docs: link call recording/transcript retention, encryption & access from Data Flow - #1262
Draft
stephenvapiai wants to merge 2 commits into
Draft
stephenvapiai wants to merge 2 commits into
stephenvapiai wants to merge 2 commits into
Conversation
Customers repeatedly ask (Zendesk/Discord/Ask AI, current week and prior 4 weeks) how long call recordings/transcripts are kept, whether they're encrypted at rest/in transit, who can access them, and how to fully opt out. Data Flow said retention was "configurable" but never linked to the actual per-plan numbers, and Ask AI kept telling customers retention "varies by plan" without a source. This adds a short section linking to the single sources of truth instead of duplicating numbers inline: - Pricing and Success Packages (raw data retention table) - Manage Success Packages and add-ons (extended retention add-on) - GDPR Compliance (encryption in transit/at rest) - SSO (RBAC / who can access artifacts) - Zero Data Retention (full opt-out) Deliberately does not restate specific day counts: PR VapiAI#1220 (2026-09-14) already moved call-recording.mdx away from hardcoded retention numbers to a link to Pricing and Success Packages, to avoid drift as plans change. This section follows that same pattern rather than reintroducing hardcoded numbers.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed
Adds a Data Retention, Encryption & Access section to
security-and-privacy/data-flow.mdx. It links to the existing sources of truth instead of duplicating numbers:Why (customer evidence)
Evaluated the last 7 days vs. the prior 7 days vs. a trailing 4-week baseline of customer feedback (Zendesk-style support tickets, Ask AI conversations, Discord, NPS surveys). "Call Artifacts" was the top volume topic this week, and inside it the single most recurring, well-defined pattern (current week and every prior week in the 4-week baseline) is customers and Vapi's own Ask AI assistant asking how long call recordings/transcripts are kept, whether they're encrypted, who can access them, and how to fully opt out — e.g. two identical support tickets on the same day asking exactly this, an EU/GDPR ticket, an HIPAA BAA subprocessor-retention question, four separate ZDR/Core-package questions in one day on Discord, and a customer who could not recover recordings once they aged out of the 14-day window.
data-flow.mdxis the page Vapi's Ask AI assistant itself keeps citing for these questions, but it only said retention was "configurable" with no link to actual numbers — Ask AI's own answers repeatedly hedge with "retention varies by plan" or call the default "undocumented." That's the gap this PR closes.Classification: Incomplete content — a relevant page (Data Flow) exists and is on-topic, but didn't cover the specific numbers/encryption/access/opt-out scenario customers keep asking about.
Why no hardcoded retention numbers
#1220 (merged 2026-09-14, 11 days before this PR) already moved
assistants/call-recording.mdxaway from hardcoded retention numbers ("Pay-As-You-Go: 30 days chats / 14 days calls…") to a link to Pricing and Success Packages, specifically so retention info doesn't drift out of sync across pages as plans change. This PR follows that same just-established pattern instead of reintroducing hardcoded numbers on a second page. Checkeddata-flow.mdx's own commit history first (most recent: #1220 touched a different page, and an Aug 25 commit added the EU-region cross-link that's already in this diff's base) — no other in-flight change to this section.Note on how this PR was opened
Direct branch creation on
VapiAI/docswas blocked by the org's OAuth App access restrictions for this connector, so this change was pushed to a personal fork (stephenvapiai/docs) and opened as a cross-repo PR per the documented fallback. Only the section above is the intended change.