Contents
Privacy Policy
Last Updated: August 3, 2026
1. Who We Are
Cognify Insights LLC, doing business as Skite.ai ("Skite," "we," "us," or "our"), provides an AI-powered voice receptionist and appointment-booking service. Businesses across industries such as dental, medical, beauty, and home-service trades (plumbing, HVAC, electrical, and similar) use Skite to answer incoming phone calls, converse with callers using an AI voice assistant, schedule and manage appointments, and relay call information back to the business.
Our registered business address is 30 North Gould Street, Sheridan, WY 82801. You can reach us at support@skite.ai.
2. Scope of This Policy and Who It Covers
Skite sits between two parties, and this policy is written to be clear about both:
- Business Clients — the companies (dental practices, medical clinics, beauty and salon businesses, and home-service trades such as plumbing, HVAC, and electrical) that sign up for and configure the Skite service. For data about a Business Client's own account, billing, and staff users, Skite acts as the data controller (or "business" under CCPA/CPRA).
- Callers — the customers, patients, or members of the public who call a Business Client's phone number and are answered by Skite's AI assistant. For data generated during those calls, Skite acts as a data processor/service provider on behalf of the Business Client, who remains the controller of their own customers' data. Our Business Clients are responsible for their own disclosures to their callers (for example, in their own patient intake forms or website privacy notices); this policy describes how we, as their vendor, handle that data.
Throughout this policy, "you" refers to whichever of these two roles applies to you — context will make clear which.
3. Speaking With an AI Assistant
When you call a business that uses Skite, you may be interacting with an AI-generated voice rather than a live person. Consistent with emerging state and international transparency requirements (see Section 13), Skite is designed so that:
- The AI assistant identifies itself as an artificial/automated assistant at the start of the interaction (or as soon as practicable), and states which business it is calling on behalf of.
- If a caller directly asks whether they are speaking with a person or a machine, the assistant will answer honestly.
- Calls may be recorded and transcribed for the purposes described in this policy; where required by law, this is disclosed on the call itself.
- Callers can request transfer to a human representative where the Business Client has configured this option.
4. Information We Collect
4.1 From Business Clients
- Account and contact information: business name, industry/vertical, owner or staff name, email, phone number, and physical business address.
- Authentication data: login credentials are managed through our identity providers — we do not directly store passwords.
- Billing information: processed through Stripe; we retain records of plan tier, invoices, and payment status, but full card numbers are held by Stripe, not us.
- Configuration data: call-routing preferences, business hours, appointment types, staff calendars, and scripts/prompts the Business Client sets up for their AI assistant.
- Support communications: anything you send us directly via email or support channels.
4.2 From Callers (via voice interactions)
- Call audio and transcripts: the AI assistant listens to and processes the spoken conversation in order to respond and take action (e.g., booking an appointment).
- Call metadata: caller phone number, call duration, timestamp, and call outcome (e.g., appointment booked, message taken, call transferred).
- Information volunteered during the call: name, callback number, reason for calling, appointment preferences, and — depending on the Business Client's vertical — health-related information a caller shares (for example, "I have a toothache" to a dental office, or symptoms described to a medical office). See Section 9 on how we handle this as Protected Health Information (PHI) where applicable.
- Appointment and scheduling data: date, time, service type, and any notes associated with a booking.
4.3 Automatically Collected / Technical Data
- Dashboard usage logs (which staff member viewed or approved what, general device/browser info) when Business Client staff use the Skite web dashboard.
- System and error logs generated by our infrastructure, which may incidentally include identifiers like a phone number or account ID.
4.4 Sensitive / Special Category Data
Because Skite serves dental and medical practices, calls to those Business Clients may include health information from callers (symptoms, appointment reasons, provider names). We treat this as sensitive data and apply the additional protections described in Section 9 (HIPAA) regardless of which state or country the call originates from.
We do not knowingly collect Social Security numbers, government ID numbers, or payment card numbers through call audio; if a caller volunteers this information verbally, we minimize its retention and access as described in Section 10.
5. How We Use Information
- To operate the core service: answering calls, understanding caller intent, booking or modifying appointments, generating call summaries, and delivering that information to the Business Client's dashboard.
- To generate the AI voice response: caller speech is processed by our conversational AI systems (Section 6) to determine what to say back, and the response text is converted to speech.
