Last Updated: August 31, 2026

At FieldCue, we respect your privacy and are committed to protecting the personal data and call transcription information we process. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our post-call CRM automation platform.

1. Information We Collect

When you register for and use FieldCue, we collect information necessary to deliver our services:

  • Account Information: Name, email address, password hash, and subscription tier.
  • Integration Tokens: Securely encrypted OAuth tokens and identifiers when you link your GoHighLevel location sub-accounts.
  • Call Metadata & Audio: Recording URLs and metadata sent via your configured GoHighLevel call status webhooks.
  • BYOK API Credentials: Encrypted OpenAI and Anthropic API keys if you opt to use your own developer keys.

2. How We Use Your Information

We process your information solely to execute the post-call automation pipeline:

  • Downloading and transcribing your call recordings using speech-to-text services (AssemblyAI for recorded calls; OpenAI Whisper for uploaded files, for tenants using their own OpenAI key, and as a fallback).
  • Diarizing speaker turns and extracting custom fields using AI systems (such as Claude).
  • Syncing call logs, compliance summaries, tasks, and stage changes directly back to your GoHighLevel sub-account contacts and opportunities.
  • Managing account administration, processing subscriptions, and handling customer support requests.

3. Data Retention and Security

We prioritize the security of your data:

  • All sensitive tokens (OAuth client tokens, user API keys) are encrypted in our database using industry-standard AES-256-GCM algorithms.
  • Password storage utilizes salted `scrypt` hashing to prevent unauthorized extraction.
  • We only download call audio temporarily to transcribe it. Audio files are discarded immediately after processing is complete.
  • Completed call logs, compliance grades, and transcripts are stored in our secure database to display on your user dashboard.

How long we keep each kind of record:

  • Call audio: not retained. It is fetched to be transcribed and discarded when processing finishes.
  • Call records (transcripts, summaries, extracted fields, scores): kept for as long as the location they belong to exists, so they stay on your dashboard. Deleting a location deletes its call records immediately.
  • Expired links and counters (password resets, email confirmations, unaccepted invitations, failed-login counters): deleted automatically by a daily job once past their expiry.
  • Tester waitlist entries (the name, email, company and note you gave us while registration was closed): kept until you have an account or until the entry is removed. Registering deletes it automatically on the next daily run of that job, deleting your account afterwards deletes it in the same step, and you can ask us to take you off the list at any time by emailing support@fieldcue.app. Nothing on the list expires on age, so an entry stays until one of those happens.
  • Your account: kept until you delete it. Deleting your account removes it, every location you own, and all of their call history. This is irreversible.
  • Backups: deleted data may remain in encrypted database backups until those backups age out on their normal cycle. It is not restored to the live service in the meantime.

4. Sharing and Disclosure

FieldCue does not sell or lease your data or call recordings to third parties, and your calls are never used to train AI models. We share data only with the infrastructure partners and sub-processors required to deliver the service — hosting, the database, transcription and language models, payments, and email delivery.

Every one of them is named on our sub-processor list, along with what it handles and where it processes data. Ask us to add you to the notification list and we will give you 30 days' notice before a new one starts handling customer data.

5. User Rights and Data Control

You retain full ownership and control over your data, and you do not need to ask us to exercise most of it. Under Settings → Your Data you can download a complete machine-readable copy of your account — including every call, transcript, summary and extracted field — and you can permanently delete your account from the same place. Disconnecting your GoHighLevel sub-account from the settings panel immediately revokes OAuth access and halts webhook ingestion.

For anything those controls do not cover, such as erasing a single caller's records while keeping the rest, contact us and we will assist within 30 days. Business customers processing personal data through FieldCue are covered by our Data Processing Addendum, which sets out our obligations as your processor under GDPR and CCPA.

6. Contact Information

For privacy inquiries, GDPR/CCPA data removal requests, please contact us at privacy@fieldcue.app, and for general support contact support@fieldcue.app.