By Industry

View all industries

Have questions? Give us a call — our team is happy to help: (469) 812-5544

Call our team

Product Categories

Have questions? Give us a call — our team is happy to help: (469) 812-5544

Call our team

Scenarios

View all use cases

Have questions? Give us a call — our team is happy to help: (469) 812-5544

Call our team

Library

Have questions? Give us a call — our team is happy to help: (469) 812-5544

Call our team
Quick Links
Home/
AI Receptionist/features
Pricing/pricing
Contact/contact
Book a Demo/contact
About/about
Partners/partners
Security/security
Developers/developers
to selectTab to navigateEsc to close

By Industry

DentalOptometryMedicalVeterinaryMedical SpaPlastic SurgeryPhysical TherapyMental HealthPrimary CareView all industries

By Role

Practice OwnersOffice ManagersFront Desk StaffView all roles

Enterprise

Dental Service Organizations (DSO)Medical GroupsVision GroupsVeterinary Chains

Call Management

AI ReceptionistCall RecordingCall IntelligenceMissed Call Text BackVoicemailPhone Porting

Scheduling

Smart SchedulingOnline SchedulingAI ChatbotCalendar SyncWaitlistBooking Widget

Patient Engagement

Two-Way TextingRemindersReview RequestsPatient OutreachRecall & Reactivation

Practice Management

Multi-LocationTeam ManagementDigital FormsPaymentsPatient CRM

EHR & Billing

EHR OverviewClinical NotesAI Progress NotesSuperbillsBillingClient PortalTherapy EHR

Analytics & AI

Call AnalyticsPractice AnalyticsProvider DashboardCustom AI Voice
AI ReceptionistVirtual Receptionist24/7 Answering ServiceAfter-Hours AnsweringHoliday Call AnsweringMissed Call RecoveryOverflow Call AnsweringVoicemail ReplacementAI Call Answering ServiceAppointment Booking ServicePatient Reactivation CallsPatient Recall & Recare CallsAppointment Reminder CallsPost-Visit Follow-Up CallsOnline Appointment SchedulingHIPAA-Compliant AISpanish-Speaking AIReplace Your Answering ServicePricing vs Answering ServiceCost of an Answering ServiceAnswering Service Pricing GuideView all use cases
Templates & ScriptsIndustry GuidesBlogResultsCase StudiesHealthcare GlossaryIntegrationsChangelog
Tools
Get StartedLog InSales: (469) 812-5544

Data retention and deletion

Defaults differ by data type and whether you're a healthcare org — call recordings 7 years (healthcare) or 1 year (non-healthcare), transcripts the same, patients indefinitely, audit logs 6 years. All defaults are configurable, and you can honor individual deletion requests with the per-patient delete tool.

Updated July 31, 20263 min read

Data retention is the boring-but-critical side of compliance. FrontDesk ships sensible defaults that meet HIPAA, GDPR, and CCPA out of the box, and gives you levers to tighten or relax them based on your jurisdiction and policies.

Default retention periods

Data typeHealthcare orgNon-healthcare
Call recordings (audio)7 years1 year
Call transcripts7 years1 year
Patient recordsIndefiniteIndefinite
AppointmentsIndefiniteIndefinite
SMS messages7 years1 year
Audit log6 years1 year
Voicemail audio1 year90 days

Healthcare defaults are set to match HIPAA's 6-year minimum for records of disclosures plus a 1-year buffer. Non-healthcare defaults match common state-law minimums.

Change retention periods

  1. Open Settings → Compliance → Data Retention.
  2. For each category, choose from the dropdown (30 days, 90 days, 1 year, 3 years, 7 years, indefinite).
  3. Click Save.

For healthcare orgs the dropdown won't let you go below HIPAA minimums (6 years for audit). For all orgs, lengthening retention takes effect immediately; shortening retention triggers a background cleanup over the next 24 hours.

Per-patient deletion (right to be forgotten)

When a patient invokes their GDPR, CCPA, or HIPAA right to deletion:

  1. Open Patients → search the patient → click their row.
  2. Click the menu → Delete Patient Data.
  3. Confirm by typing the patient's name.

What happens:

DataAfter deletion
Name, phone, emailReplaced with hashed values (e.g., Patient-a3f8b1)
Call recordingsAudio files deleted from S3
TranscriptsPersonally identifying content scrubbed
AppointmentsKept (anonymized) for your business records
Audit log entryRecords that the deletion happened, who requested it, and when

The operation is irreversible. We retain the audit-log entry for the deletion itself even after the data is gone — required for your compliance records.

Automated cleanup

A background job runs daily and deletes data that has exceeded its retention period. You'll see line items in your audit log:

[2026-01-15 02:00] System auto-deleted 247 call recordings older than 7 years (retention policy)
[2026-01-15 02:01] System auto-deleted 1,892 SMS messages older than 7 years

Export all your data

Want an offline copy of your data — before shortening retention, or if you're leaving the platform? An owner or admin can export everything:

  1. Open Settings → Audit Trail.
  2. Click the menu in the top-right corner → Export all account data.
  3. Choose which locations and which data to include (patients, appointments, call logs), and optionally include call recordings (audio).
  4. Click Request export.

We build a secure ZIP archive in the background and email a download link to the address on your account. The link expires in 72 hours, and the file contains sensitive information — store it somewhere safe. The export itself is recorded in your audit trail.

Recordings can make the archive much larger, so the email may take a few minutes to arrive. Smaller, single-dataset exports (appointments, waitlist, analytics) are still available as instant CSV downloads on their own pages.

What's next

Frequently asked questions

What are the default retention periods?
Healthcare orgs — call recordings and transcripts 7 years, patient records indefinite, audit log 6 years (HIPAA minimums). Non-healthcare orgs — call recordings and transcripts 1 year, patient records indefinite, audit log 1 year.
Where do I change retention settings?
Settings → Compliance → Data Retention. You can shorten or lengthen each category; healthcare orgs can't go below HIPAA minimums.
How do I delete a specific patient's data?
Patients → search the patient → ⋯ → Delete Patient Data. We anonymize their record (replacing identifiers with hashed values), delete their call recordings and transcripts, and log the deletion in the audit trail. Operation is permanent and can't be undone.
Can I export all of my data before I leave?
Yes. An owner or admin can open Settings → Audit Trail → the ⋯ menu (top right) → Export all account data, choose which locations and data to include, and we'll email a secure download link. The link is a ZIP archive (JSON plus optional call-recording audio) and expires in 72 hours.
Do I have to honor deletion requests?
Under GDPR (EU residents), CCPA (California), and similar state laws — generally yes, with some exceptions for legal/regulatory record-keeping. The per-patient delete tool produces a compliant deletion. We log the request and the deletion for your records.

Was this article helpful?

Related articles

Still need help?

Our team replies fast. Or just ask the in-app Setup Assistant.

Contact support