This Privacy Policy explains how the Retell integration apps listed below access and use data. Each app has its own section describing the data it can access and why it needs that access. If a marketplace asks for a Privacy Policy URL, you can link directly to the relevant app section (for example, /privacy-policy#salesforce).
1. How These Integrations Work
Each app is installed inside a third-party platform such as Salesforce, Zoho CRM, Airtable, Google Sheets, Notion, Slack, or Epic. It connects your account on that platform to Retell AI (retellai.com), a third-party conversational voice AI platform, so AI phone agents can place or receive calls using data from the connected platform.
All of the apps use the same backend service, called the "Integration API." It:
- For each connected account ("tenant"), stores the connected platform's OAuth access and refresh tokens, your Retell AI API key, your selected Retell agent ID, a hashed webhook secret, and setup status. This information is stored in a database operated by Retell AI.
- Uses the Retell AI API/SDK to start outbound calls and receives "call ended / call analyzed" webhooks with the recording URL, transcript, AI-generated summary, sentiment, and outcome.
- Writes selected call results, such as status, summary, recording link, and outcome, back to the related record, row, page, or channel in the connected platform.
| Sub-processor / third party | Role |
|---|---|
| Retell AI, Inc. (retellai.com) | Places and receives phone calls and generates recordings, transcripts, and summaries. Retell AI's own privacy policy applies. |
| The connected platform (Salesforce, Zoho, Airtable, Google, Notion, Slack, or Epic) | Provides the contact/record data and receives updates back. That platform's own terms apply. |
| Hosting / database provider | Runs the Integration API and stores tenant configuration in a PostgreSQL database. |
We do not sell personal data, and we do not use it for advertising or ad targeting.
2. Personal Information and Data We Collect
Retell for Salesforce
Managed package: Setup Wizard (LWC) + "Start Retell Outbound Call" Flow action, distributed via Salesforce AppExchange.
Salesforce access works in two layers. The first is OAuth 2.0, used when you connect Salesforce to our Integration API. The second is an in-org permission set for users who run the setup wizard, Flow actions, or outbound calls inside your organization. We do not request OAuth scopes such as full, chatter_api, openid, profile, or email.
OAuth Scopes (Connected App / Backend)
When you connect Salesforce through the setup wizard, you authorize our integration service to access your Salesforce organization through OAuth 2.0 using only the scopes listed below:
| Scope | What it means | Why we use it |
|---|---|---|
| api | Access Salesforce data through REST/SOAP APIs | Write call results back to Salesforce (e.g. upsert Retell_Call_Log__c, optional field mappings), and read CRM context tied to calls. |
| refresh_token | Get new access tokens without requiring you to sign in again | Keep the "Connect Salesforce" connection active without asking you to sign in every time. |
The api scope allows REST/SOAP access, but only to records the authorizing Salesforce user is allowed to see or edit under your organization's sharing rules, CRUD permissions, and field-level security. Backend writebacks use the stored OAuth token from the user who completed "Connect Salesforce." Calls started inside Salesforce run as the Flow/Apex user, who must also have the permission set described below.
In-Org Permission Set: Retell Integration User
You must assign the Retell Integration User permission set to users who run setup, outbound calls, or Flow actions. This permission is separate from OAuth and controls what Apex/LWC users can do inside your Salesforce organization.