- To notify Business Clients: e.g., a new appointment was booked, a call requires follow-up, or a call could not be completed.
- To send appointment reminders: where a Business Client has enabled reminders, we may send automated SMS text messages and/or place automated AI-voice calls to the caller ahead of a scheduled appointment. Because these are outbound, AI-generated communications, they are subject to TCPA consent requirements independent of the caller's existing relationship with the Business Client (see Section 13) — Business Clients are responsible for obtaining appropriate consent to send these reminders at the time of booking.
- For billing: to charge Business Clients per their selected plan and usage.
- To maintain and improve the service: debugging, reliability monitoring, and — only in aggregated or de-identified form wherever possible — improving how our AI assistant handles calls.
- For security and fraud prevention: detecting abuse of the platform, unauthorized access, or fraudulent account activity.
- For legal compliance: responding to lawful requests, regulatory obligations, and enforcing our agreements.
We do not sell personal information, and we do not use caller data for advertising or to build profiles for any purpose outside operating the service for the relevant Business Client.
6. AI Systems That Process Conversations
Skite's assistant uses a pluggable AI architecture. Depending on configuration, a call may be processed by one or more of the following in order to generate a response:
- OpenAI (Realtime API) — processes live conversational audio to understand caller intent and generate a spoken response.
- Google (Gemini) — may process conversational audio/text as an alternative conversational AI provider.
- Anthropic (Claude) — may process conversational audio/text as an alternative conversational AI provider.
- Self-hosted models — for some configurations, conversation processing occurs on infrastructure we operate directly rather than being sent to a third-party AI vendor; in that case, the data does not leave our own systems and is protected under the security measures in Section 11 rather than a third-party subprocessor agreement.
- ElevenLabs — converts text responses into synthesized speech (text-to-speech).
These providers process data solely to return a result to Skite and, in turn, to the Business Client — not to train their own general-purpose models on our data, consistent with their enterprise/API data-use terms. We maintain data processing agreements with these providers, and, for Business Clients in regulated healthcare verticals, Business Associate Agreements (BAAs) covering any Protected Health Information that passes through these systems (Section 9).
7. How We Share Information (Subprocessors)
We do not sell personal data or share it with third parties for their own marketing. We share data only with the service providers below, each of whom is contractually limited to using data solely to provide their service to us.
| Subprocessor | Role | Data involved |
|---|---|---|
| Twilio | Telephony — call routing, connection, and (where enabled) recording, using a dedicated subaccount per Business Client | Caller phone number, call audio, call metadata |
| OpenAI | Conversational AI processing (Realtime API) | Call audio/transcripts, conversation content |
| Google (Gemini) | Alternative conversational AI processing | Call audio/transcripts, conversation content |
| Anthropic (Claude) | Alternative conversational AI processing | Call audio/transcripts, conversation content |
| ElevenLabs | Text-to-speech voice synthesis | Text of AI responses |
| Clerk | Authentication for Business Client staff accounts | Staff login credentials, session data |
| Stripe | Payment processing and billing | Business Client billing and payment data |
| Resend | Transactional email delivery (e.g., account notifications, receipts, appointment confirmations) | Recipient email address, message content |
| Cloud hosting providers | Infrastructure hosting for our application and databases | All data described in this policy, encrypted at rest and in transit |
Our appointment-scheduling system runs on self-hosted infrastructure that we operate directly, rather than a third-party scheduling vendor. Similarly, for configurations using our self-hosted conversational AI model rather than a third-party LLM provider, conversation data stays on infrastructure we operate directly. In both cases, that data is subject to the same security measures described in Section 11 rather than a third-party subprocessor agreement.
We may also disclose information:
- To the Business Client — call summaries, transcripts, and appointment data are, by design, delivered to the relevant Business Client's dashboard.
- For legal reasons — in response to a valid subpoena, court order, or other lawful request, or to protect against fraud, security threats, or harm, we will notify the affected Business Client of such a request unless legally prohibited from doing so.
- In a business transfer — if Skite is involved in a merger, acquisition, or asset sale, personal data may be transferred as part of that transaction, subject to this policy or a policy providing at least equivalent protections.
8. Call Recording and Consent
Call recording laws vary by state. Roughly a dozen U.S. states require all-party consent to record a phone call, while the rest require only one-party consent. Where a call crosses state lines, the stricter law generally governs. Business Clients are responsible for configuring recording disclosures appropriately for the jurisdictions they operate in, and Skite's platform is designed to support an audible recording notice at the start of a call.
