CallSara
callsara.aiCallSara is an AI voice-agent platform for healthcare organizations that maintains a healthcare-appropriate legal framework: a BAA governs all Protected Health Information (PHI), it holds SOC 2 Type II certification, and it commits not to train general-purpose AI models on call audio, transcripts, or PHI without explicit written consent. These are strong, enterprise-oriented protections. However, several vendor-favorable terms warrant caution before use with sensitive or proprietary data: an 'AS-IS' warranty disclaimer, a liability cap of fees paid in the prior 12 months (or $100), a broad indemnification obligation placing TCPA/telephone-law compliance entirely on the customer, mandatory binding arbitration with a class-action waiver, a one-year claim limitation, and the vendor's right to delete data and disclaim responsibility for data storage. The publicly posted Privacy Policy notably does not govern PHI at all — that protection depends entirely on separately executing a BAA, which regulated customers must ensure is in place.
AI Transparency Facts
Independent analysis by TermsWatchdog · © 2026 TermsWatchdog
Input Data Ownership
The customer retains full ownership of all content uploaded, submitted, or generated through the Services. PHI is explicitly carved out and governed by the BAA rather than the general content license.
Output Data Ownership
Customer Content is defined to include content the customer generates through the Services, and the customer owns it. AI outputs generated on behalf of the customer therefore belong to the customer, with PHI governed by the BAA.
Training Data Usage
CallSara commits not to use customer call audio, transcripts, or PHI to train general-purpose AI models without the customer's explicit, separate written consent. This is a favorable, healthcare-appropriate stance, though the qualifier 'general-purpose AI models' leaves some ambiguity about narrower model tuning.
Data Retention & Deletion
The Privacy Policy provides an unusually detailed retention schedule (e.g., 24 months for enquiries, 14 months analytics, 90 days server logs, 7 years billing/tax records) and offers deletion rights subject to legal exceptions. However, the Terms allow CallSara to delete data and disclaim responsibility for storage, and PHI retention is deferred entirely to the BAA rather than stated here.
Third-Party Data Sharing
CallSara states it does not sell personal data and shares data with service providers under data processing agreements, plus advertising platforms for campaign measurement. Sharing appears disclosed and limited, with a public sub-processor list; the main caveat is website-level marketing data flowing to Google/LinkedIn advertising platforms, mitigated by Consent Mode v2 for EU/UK users.
Opt-Out Rights
The policy provides multiple concrete opt-out mechanisms: unsubscribe from marketing, cookie preference management, Google Consent Mode v2 (EU/UK default-off for non-essential cookies), and industry ad-opt-out links. U.S. state residents can opt out of sale/sharing and automated profiling by email.
Compliance & Certifications
CallSara explicitly claims SOC 2 Type II certification (with report available under NDA), HIPAA compliance via BAA, GDPR/UK GDPR with SCCs, India's DPDP Act, and enumerates numerous U.S. state privacy laws. The breadth and specificity are strong, though only SOC 2 is a named third-party attestation and no audit report is publicly published.
Model Explainability & Auditability
The documents warn that AI outputs may contain errors and place clinical oversight responsibility on the customer, but offer no transparency into model behavior, logic, or enterprise audit capabilities. There is no mention of explainability tooling, audit logs, or model documentation available to customers.
Security Practices & Breach History
CallSara discloses a solid set of security controls: TLS 1.2+ encryption in transit and at rest, role-based access controls, MFA for internal systems, regular penetration testing, incident response procedures, and defined breach notification timeframes. SOC 2 Type II is claimed; no breach incidents are disclosed and no dedicated public trust center is referenced beyond the NDA-gated report.
Enterprise vs. Consumer Risk Delta
CallSara is a B2B platform with no consumer/free tier described; the key distinction is between website visitors (governed by the Privacy Policy) and platform Customers whose patient data is governed by a separately executed BAA and Order Form/MSA. The critical implication is that PHI protections and stronger contractual terms only apply if a BAA is executed — the public policies alone do not extend HIPAA-grade protection.
Human Review of User Inputs
The Terms reserve the right to preserve and disclose Customer Content to comply with legal process, enforce terms, or protect rights/safety, and the Privacy Policy notes data may be processed to operate and improve the platform. There is no explicit statement of routine human review of prompts/outputs, but the broad preservation and 'improve our platform' language leaves the door open; PHI review would be constrained by the BAA.
Regulatory & Litigation Exposure
The documents disclose cooperation with lawful government/law-enforcement requests, mandatory binding arbitration with a class-action waiver, a one-year contractual limitation on claims, and Delaware governing law. Heavy customer-side indemnification for telephone-law (TCPA/TRAI) violations shifts significant regulatory risk onto the customer, which is material given the outbound-calling use case.
PII & SPI Data Inventory
The website collects standard business PII (name, work email, phone, company, job title, IP, device/browser, usage data, ad identifiers) with clear purpose limitation and no SPI collected via web forms. However, the platform itself processes voice call audio, transcripts, and caller phone numbers — highly sensitive data including PHI — which is disclosed but deferred entirely to the BAA rather than governed by the public policy, warranting a moderate rating and BAA verification.
You've read all 15 risk ratings for CallSara. Create a free account to see the exact policy wording behind each rating.