https://myphoneflow.com/legal/service-terms/v1.0/
PhoneFlow AI & Telephony Service Terms
Version 1.0 · Effective: 2026-09-27 · Last updated: 2026-09-26
Summary (not a substitute for the terms below):
- When recording is on, AI phone calls open with the Customer's own recording notice (by default "This call is recorded."). Turning recording off removes it. PhoneFlow does not add a spoken AI announcement, and the Customer must never set up an agent to claim to be human. Any further notice or consent the law requires, including any AI disclosure and any notice for widget visitors, is the Customer's job.
- PHONEFLOW IS NOT AN EMERGENCY SERVICE. IT CANNOT CONNECT ANYONE TO 911, AND THE AI CANNOT SEND HELP. The Customer must keep its own way to reach emergency services.
- The Customer is the caller and sender for outbound AI calls, reminders and texts. Outbound AI calls are for informational messages to existing clients. Promotional AI calls need prior express written consent and PhoneFlow's written approval. Consent records are kept for 5 years.
- AI answers, transcripts and summaries can be wrong. The Customer configures and approves its agents and checks anything important before relying on it.
- The Customer is responsible for texting consent and registration, the pages it puts the widget on, the websites it asks us to crawl, and the integrations it connects.
- Forwarded numbers remain the Customer's, and PhoneFlow never blocks an authorized port. No health information (PHI), no voice cloning without the voice owner's signed consent, and no voiceprints.
1. About these Service Terms #
1.1 Part of the Agreement #
These AI & Telephony Service Terms (the "Service Terms") form part of the PhoneFlow Master Customer Agreement (https://myphoneflow.com/legal/customer-agreement/) (the "MCA") between the Customer and Electric Software LLC, a Michigan limited liability company doing business as PhoneFlow ("PhoneFlow", "we", "us"). Capitalized terms have the meanings in the MCA unless this document defines them. Accepting the MCA also accepts these Service Terms.
1.2 Scope and precedence #
These Service Terms add rules for the telephone, messaging, voice and AI parts of the Services. They apply whether the Customer configured a feature itself or PhoneFlow configured it through Setup Services. Where they conflict with the body of the MCA, the PhoneFlow Acceptable Use Policy (https://myphoneflow.com/legal/aup/) (the "AUP") or the Documentation, these Service Terms control for the feature they cover. A signed Order Form, the PhoneFlow Data Processing Addendum (https://myphoneflow.com/legal/dpa/) (for data protection) and, where it applies, the PhoneFlow Professional Services Addendum (Legal) (https://myphoneflow.com/legal/professional-services-addendum/) control over these Service Terms, following the MCA's order of precedence.
1.3 Terms defined in this document #
- Recording Notice: the recording notice the Customer sets for an agent (by default "This call is recorded."), which the Services play at the start of AI phone calls while recording is on (Section 2.3).
- Required Disclosure: the Recording Notice, and any other notice or introduction the Services play or show at the start of a call or session, such as a notice the web voice widget shows before the microphone opens (Section 2). No Required Disclosure includes a spoken statement that the Caller is talking with an AI.
- Outbound Communications: calls placed and texts sent through the Services, including AI calls, reminder calls, callbacks, reminder texts and follow-up texts, however they are triggered.
- PhoneFlow Numbers: numbers PhoneFlow obtains for the Customer through its carrier. Customer Numbers: numbers the Customer gets from its own carrier and forwards or points to the Services.
- Integration Credentials: API keys, OAuth tokens, passwords, webhook secrets and similar access details the Customer supplies to connect a Third-Party Service.
Beta Features has the meaning in the MCA.
1.4 Confirmations inside the product #
Some features may ask a Customer User to confirm a statement before they switch on, for example when enabling outbound calling, importing contacts, changing the Recording Notice or turning recording off, publishing a widget, activating a number or connecting an integration. A confirmation given by a Customer User is a statement by the Customer and is part of the Agreement. A missing or skipped confirmation does not reduce the Customer's obligations.
2. Caller disclosures #
2.1 PhoneFlow's default disclosures #
On inbound AI phone calls, the Services play these Required Disclosures before the agent's greeting:
| Where | What is said first |
|---|---|
| Inbound AI phone call, recording on | The Customer's Recording Notice, then the agent's greeting. The setup wizard's default wording is "This call is recorded." If the notice is left blank, the Services say "This call may be recorded for quality assurance purposes." |
| Inbound AI phone call, recording off | Nothing. The agent's greeting plays first. |
The Recording Notice is played in the wording the Customer sets. A Customer whose Callers speak a language other than English must write its Recording Notice, and any other notice it gives, in the language its Callers use.
PhoneFlow does not add a spoken statement that the Caller is talking with an AI. Section 2.2 explains what the Customer must add where the law requires more.
Web voice widget. The widget may show a notice on screen before it opens the Widget Visitor's microphone, and the Services may speak the Recording Notice at the start of a widget session while recording is on. Not every widget placement or version shows or speaks a notice, so the Customer must give Widget Visitors every notice the law requires, including on the pages that host the widget (Section 8).
