My Synergy Phone
Privacy policy
Last updated: October 9, 2026
My Synergy Phone is a business phone app for builders and their staff who use Structure Studio, the CRM from CSM Synergy. It comes as a mobile app for Android and iPhone, and as an extension for the Chrome browser on a computer. You use it to make and answer calls on your business number, text customers, listen to voicemail, and see call and text history for your Structure Studio contacts. A contact's conversation also shows the emails between your business and that contact, and you can email them from there.
The app is published by CSM Synergy (CSM Synergy LLC). In this policy, "we" and "us" mean CSM Synergy. This policy covers the My Synergy Phone mobile app (Android and iPhone) and the My Synergy Phone Chrome extension. "The app" means both. Where the Chrome extension works differently, we say so. Structure Studio itself is covered by the Structure Studio privacy policy.
1. Who can use the app
My Synergy Phone is for people who work for a business that uses Structure Studio. Your business creates your account and decides what you can see. You can't sign up in the app. You sign in with the Structure Studio email and password your business gave you. The app is a work tool. It isn't meant for personal use or for children.
2. Information the app handles
Your sign-in
When you sign in, your email and password go over an encrypted connection to our sign-in service, which runs on Supabase. The app never stores your password. It keeps your login session so you stay signed in: on a phone, in the phone's secure storage, and in Chrome, in the extension's own storage on your computer (see section 4). In the mobile app, if you tap "Forgot password", the sign-in service emails you a reset link.
Your account details
After you sign in, the app receives your name, email, user ID, the business you work for, your phone access level, your business phone number and your phone settings. It uses them to show you the right calls and texts and to call from the right number.
Microphone and call audio
The app asks for microphone permission before your first call. It uses the microphone only during a call, or while you run "Test my setup" from Settings, which places a short test call. In the Chrome extension, you give permission on its setup page: when you click "Allow microphone", the microphone turns on for a moment so Chrome can ask you, then turns off. Calls in Chrome run in a hidden page that belongs to the extension (Chrome calls it an offscreen document), and that page uses the microphone only during a call. Call audio travels live between your phone or computer and the phone network through Twilio, our calling provider. On networks that block call audio, the app sends the audio through Twilio's relay servers instead. Call recording isn't switched on yet. Once it is, calls are recorded unless your business's owner turns call recording off (see "Call recording, transcripts and summaries" below).
Calls and call history
When you place a call, the app sends the number you dialed and, if the number belongs to a Structure Studio contact, that contact's ID. For each call we store the numbers involved, which team member placed or answered it, the times, the length, the cost and how it ended.
The app also sends timing marks: when you pressed Call, when it rang, when it was answered and when it ended, plus any error codes. We use them to keep call history and to measure how quickly calls connect. During calls, Twilio's calling software sends Twilio call-quality measurements and basic device details, which Twilio uses to diagnose call problems.
Call recording, transcripts and summaries
Call recording isn't switched on yet for any business. Once we switch it on, it will be on by default for every business, and your business's owner can turn it off in Structure Studio. While it's on, calls to and from your business number are recorded from the moment someone answers. Every caller first hears "This call may be recorded." (or the business's own announcement) before it rings your team, and on calls your team places, the customer hears it when they pick up. Recording pauses while a customer is on hold, except while the call is being passed to a teammate, and stops before a caller is sent to voicemail. The iPhone app shows "Recorded call" on a call that is being recorded, and the Android app does from its next update. The Chrome extension doesn't show or play recordings yet.
Twilio makes the recording, and it stays at Twilio. The mobile app and Structure Studio play it from there, and we don't keep our own copy of the audio. Transcripts and summaries are switched off for every business for now, and we'll update this policy before we switch them on. Once they are, and if your business has transcripts turned on, a minute or two after the call ends our phone service sends the recording to Cloudflare Workers AI, which turns it into a written transcript, and sends the transcript to Anthropic, whose Claude AI writes a short summary of the call with any action items. We store the transcript and the summary with the call. People at your business who can see a call can play its recording and read its transcript and summary, according to the access your business owner set.
Voicemail
When someone calls your business and leaves a voicemail, Twilio records the caller's message. The recording stays at Twilio. The app plays it from there when you open it, and we don't keep our own copy of the audio. We delete voicemail recordings from Twilio 12 months after they are left. We also note when a voicemail was played and by whom, so your team knows it has been heard.
Voicemail transcription (turning the message into text) is currently off. If we turn it on, we'll update this policy first and say how long transcripts are kept.
