Your jobs, your recordings, your customers — yours.
Rowlty listens to a lot of private conversations on a lot of private property. Here is exactly how we handle that.
Recording and consent
Rowlty Notes announces out loud that the conversation is being recorded before it starts, and logs that announcement with a timestamp. In states that require all-party consent, two-party mode requires an affirmative acknowledgement before recording begins, and the estimator sees a clear on-screen indicator the entire time.
Homeowners can ask to stop the recording at any point. Your team can delete a recording permanently from the job record, and deleted audio is purged from backups within 30 days.
You choose retention: 90 days, 365 days, or a custom period on Enterprise. Transcripts and structured notes can be retained after audio is deleted, if that's what you want.
How your data is used
We do not train shared or public AI models on your data. Not your recordings, transcripts, photos, job records, pricing, or customer information. Corrections your team makes improve your own company's terminology glossary and nothing else.
We use third-party model providers under agreements that prohibit them from training on data we send. We do not sell data, and we do not share it with advertisers or data brokers.
Encryption and infrastructure
- TLS 1.2+ for all data in transit
- AES-256 for data at rest, including media files
- Hosted on major US cloud infrastructure; regional data residency available on Enterprise
- Encrypted, geographically separated backups with tested restore procedures
- Secrets managed in a dedicated vault, rotated on a fixed schedule
Access control
- Role-based permissions down to the module and the record type
- Recordings and transcripts can be restricted to the rep, their manager, and admins
- SSO / SAML and SCIM provisioning on Enterprise
- Multi-factor authentication available on all plans, enforceable org-wide
- Full audit log of access and export events; exportable on Pro and Enterprise
- Rowlty staff access to customer data requires documented authorization and is logged
Compliance posture
Rowlty is built to SOC 2 Type II control objectives, with our first formal audit underway. We'll publish the report to customers under NDA when it completes rather than claiming certification before we have it.
We support CCPA and comparable state privacy rights, including deletion and access requests on behalf of your customers. A Data Processing Addendum is available for any customer who wants one.
Where insurance claim documentation is involved, Rowlty acts as your processor. We are not a public adjuster and do not negotiate claims on a homeowner's behalf.
Reliability
- 99.5% uptime target on Pro; 99.9% with service credits on Enterprise
- Offline capture on mobile so a network outage never costs you an inspection
- Documented incident response with customer notification commitments
- Public status page and published incident history
Getting your data out
Full export at any time, in standard formats: jobs, contacts, photos, documents, recordings, transcripts, and pipeline history. No exit fee, no waiting period, no retention hostage-taking. If you cancel, your data stays available for export for 60 days and is then permanently deleted.
Reporting a vulnerability
Email susan@rowlty.com with "Security" in the subject line and we will acknowledge within one business day. We don't pursue legal action against good-faith researchers who give us a reasonable window to fix things.
Have a security questionnaire from your insurer or a national account? Send it to susan@rowlty.com — we fill those out rather than dodging them.