Outbound calls. Outbound AI calls and reminder calls open with an introduction that comes from the Services or from the Customer's configuration. The Customer must make sure that introduction meets Section 6.4.
Voicemail. Voicemail messages are recorded and may be transcribed. PhoneFlow's default voicemail prompt does not by itself give every notice the law may require. A custom voicemail greeting set by the Customer or a Customer User replaces the default prompt. The Customer must make sure its voicemail greeting includes any notice the law requires.
2.2 Honesty about the AI, and AI disclosures the law requires #
PhoneFlow does not add a spoken announcement that the Caller is talking with an AI. The Customer must not configure an agent to claim or imply that it is human, or to deny being an AI when asked.
Some laws require an AI disclosure without being asked, or in a set form. For example, Utah (Utah Code Title 13, Chapter 77) requires people in regulated occupations to disclose AI use at the start of certain high-risk interactions, Maine (10 M.R.S. §1500-DD) regulates AI chatbots that could lead a consumer to believe they are dealing with a human, and California regulates undisclosed bots online (Cal. Bus. & Prof. Code §17940 et seq.). The Customer is responsible for deciding whether any such law applies to it or its End Users and, where one does, for giving the disclosure it requires. The Customer can add that wording to its agent's greeting. PhoneFlow does not add it by default.
2.3 The Recording Notice and the recording switch #
While recording is on, the Services play the Recording Notice at the start of each AI phone call, before the agent's greeting. The Customer may change the wording of its Recording Notice, but the notice must still say that the call is recorded and must not be misleading. The Services do not play a blank notice: if the Customer leaves it blank, they say "This call may be recorded for quality assurance purposes." Turning recording off for an agent removes the notice. The Customer may not use any other setting or tool to record without it. Agents built with the PhoneFlow setup wizard record by default. Agents built in other ways may not, so the Customer must check the recording setting of each of its agents. A recording step that the Customer adds to a custom call workflow, outside the AI agent, plays no notice unless the Customer adds one, and the Customer must add one wherever the law requires.
2.4 Further notices and consents are the Customer's responsibility #
The Required Disclosures are a baseline. They do not guarantee compliance with any particular law. The Customer must give every further notice, and obtain every consent, that the laws of its own location and of each End User's location require. In particular:
- All-party-consent states. California, Florida, Maryland, Massachusetts, Montana, New Hampshire, Pennsylvania and Washington require the consent of everyone on a call before it is recorded, and Illinois, Nevada and Connecticut have similar rules. California's law can reach out-of-state businesses that record calls with Californians.
- Form of notice. Some states set how notice must be given. Washington counts an announcement as consent only if the announcement is itself recorded. Connecticut accepts a recorded verbal notice at the start of the call or a warning tone. If a call flow the Customer designed or approved, such as a menu, transfer or recording step outside the AI agent, means the default notice is not recorded, is not heard before the conversation starts, or does not cover part of the call, the Customer must give notice in a form those laws accept. PhoneFlow plays the Recording Notice at the start of recorded AI calls as described in Section 2.1. Where a call first passes through a call-screening step, including one answered by PhoneFlow's auto-answer, the notice may play before the Caller is connected, and the Customer is responsible for any further notice its Callers' jurisdictions require.
- Michigan. Michigan's eavesdropping law (MCL 750.539a et seq.) can reach someone who records at a participant's request. The Customer must not treat its own consent as enough to authorize PhoneFlow and its providers to record.
- Professional and industry rules. Disclosures required by the Customer's profession, licensing body or industry, including any AI disclosure (Section 2.2).
- Privacy notices. The Customer's own privacy policy must describe its use of the Services, including AI answering, recording, transcription and sharing with service providers.
- What the Recording Notice covers. The default Recording Notice says only that the call is recorded. It does not mention AI handling, transcription, or processing by service providers. Where the law of the Customer's location or an End User's location requires notice of any of those, the Customer must add it, for example to its Recording Notice or greeting.
Under the MCA, the Customer's own violations of Communications Laws, including recording notices it removed or altered and consents it was responsible for, are Excluded Claims and fall within the Customer's indemnity.
2.5 Customer personnel, transfers and pre-answer audio #
Customer personnel who take transferred calls, join calls or review recordings are also parties to those conversations, and the Customer must tell them that calls handled through the Services may be recorded and transcribed. Where a transferred portion of a call is recorded, any further notice the law requires for that portion is the Customer's responsibility. Whether a transferred portion of a call is recorded depends on the Customer's recording settings. Anything that plays before the Services answer, such as the Customer's carrier greeting, or a call-screening prompt or menu run by the Customer's own carrier or phone system (not PhoneFlow's auto-answer), is outside PhoneFlow's control, and the Customer must make sure it does not record Callers without notice.
3. Call recording, voicemail and transcription #
3.1 What is processed #
Depending on the Customer's settings, the Services may record the audio of AI calls, widget sessions and voicemails; convert speech to text in real time so the agent can respond, and store the transcript; transcribe voicemails; and produce summaries, extracted fields and classifications. With recording off, no audio recording of the call is stored, but the agent still converts speech to text in real time in order to respond. Turning recording off stops the audio recording only: transcripts, summaries and other Output may still be created and stored.
