By Sagar Shankaran, Founder of CallSphere
How long should you keep call recordings? CallSphere ships per-vertical retention defaults; Vapi customers DIY. Compare lifecycle and erasure flows.
Key takeaways
Retention is a deceptively complex compliance problem. Keep recordings too long and you create unnecessary risk; too short and you fail audit / legal hold requirements. CallSphere ships per-vertical retention defaults (healthcare, sales, salon, IT helpdesk, after-hours) with documented archive and erasure flows. Vapi.ai is voice infrastructure — retention is whatever the customer's storage vendor and DIY scripts produce, with no built-in lifecycle management. This post walks through retention windows by vertical, the lifecycle pipeline (active → warm → cold → erase), and gives you a procurement checklist.
Three forces pull retention in opposite directions:
A platform with per-vertical defaults gives the customer a defensible starting point that maps to common regulatory regimes. A platform that requires the customer to design retention from scratch typically results in either "keep everything forever" (high risk, high cost) or accidental data loss.
| Vertical | Active | Warm | Cold / Archive | Total | Notes |
|---|---|---|---|---|---|
| Healthcare | 30 days | 1 year | 6 years | ~7 years | Aligns to HIPAA documentation retention |
| Sales | 14 days | 90 days | 1 year | ~1 year | Coaching + dispute window |
| Salon | 7 days | 30 days | 90 days | ~90 days | Operational only |
| IT Helpdesk | 14 days | 60 days | 1 year | ~1 year | Incident review |
| After-Hours | 30 days | 90 days | 1 year | ~1 year | Escalation review |
These defaults are starting points — every customer can adjust per their legal and operational needs. The lifecycle pipeline is the same: a recording moves from hot storage (fast access) to warm (cheaper) to cold (archive) and finally to erasure.
Because Vapi is voice infrastructure with no built-in storage layer, the customer:
A typical maturity curve: customer defaults to "keep forever in S3 standard" for the first 18 months, until storage costs or a breach exposes the gap, then panics and rebuilds.
CallSphere's retention pipeline is built into the platform:
Per-tenant policy controls dictate the days at each stage. The right-to-erasure workflow is exposed via the dashboard and a documented API.
stateDiagram-v2
[*] --> Active: Recording created
Active --> Warm: day N (per vertical)
Warm --> Cold: day M (per vertical)
Cold --> Erased: day P (per vertical)
Active --> Erased: right-to-erasure request
Warm --> Erased: right-to-erasure request
Cold --> Erased: right-to-erasure request
Erased --> [*]
Active --> Hold: legal hold
Warm --> Hold: legal hold
Cold --> Hold: legal hold
Hold --> Active: hold released
The state machine is explicit. Every transition is logged in the audit_logs table with the policy that triggered it.
| Retention Capability | Vapi DIY | CallSphere |
|---|---|---|
| Per-vertical defaults | Build yourself | Built-in |
| Hot/warm/cold tiers | Build yourself | Default |
| Cryptographic erasure | Build yourself | Default |
| Right-to-erasure API | Build yourself | Built-in |
| Legal hold workflow | Build yourself | Built-in |
| Audit log of transitions | Build yourself | Default |
| Per-tenant policy override | Build yourself | Config |
| State / regional retention rules | Build yourself | Config |
| Time-to-compliance retention | Months | Day 1 |
A patient submits a deletion request. The flow:
Hear it before you finish reading
Talk to a live CallSphere AI voice agent in your browser — 60 seconds, no signup.
In a Vapi-based stack, step 4 alone often spans 5 vendors and the customer's own glue code. Each handoff is a chance for partial deletion, which is itself a compliance issue.
A typical mid-sized contact center generates ~50,000 minutes of recordings per month. At 24 kbps stereo, that's ~10 GB / month, ~120 GB / year. Over 5 years of "keep forever" with no lifecycle:
Cost is small but the blast radius difference is enormous: a breach of an unmaintained "keep forever" bucket exposes 5 years of PII. Lifecycle limits exposure to the active window.
Lifecycle is what separates "we have recordings" from "we have a defensible retention posture." Book a CallSphere demo, or check our pricing for retention tiers.
Yes — per-tenant policy can extend retention to meet legal hold, audit, or training data requirements. Each extension is documented.
Both follow the same lifecycle by default. Customers can choose to retain transcripts longer than audio (cheaper, lower-risk) under documented policy.
CallSphere's standard SLA is 30 days from verified request to confirmed erasure across all tiers, well within GDPR / CCPA windows.