Separately, and regardless of recording, several states now require disclosure that a caller is interacting with an AI system (Section 13). We build our assistant to support this disclosure and encourage every Business Client to keep it enabled.
9. HIPAA and Protected Health Information (PHI)
Because Skite serves dental and medical practices, some Business Client accounts are flagged internally as handling PHI. For those accounts:
We act as a Business Associate under HIPAA with respect to PHI processed on behalf of the Business Client (who is the HIPAA Covered Entity).
We are in the process of executing, Business Associate Agreements (BAAs) with subprocessors that may handle PHI in the course of providing the service.
- Twilio: Is a signed BAA currently in force on our account for the specific Twilio products we use (voice, recording, subaccounts)?
- OpenAI: Is a signed BAA currently in force covering the Realtime API specifically (not just OpenAI's API generally)?
- Google (Gemini): If Gemini is the active conversational AI provider for a medical/dental account, is a signed BAA in force covering that specific API/product?
- Anthropic (Claude): If Claude is the active conversational AI provider for a medical/dental account, is a signed BAA in force covering that specific API/product?
- ElevenLabs: ElevenLabs will sign a BAA, but only extends HIPAA eligibility to accounts that (a) have a countersigned BAA on file and (b) have Zero Retention Mode actively enabled in the account configuration. Confirm both conditions are met for every medical/dental Business Client — if either is missing, PHI should not be routed to ElevenLabs for that account.
- Self-hosted conversational AI: no third-party BAA applies here, since the data never leaves our own infrastructure — but our own internal safeguards (Section 11) still need to meet HIPAA Security Rule standards for that data.
Until each is confirmed for the specific provider actually configured on an account, treat that account as not yet covered for that vendor, and route or restrict PHI accordingly.
We apply the HIPAA Security Rule's required and addressable safeguards to PHI in our systems, including access controls, audit logging, and encryption in transit and at rest.
We limit use and disclosure of PHI to the minimum necessary to provide the service.
In the event of a breach involving unsecured PHI, we will notify the affected Business Client without unreasonable delay, consistent with HIPAA's breach notification requirements, so that the Business Client can meet their own notification obligations to patients and, where required, regulators.
PHI retention follows the terms of the applicable BAA and the Business Client's own record-retention obligations under state law (which commonly range from several years to longer for medical records); we do not independently shorten or extend that schedule without the Business Client's instruction.
Business Clients that are not in regulated healthcare verticals (e.g., a plumbing or HVAC business) are not treated as HIPAA Covered Entities, and no PHI-level handling is applied to their data, since none is expected.
10. Data Retention
- Business Client account data: retained for as long as the account is active. Upon account closure, we delete or anonymize this data within 90 days, except where longer retention is required for legal, tax, or dispute-resolution purposes.
- Call recordings and transcripts: retained by default for 12 months to allow the Business Client to review call history, after which they are deleted or archived, unless PHI retention rules (Section 9) or a Business Client's own instructions require a different schedule.
- Billing records: retained as required by tax and accounting law (typically several years).
- Logs and backups: rotated and purged on a regular schedule; encrypted backups are retained only for disaster-recovery purposes for a limited time.
Deletion requests from a Business Client or, where applicable, a caller exercising their own privacy rights, will be honored as described in Section 14, except to the extent we are legally required to retain certain records.
11. Data Security
- Encryption: all data in transit between Skite, Business Clients, and our subprocessors uses TLS/HTTPS. Sensitive fields at rest (such as caller contact details) are encrypted using AES-256-GCM.
- Access controls: access to production systems, call recordings, and databases is restricted to personnel who need it, authenticated, and logged.
- Infrastructure isolation: each Business Client's telephony is provisioned through a dedicated Twilio subaccount, limiting cross-account data exposure.
- Vendor vetting: subprocessors are evaluated for security practices and, where relevant, compliance certifications (e.g., SOC 2).
- Monitoring: we monitor for suspicious activity and maintain an incident-response process to contain, investigate, and notify affected parties of any security incident as required by law.
No method of transmission or storage is 100% secure, but we follow industry-standard practices to protect data across the service.