3.2 Purpose #
Recording, transcription and summarization are part of how the Services answer calls, take messages and report to the Customer. PhoneFlow performs them for the Customer, on its instructions, and uses Customer Data only as the MCA and the Data Processing Addendum allow.
3.3 Storage and retention #
Call recordings are stored by our hosting providers, including Twilio. Transcripts and Output are stored in PhoneFlow's database, hosted in the United States. Data is encrypted in transit, and at rest by our hosting providers. Customer Data is kept for the life of the account unless the Customer deletes it or asks us to; PhoneFlow does not currently apply automatic deletion periods. The Customer may request export or deletion of recordings, transcripts or other Customer Data at [email protected]. PhoneFlow completes deletion requests within 60 days, including recordings held at Twilio. The MCA covers data after termination.
3.4 Staff access and downstream use #
Production access is limited to PhoneFlow staff who operate the Services. They may listen to recordings or read transcripts only to provide, secure and support the Services, to perform Setup Services, to investigate a suspected breach of the Agreement, or at the Customer's request. Once recordings, transcripts or Output leave the Services, for example by email, text, integration or webhook, the Customer is responsible for how they are used, shared and kept. Recording links can appear in data sent to destinations the Customer configured, and the Customer must protect those links as it would the recordings.
4. AI Features #
4.1 How they work #
Calls are carried by Twilio. Speech-to-text (Deepgram) and text-to-speech (ElevenLabs) run through Twilio. ElevenLabs also receives text directly from PhoneFlow for some features, such as when an administrator previews a voice in the dashboard. The language model is OpenAI by default, or Anthropic where selected. Voicemails are transcribed with OpenAI Whisper. The PhoneFlow Subprocessor List (https://myphoneflow.com/legal/subprocessors/) lists current providers, and PhoneFlow may change them as the Data Processing Addendum allows.
4.2 Their limits #
The AI Features predict; they do not understand. They can mishear speech (especially with accents, noise, weak connections, names and numbers), misread what a Caller wants, put a call in the wrong category, miss or overstate urgency, and give answers that are incomplete, outdated or invented. They are only as good as the Customer Materials behind them.
4.3 The Customer configures, approves and reviews #
The Customer decides what its agents do: greetings, instructions, call types, collected fields, knowledge base, transfer targets, messages and integrations. When PhoneFlow builds an agent through Setup Services, it follows the Customer's instructions, and the Customer must review and approve the result before live calls. A configuration the Customer approves, or puts in front of live callers, is the Customer's configuration. The Customer must test its agents after changes, review Output before relying on it for anything important (such as appointments, prices, deadlines, legal matters, payments or safety), and give Callers a way to reach a person when the agent cannot help.
4.4 Prohibited configurations #
The AUP sets out what agents may not do. In particular, an agent may not give individualized legal, medical, mental-health, tax or financial advice, or decide a person's eligibility for credit, housing, employment, insurance, education, healthcare, benefits or legal representation without human review.
4.5 System guardrails #
PhoneFlow applies fixed instructions to AI agents on calls that the Customer cannot override, such as instructions that keep the agent in the role the Customer configured. PhoneFlow does not set a platform rule for how agents handle emergencies or urgent calls; that is part of the Customer's configuration (Section 4.3). These are rules the agent follows during the conversation, not announcements it makes at the start of a call. PhoneFlow may add or change guardrails when a law, a carrier or AI-provider policy, or a safety concern calls for it. Where a guardrail and a Customer instruction conflict, the guardrail applies. Guardrails reduce risk but do not remove it, and they do not make PhoneFlow responsible for the Customer's configuration.
4.6 No training #
PhoneFlow does not use Customer Data to train, fine-tune or otherwise improve any AI model. Its AI providers receive Customer Data through their business APIs.
4.7 AI disclaimer #
THE AI FEATURES AND ALL OUTPUT ARE SUBJECT TO THE LIMITS IN SECTION 4.2. PHONEFLOW DOES NOT WARRANT THAT ANY TRANSCRIPT, SUMMARY, CLASSIFICATION, EXTRACTED FIELD, ANSWER OR OTHER OUTPUT WILL BE ACCURATE, COMPLETE, CURRENT OR SUITABLE FOR ANY PURPOSE. OUTPUT IS NOT PROFESSIONAL ADVICE, AND THE CUSTOMER DECIDES WHETHER AND HOW TO RELY ON IT. THIS SECTION ADDS TO THE WARRANTY DISCLAIMERS AND LIMITATION OF LIABILITY IN THE MCA AND DOES NOT NARROW THEM.