Yes. Legal hold halts lifecycle transitions and erasure requests for affected records, with audit trail.
Aggregate metrics persist (counts, sentiment averages) but per-call rows are scrubbed. The result is statistically equivalent without retaining individual PII.
The HIPAA Privacy Rule does not specify a retention period for PHI itself, but the Security Rule (45 CFR § 164.530(j)) requires retention of compliance documentation for 6 years from creation or last effective date. Many states impose longer medical record retention (commonly 7-10 years for adults, longer for minors). CallSphere's healthcare default of ~7 years balances HIPAA documentation retention with state-specific minimums.
Specific retention extensions:
Sales call retention is driven by:
The default 1-year retention covers typical sales cycle and dispute resolution windows.
Still reading? Stop comparing — try CallSphere live.
CallSphere ships complete AI voice agents per industry — 14 tools for healthcare, 10 agents for real estate, 4 specialists for salons. See how it actually handles a call before you book a demo.
Lower-stakes operational data — 90 days covers typical operational review and dispute windows.
Typically retained for incident review, root cause analysis, and post-incident learning. 1 year covers typical incident escalation and trend analysis.
Retained for escalation review and pattern analysis. After-hours calls may have legal hold requirements (e.g., if escalated to emergency services).
A typical 50,000-minute-per-month customer:
| Storage Tier | Monthly Volume | Storage Class | Cost |
|---|---|---|---|
| Active (30 days) | ~10 GB | S3 Standard | ~$0.23 |
| Warm (60 days) | ~20 GB | S3 Standard-IA | ~$0.25 |
| Cold (5+ years) | ~600 GB | S3 Glacier | ~$2.40 |
| Total monthly | ~$2.88 |
Compared to "keep all in S3 Standard forever":
| Tier | Volume after 7 years | Storage | Cost |
|---|---|---|---|
| All Standard | ~840 GB | S3 Standard | ~$19.32/month |
The lifecycle approach is ~85% cheaper at steady state, plus dramatically smaller blast radius.
Backups are the trickiest part of right-to-erasure. Industry best practice:
CallSphere documents this clearly. A Vapi-based stack inherits whatever backup behavior each upstream vendor exposes — often opaque.
When litigation or regulatory hold is anticipated, the typical workflow:
Hold events are audit-logged and exportable. Legal teams can produce a "litigation hold report" showing which records are on hold and when each hold was applied / released.
After erasure, customers can request verification:
This verification package is the kind of evidence a regulator would demand if a deletion request was contested.
A real CallSphere customer's policy (anonymized):
Healthcare practice with multi-state operations:
Active: 30 days hot storage
Warm: 1 year warm storage
Cold: 6 years cold archive
Erasure: cryptographic shred + storage delete
Backups: 35 days, then purged
Legal hold: per-record flag with audit log
Right-to-erasure SLA: 30 days end-to-end
Each parameter is configurable in the dashboard, with audit log on every change.

Written by
Sagar Shankaran· Founder, CallSphere
LinkedInSagar Shankaran is the founder of CallSphere, where he builds production AI voice and chat agents deployed across healthcare, hospitality, real estate, and home services. He writes about agentic AI, LLM engineering, and shipping voice agents that handle real calls in production.
See how AI voice agents work for your industry. Live demo available -- no signup required.
CallSphere ships multi-tenant practices natively. Deploying 50 clinics on Vapi means 50 manual setups or building a multi-tenant layer. The cost breakdown.
Tenants, leases, rent ledger, maintenance — all built into CallSphere Real Estate. On Vapi, build it yourself. Full tenant lifecycle breakdown.
CallSphere's Mortgage Calculator agent runs affordability, repayment, and live bank rate scenarios. Vapi has no built-in financial agent. Here is the path.
CallSphere's Suburb Intelligence agent fuses schools, demographics, commute, and forecasts in real time. On Vapi, you build all of it. The data engineering breakdown.
A caller texts a property photo mid-call. CallSphere analyzes it and integrates the answer into the voice flow. Vapi has no native vision. Here is how it works.
Recording disclosure, opt-out, and HIPAA consent capture in voice AI. CallSphere ships consent flows; Vapi customers script their own.
© 2026 CallSphere Inc. All rights reserved.
Made within San Francisco
Watch how CallSphere handles real customer calls, schedules appointments, and processes payments — live.
Try Live DemoBook a DemoCalculate Your ROI