Skip to content
Tilly

Your clients' data, protected and kept where it belongs

Your clinic owns its data. Tilly processes it only to answer your calls and messages, keeps it in the US, encrypts it, deletes it on the schedule you set, and never uses it to train AI models.

Updated

  • US hosting
  • Encrypted in transit and at rest
  • Audio kept 30 days by default
  • No card numbers by phone
  • No training on your data
  • SSO and two-factor sign-in for every plan

Your data stays in the US.

Tilly is hosted in the United States. Your calls, transcripts, recordings, backups and exports are stored and processed there.

Security built in

  • Encryption.

    TLS 1.2 or higher for everything in transit, and encryption at rest for databases, recordings and backups.
  • Separation between clinics.

    Every clinic's data is isolated at the database level, and automated tests try to break that separation on every endpoint.
  • Sign-in.

    Magic link, Google or Microsoft sign-in and SAML single sign-on on every plan (SAML is most often used by groups), and two-factor authentication you can require for your whole team.
  • Roles and locations.

    Give each person the access their job needs, limited to their locations.
  • Audit log.

    Every change by your team, by Tilly's AI and by Tilly staff is recorded and visible to you.
  • Tilly staff access.

    Our staff use hardware security keys, must give a support-ticket reason to open your account, and every access appears in your audit log.
  • Practice software credentials.

    Stored in a secrets vault and never shown again, not even to you.
  • Testing.

    Annual independent penetration tests and secure development to OWASP ASVS level 2.
  • Incidents and support.

    If a problem on our side affects your calls, we tell your owners, admins and managers within 15 minutes in the dashboard, by email and by text, and post updates at status.tillyvet.com. A person from our support team responds within 15 minutes, 24/7, when calls aren't being answered , and the one-tap switch sends every call straight to your clinic whenever you want.

Service status →

How support works →

Kept only as long as you need it

You choose how long Tilly keeps each kind of data, within the limits below. When the time is up, it's deleted automatically.

DataDefaultYou can choose
Call recordings30 days0 (don't record) to 365 days
Transcripts and summaries365 days30 to 1,095 days
Messages (SMS, WhatsApp, email, chat)365 days30 to 1,095 days
Urgent conversation records365 days365 to 1,095 days (never less than a year)
Call details without content (time, length, outcome)1,095 days365 to 2,555 days

Urgent conversations are always kept at least a year, so you can answer questions about them later. Deleted data leaves our backups within 35 days. You can place a legal hold on anything you need to keep longer.

Recording, only with notice

If you record calls, every caller hears a recording notice at the start, and can say they'd rather not be recorded. Tilly stops at once and deletes what it already captured. In US states that require everyone's consent, Tilly applies the stricter rule automatically. Only Tilly's part of the call is recorded; recording stops when a call is transferred to your team. Want no recordings at all? Set recordings to 0 days and Tilly won't record or play a notice.

No card numbers by phone or message

Tilly never takes card details by voice or message. If a caller starts reading out a card number, Tilly stops them, removes the digits from the transcript and the recording before anything is stored, and texts a secure payment link instead. Payments are taken on your payment provider's own hosted page, and the money goes straight to your account. This keeps card data out of Tilly entirely (PCI DSS SAQ A scope for payment pages hosted by your provider).

You stay in charge of your data

  • No AI training.

    Your data is never used to train shared AI models. Our AI providers are set up not to keep or train on your data.
  • Client requests.

    Export everything Tilly holds about a client, or delete it, from your dashboard. Exports are ready within 72 hours, usually within an hour.
  • Leaving Tilly.

    You get a full export of your data. Everything is deleted 30 days after your contract ends, and you receive a deletion certificate.
  • Data processing agreement.

    Every clinic signs our DPA at signup. You're the controller; Tilly is your processor.

Data processing agreement →

Subprocessors →

Privacy policy →

Questions

Is Tilly HIPAA compliant?

HIPAA covers human health information and doesn't apply to veterinary records. We protect your clients' data to the standards on this page regardless.

Who are your subprocessors?

Our current list, with what each one does and where it processes data, is at /legal/subprocessors. We notify clinics before adding a new one.

Can we turn recording off?

Yes. Set call recordings to 0 days and Tilly won't record calls or play a recording notice. Transcripts are still kept for your team to review.

Where are call recordings stored?

In the US, encrypted, for the number of days you choose (30 by default). Playing a recording is logged in your audit log.

Do you sell or share our data?

No. Tilly processes your data only to provide the service to your clinic.

Questions from your IT or privacy lead?

We'll answer them in writing or on a call.

Email security@tillyvet.com