5. NOT AN EMERGENCY SERVICE — NO 911 #
5.1 No connection to emergency help #
PHONEFLOW IS NOT AN EMERGENCY SERVICE AND DOES NOT REPLACE A TELEPHONE LINE. THE SERVICES CANNOT CALL 911 OR ANY OTHER EMERGENCY NUMBER AND CANNOT CONNECT A CALLER TO EMERGENCY SERVICES. THE AI ASSISTANT CANNOT SEND POLICE, FIRE, AMBULANCE OR ANY OTHER HELP, AND CANNOT GIVE RESPONDERS A CALLER'S LOCATION. IT MAY FAIL TO RECOGNIZE AN EMERGENCY, MISJUDGE URGENCY, OR DELAY OR MISROUTE AN URGENT CALL.
5.2 PhoneFlow devices cannot call 911 #
THE PHONEFLOW SOFTPHONE, ANY SIP PHONE OR DEVICE CONNECTED TO THE SERVICES, AND THE PHONEFLOW MOBILE APP CANNOT CALL 911 OR ANY OTHER EMERGENCY NUMBER. DO NOT USE THEM FOR EMERGENCY CALLS.
5.3 The Customer's duties #
THE CUSTOMER MUST:
- KEEP AT EVERY LOCATION WHERE ITS PERSONNEL WORK AT LEAST ONE WAY TO CALL 911 THAT DOES NOT DEPEND ON PHONEFLOW, SUCH AS A LANDLINE OR MOBILE PHONE;
- TELL ITS PERSONNEL, AND ANYONE ELSE USING THE SERVICES THROUGH ITS ACCOUNT, THAT THE SERVICES CANNOT CALL 911; AND
- NOT HOLD OUT ANY PHONEFLOW NUMBER, AGENT OR WIDGET AS A SUBSTITUTE FOR 911 OR AS A CRISIS, SUICIDE, ALARM OR MEDICAL-ALERT SERVICE.
Routing urgent matters (for example after-hours repairs, flood or fire restoration, pastoral emergencies or client deadlines) to the Customer's own people is the Customer's choice. How its agents treat emergencies and urgent calls is part of the Customer's configuration under Section 4.3, and PhoneFlow does not prescribe it.
5.4 Allocation of risk #
TO THE FULLEST EXTENT THE LAW ALLOWS, PHONEFLOW IS NOT LIABLE FOR ANY INABILITY TO REACH EMERGENCY SERVICES THROUGH THE SERVICES, OR FOR ANY FAILURE OR DELAY IN RECOGNIZING, ANSWERING, ROUTING OR ESCALATING A CALL ABOUT AN EMERGENCY. THE CUSTOMER'S BREACH OF SECTION 5.3 IS COVERED BY THE CUSTOMER'S INDEMNITY AS SECTION 19.1 OF THE MCA PROVIDES.
5.5 Beta labels and changes #
A BETA OR PREVIEW LABEL DOES NOT CHANGE THIS SECTION 5. ANY CHANGE TO THIS SECTION 5 IS A MATERIAL CHANGE UNDER THE MCA.
6. Outbound AI calls and reminders #
6.1 The Customer is the caller #
For every Outbound Communication, the Customer is the caller, sender and initiator. It decides whom to contact, when, how often and with what message, and it supplies or approves every contact list, schedule, script and trigger. Setup Services do not include choosing recipients, uploading contact lists or scheduling Outbound Communications. If a Customer User asks PhoneFlow staff to carry out any of those steps, staff act only on the Customer's written instructions and the Customer remains the caller. A contract cannot control whom a court or regulator treats as the caller, so the Customer's obligations in this Section apply in full regardless of that outcome.
6.2 Permitted use #
Outbound AI calls may be used only for informational, non-marketing messages to the Customer's existing clients and to people who asked to hear from it, such as appointment reminders and confirmations, requested callbacks, and updates on a person's order, job or service. The Customer must hold the consent the law requires for each call. That includes prior express consent for artificial-voice calls to mobile numbers and, unless an exemption applies, to residential lines. The FCC treats AI-generated voices as artificial voices. PhoneFlow may limit, suspend or disable outbound AI calling at any time.
6.3 Promotional AI calls #
The Customer must not use the Services for calls that advertise or market goods, services or property, or for any telemarketing, unless (1) it holds each recipient's prior express written consent in a form that satisfies the TCPA and any stricter state law, and (2) PhoneFlow has approved that use in writing before the first call. PhoneFlow may refuse or withdraw approval at its discretion. Approval is not a review of the Customer's consents.
6.4 Identification and callback number #
Every outbound AI call and reminder call must state the name of the Customer's business at the start of the call. The Customer must set its business name in its account and agent configuration, must make sure each call's opening introduction names its business, and must not remove or change any identification the Services add to the start of an outbound call. The Customer must also make sure that the business name used is the name under which it is registered to do business with its state; that a working callback number is configured at which a person can ask not to be called again; and that agents do not leave voicemail or answering-machine messages unless those messages meet every identification and opt-out rule that applies, including a toll-free opt-out number where required.