You can record your own voicemail greeting. When you press Record, our phone service rings you in the app, and what you say after the tone is recorded by Twilio and stays at Twilio, like a voicemail. We store which recording is yours and when you made it. It plays to callers when a call meant for you goes to voicemail, and you can play it back yourself in the app or in Structure Studio. When you record a new one, or choose "Use the standard greeting", we delete the old recording from Twilio.
Text messages
Texts you send go from the app to our phone service and then through Twilio to the customer. We store the texts your business sends and receives, including the message, the numbers involved and the times, so conversations appear in the app and in Structure Studio. We also store how many parts (segments) each text went in and what it cost. Photos a customer sends by text stay at Twilio and are loaded only when you open the conversation. The app can't send photos.
Before your business can text a customer, there has to be a record that the customer agreed to receive texts. When you record that a customer agreed, we store the statement you confirmed, any note you add, who recorded it and when, and the IP address and app or browser identifier (user agent) of the device you used. We also keep records of customers who opted out, for example by replying STOP.
In the mobile app and the Chrome extension, a contact's conversation also shows the emails between your business and that contact from Structure Studio: the emails your team sends them, including quotes and invoices, and the replies they send back. When you email a contact from the app, Structure Studio sends it from the email address your business set up there, adds your email signature if you saved one, and keeps what was sent, who sent it and when. For a reply, Structure Studio keeps the sender's name and email address, the subject, the message, when it arrived, and the email service's check of whether it really came from that sender. The app shows only an email's text, not its pictures, attachments or formatting. The Structure Studio privacy policy covers how Structure Studio sends and stores email.
Contacts and search
The app shows your business's contacts from Structure Studio (in the Contacts tab on a phone, and in search results in the Chrome extension), limited to what your role lets you see. When you search, the name, number or email address you type is sent to our phone service to find matches. We don't store your searches, but they can appear in our hosting provider's request logs. If you save a number as a contact, the name and number are added to your business's contacts in Structure Studio.
The app does not read the contacts, call log, photos or location on your phone.
The Chrome extension does not read your browsing history, your tabs, the websites you visit or the files on your computer. The only web pages that can talk to it are Structure Studio's own pages. They can ask it to start a call or open a text conversation, and check which Structure Studio user is signed in to it.
Availability and forwarding
If you turn on Do Not Disturb, we store that setting and when it ends, so calls skip you. If you choose a teammate to ring while you're away, we store which teammate, so your calls ring them instead. If you set the hours your phone rings, we store those hours and your time zone, so calls reach you only then. Your teammates can see your hours. If you enter a cell number in "Forward to my cell", we store it and use it only to forward your business calls to you. While you're signed in, teammates can see whether you're online or on a call. That status is live only and is not stored.
Notifications and device tokens
To ring your phone and alert you to new texts and emails, the app registers your phone for push notifications. This gives your phone a push token. We store the token with your user ID, your business, your phone type, the app version and when the phone last checked in. Twilio holds the same token so it can deliver incoming calls.
Notifications reach your phone through Google Firebase Cloud Messaging on Android, or Apple's push notification service on an iPhone. A call notification includes the caller's number. A text alert includes the contact's name (or number, if there's no contact) and up to the first 140 characters of the text. An email alert includes the contact's name and the email's subject, never the email itself. Firebase also creates a Firebase installation ID on your phone and sends it to Google so notifications can be delivered. On Android, text and email alerts are marked private, so a locked phone hides what they say unless you've set your phone to show sensitive notification content.
The Chrome extension doesn't use push notifications or a push token. Calls ring through its own connection to Twilio, and it hears about new texts and emails over its live connection to our servers. Chrome then shows the alert on your computer. A call alert includes the caller's number, and their name if we have it. A text alert includes the contact's name (or number, if there's no contact) and up to the first 140 characters of the text. An email alert includes the contact's name and the email's subject, never the email itself. When you sign in, and about once a day after that, the extension checks in with our phone service. We store your user ID, your business, that it's the Chrome extension, its version and when it last checked in, so your business can see in Structure Studio which devices you've signed in on.
Error reports
When something goes wrong in the app, it sends us an error report. From the mobile app, a report has an error code, a short description, related IDs and codes, the app version, the phone type and, for a crash, a few lines of technical trace. Our phone service adds your user ID, your business and the app's user agent.
From the Chrome extension, a report has an error code, a short description, which part of the extension it came from, how many times the error repeated, the extension version and your browser's version and platform. Before it is stored, our phone service removes your user ID and your business ID, and scrubs email addresses, phone numbers and call IDs out of its text. Your IDs are replaced with a coded reference that only lets us group repeated errors and find your reports if you ask us for help.
We look at error reports, including our servers' own error logs, only in summary (counts by error), unless you ask us for help, for security, or when the law requires it. We use them only to find and fix problems.