Standard Objects (Read-Only)
| Object | Fields | Purpose |
|---|---|---|
| Contact | Phone, MobilePhone | Find the phone number for an outbound call and link the call to the right CRM record. |
| Lead | Phone, MobilePhone | Find the phone number for an outbound call and link the call to the right CRM record. |
| Account | Phone | Find the phone number for an outbound call and link the call to the right CRM record. |
| Case | ContactPhone, ContactMobile, SuppliedPhone | Find the phone number for an outbound call and link the call to the right CRM record. |
| Opportunity | Object-level read | Check that records exist and support Flow use. |
Retell Custom Objects (Create / Read / Update)
| Object | Purpose |
|---|---|
| Retell_Call_Log__c | Call status, transcript, summary, recording URL, sentiment, phone numbers, links to Contact/Lead. |
| Retell_Field_Mapping__c | Optional mappings from Retell variables to Salesforce fields. |
| Retell_Integration_Settings__c | Integration config (URL, masked token hints, defaults). |
| Retell_Org_State__c | Setup and connection state. |
| Retell_Integration_Event__c | Audit trail of integration events. |
| Retell_Integration_Activity__c | Audit trail of setup and writeback activity (actor name, event type, timestamp). |
Other In-Org Permissions
| Access | Resource | Purpose |
|---|---|---|
| Create / Edit | Task | Optional post-call automation - log the call on the Contact/record activity timeline. |
| Execute | Apex classes | Setup wizard, outbound Flow action, and HTTP callouts to the Integration API. |
| Access | External Credentials (Retell_Integration_API, Retell_Salesforce_API) | Authenticate callouts to the Integration API and Salesforce APIs. |
| Outbound HTTP callouts | Configured API Base URL (Remote Site Setting) | Communicate with the Integration API / Retell AI on your org's behalf. |
| Stored secret | Bearer token in a Custom Setting | Authenticates the org to the Integration API (visible to org admins). |
| Visibility | Retell AI app tab | Access setup wizard and integration features. |
Data We Access and Why
Retell may access and process:
- Phone numbers and record identifiers from CRM records (Contacts, Leads, Accounts, Cases, and Opportunities) when starting outbound calls or linking calls to records.
- Call metadata and outcomes status, duration/timestamps, summaries, transcripts, recording URLs, and sentiment stored in Retell_Call_Log__c records.
- Integration configuration stored in Retell custom settings and related setup objects in your Salesforce org.
- Optionally, fields you configure through Retell field mappings.
When a user starts a call through Flow or the wizard's Outbound tab, we read the phone number, related fields, and any dynamic variables configured by an administrator. We send that information to Retell AI to place the call. When the call ends, we write the transcript, recording link, AI summary, sentiment, and outcome back to Retell_Call_Log__c and, if configured, to a related Task.
Retell AI receives call-related data, including phone numbers, call metadata, transcripts, and summaries, as described in Retell AI's privacy policy.
Authorization and Access Control
API access follows the Salesforce permissions and sharing rules of the user who completes "Connect Salesforce" for backend OAuth writebacks, and of each user who has the Retell Integration User permission set for in-org actions. Apex runs "without sharing" only where it is required to write shared objects.
You can revoke access at any time. You can disconnect the integration in the setup wizard, uninstall the package, or remove the Connected App authorization in Salesforce.
Data Retention and Deletion
Call logs remain in your Salesforce organization and follow your own retention and backup policies. When you choose Uninstall in the setup wizard, we clear stored custom settings and field mappings and make a best-effort request to delete your tenant record, including OAuth tokens and the Retell API key, from the Integration API database. Existing Retell_Call_Log__c and Task records in Salesforce are not deleted.
Retell for Zoho CRM
Zoho CRM extension (Sigma / Extension Toolkit): settings widget + outbound-call custom action, distributed via the Zoho Marketplace.
Retell for Zoho CRM connects your Zoho CRM organization to Retell AI through our integration service. Access works in two layers: the Sigma extension widget uses embedded SDK capabilities, and a separate Zoho Connected App OAuth flow is used when you click "Connect Zoho CRM" and authorize our Node integration server. The OAuth scopes are configured on the Connected App used by our Integration API, not in the extension manifest.
Extension Capabilities (In-App)
- Deluge proxy - The settings widget calls ZOHO.CRM.FUNCTIONS.execute("retell_integration_proxy"). This runs the Deluge function installed by your administrator so it can reach our integration server. The org secret (retell_org_secret) is stored in Zoho org variables and is not exposed to the browser.
- Tenant ID - Your CRM organization key (zgid) is stored in the org variable retell_zoho_tenant_id.
- Zoho CRM OAuth - A browser pop-up redirects you to our Integration API (/api/v1/auth/zoho/start). After you consent, our server stores the refresh tokens and configures the org variables.
- Deluge / Workflow outbound calls - Deluge functions installed by an administrator (see bundled samples) send POST .../calls requests to our server using the org secret.
- Activity tab - Integration activity is loaded through the Deluge proxy, with audit events from status used as a fallback.
OAuth Scopes (Connected App / "Connect Zoho CRM")
When an administrator authorizes access via Zoho OAuth, our Connected App requests these scopes:
| Scope | Why we use it |
|---|---|
| ZohoCRM.org.READ | Resolve organization ID (zgid) during setup and identify your tenant. |
| ZohoCRM.settings.variables.READ | Read org variables (retell_org_secret, retell_node_base, retell_zoho_tenant_id). |
| ZohoCRM.settings.variables.CREATE | Create org variables on first connect. |
| ZohoCRM.settings.variables.UPDATE | Update org variables after OAuth and setup. |
| ZohoCRM.settings.modules.READ | List CRM modules for the outbound-call custom action module picker. |
| ZohoCRM.modules.READ | Read CRM records when our server handles webhooks, call logging, or server-side sync. |
| ZohoCRM.users.READ | Read the current CRM user's name for display in the settings UI. |
| offline_access | Keep the server connection active with a refresh token so repeated logins are not required. |
We do not use the broad ZohoCRM.modules.ALL group scope. Deluge functions that read records through getRecordById use the profile permissions of the CRM user who runs them. Those permissions are separate from the OAuth scopes listed above.
Data We Access in Zoho CRM
| Data | How | Purpose |
|---|---|---|
| Organization ID (zgid) | Embedded SDK + org API | Identify the connected organization for the integration |
| Current user name | getCurrentUser() | Show the user name in the interface and activity view |
| CRM module list | Integration API via Deluge proxy | Outbound-call module picker |
| Record ID + module name | Deluge / workflow | Link calls to the correct CRM records |
| Phone / Mobile fields | getRecordById when "To number" is blank | Place outbound calls through Retell |
| Org variables | Created/updated after OAuth | Store integration credentials on the server in Zoho |
Data Processed on Our Servers
| Data | Purpose |
|---|---|
| Retell Webhook API key | Connect Retell to your webhook endpoint |
| OAuth refresh tokens | Maintain CRM connection on our Integration API |
| Per-org integration secret (retell_org_secret) | Authenticate Deluge -> server calls |
| Call metadata (numbers, record id, dynamic variables) | Start outbound calls through Retell |
| Integration activity / audit events | Settings dashboard Activity tab |
| Webhook URL | Receive Retell call-ended events |
CRM API secrets are not stored in your browser. They are kept in Zoho organization variables and used only by the server-side Deluge functions you install.
Browser-Only Storage
The settings widget uses localStorage in your browser for wizard state, tenant hints, and the webhook URL cache. The Integration API bearer token is not stored in the browser.
Optional Deluge / Workflow Features
If you set up workflows or custom actions, Deluge functions installed by an administrator may read phone numbers from CRM records and send call requests to Retell. Any dynamic variables you configure can include CRM merge fields you choose. These Deluge functions run with the CRM permissions of the user who triggers the workflow or action.
Third-Party Services
Data is shared with our hosted Integration API and with Retell AI for voice telephony and AI agent processing, as described in Retell AI's privacy policy. We do not sell your data.
Regional Data Routing
The extension is allow-listed through Content-Security-Policy to connect to Zoho API hosts across all Zoho data centers (.com, .eu, .in, .com.au, .jp, .sa, .ca). This lets the extension work regardless of where your Zoho organization is hosted. At runtime, it only connects to your own organization's data center.
Your Control
You can disconnect the integration by choosing Uninstall app in settings. This calls our API to remove the integration. You should also revoke OAuth access in your Zoho Connected App settings and remove or update organization variables according to your administrator procedures.
Data Retention and Deletion
Call notes and CRM records stay in Zoho CRM and follow your organization's retention settings. The extension's Disconnect/Uninstall action requests deletion of your tenant record from the Integration API, including stored OAuth tokens, the Retell API key, and related configuration.
Retell for Airtable
Airtable Custom Extension (Blocks SDK): setup wizard + dashboard + Outbound Call tab.
OAuth Scopes Requested
When you connect Airtable through OAuth, the integration requests exactly the three scopes listed below. During the connection process, you choose which bases it can access. The app can only read or write the bases you explicitly authorize.
| Scope | What you grant | Why we use it |
|---|---|---|
| schema.bases:read | View the base structure, including tables and field types | Discover authorized bases and tables, resolve table names for API calls, and scan activity across bases. |
| data.records:read | Read record data only in bases you authorized | Read phone numbers and contact fields from dial-target rows before outbound calls. |
| data.records:write | Create and update records only in bases you authorized | Post-call writeback - update the originating row's Long text column with call summary and metadata. |
Data We Access from Airtable
With Airtable OAuth, we only access the bases you select. We read the base schema and contact or lead records, including phone numbers and related fields used for calling. After a call ends, we update the fields you have designated, such as call notes.
The extension reads the base id, table, record id, and the fields you mapped, usually a phone number and name. It sends this information to the Integration API to start an outbound call through Retell AI.
Airtable Extension (Blocks SDK) Permissions
Separate from OAuth, the custom extension:
- Runs inside an Airtable base you open it in.
- Reads the current base ID (app...) via the Blocks SDK.
- Stores setup data in the extension's globalConfig, including the OAuth token, tenant ID, and outbound settings. Base collaborators with extension edit access may be able to see this information.
- Uses localStorage in your browser to cache tenant ID and webhook URL.
- Requires permission to write globalConfig (hasPermissionToSet) before saving OAuth credentials and settings.
Collaborators who can access both the base and the extension may be able to see stored integration settings. Do not connect credentials or tokens you are not comfortable making visible to those collaborators.
Retell AI Data You Provide
| Data | Purpose |
|---|---|
| Retell API key | Stored server-side (encrypted); used to place calls and receive webhooks. |
| Retell Agent ID | Identifies the voice agent that handles your calls. |
| Outbound caller ID | The phone number Retell uses to place outbound calls. |
| Webhook URL | Retell sends call-ended events to our integration server. |
Retell AI receives call-related data, including phone numbers, call metadata, transcripts, and summaries, as described in Retell AI's privacy policy. Our server then writes the call summaries back to Airtable.
Data We Store
We store Airtable OAuth tokens (encrypted on our servers), your Retell API credentials and configuration, integration tokens used for API access, and activity or audit logs related to calls and writebacks. Some settings are also stored in the Airtable extension's global configuration inside your base.
How We Use the Data
We use this data to place outbound AI phone calls through Retell AI, receive call-completion webhooks, write call results back to Airtable, and show setup and activity status in the extension.
Data Sharing
Data is shared with Retell AI to carry out voice calls and with the Airtable API to read and write the records you authorized. We do not sell your data.
Your Control
You can disconnect the integration from the Uninstall app option, revoke access in Airtable OAuth settings, and choose which bases are authorized when you connect.
Data Retention and Deletion
Record data stays in your Airtable base and follows your own retention settings. Choosing Uninstall requests deletion of your stored tenant record from the Integration API, including OAuth tokens, the Retell API key, and related configuration. Revoking access in Airtable OAuth settings stops future API access immediately.
Retell for Google Sheets
Google Workspace Add-on: setup wizard + sidebar, distributed via the Google Workspace Marketplace.
Retell for Google Sheets is a Google Sheets add-on that connects to Retell AI. Google permissions are requested in two layers: the Apps Script add-on when you install or run it in Sheets, and backend Google OAuth when you connect your Google account through our Integration API.
We do not request access to Gmail, Google Calendar, Google Contacts, or your full Google Account. We only access the data needed to run the Retell integration in the spreadsheet and connected files you use with the service.
Apps Script Permissions (Google Sheets Add-On)
These scopes are listed in the add-on manifest and are authorized when you install or run the add-on in Google Sheets.
| Scope | What it allows |
|---|---|
| .../auth/spreadsheets | Read and write data in the Google Sheet where the add-on is installed (rows, columns, call status, summaries, etc.). |
| .../auth/script.external_request | Send HTTPS requests to our Retell integration server (e.g. retell-app.abark.tech) to process rows, sync configuration, and fetch activity logs. |
| .../auth/script.scriptapp | Create and manage installable triggers (e.g. optional automatic processing when a sheet is edited). |
| .../auth/userinfo.email | Read your Google account email address for identification and workspace linking - not for marketing. |
| .../auth/script.locale | Use your locale/language for add-on UI. |
| .../auth/script.container.ui | Show sidebars, dialogs, and menus inside Google Sheets (setup wizard, settings popup). |
Google OAuth Permissions (Backend Connection)
These scopes are requested when you connect your Google account through our Integration API OAuth consent flow. This authorization is separate from the Apps Script add-on authorization.
| Scope | What it allows |
|---|---|
| .../auth/spreadsheets | Read and write spreadsheet data from our backend (e.g. write call results and status back after Retell calls). |
| .../auth/drive | Access Google Drive to create, store, or link call-related files and artifacts. |
| .../auth/documents | Access Google Docs to create or update documents related to call activity. |
| .../auth/userinfo.email | Identify you and associate your Google account with your workspace. |
Data We Access and Why
We read the phone number and, if provided, the name from the row you edit. We check the phone number format and send the information to the Integration API to start a call through Retell AI. The call outcome and AI-generated summary are then written back to the Status and Summary columns you configured.
Retell AI receives call-related data, including phone numbers, call metadata, transcripts, and summaries, as described in Retell AI's privacy policy. Our server may write call results back to your spreadsheet and, if you have configured it, to linked Google Drive files or Google Docs.
Limited Use and AI / ML
The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
We use Google Workspace user data only to provide the user-facing features of this add-on: read the mapped row, start the outbound call the user requested, and write call results back to that same Sheet and to app-created Drive / Docs files.
We do not:
- sell Google user data
- use it for advertising or ad targeting
- use raw, aggregated, or derived Workspace user data to create, train, or improve foundational or generalized AI / ML models
- transfer Workspace user data to a third-party AI service for that service to train its models
Third-party AI integration
The only third-party AI service this add-on uses is Retell AI, on the Pro or Enterprise plan associated with the Retell API key you connect (Retell's paid Pay-as-you-go or Enterprise plans; not a free consumer AI plan). We do not integrate OpenAI, Anthropic, or other model providers directly.
Mapped Sheet fields (typically phone number and name, plus any extra columns you map) are sent to Retell only to place that outbound call and return the transcript, summary, recording URL, and outcome. Retell is a conversational voice platform. Call processing is described in Retell AI's privacy policy.
Retell may use upstream speech / language / voice models listed at https://trust.retellai.com/subprocessors. Those models are reached only through Retell. We do not operate a model gateway or aggregator of our own.
This add-on does not train models on Workspace user data. Retell documents that customer call data is not used to train or fine-tune Retell models, and that provider-level training opt-outs are enforced for those upstream models. On the connected Retell agent, you can set Data Storage Settings (Everything, Everything except PII, or Basic Attributes Only) and a retention period of 1–730 days so recordings, transcripts, and logs are limited or automatically deleted. Those controls are configured in Retell, not by this add-on.
Self-hosted or offline models
We do not use self-hosted or offline AI models. All AI processing for calls runs on Retell AI's hosted service.
External Services and Local Storage
- The add-on communicates with our Retell integration server (e.g. retell-app.abark.tech) and Google APIs (oauth2.googleapis.com, www.googleapis.com).
- User settings (API key reference, column mappings, auto-process toggle, etc.) are stored via Google Apps Script PropertiesService on your Google account.
- OAuth tokens and Retell configuration for backend access are stored encrypted on our servers as part of your tenant record in the Integration API.
Auto-Process Notice
If you enable "Auto-process," a call starts automatically whenever a mapped Phone cell is edited through an Apps Script installable trigger. You are responsible for making sure this setup meets your consent and compliance requirements before using it on a live sheet.
Your Control
You can uninstall the add-on from Google Workspace Marketplace > Remove. This stops all script triggers and clears local integration settings stored in Apps Script user properties. You can also revoke backend OAuth access in your Google Account permissions settings.
Data Retention and Deletion
Your sheet data remains in your own Google Drive under your control. Uninstalling the add-on stops all script triggers and clears local add-on settings. To request deletion of your stored tenant record from the Integration API, including OAuth tokens, the Retell API key, and related configuration, contact integrations@retellai.com.
Retell for Notion
Notion public OAuth integration with a companion setup/dashboard web app.
Retell for Notion uses Notion integration capabilities rather than Slack-style OAuth scope strings. When you connect your Notion workspace, you authorize a public integration and choose which pages and databases to share. The integration can only access the pages and databases you select.
Notion Capabilities Required
In Notion Developer Tools, enable only Read content and Update content. Use the same settings in your integration's Capabilities section.
| Capability (UI label) | API capability | Why we use it |
|---|---|---|
| Read content | read_content | Read database rows and pages you share during OAuth - phone number, consent/DNC, status, and other fields used to place calls. |
| Update content | update_content | Write call results back to the same Notion row (summary, recording URL, status, etc.). |
We do not request Insert content, Read user information, Read comments, or file upload/read capabilities unless those capabilities are added in a future version of the integration.
Data We Read (Read Content)
Retell only reads the Notion properties you configure on pages or databases that you explicitly share during OAuth:
- Phone number property - used to place outbound calls.
- Consent / DNC property - must be checkbox, Yes, or Allowed before dialing; outbound calls require this to be set.
- Other row fields needed to trigger and run calls, including any dynamic variables you configure.
Data We Write (Update Content)
- Call summary - AI-generated summary of the call.
- Recording URL - link to the call recording from Retell AI.
- Call status - configured status value after the call completes.
How Data Is Handled
- The setup interface is hosted on our integration service. Retell AI places the calls and processes the results.
- The Notion properties you choose to connect are sent to our Integration API so calls can be placed and results can be written back.
- Notion OAuth tokens are stored on our Integration API servers for webhook handling and writeback. They are not stored in your browser.
- Retell API keys are stored only on our servers and are never kept in browser storage.
- Webhooks - Notion automation can send events to our server. We process those events and write the results back to Notion.
- We skip duplicate automation events and recently dialed numbers to avoid placing the same call more than needed.
Retell AI receives call-related data, including phone numbers, call metadata, transcripts, and summaries, as described in Retell AI's privacy policy. We do not sell your data.
Your Control
You choose which pages and databases to share during Notion authorization. You can change those choices or revoke access in Notion's Connections settings, or disconnect the integration from the Retell setup dashboard.
Data Retention and Deletion
Page content stays in your Notion workspace and follows your own retention settings. Disconnecting the integration in Notion's Connections settings revokes our access. Uninstalling it from the setup dashboard removes the workspace connection from our server. To request deletion of your stored tenant record from the Integration API, including OAuth tokens, the Retell API key, and related configuration, contact integrations@retellai.com.
Retell for Slack
Slack app (bot + slash commands) with a companion setup/dashboard web app, distributed via the Slack App Directory.
When you install the Retell AI Slack app, you authorize the bot token scopes needed for the workspace installation. We do not request user token scopes or message-history scopes such as channels:history or groups:history.
OAuth Bot Scopes This App Requests
| Scope | Why we use it |
|---|---|
| chat:write | Post messages to Slack mainly call summaries and related notifications in the channel you choose. |
| channels:read | List public channels so you can pick a default channel during setup. |
| channels:join | Join public channels so the bot can post call summaries there. |
| groups:read | List private channels the bot has been invited to, so you can select them in the channel picker. |
| commands | Register and handle slash commands (e.g. /retell-call +15551234567) to trigger Retell outbound calls from Slack. |
What Slack Data the App Accesses
The integration uses Slack to:
- Connect your workspace through OAuth. The tokens are stored on our Integration API servers, not in your browser.