6.5 Calling hours and frequency #
The Customer must contact people only at the hours, and no more often than, the laws of the recipient's location allow. Federal rules limit telephone solicitations to 8 a.m.–9 p.m. local time. Texas allows solicitation calls only 9 a.m.–9 p.m. Monday to Saturday and noon–9 p.m. Sunday. Florida, Oklahoma and Maryland limit them to 8 a.m.–8 p.m. and 3 calls in 24 hours. PhoneFlow recommends a window of 9 a.m.–8 p.m. Monday to Saturday and noon–8 p.m. Sunday, recipient's local time, for all Outbound Communications. The Customer sets the timing and frequency of its Outbound Communications and is responsible for them.
6.6 Opt-outs #
The Customer must honor every request to stop contact that the law requires it to honor, however it arrives: saying "stop" on a call, replying STOP to a text, asking the inbound agent, or calling, emailing or telling the Customer's staff. It must stop the Outbound Communications the request covers as soon as practicable and never later than the law allows, and must not insist on a particular opt-out method. A spoken "stop" on an automated or AI call opts the number out of automated and AI calls; it does not by itself bar live calls from the Customer's staff.
The opt-outs the Services record apply to automated and AI Outbound Communications only, and the Services do not check every opt-out for every kind of Outbound Communication. A STOP reply to a text is recorded and checked before automated appointment-reminder texts are sent; it does not stop calls. Other automated texts (such as confirmations sent during a call, notifications, and texts sent through integrations or tools) do not check the opt-out list. Where the Services record other kinds of opt-out, such as a spoken "stop" on an automated or AI call, they apply them only to the Outbound Communications that check them. Requests made to the inbound agent or to the Customer's staff are not recorded automatically. Except where the Services both record an opt-out and check it for a given kind of Outbound Communication, the Customer must suppress the recipient itself and keep its own record of the opt-out.
The Services never block live calls placed by the Customer's staff, including to a number that opted out of automated calls. Whether to place a live call is the Customer's decision, and the Customer remains responsible for honoring any request, such as a do-not-call request under Section 6.7, that the law applies to live calls.
6.7 Do-Not-Call lists #
For telemarketing or promotional calls and texts, the Customer must check recipients against the National Do-Not-Call Registry, applicable state lists and its own internal do-not-call list unless an exemption applies, and must keep an internal list and written do-not-call policy where the law requires.
6.8 California #
California restricts automatically dialed calls that play recorded or artificial-voice messages. It generally requires a live, natural-voice introduction unless the recipient agreed in advance or has an established relationship with the caller, and bans these calls from 9 p.m. to 9 a.m. California time. An AI voice cannot give that introduction. The Customer must place outbound AI calls to California numbers only to people who agreed in advance or have an established relationship with it, and must not use the same outbound setup for cold or sequential dialing.
6.9 Consent records #
The Customer must keep a record of each consent it relies on, showing who consented, the number, the date and time, how consent was given, the exact wording shown or spoken, and what it covered. Each record must be kept for at least 5 years after the consent was given, or longer if the law requires, and provided to PhoneFlow within 5 business days of a request, or sooner if a carrier, Twilio or regulator requires.
6.10 Healthcare reminders #
Some federal exemptions for healthcare calls apply only to HIPAA covered entities and business associates. PhoneFlow offers no business associate agreement, so the Customer must not rely on those exemptions for calls through the Services and must not include PHI in any Outbound Communication (Section 15.1).
7. Text messaging (SMS) #
7.1 Consent by message type #
Before each text, the Customer must hold the consent the law and carrier rules require. Conversational texts, replying to a message the person sent first, may rely on the person starting the conversation. Informational texts, such as reminders, confirmations and service updates, need express consent, which may be spoken, for example when the agent asks "Can I text you a confirmation at this number?" and the Caller agrees. Promotional texts need express written consent and are subject to Section 6.3. Consent covers only the sender and the kind of message it was given for; it does not carry over to another business, campaign or message type. Texts that solicit sales are also covered by state telemarketing laws, including Texas law, which has applied to texts since September 1, 2025.
7.2 Identification and content #
Each text must name the Customer's business, apart from follow-ups within an ongoing conversation. The first text to a person must explain how to opt out, for example "Reply STOP to opt out." Texts must not carry content that carriers or Twilio prohibit or restrict (see the AUP) and must not be used to collect Prohibited Data.
7.3 STOP and HELP #
The Services record STOP and the other standard opt-out keywords and stop automated appointment-reminder texts to numbers that opted out (other texts do not yet check the list; see Section 6.6). The Customer must also honor opt-outs in plain words ("please don't text me again") and answer HELP requests with its business name and contact details.
7.4 Registration and verification #
US carriers block business texts from unregistered local (10DLC) numbers and unverified toll-free numbers. Business texting may be unavailable or limited until the Customer's number or messaging is registered or verified with the carriers. PhoneFlow may register the Customer's messaging, or decline or limit messaging for the Customer, as carrier and registry rules require. The Customer:
- authorizes PhoneFlow to submit its business information to Twilio, The Campaign Registry and the carriers for any brand, campaign, toll-free verification or caller-authentication (STIR/SHAKEN) registration that carriers require;
- must supply accurate, complete and current details for any registration carriers require (such as exact legal name, EIN or other tax ID, address, website, contact person, the messages it will send and a truthful description of how people opt in) and report changes promptly;
- accepts that carrier rules may limit how a Customer without an EIN can be registered, for example to one campaign with low volume limits; and
- accepts that carriers and registries, not PhoneFlow, approve or reject registrations, and that approval takes time.
