> ## Documentation Index
> Fetch the complete documentation index at: https://docs.captivolabs.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Sensitive Data Redaction Plugin

> Mask card numbers and other personal data in call notes, AI summaries and transcripts before they're saved to your CRM.

Sensitive Data Redaction is a free App Connect plugin. It masks payment card details, and optionally email addresses, phone numbers and ID numbers, in your call logs before App Connect saves them to your CRM.

If a caller reads out their card number, it might appear in the AI summary or transcript like this:

> Card 4532 0151 1283 0366, expiry 09/27, CVV 123.

With the plugin on, your CRM receives this instead:

> Card XXXX XXXX XXXX XXXX, expiry XX/XX, CVV XXX.

## Install the plugin

<Steps>
  <Step title="Open App Connect plugins">
    In App Connect, open **Settings** and go to **Plugins**.
  </Step>

  <Step title="Install Sensitive Data Redaction">
    Find **Sensitive Data Redaction** and select **Install**. You don't need to sign in to anything: the plugin doesn't access your RingCentral or CRM accounts.
  </Step>

  <Step title="Choose what to mask">
    Turn on the options you want (see [Settings](#settings)). Card redaction is on by default.
  </Step>
</Steps>

From then on, every call you log is checked before it's saved.

## What it masks

| Data | How it's recognised | Shown in your CRM as |
| - | - | - |
| **Card numbers** | 13–19 digits with a card network's prefix that pass the card checksum, written or spoken ("four five three two…") | `XXXX XXXX XXXX XXXX` |
| **Card numbers by context** | 8–19 digits said straight after "card number", "credit card", "Visa", "Mastercard" and similar, even if some digits were misheard | `XXXX XXXX XXXX` |
| **Expiry dates** | A date after "expiry", "expires", "valid thru" and similar, or straight after a card number | `XX/XX` |
| **Security codes** | 3–4 digits after "CVV", "CVC", "security code", "code on the back" and similar | `XXX` |
| **Email addresses** *(optional)* | Written (`jane@example.com`) or spoken ("jane at example dot com") | `[email redacted]` |
| **Phone numbers** *(optional)* | Phone numbers mentioned in the conversation, written or spoken | `[phone redacted]` |
| **ID numbers** *(optional)* | US Social Security numbers (`NNN-NN-NNNN`), and numbers given as a social security number, SSN, tax file number or TFN | `XXX-XX-XXXX` |

<Tip>
  Turn on **Show the last four digits of card numbers** to keep cards identifiable, for example `XXXX XXXX XXXX 0366`.
</Tip>

## Settings

| Setting | Default | What it does |
| - | - | - |
| **Redact payment cards** | On | Masks card numbers, expiry dates and security codes. |
| **Show the last four digits of card numbers** | Off | Leaves the last four digits of a card number visible. |
| **Redact email addresses** | Off | Replaces email addresses with `[email redacted]`. |
| **Redact phone numbers mentioned in the conversation** | Off | Replaces phone numbers with `[phone redacted]`. The caller's own number on the call log isn't changed. |
| **Redact ID numbers** | Off | Masks social security and tax file numbers. |

## What it checks, and what it leaves alone

The plugin only checks the parts of a call log that contain what was said or written:

* your call notes
* the AI summary
* the transcript

It never changes the details App Connect needs to log the call correctly: the caller's phone number, the contact, the matter or deal you selected, the subject, or the call's times and duration.

To avoid masking things that aren't sensitive, card numbers must pass the same checks card networks use. Expiry dates and security codes need their keyword, or must follow a card number. That keeps ordinary numbers like invoice numbers, matter numbers and appointment dates as they are.

## If something isn't masked

Redaction works from the text App Connect receives. If a transcription garbles a number badly, or someone spells out details in an unusual way, it may not be recognised. Treat the plugin as a strong safeguard, not a guarantee, and edit the record in your CRM if you spot something it missed.

If the plugin ever can't process a call, the call is still logged as normal, so you don't lose it, and App Connect shows a message asking you to check the notes.

<Note>
  On CRMs connected through App Connect's built-in connectors, such as Pipedrive, the AI summary and transcript of a **newly logged** call aren't masked yet. Your notes are, and so are AI summaries and transcripts when a log is updated. Calls logged with Captivo Labs connectors (Smokeball, ConnectWise, Odoo) are masked in full.
</Note>

## Privacy

* **No call content is stored.** The plugin reads the call log, masks it and hands it back to App Connect. Nothing it reads is kept.
* **No account access.** It doesn't connect to your RingCentral or CRM account, which is why installing it doesn't ask you to sign in.
* **Usage counts only.** We record how many calls the plugin processed and how many items it masked for each account, so we know how it's used. We never record what was masked.

## FAQ

<AccordionGroup>
  <Accordion title="Does it cost anything?">
    No. Sensitive Data Redaction is free for now but subject to change in the future.
  </Accordion>

  <Accordion title="Can it unmask something later?">
    No. The original text never reaches your CRM, and the plugin doesn't keep a copy. If you need the original wording, check the call in RingCentral.
  </Accordion>

  <Accordion title="Will it mask my customers' phone numbers on the call log?">
    No. The caller's number on the call itself is never changed. **Redact phone numbers** only masks numbers mentioned in the notes, AI summary or transcript.
  </Accordion>

  <Accordion title="Does it work with server-side call logging?">
    Yes. Calls logged automatically by server-side call logging are checked the same way as calls you log yourself.
  </Accordion>
</AccordionGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.