Reliability

A phone that does not ring out

What happens if the AI fails? Your mobile rings. For a small business an unanswered phone is worse than a slow app — you lose the customer and you never find out it happened — so every decision below starts from that one failure.

Your number lives with the carrier, not inside the AI

That is the whole reason the carrier stays in the picture. Because the number is theirs to route, we get to decide who answers when the voice model cannot — four seconds of silence and the call falls through to a spoken message and then to your mobile. If the number lived inside the AI, an outage there would mean nobody answers at all, and your caller would hear a dead line.

There is no call recording, by construction

Audio travels from the carrier directly to the voice model. It does not pass through our servers, so there is no recording to keep, to leak, or to hand over. This is a consequence of how the calls are routed, not a setting somebody could switch on by mistake.

Every call leaves a written trail

What the caller said, what the receptionist said, which lookups it ran and what came back. When a booking goes wrong — it said there was a table and then the booking failed — the transcript is the only thing that shows where. That is exactly why it exists.

It does not guess, and it does not fill in the blanks

The receptionist can state your hours, your services and their prices, your staff and who does what — and nothing else. Ask it about parking, allergens, whether dogs are welcome or if there are high chairs, and it says plainly that it cannot confirm that one. It will not reason from what is usual for a business like yours. An invented “yes, dogs are fine” sends someone to a shop that turns them away at the door, and you never find out why they did not come back.

What it cannot answer becomes a callback, not a dead end

Saying “I cannot confirm that” on its own would just lose you the customer. So it asks for their number, reads it back digit by digit, writes down the question in their own words, and tells them you will get back to them. It lands at the top of your dashboard as somebody waiting on a call — because that is exactly what it is.

It stays in its lane

Callers try things. They ask a restaurant to recommend a car, ask the receptionist out, ask what it thinks of the president, or ask for a haircut at a place that serves dinner. It answers none of it — it does not give an opinion, it does not play along, and it does not book you something else and call it the thing they asked for. It says warmly that it is only here for bookings and goes back to the booking. It speaks in your name, to your customer.

Card details never reach us

Checkout runs on Stripe’s own page. We never see a card number and we never store one, so there is nothing of yours sitting on our side waiting to go wrong.

Plainly stated

What happens, and where things live

Where your number livesWith the carrier — which is what makes failover ours to control
If the voice model is unreachableA spoken message, then the call rings your mobile
What triggers failoverFour seconds without a response
Call audioNever reaches our servers, so it is never stored
Call transcriptsKept with the booking and visible in your dashboard
Double bookingsBlocked by the database itself, not only by application checks
PaymentsStripe-hosted checkout — no card data on our side
Anything you have not told itIt says it cannot confirm, then takes a message for you
Off-topic, personal or politicalDeclined every time, then back to the booking

Want the version with the diagrams?

We will walk your IT person, your franchise office or your accountant through the call path, the failover and exactly what we keep.

Talk to us