7.5 Carrier fees and penalties #
Registration, vetting and campaign fees, carrier surcharges, and any fine, penalty or charge a carrier, registry or Twilio imposes because of the Customer's messages or registration details are charged to the Customer as the MCA provides.
7.6 Twilio policies #
Twilio's Messaging Policy (https://www.twilio.com/en-us/legal/messaging-policy) and Acceptable Use Policy (https://www.twilio.com/en-us/legal/aup), including the industry messaging standards they refer to, are incorporated into these Service Terms for texts sent through the Services, and the Customer must follow them.
7.7 PhoneFlow's controls #
Carriers and Twilio can block or suspend messaging for every PhoneFlow customer because of one customer's traffic. PhoneFlow may therefore pause a campaign, limit volume, require changes to content or opt-in wording, or suspend texting under Section 14.
8. Web voice widget #
8.1 Notice before the microphone opens #
Where the widget shows a notice before it opens the Widget Visitor's microphone, the Customer must not alter, hide or bypass it. The Customer must not start widget sessions automatically, or embed the widget in any way that captures audio before the visitor chooses to start a session.
8.2 The Customer's pages #
The Customer is responsible for every page that hosts its widget. It must place the widget only on websites it owns or controls, keep its widget key confidential, meet any cookie, accessibility or consent-banner rules for its site, and publish a privacy policy that describes the widget (AI handling, recording, transcription and sharing with service providers). Any privacy link the widget shows goes to the PhoneFlow Privacy Notice (https://myphoneflow.com/legal/privacy/), not to the Customer's own policy, so the Customer must make its own policy available on the pages that host the widget.
8.3 Children #
The Customer must not place the widget on a website or page directed to children under 13, or anywhere it knows children under 13 will use it, unless it has verifiable parental consent as COPPA requires and PhoneFlow has approved the placement in writing. School, youth-program and children's-ministry pages need particular care. The Customer must tell PhoneFlow promptly if a placement reaches children. PhoneFlow may switch off the widget for any placement it reasonably believes is child-directed, and will do so once it knows a placement is child-directed without the required consent.
8.4 Usage and abuse #
Widget sessions use minutes like calls. The Customer is responsible for all widget usage, including automated or abusive sessions, except usage caused by PhoneFlow's breach of its security obligations. PhoneFlow may rate-limit or disable a widget, or rotate its key, to stop abuse.
9. Knowledge base and website crawl #
9.1 Rights in the content #
By asking PhoneFlow to crawl a website, or by adding documents or text to the knowledge base, the Customer confirms that it owns or controls that website or content, or holds the rights PhoneFlow needs to copy, store, index and use it to answer End Users. The Customer authorizes PhoneFlow and its providers to access and copy the websites it names for that purpose. Crawled and uploaded content is Customer Materials.
9.2 Accuracy #
The Customer is responsible for the accuracy and currency of its knowledge base, including prices, hours, service areas, policies and staff details. A crawl captures a site as it stood at that moment and may miss, misread or misfile content. The Customer must review the knowledge base before going live and after each crawl. PhoneFlow is not responsible for answers based on inaccurate, incomplete or outdated Customer Materials. The knowledge base must not contain Prohibited Data, information the Customer may not share with Callers, or content it has no right to use.
10. Integrations, tools and credentials #
10.1 Authority and scope #
When the Customer connects a Third-Party Service (such as a CRM, calendar, ticketing, practice-management or email system, a custom HTTP tool or a webhook), it confirms it is authorized to give PhoneFlow the Integration Credentials and the access they grant. The Customer chooses the account, the permissions and the actions the agent may take, and should grant only what its agents need.
10.2 Configured actions are the Customer's #
The Services act in a connected system only as the Customer's configuration directs, for example looking up or updating records, booking appointments, opening tickets or posting to webhooks. Those actions are taken on the Customer's behalf and are the Customer's actions. Data sent to a Third-Party Service, webhook, email address or phone number the Customer configured is a disclosure by the Customer to that recipient, which is not PhoneFlow's subprocessor and has its own terms and privacy practices.
10.3 Reading records to unverified Callers #
The agent cannot confirm who a Caller is, and caller ID and spoken names can be false. If the Customer configures an agent to read out, confirm or change records (such as appointments, account status, balances or case details) for a Caller whose identity has not been verified, it does so at its own risk. The Customer decides what an agent may reveal or change, adds any identity checks its obligations require, and must never configure an agent to read back Prohibited Data.
10.4 Integration Credentials #
PhoneFlow stores Integration Credentials encrypted in its database and uses them only for the actions the Customer configured. The Customer may revoke Integration Credentials at any time in the Third-Party Service, and must do so and tell PhoneFlow if it believes they were exposed. Third-Party Services may change or withdraw their interfaces, and PhoneFlow is not responsible for their availability, accuracy or conduct.
10.5 Payment instructions #
The Customer must not configure an agent, knowledge base or tool to give, confirm or change wiring instructions, bank account details or payoff figures, and must tell its clients to verify any payment instruction by calling a number they already know. To the extent the law allows, PhoneFlow is not liable for any loss from a funds transfer made in reliance on information given through the Services, except to the extent caused by PhoneFlow's breach of its security obligations. Where such a loss arises from Customer Materials, it is covered by the Customer's indemnity as Section 19.1 of the MCA provides.
11. Phone numbers, forwarding, caller ID and porting #
11.1 Customer Numbers #
PhoneFlow never takes ownership of, or becomes the carrier for, a Customer Number; it stays with the Customer. The Customer confirms it is authorized to use and forward each Customer Number. Its carrier's forwarding setup and charges, calls the carrier or forwarding fails to deliver, and switching forwarding off when it stops using the Services are the Customer's responsibility. Forwarded calls use minutes, including spam, wrong numbers and forwarding loops, as the MCA provides.
11.2 PhoneFlow Numbers #
Twilio is the carrier of record for PhoneFlow Numbers, and the Customer may use each one while its account is in good standing. The Customer may port a PhoneFlow Number to another carrier at any time before it is released. The Customer should start any port before termination, and must complete it within the 45-day hold in Section 11.4. PhoneFlow will cooperate and give the new provider the information it needs. Port-out requests go to the support contact in Section 17.
11.3 No blocking of ports #
PhoneFlow will not refuse, delay or attach conditions to an authorized port-out request, including where fees are owed. Any amount owed is collected separately under the MCA.
11.4 After termination and inactivity #
After termination, PhoneFlow holds PhoneFlow Numbers for 45 days, during which the Customer may still port them, and then releases them to the carrier. Released numbers may be reassigned and cannot always be recovered. PhoneFlow may reclaim the PhoneFlow Number of a trial account that has never purchased minutes if that number has had no calls for 90 days, after giving the Customer notice. Suspended numbers unused for 90 days or more may be reclaimed by the carrier, and carriers or regulators may reclaim or change numbers when the law requires.
11.5 Caller ID #
The Customer may display only caller ID numbers and names it owns or is authorized to use, and must not spoof caller ID. It must give accurate business information for caller authentication (STIR/SHAKEN) and caller-name registration. PhoneFlow may refuse or stop using any caller ID it cannot verify.
12. Voice cloning and voice biometrics #
12.1 Cloned voices need the voice owner's signed consent #
Where the Services allow a custom or cloned voice, the Customer may use a voice that imitates a real person only with that person's signed, written consent to the specific use. The Customer must keep the consent while the voice is in use and for at least 5 years afterward, provide a copy on request, and stop using the voice at once if consent is withdrawn or expires. Voices imitating public figures, government officials or anyone who has not consented are prohibited.
12.2 No voiceprints #
The Services are not designed to create voiceprints, identify or verify people by voice, or build speaker profiles, and the Customer must not use or configure them, or any Output, for those purposes. Laws such as the Illinois Biometric Information Privacy Act and Texas's biometric identifier law impose strict notice, consent and retention duties on voiceprints.
13. Beta Features #
13.1 Provision #
Beta Features are optional. PhoneFlow may change, limit or withdraw them at any time, and they may never become generally available. They are excluded from the MCA's Service Warranty and from PhoneFlow's intellectual-property indemnity.
13.2 Disclaimer #
BETA FEATURES ARE PROVIDED "AS IS" AND "AS AVAILABLE", WITHOUT WARRANTY OF ANY KIND, INCLUDING ANY WARRANTY OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE OR NON-INFRINGEMENT, AND WITHOUT ANY SERVICE-LEVEL COMMITMENT. THE CUSTOMER USES THEM AT ITS OWN RISK. THE MCA'S LIMITATION OF LIABILITY APPLIES TO THEM.
13.3 What stays the same #
A Beta Feature remains subject to the rest of the Agreement. The beta label does not change Section 5, the Required Disclosures, the Customer's duties under Communications Laws, the rules on Prohibited Data, or PhoneFlow's confidentiality and data-protection obligations.
14. Telephony-specific suspension #
14.1 Grounds #
In addition to its rights under the MCA and the AUP, PhoneFlow may suspend any part of the Services if it reasonably believes that:
- Twilio, a carrier, The Campaign Registry, a traceback group, a regulator, law enforcement or a court has required or requested it, or has threatened to block, suspend or penalize PhoneFlow's numbers, messaging or carrier accounts because of the Customer's traffic;
- the Customer's calls or texts have drawn complaints suggesting unwanted, unlawful or deceptive contact;
- the Customer's traffic is abnormal, such as sudden spikes, high rates of very short or unanswered calls, forwarding loops, traffic pumping, or signs that an account, number, widget or Integration Credentials have been compromised;
- a business, identity, brand, campaign, toll-free or caller-ID verification has failed, lapsed or was based on inaccurate information;
- the Customer has disabled, bypassed or tampered with a Required Disclosure or system guardrail, or recorded without the Recording Notice; or
- continuing would expose PhoneFlow, other customers or End Users to legal liability, carrier action or harm.