- List channels you can choose as the default summary channel.
- Post call summaries to that channel after Retell calls complete.
- Accept slash commands to place outbound calls from Slack.
- Show activity in the setup dashboard. This activity is fetched from our Integration API (GET .../slack/:tenantId/activities), not through additional Slack read scopes.
Slash commands, including any phone numbers or context you provide with them, are sent to the Integration API to start a call through Retell AI. Call outcomes are posted back to the original channel or another channel you configured. Your workspace/team ID is used as the tenant identifier.
Private channels: The bot cannot see a private channel unless someone in that channel runs /invite @Retell AI.
How Data Is Stored
- Slack OAuth tokens are stored on our Integration API servers so the connection can stay active and messages or commands can be delivered. They are not stored in your browser.
- Retell API keys are stored on our servers only.
- Call activity shown in the Retell setup dashboard is processed and stored by our integration service as part of call and writeback logs.
Retell AI receives call-related data, including phone numbers, call metadata, transcripts, and summaries, as described in Retell AI's privacy policy. We do not sell your data.
Your Control
You can disconnect the integration at any time by using Uninstall in the setup dashboard. This removes the workspace connection from our server. You can also remove the app from your Slack workspace (Slack > Apps > Remove), which revokes its tokens.
Data Retention and Deletion
Messages posted by the bot stay subject to your Slack workspace's retention policy. Uninstalling removes the workspace connection from our server. To request deletion of your stored tenant record from the Integration API, including OAuth tokens, the Retell API key, and related configuration, contact integrations@retellai.com.
Retell for Epic
SMART on FHIR EHR Launch web app embedded in Epic Hyperspace: setup wizard + outbound AI calls + clinical note writeback, distributed via Epic App Orchard / Build Apps.
Retell for Epic connects your Epic organization to Retell AI through our Integration API using SMART on FHIR OAuth 2.0 (EHR Launch from Hyperspace). You can also use Epic Backend Services with JWT client-credentials. Access is limited to the FHIR R4 clinical-note permissions configured in Epic Build Apps and does not provide a full-chart export.
Epic Build Apps / Incoming APIs (FHIR R4)
Your Epic app registration must enable the following Incoming APIs, shown as permissions in Build Apps:
| Build Apps permission | SMART scope (typical) | Why we use it |
|---|---|---|
| DocumentReference.Create (Clinical Notes) (R4) | user/DocumentReference.write, patient/DocumentReference.write (and Epic aliases such as DocumentReference.c) | After a Retell call ends, create a FHIR DocumentReference clinical note (Progress Note) on the patient, linked to the launch encounter, containing call summary, duration, and links to recording/transcript when available. |
| Binary.Read (Clinical Notes) (R4) | user/Binary.read, patient/Binary.read (and Epic aliases such as Binary.r) | Read binary attachment content for clinical notes when a DocumentReference points at a Binary resource - e.g. to verify note content or support future read/display features. We do not use this scope to bulk-export unrelated clinical documents. |
SMART OAuth Scopes (EHR Launch Authorize Flow)
When a user launches the app from Epic Hyperspace, authorization requests the following scopes in addition to the clinical-note scopes listed above:
| Scope | What it means | Why we use it |
|---|---|---|
| launch | EHR launch context from Epic | Bind the session to the patient chart and encounter the user had open when launching. |
| openid | OpenID Connect identity | Authenticate the Epic user session during OAuth. |
| fhirUser | FHIR Practitioner/User identity | Identify the authorizing clinician context per SMART on FHIR. |
| offline_access | Refresh token (when Epic "Requires Persistent Access" is enabled) | Allow post-call writeback after access tokens expire (~1 hour) without forcing the user to re-launch for every call. |
Epic grants patient- and user-scoped FHIR permissions based on your Build Apps settings and the authorizing user's Epic security. Backend writeback uses the stored OAuth token from the user who completed the launch. Creating a clinical note requires an encounter id from the EHR launch, so the app must be launched from an open patient chart with an active encounter.