12. International Data Transfers
Skite's infrastructure and subprocessors are primarily based in the United States. If a Business Client, caller, or their data originates outside the U.S. (including the EEA, UK, or elsewhere), data may be transferred to and processed in the U.S. Where required, we rely on Standard Contractual Clauses (SCCs) or equivalent legally recognized transfer mechanisms with our subprocessors to protect data transferred internationally.
13. AI-Specific Disclosure Laws
Regulation of AI voice systems is evolving quickly. As of this policy's last update:
- Federal (FCC/TCPA): The FCC has clarified that calls using AI-generated voices are treated as "artificial voice" calls under the TCPA for outbound calling, but has stated that TCPA consent requirements do not extend to technologies used to answer inbound calls — which is Skite's core function. Our outbound appointment-reminder feature, which uses both SMS text and AI-generated voice calls, remains subject to TCPA consent rules independent of any prior business relationship with the caller; Business Clients are responsible for obtaining the appropriate consent at the time of booking, and AI-generated text messages must disclose their AI-generated nature.
- California: AB 2905 requires disclosure when a caller is interacting with an AI agent, and AB 489 specifically prohibits AI systems from falsely claiming healthcare credentials and requires disclosure when AI communicates with patients — directly relevant to our dental/medical Business Clients. SB 1001 requires bot disclosure in calls intended to incentivize a commercial transaction.
- Maine: 10 M.R.S. §1500-DD (effective September 2025) requires disclosure when a caller is interacting with a voice-based automated system.
- Texas: TRAIGA (HB 149), effective January 1, 2026, imposes AI-interaction disclosure requirements on certain regulated industries.
- EU AI Act, Article 50 (effective August 2, 2026): providers of voice assistants and chatbots that interact directly with people in the EU must ensure users are informed they are dealing with AI, no later than the first interaction, in a way that's perceivable within the interaction itself (not just buried in a privacy policy).
- Colorado: the original Colorado AI Act's risk-based framework has been substantially narrowed and its effective date delayed to January 1, 2027; it now focuses on disclosures around automated decision-making rather than a broad risk-management regime, and its scope (employment, housing, healthcare, etc.) should be monitored for relevance as it's finalized.
This area changes often; we review our disclosure practices periodically against new state and international requirements as they take effect.
14. Your Privacy Rights
14.1 U.S. State Privacy Laws (CCPA/CPRA and similar)
Residents of California, and increasingly other states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, and others), generally have the right to:
- Know what personal information we collect and how it's used
- Access a copy of that information
- Correct inaccurate information
- Delete personal information (subject to legal exceptions)
- Opt out of the sale or sharing of personal information (we do not sell or share personal information for cross-context behavioral advertising)
- Limit use of sensitive personal information
- Not be discriminated against for exercising these rights
14.2 GDPR / UK GDPR (where applicable)
If you are located in the EEA or UK, you have the right to access, rectify, erase, or restrict processing of your personal data; to data portability; to object to certain processing; and to lodge a complaint with your local supervisory authority. Our legal bases for processing include performance of a contract with the Business Client, our legitimate interests in operating and securing the service, and — for certain health-related data — explicit consent or another applicable Article 9 condition.
14.3 How to Exercise These Rights
Contact us at support@skite.ai. Because we act as a processor for caller data on behalf of Business Clients, if a caller contacts us directly, we will typically direct the request to the relevant Business Client (who controls that data) or notify the Business Client of the request, consistent with our obligations as their service provider. We may need to verify your identity before fulfilling a request.
15. Children's Privacy
Skite's service is directed at businesses and their adult customers, not children. We do not knowingly collect personal information from children under 13 (or the relevant age of digital consent in your jurisdiction) through our dashboard. Call interactions are answered without age verification, as is standard for business phone lines; if we become aware that a caller is a child and personal information has been retained inappropriately, we will take steps to delete it upon request from a parent, guardian, or the Business Client.
16. Cookies and Website Data
Our website and dashboard may use cookies or similar technologies for authentication, basic analytics, and remembering preferences. We do not use cookies for cross-site advertising tracking.
17. Changes to This Policy
We may update this policy from time to time to reflect changes in our practices, our technology, or legal requirements. We will update the "Last Updated" date above, and for material changes, we will provide more prominent notice (such as an email to Business Clients).
18. Contact Us
Questions about this policy or how Skite handles your data can be directed to support@skite.ai.