dohosGet started
PLATE Nº 081 · DOCUMENT

State recording law

TARGET-STATE DRAFT — NOT APPROVED OR EFFECTIVE
STATUSTarget-state draft
LAST REVIEWEDNone yet — no review has run
CONTACTvia /contact/security
DRAFT NOTICEThis page describes how Dohos's internal voice, recording, and biometric policy separates call-related capabilities and what each one's default state is. It is not a jurisdiction-by-jurisdiction legal analysis of which states require one party's consent to record a call versus every party's consent — that analysis is a counsel-completed matrix, not yet finished, and this page does not substitute for it. Where a specific claim would require that unfinished analysis, this page says so rather than guessing.

01Recording, transcript, and voice identity are separate capabilities

State recording and wiretap law is easiest to get wrong by treating "the call" as one thing. Dohos's policy doesn't: it separates a call into five distinct capabilities, each with its own authority and its own default, and approval of one never implies approval of another.

  • AI voice interaction. The real-time speech processing needed to conduct the call itself — understanding what's being said well enough to respond to it.
  • Audio recording. Persisting the call's actual audio in a form that can be retrieved and played back later.
  • Transcript storage. Persisting the call's spoken content as text, beyond the momentary processing needed to conduct the call.
  • Voiceprint. A voice-derived representation capable of identifying, authenticating, or distinguishing a specific person — a biometric identifier.
  • Sensitive inference. Inferring health, emotional, or protected-class information from how someone sounds or what they say.

02The default position

CAPABILITYDEFAULT
AI voice interactionActive where a location is configured for it — this is what conducts the call
Audio recordingOff, unless a restaurant has separately enabled and disclosed it for that location
Post-call transcript — see corrected belowRetained for this pilot, gated by staff role and a retention period
Voiceprint / voice biometric identityProhibited
Sensitive inference from voice or contentProhibited

A disclosure is delivered at the start of the interaction, and again after a material reconnect or transfer, regardless of which of these capabilities is active for that location — the disclosure identifies that the caller is speaking with an automated system in understandable language and names the human or restaurant alternative. What the disclosure never does is claim a call is recorded when audio recording is off, or bury a recording disclosure inside a generic privacy reference where a caller could easily miss it.

03[CORRECTED] Post-call transcripts

CORRECTEDDohos's internal voice-and-recording policy frames transcript storage as off by default, independently gated from recording, in the same way audio recording is. That framing describes the general target design; it is not what the pilot restaurant actually runs. A text transcript of each completed call is retained under the pilot's standard configuration — for the restaurant's own operational use, access limited to authorized staff, and bound by the retention period in the Privacy Notice. This is the same correction already applied to AI and Voice Transparency Notice and Communications, carried through here because this page is exactly where a reader would otherwise be told the opposite.

Raw audio recording is the capability that genuinely matches the policy's off-by-default framing without correction: it stays off unless a restaurant has separately enabled and disclosed it for that specific location.

04How disclosure works across different states' rules

Some states require every participant's consent before a call may be recorded; others require only one participant's. Rather than build a jurisdiction-specific toggle that has to guess a caller's location correctly every time, Dohos's policy applies the same disclosure at the start of every call where recording is enabled, regardless of which state's rule would otherwise apply. The policy treats an unknown or ambiguous participant location as a reason to keep recording off, not a reason to guess and proceed.

Whether a specific state's consent requirement is satisfied by that disclosure and the caller's continued participation is a legal conclusion this page does not draw. Dohos's policy requires a counsel-approved, location-by-location legal matrix to be completed before recording activates for any jurisdiction — that matrix is an internal control, not yet finished, and no specific state-by-state list is published here because publishing one ahead of that review would overstate how settled the analysis is.

PLACEHOLDER — The completed, counsel-approved jurisdiction matrix naming which states require one-party versus all-party consent, and Dohos's specific handling for each. Not yet complete.

05Spoken card numbers are never part of this

Before a caller's speech reaches any recording, transcript, or model-processing path, Dohos's voice policy requires likely card or account credential speech to be detected and the capture interrupted — the system states that Dohos cannot take card details by voice and redirects to the secure payment path instead of asking the caller to repeat the number. Any suspected persistence of a spoken credential is treated as a security incident, not a data-quality issue to clean up later. See the PCI position for the rest of that boundary.

06Configuration

Whether a specific location records calls, and the exact wording of the disclosure a caller hears, is a per-location configuration decision a restaurant makes as part of setup — not a single global switch. This page describes the boundary the configuration operates inside; it does not expose the configuration screens themselves, which are part of the operator product rather than a public trust page.