Security & Data Protection

Last Updated: September 6, 2026

At FieldCue, we recognize that your client conversations, recording audios, and CRM data are highly sensitive. This Security Policy details the technical safeguards, encryption standards, and data handling procedures we employ to protect your information.

1. Platform Data Flow & Architecture

FieldCue operates as a post-call processing system for GoHighLevel. Here is how your data travels through our platform:

  1. Ingestion: When a call completes, a HighLevel workflow triggers a webhook containing the recording URL, contact ID, and opportunity ID.
  2. Transcription: FieldCue downloads the audio file temporarily over HTTPS to generate a speaker-separated text transcript. Recorded calls are transcribed by AssemblyAI. OpenAI Whisper handles uploaded files, tenants transcribing with their own OpenAI key, and any call AssemblyAI cannot complete.
  3. Analysis: The text transcript is analyzed using language models (Claude) to extract custom fields, check compliance script adherence, and identify objections.
  4. CRM Synchronization: Extracted custom fields are synchronized back to the GHL contact or opportunity, a task is scheduled (if Objections are detected), and the transcript is posted to the contact record notes.

2. Call Recording & Audio Handling

Audio reaches us two ways, and they are not retained the same way. This section says exactly what happens to each, and matches section 5 of the Privacy Policy word for word.

  • Recordings in your CRM are not retained: we fetch the file, transcribe it, and discard our copy when processing finishes. The recording itself stays where you store it, under your control.
  • The link to that recording is kept: the call record holds the recording URL for as long as the call record exists, so the call page can hand you back to your CRM. Deleting the call in FieldCue removes our link. It does not delete your CRM's copy — that is done in your CRM.
  • Audio you upload directly to us is stored: it is kept on our servers so you can play it back from the call page, and is deleted when the call record is deleted.
  • Secure Downloads: All recording files are retrieved exclusively over HTTPS encrypted connections.
  • Backups: deleted data can persist in encrypted database backups until those age out on their normal cycle. It is not restored to the live service in the meantime, and if a backup is restored for disaster recovery we re-apply outstanding deletions.

3. Encryption Standards

FieldCue applies cryptographic security at rest and in transit:

  • In Transit: All internet communications, API requests, dashboard access, and webhook transmissions use TLS 1.3 (HTTPS) encryption.
  • BYOK & Credential Encryption: Custom API keys (OpenAI, Anthropic) and GoHighLevel location OAuth tokens are encrypted in our database at rest using AES-256-GCM encryption with unique initialization vectors (IV) and authentication tags.
  • Password Security: User passwords are encrypted at rest using salted cryptographic scrypt hashing functions to protect against database leaks.

4. Integration & OAuth Access Scopes

We authorize connection with GoHighLevel via official OAuth 2.0 channels. FieldCue requests access solely for scopes required to automate post-call admin workflows:

  • Contacts (Read/Write): To locate contacts, read custom field values (for overwrite protection checks), and update extracted fields.
  • Opportunities (Read/Write): To transition opportunity stages in your sales pipelines and sync custom deal fields.
  • Tasks (Write): To assign post-call tasks and deadlines to contact owners when objections or cues require follow-up.
  • Conversations (Read/Write): To read message details, download call attachments, and append text transcripts as contact notes.

5. User Controls & Data Deletion

You retain control over your GHL integrations and stored history:

  • Connection Revocation: You can revoke FieldCue's OAuth access at any time by disconnecting the location in your Settings dashboard.
  • Data Export: Under Settings → Your Data you can download a complete machine-readable copy of your account, including every call, transcript, summary and extracted field. Credentials and CRM tokens are excluded.
  • Deleting a single call: every call page carries a Delete control. It permanently removes that call record, its transcript, its processing logs, its extracted field results and any audio uploaded for it. This is the remedy when someone on a call objects to having been recorded: it is two clicks from the call, and it does not touch the rest of your history.
  • Data Purging: From the same panel you can permanently delete your account, every location you own, and all of their call history. Deletion is immediate and irreversible, and cancels any active subscription. For anything narrower — erasing one caller's records across many calls while keeping the rest — contact support.
  • Automatic Purging: Expired password reset links, email confirmation links, unaccepted invitations, and failed-login counters are deleted by a daily job once past their expiry.

Our retention periods, the sub-processors that can see customer data, and our processor obligations under GDPR and CCPA are set out on the Privacy Policy, Sub-processor list, and Data Processing Addendum.

6. Contact & Responsible Disclosure

We welcome feedback and vulnerability disclosures. Please contact us using the dedicated branded channels: