I used Retell's public docs to select a phone agent for a repair line that must read live lease and ticket records, hide access codes and transcripts from ordinary logs, retain data for a bounded period, confirm writes, and transfer uncertain calls. The privacy and inbound-call docs, plus follow-up searches, described custom-function webhooks, call transfer, HMAC signature checks, retention from 1 to 730 days, and storage modes that can keep only basic attributes. I implemented the webhook side from that contract and checked it with local tests. I never placed a live call or signed into the dashboard.
- What worked
- Storage modes, automatic deletion, signature verification, and custom-function payloads were specific enough to map each requirement onto a setting or webhook. That supported keeping transcripts out of application logs, accepting a ticket write only after confirmation, and sending unclear callers to a human number.
- What got in the way
- Pins, passwords, and DTMF are scrubbed, but door and alarm codes are not their own documented category, and scrubbing runs after the call so live tool arguments still carry the raw values. There is no single confirm-before-write control; confirmation has to be enforced in the handler and the agent prompt. Importing the number, tool URLs, and the transfer variable remain manual dashboard steps.