Data We Receive from Epic (EHR Launch)
| Data | Source | Purpose |
|---|---|---|
| Patient FHIR id | OAuth token (patient) | Tenant identifier; ties calls and writeback to the correct patient. |
| Encounter FHIR id | OAuth token (encounter) when present | Link the clinical note DocumentReference to the active encounter. |
| FHIR base URL (iss / aud) | Launch + OAuth | Route FHIR API requests to your Epic environment. |
| OAuth access + refresh tokens | Token endpoint | Authenticated FHIR writeback and token refresh. |
In the default flow, we do not automatically read the patient's phone number, address, or full chart from Epic. The clinician enters the outbound phone number in the launch interface. Optional Backend Services connections may request additional system/*.read scopes that you explicitly configure when connecting.
Data We Write to Epic (Post-Call Writeback)
When Retell AI reports that a call has ended, we send a FHIR R4 DocumentReference to your Epic FHIR base with:
- Patient reference (Patient/{id})
- Encounter reference from launch (Encounter/{id})
- Plain-text attachment containing Retell call id, AI summary, duration, recording URL, and transcript URL when available
- Document type coded as Progress Note (LOINC 11506-3)
The note created in Epic remains in your Epic organization and follows your retention and access policies.
DATA YOU PROVIDE TO RETELL AI
| Data | Purpose |
|---|---|
| Retell API key | Stored encrypted server-side; places calls and receives webhooks. |
| Retell Agent ID (optional) | Which voice agent handles calls. |
| Outbound caller ID (from number) | Retell number used when placing outbound calls. |
| To phone number (E.164) | Destination number entered at call time. |
| Patient / record identifiers in call metadata | Associate webhook writeback with the correct Epic patient. |
Retell AI receives call-related data, including phone numbers, recordings, transcripts, and AI summaries, as described in Retell AI's privacy policy. Call content may include PHI if your agents or workflows include it.
Data We Store on Our Integration API
| Data | Purpose |
|---|---|
| Epic OAuth access + refresh tokens | FHIR writeback and token refresh. |
| FHIR base URL | Epic environment routing. |
| Patient id (tenant id) + encounter id | Call association and clinical note context. |
| Retell API key, agent id, from number, webhook secret | Integration configuration. |
| HttpOnly browser session cookie | Epic iframe / launch UI session (not your OAuth tokens in browser storage). |
| Call / integration activity logs | Setup status, errors, and writeback auditing. |
Protected Health Information (PHI)
This integration can process PHI, including patient identifiers and call summaries written to Epic clinical notes. We use this data only to run the integration: place calls, receive Retell webhooks, and write results back to Epic. We do not sell PHI or use it for advertising. Your organization controls Epic access and workforce permissions and is responsible for deciding whether its use of Retell AI meets HIPAA requirements, including any Business Associate Agreements that may be needed.
Third-Party Services
Data is shared with Epic through the FHIR APIs in your environment, with Retell AI for telephony and AI processing, and with the hosting/database provider that runs the Integration API. Each service is governed by its own terms and privacy policy.
Your Control
Use Uninstall app in the Epic launch interface to delete stored Retell settings and OAuth tokens for that patient tenant from our servers and clear your browser session. Organization administrators should also revoke the app in Epic Connected Apps / Build Apps and rotate credentials according to their security policy.
Data Retention and Deletion
Clinical notes created in Epic remain in your Epic organization and follow your own policies. Uninstalling requests deletion of your tenant record from the Integration API, including OAuth tokens, the Retell API key, encounter context, and related configuration. For additional deletion requests, contact integrations@retellai.com.
3. Data Deletion Requests
You can ask us to delete any data we hold about your account at any time by emailing integrations@retellai.com. This is in addition to the uninstall options described above for each app.
4. Changes to This Policy
We may update this Privacy Policy from time to time. If we make a material change, we will update the effective date shown at the top of this page.