Privacy Policy
Last updated: October 2, 2026
Outcome Lab ("we," "us") builds and operates software and AI systems for our clients. This policy describes what information we collect through our website and through the software we operate — including Troy Method Dashboard, our client HighLevel integration, Syncline, our Aircall ↔ HighLevel call-logging integration, and Ringline, our RingCentral ↔ HighLevel call-logging integration — how we use it, and the choices you have.
Our website
Browsing our website does not require an account. Our account-access form sends the email address you enter to Syncline and Ringline to request access instructions; it does not create a separate website account. If you contact us by email, we keep the correspondence so we can respond and maintain a record of the relationship. We do not sell visitor information or use it for advertising.
Troy Method Dashboard (HighLevel integration)
Troy Method Dashboard is an integration for authorized client operations. It keeps the client's dashboard connected to their HighLevel account. Authorized dashboard users can send messages and update CRM data within the permissions configured for their account.
What it receives
- Conversation event notifications from HighLevel (inbound and outbound messages), including message content, channel type (SMS, email, etc.), contact and conversation identifiers, timestamps, and delivery status.
- Contact information and CRM updates, such as tags, used by authorized dashboard features.
How that data is used
- To support that client's authorized operations, including conversations and CRM updates, inside their dashboard.
- It is never sold, rented, or shared with third parties.
- It is never used for advertising or marketing to contacts.
- It is never used to train AI or machine-learning models.
How it is protected
- Webhook deliveries are authenticated before processing.
- Data is encrypted in transit (TLS) and at rest.
- Access is limited to the client's own authorized dashboard users and the Outcome Lab personnel who operate the service.
- Stored data and logging are minimized by design — we keep what the client's conversation record needs, nothing more.
Syncline (Aircall ↔ HighLevel integration)
Syncline is our publicly available HighLevel marketplace app. Its sole purpose is to log a customer's Aircall phone calls into that customer's own HighLevel account as native call records.
What it receives and stores
- Call event notifications from Aircall: phone numbers involved, direction, timestamps, duration, call outcome (answered, missed, voicemail), and a link to the recording where one exists.
- Contact identifiers from HighLevel needed to attach each call to the right contact, and the phone number of unknown callers when Syncline creates a contact on the customer's behalf.
- OAuth credentials for the customer's HighLevel installation, stored encrypted at rest and used only to write call records into that customer's account.
What it does not do
- Syncline does not store call audio. Recordings remain in the customer's Aircall account; Syncline stores only a link.
- It does not read, store, or process message content from HighLevel conversations.
- Call data is never sold, rented, shared with third parties, used for advertising, or used to train AI or machine-learning models.
How it is protected
- Webhook deliveries are authenticated per customer before processing.
- Data is encrypted in transit (TLS) and at rest; credentials are additionally encrypted at the application layer.
- Each customer's data is isolated to their own installation and visible only to them and to the Outcome Lab personnel who operate the service.
Ringline (RingCentral ↔ HighLevel integration)
Ringline connects the RingCentral accounts you authorize to your HighLevel locations. It writes native call records and applies call-outcome tags to help you run workflows.
What it receives and stores
- RingCentral account and phone-number identifiers, the number-to-location mappings you choose, call event and call-log data such as phone numbers, direction, timestamps, duration and outcome, and processing or error details used to operate the connection.
- Recording identifiers, voicemail message and attachment identifiers when available, and signed playback links. Ringline streams audio from RingCentral for playback; it does not keep an audio archive. Playback depends on RingCentral retaining the media and on the connection remaining authorized.
- HighLevel location, contact and conversation identifiers used to find or create the right contact, post call records, and apply and remove outcome tags.
- Account contact information, encrypted OAuth credentials for RingCentral and HighLevel, connection and subscription status, and client connect-link labels and status needed for setup and service operation.
- Account-security data for the sign-in method you use. When password sign-in is enabled, this includes a password hash, session and password-reset token hashes, and login-attempt records keyed to email and network address for rate limiting. We do not store your password in plain text.
Permissions and connection controls
- RingCentral's Read Messages permission is used to find voicemail messages and retrieve their audio. Ringline does not use it to sync RingCentral SMS.
- Call Control allows Ringline to receive call events. Ringline does not place, answer, or transfer calls. It creates and manages its own event subscription.
- Each connection keeps its own authorization and number mapping. Client connect links allow RingCentral authorization without opening the agency dashboard; they are single use, expire after seven days, and can be revoked by the agency.
- Disconnecting a RingCentral connection clears its stored OAuth tokens and number mapping and stops logging for that connection. Ringline also attempts to remove its event subscription and revoke the authorization at RingCentral. Disconnecting does not erase call records already written to HighLevel or all stored service data; deletion requests are covered below.
Health information (HIPAA)
Some of our clients are healthcare providers whose messages may contain protected health information. We design our integrations around HIPAA-conscious data handling, and where required we enter into Business Associate Agreements with covered entities. Message content received on behalf of a healthcare client is treated as confidential patient information regardless of its content.
Retention and deletion
- Data is retained for the duration of the client's service agreement or subscription with us.
- Uninstalling Syncline or Ringline from a HighLevel location stops call logging to that location. A phone-system connection can continue receiving events for other connected locations; disconnect that connection separately to stop its call processing.
- Clients may request deletion of their stored data at any time by contacting us; we honor those requests promptly, subject to any legal retention obligations.
Service providers
We host our software on established cloud infrastructure providers. These providers store data on our behalf under their own security programs; they have no independent right to use it.
Changes and contact
If we make material changes to this policy, we will update this page and the date above. Questions or requests: [email protected].