Privacy Policy

Last updated: August 8, 2026

Outcome Lab ("we," "us") builds and operates software and AI systems for our clients. This policy describes what information we collect through our website and through the software we operate — including Troy Method Dashboard, our private HighLevel marketplace integration, and Syncline, our Aircall ↔ HighLevel call-logging integration — how we use it, and the choices you have.

Our website

Our website does not require an account and does not ask you for personal information. If you contact us by email, we keep the correspondence so we can respond and maintain a record of the relationship. We do not sell visitor information or use it for advertising.

Troy Method Dashboard (HighLevel integration)

Troy Method Dashboard is a private integration installed on a client's HighLevel sub-account. Its sole purpose is to keep the client's own operations dashboard in sync with the conversations happening in their HighLevel account.

What it receives

  • Conversation event notifications from HighLevel (inbound and outbound messages), including message content, channel type (SMS, email, etc.), contact and conversation identifiers, timestamps, and delivery status.

How that data is used

  • Solely to maintain that client's own conversation record inside their dashboard.
  • It is never sold, rented, or shared with third parties.
  • It is never used for advertising or marketing to contacts.
  • It is never used to train AI or machine-learning models.

How it is protected

  • Webhook deliveries are authenticated before processing.
  • Data is encrypted in transit (TLS) and at rest.
  • Access is limited to the client's own authorized dashboard users and the Outcome Lab personnel who operate the service.
  • Stored data and logging are minimized by design — we keep what the client's conversation record needs, nothing more.

Syncline (Aircall ↔ HighLevel integration)

Syncline is our publicly available HighLevel marketplace app. Its sole purpose is to log a customer's Aircall phone calls into that customer's own HighLevel sub-account as native call records.

What it receives and stores

  • Call event notifications from Aircall: phone numbers involved, direction, timestamps, duration, call outcome (answered, missed, voicemail), and a link to the recording where one exists.
  • Contact identifiers from HighLevel needed to attach each call to the right contact, and the phone number of unknown callers when Syncline creates a contact on the customer's behalf.
  • OAuth credentials for the customer's HighLevel installation, stored encrypted at rest and used only to write call records into that customer's account.

What it does not do

  • Syncline does not store call audio. Recordings remain in the customer's Aircall account; Syncline stores only a link.
  • It does not read, store, or process message content from HighLevel conversations.
  • Call data is never sold, rented, shared with third parties, used for advertising, or used to train AI or machine-learning models.

How it is protected

  • Webhook deliveries are authenticated per customer before processing.
  • Data is encrypted in transit (TLS) and at rest; credentials are additionally encrypted at the application layer.
  • Each customer's data is isolated to their own installation and visible only to them and to the Outcome Lab personnel who operate the service.

Health information (HIPAA)

Some of our clients are healthcare providers whose messages may contain protected health information. We design our integrations around HIPAA-conscious data handling, and where required we enter into Business Associate Agreements with covered entities. Message content received on behalf of a healthcare client is treated as confidential patient information regardless of its content.

Retention and deletion

  • Data is retained for the duration of the client's service agreement or subscription with us.
  • Uninstalling an integration from a HighLevel sub-account immediately stops all event delivery for that location.
  • Clients may request deletion of their stored data at any time by contacting us; we honor those requests promptly, subject to any legal retention obligations.

Service providers

We host our software on established cloud infrastructure providers. These providers store data on our behalf under their own security programs; they have no independent right to use it.

Changes and contact

If we make material changes to this policy, we will update this page and the date above. Questions or requests: [email protected].