14.2 Manner #
PhoneFlow will confine a suspension to the agents, numbers, campaigns, widgets, integrations or features involved where it can, and will give notice (email is enough) beforehand where practicable and lawful. If a carrier, regulator or urgent risk requires immediate action, PhoneFlow may act first and notify the Customer promptly afterward. PhoneFlow restores the suspended part once the cause is fixed, unless the Agreement has ended. Suspension does not reduce Purchased Minutes, but calls and texts that cannot be delivered during it are not credited. A suspension that complies with this Section is not a breach of the Agreement.
14.3 Cooperation #
The Customer must cooperate with carrier, traceback and regulatory inquiries about its traffic, including by providing consent records, business verification and call details within the time PhoneFlow reasonably sets. PhoneFlow may give carriers, traceback groups, regulators and law enforcement the information about the Customer's traffic they lawfully request, as the Data Processing Addendum permits.
15. Regulated industries and international use #
15.1 Healthcare: no PHI #
Protected health information (PHI) is Prohibited Data. PhoneFlow does not currently sign business associate agreements, and no feature, setting or template makes PhoneFlow a business associate. A Customer that is a HIPAA covered entity or business associate (for example most medical, dental and therapy practices, pharmacies, and many non-emergency medical transportation providers) must not use the Services to create, receive, keep or send PHI. Its agents must not collect symptoms, diagnoses, treatment or insurance details, and its reminders and texts must not contain PHI. The Customer must not describe its use of PhoneFlow as HIPAA-compliant. PhoneFlow does not name healthcare Customers publicly without consent, as the MCA provides.
15.2 Law firms #
Law-firm Customers must also accept the PhoneFlow Professional Services Addendum (Legal) (https://myphoneflow.com/legal/professional-services-addendum/), and PhoneFlow can set up recommended intake guardrails for a firm's agents, such as instructions not to claim to be a lawyer and not to give legal advice. Those guardrails live in each agent's editable guardrail settings, and the firm controls them and is responsible for them, as that Addendum provides; the AUP's ban on individualized legal advice applies whatever they say. They are rules the agent follows; they do not add a spoken announcement at the start of a call. PhoneFlow is not a law firm, provides no legal services, and forms no attorney-client relationship with anyone. The firm is responsible for its intake configuration and its professional obligations, including supervising non-lawyer assistance and handling information from prospective clients.
15.3 Other licensed professions #
Customers in other licensed professions, such as accountants, financial advisers, insurance agents and real-estate brokers, are responsible for any AI disclosure and supervision their licensing rules require. Utah, for example, requires certain licensed professionals to disclose AI at the start of high-risk interactions. PhoneFlow does not add that disclosure; the Customer can add it to its agent's greeting (Section 2.2).
15.4 Outside the United States and Canada #
The Services are intended for US and Canadian numbers, Callers and Widget Visitors, and use elsewhere needs PhoneFlow's written approval as the MCA provides. For End Users outside those countries, the Customer is responsible for local rules on recording, AI disclosure and electronic marketing, including CASL in Canada, PECR in the United Kingdom and the deployer duties of the EU AI Act.
16. Responsibility, compliance help and changes #
16.1 Who is responsible for what #
PhoneFlow is responsible for delivering the Required Disclosures and system guardrails described here, for never blocking an authorized port, and for its other obligations in the Agreement. The Customer is responsible for its configuration, its Customer Materials, its Outbound Communications, the consents and further notices described here, and the Third-Party Services it chooses. The MCA's limitation of liability and indemnity sections apply to these Service Terms, and nothing here enlarges or shrinks the MCA's list of Excluded Claims.
16.2 Compliance help is not legal advice #
TEMPLATES, DEFAULT DISCLOSURES, RECOMMENDED CALLING WINDOWS, SAMPLE WORDING, CHECKLISTS AND OTHER COMPLIANCE HELP FROM PHONEFLOW ARE CONVENIENCES, NOT LEGAL ADVICE. PHONEFLOW DOES NOT WARRANT THAT USING THEM MAKES THE CUSTOMER'S USE OF THE SERVICES LAWFUL IN ANY PLACE. THE CUSTOMER SHOULD TAKE ITS OWN LEGAL ADVICE ON THE COMMUNICATIONS LAWS THAT APPLY TO IT.
16.3 Changes #
PhoneFlow may change these Service Terms as described in the change section of the MCA. A change to Section 5, or one that adds to the Customer's obligations, is a Material Change and needs re-acceptance as the MCA provides. Earlier versions remain available at their version URL, for example https://myphoneflow.com/legal/service-terms/v1.0/, and the current version is always at https://myphoneflow.com/legal/service-terms/.
17. Contact #
- Legal notices and questions: [email protected]; Electric Software LLC, 120 N Washington Square, Suite 300, Lansing, MI 48933.
- Export and deletion requests: [email protected].
- Support, numbers and porting: [email protected] · +1 947 777 7449.
- In an emergency, call 911 from a phone that does not depend on PhoneFlow.