The app has no ads and no analytics, advertising or crash-reporting software from other companies.
3. How we use it
- To run the app: placing and ringing calls, sending and receiving texts and emails, playing voicemail and sending you alerts.
- To keep call, text, email and voicemail history for your business in the app and in Structure Studio.
- Once call recording is switched on, to record calls, unless your business turns call recording off, and, when your business has transcripts on, to write their transcripts and summaries.
- To charge your business for the calls and texts it makes and receives, where they are billed. Each charge is a line in your business's Structure Studio wallet, showing the other number, the length or the number of text segments, and the price.
- To keep records of customer consent and opt-outs, so texting follows the law.
- To measure how quickly calls connect, and to find and fix problems.
- To manage your sign-in, including password reset emails.
We don't sell personal information, and we don't use or share it for advertising.
How the Chrome extension uses information
The use of information received from the My Synergy Phone Chrome extension will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
We use what the Chrome extension handles only to provide its calling, texting and email features (which includes charging your business for its calls and texts) and keep them working, as this policy describes. We don't sell it or transfer it to anyone for any other purpose. We don't use or share it for advertising, and we don't use it to judge anyone's creditworthiness or for lending. It's shared only as section 5 describes, and the error reports it sends are described in section 2.
4. What stays on your device
On your phone
The app keeps your login session in the phone's secure storage, which is protected by the Android Keystore (or the iPhone Keychain). It also saves a copy of your account details, recent calls (with a recorded call's short summary), conversations (texts and emails), your team list and the contact names you've already seen. A recorded call's transcript is never saved on the phone: the app loads it when you ask to see it and drops it when you leave the conversation. This lets it open quickly and show who's calling before the network answers. That copy lives in the app's private storage, which other apps can't read. The app doesn't add its own encryption to it beyond the phone's protections. Photos you open may stay in the app's temporary image cache.
Signing out deletes your session and the saved copy. So does another person signing in on the same phone. On Android, the app is excluded from cloud backups. Uninstalling the app removes everything it stored.
On your computer (Chrome extension)
The extension keeps your login session and your account details in Chrome's storage for the extension, so you stay signed in. It also keeps your headset, speaker and ringtone choices, whether your network needs the relay for call audio, and a few timestamps, such as when it last checked in with our phone service. While Chrome is open, it also keeps the current call and line status, and any text or email you typed but didn't send. Those are erased when Chrome closes.
To open quickly and show who's calling before the network answers, the extension saves a copy of your recent calls and voicemails, your text conversations, your list of conversations (which shows the subject of a conversation's newest email), and the contact names and numbers you've seen or searched for. That copy lives in a small database inside Chrome. Websites and other extensions can't read the extension's storage. The extension doesn't add its own encryption to it beyond your computer's protections, and none of it is synced to your Google account or your other computers. Voicemails, photos and emails you open are held in memory while you look at them and aren't saved to the computer. The saved copy of recent calls can include a recorded call's short summary, never its transcript.
Signing out deletes your session, your account details, the saved copy and any unsent texts and emails. Signing in as someone else clears them first. Your headset, speaker and relay settings stay. Removing the extension from Chrome deletes everything it stored.
5. Who receives it
We use these service providers to run My Synergy Phone. They process information for us, under our instructions:
- Twilio, for phone calls, texts, voicemail recordings, call recordings, photos customers send, call-quality data and incoming-call notifications.
- Google Firebase Cloud Messaging, to deliver call, text and email notifications to Android phones.
- Apple's push notification service, to deliver notifications to iPhones.
- Supabase, which hosts our database, sign-in service and live updates.
- Cloudflare, which runs our phone service (the server the app talks to) and keeps its request logs. When your business has call recording and transcripts on, Cloudflare Workers AI also turns call recordings into transcripts.
- Anthropic, whose Claude AI writes the short summary of a recorded call from its transcript, when your business has call recording and transcripts on.
- The email delivery service our sign-in provider uses, which delivers password reset emails.
- Expo, which we use to build the mobile app. Expo does not receive your information while you use the app.
The Chrome extension connects only to our phone service, Supabase and Twilio.
Inside your business, teammates may see calls, texts, emails and voicemails depending on the access your business owner set. For example, a manager may see the whole team's calls.
When you call or text a customer, your call or message goes to that customer through the phone network because you sent it. An email you send goes to the customer through Structure Studio's email service.
We may also disclose information when the law requires it, for example to comply with a valid court order.
