Trust & compliance

AI & compliance

Placeholder copy pending legal review — this page describes how the product is built to comply; final wording should be confirmed with counsel.

AI disclosure

Your AI teammates identify themselves as AI. When Rosai answers the phone she opens with an audible disclosure that the caller is speaking with an AI assistant, and messages from Sophai/Stanlai are sent on your behalf under your business name with your approval.

Calls & recording consent

Rosai operates on a call-by-call basis and, where call recording is enabled, provides the disclosures required in two-party-consent jurisdictions. Recording is off by default; transcripts are stored as PII (see below).

Text messaging (TCPA / A2P 10DLC)

We only text contacts with recorded opt-in (consent_sms), register SMS senders under A2P 10DLC, and honor STOP/UNSUBSCRIBE immediately. Reply START to opt back in.

Social permissions

Instagram/Facebook access uses Meta's Graph API under reviewed permissions; we store only the scopes you grant and act on your accounts with your approval unless you enable autopilot.

Your data

  • Call transcripts and lead data are treated as PII and encrypted at rest.
  • Provider tokens are stored as encrypted references (Supabase Vault), never in plain text.
  • Every account's data is isolated by row-level security.
  • You can export or delete your data on account close.