6. Information about your customers
The people your business calls, texts and emails don't use the app, but the app handles some of their information: their phone numbers and email addresses, the times and lengths of calls, voicemails they leave, the texts, photos and emails they send, the emails your business sends them (and whether those arrived or were opened, when the email service reports it), and records of their consent or opt-out. Once call recording is switched on, and unless the business turns it off, it also includes the recordings of their calls (and, once transcripts are switched on, the transcripts and summaries made from them); every caller first hears "This call may be recorded." or the business's own announcement. We handle this information on behalf of your business, which decides who on its team can see it. A customer with questions about it can contact the business or us.
7. How long we keep it
- Voicemail recordings are deleted from Twilio 12 months after they are left. The call history entry for the voicemail stays.
- Call recordings are deleted from Twilio after the period your business chose: 12 months unless it picked 30 days, 90 days, 6 months or 2 years. A call's transcript is deleted with its recording. Its short summary stays with the call history, like the rest of your business's records.
- Call history, texts, emails, contacts, and consent and opt-out records are part of your business's records. We don't delete them on a schedule. They are kept while your business uses Structure Studio. After a business closes its account, it can ask us in writing to delete or return its data, and we keep only what the law requires us to keep. We do this by hand within 30 days of the written request.
- Photos customers send are stored at Twilio with your business's records; we don't delete them on a schedule.
- Your own voicemail greeting is kept at Twilio until you record a new one or choose "Use the standard greeting". Then we delete it from Twilio.
- Your Do Not Disturb and forwarding settings are kept until you or your business changes them, or until your account is deleted. They are kept if you leave your business's team, so they come back if you're added again.
- Push tokens are deleted when you sign out, when you use "Sign out of all devices", when your business signs you out of all devices from Structure Studio, or when Google or Apple tells us the token no longer works.
- The Chrome extension's check-in record has no push token. It stays when you sign out of the extension, and is deleted when you use "Sign out of all devices" in the mobile app or when your business signs you out of all devices from Structure Studio.
- Error reports are kept while we need them to find and fix problems; we don't delete them on a fixed schedule.
- Technical logs at our service providers, such as sign-in records with IP addresses and request logs, are kept for the periods those providers set.
- Deleted information can stay in our database backups for up to 7 days, until those backups expire.
8. Deleting your account
In the mobile app, open Settings (the gear icon), scroll to the bottom and tap "Delete my account". This opens our account deletion page, which explains what we delete and what we keep, and lets you send a request. If you use the Chrome extension, open the same page in your browser. You can also email support@csmsynergy.com from the address you sign in with. You don't need the app installed to ask.
Your My Synergy Phone login is your Structure Studio login, so deleting it also ends your access to Structure Studio.
9. Your rights and choices
- You can change Do Not Disturb and your forwarding number in Settings at any time.
- Whether calls are recorded, and for how long recordings are kept, is your business owner's choice in Structure Studio. For questions about a recording of you, ask your business owner or us.
- You can turn off notifications or microphone access in your phone's settings. Without them, the app can't ring for calls or carry your voice.
- In Chrome, you can block the extension's microphone in Chrome's settings, and turn off Chrome's notifications in your computer's settings. Without the microphone, the extension can't carry your voice. Without notifications, you won't see its call, text and email alerts.
- You can ask us for a copy of your personal information, ask us to correct it, or ask us to delete it. Depending on where you live, privacy laws (such as California's) may give you these rights by law. We won't treat you differently for using them.
To make a request, email support@csmsynergy.com. We'll confirm the request came from you before acting on it. Calls, texts and contacts belong to your business's records, so for some requests we may need to involve your business owner.
10. Security
All traffic between the app and our services is encrypted (HTTPS and secure WebSockets). Call audio is encrypted between the app and Twilio. Once a call reaches the regular phone network to reach your customer, it travels like any other phone call. The app sends your login token only in a secure request header, never in a web address. On a phone, your login session is kept in secure storage. In Chrome, it's kept in the extension's own storage, which websites and other extensions can't read. Inside your business, access to calls, texts and voicemails follows the roles your business owner set. No system is perfectly secure, so if you think your account has been misused, contact us.
11. Emergency calls (911)
My Synergy Phone can't call 911 or other emergency numbers. The app blocks them. In an emergency, call 911 from your cell phone's regular dialer.
12. Children
My Synergy Phone is a business tool for adults. It is not directed to children under 18, and we don't knowingly collect personal information from children. If you believe a child's information has reached us, contact us and we'll delete it.
13. Where data is stored
We store information in the United States. Google and Apple deliver notifications to phones through their own networks, which may pass through other countries.
14. Changes to this policy
If we change this policy, we'll update the date at the top. If a change affects how your information is used, we'll also tell your business owner.
15. Contact us
Email: support@csmsynergy.com
If your question is about your business's records, you can also ask your business owner, who manages your Structure Studio account.