FreeCallMe
Guide8 min read

Legal firms and confidential client calls: what you need to know

Attorney-client privilege is a legal doctrine, not a feature of any phone line. VoIP does not automatically protect a privileged conversation, and it does not automatically endanger one either. What matters is understanding exactly what the technology secures and what it leaves exposed. This is a plain-language breakdown for lawyers deciding how to make confidential calls. This is not legal advice. For your own duties, consult your bar's ethics guidance and, where needed, ethics counsel.

JP
John Patino·Founder, FreeCallMe

Related: Are VoIP calls private? What actually gets encrypted →

On this page

The short answer

Attorney-client privilege attaches to the relationship, not the phone line, and no VoIP feature creates or destroys it on its own. Your duty, under ABA Model Rule 1.6 and its state equivalents, is to make reasonable efforts to protect client confidentiality, scaled to how sensitive the matter is. Understand the three kinds of encryption, know that encryption does not cover metadata, endpoints, recordings, or legal process, and pick a channel that fits the matter. This is not legal advice.

Attorney-client privilege and communication channels

Attorney-client privilege protects confidential communications made for the purpose of seeking or giving legal advice. It is a legal doctrine that lives in the nature of the communication, not in the wire it travels over. A privileged conversation is privileged whether it happens in a conference room, on a landline, or over a browser call.

What the communication channel affects is whether the conversation stays confidential in the first place. Privilege can be waived if the communication is not kept confidential, for example if a third party can overhear it or intercept it. So the practical question for a lawyer is not "does this phone line create privilege" but "does this channel let me keep the conversation confidential enough that privilege is not put at risk."

That reframes the technology question entirely. You are not shopping for a product that grants privilege. You are choosing a channel whose confidentiality properties are appropriate to the sensitivity of the matter, and you are exercising reasonable judgment about it, which is exactly what the ethics rules ask.

How VoIP encryption works

"Encrypted" is not one thing. When a vendor says a call is encrypted, it is worth knowing which of these three they mean, because they offer very different protection. For a fuller treatment, see are VoIP calls private.

Transport encryption (the connection is protected)

Transport encryption protects the link between your device and the provider's servers. It is the same idea as the padlock in your browser bar. Someone sitting on the same coffee-shop Wi-Fi cannot read the traffic, and a casual eavesdropper on the network cannot reconstruct the call.

What it does not do is hide the call from the provider. The audio is decrypted on the provider's servers to route it, which means the company operating the service can, in principle, access it. Most business VoIP falls into this category. It is meaningfully secure against outsiders and meaningfully open to the vendor.

End-to-end encryption (only the two parties can hear it)

End-to-end encryption (E2EE) means the call is encrypted on your device and only decrypted on the other person's device. Nobody in between, including the provider, can access the content. This is the standard set by Signal and by browser-to-browser WebRTC calls.

E2EE is the strongest confidentiality guarantee available, but it comes with a real constraint: it only works when both endpoints are running compatible encrypting software. The moment a call crosses onto the ordinary phone network to reach a regular number, end-to-end encryption ends, because the phone network cannot decrypt it.

SRTP and DTLS (the protocols underneath)

SRTP (Secure Real-time Transport Protocol) encrypts the actual voice packets, and DTLS handles the key exchange that sets up that encryption. These are the building blocks that make both transport encryption and WebRTC end-to-end encryption possible.

For a browser-to-browser WebRTC call, DTLS negotiates keys directly between the two browsers and SRTP encrypts the media between them, with no server in the middle holding a decryptable copy. That is what makes a browser call end-to-end encrypted rather than merely transport-encrypted.

What VoIP does not protect

Encryption is a narrow tool. Even the strongest end-to-end encryption leaves several things untouched, and each one is a place a confidential conversation can leak.

Metadata is not the content, but it is still revealing

Encryption protects what was said. It does not usually hide who called whom, when, and for how long. That record, the metadata, can itself be sensitive: the fact that a particular client called a particular attorney at a particular time can reveal a relationship you would rather keep private, even if nobody ever hears a word of the conversation.

The endpoint is the weakest link

The most secure call in the world is worthless if the device on either end is compromised. Malware on a laptop, a shared family computer, an unlocked phone, or someone standing within earshot defeats any encryption. Confidentiality is a property of the whole situation, not just the wire.

Recordings live outside the encrypted call

If a call is recorded, the recording is a stored file that encryption of the live call says nothing about. Where it lives, who can access it, and how it is protected are separate questions. FreeCallMe does not record calls, so there is no stored recording to secure, but any tool that does record moves confidentiality onto the storage layer.

Legal process can compel disclosure

Encryption is a technical control, not a legal shield. A provider that can access call content or metadata can be served with a subpoena or a warrant and required to produce what it holds. True end-to-end encryption limits what a provider is able to hand over because it never holds the content in readable form, but that is a property of the architecture, not a promise the provider makes to a court.

Session persistence: does the call leave a trace after it ends?

A quieter confidentiality question is what remains after you hang up. A browser-to-browser FreeCallMe call is ephemeral: the session ends when the tab closes, there is no stored recording, and nothing about the conversation is retained. A platform that keeps rooms, transcripts, or history alive after the call is a different confidentiality posture, and worth checking before you use it for privileged conversations.

An end-to-end encrypted browser call, no account

Browser-to-browser calls are free and end-to-end encrypted. The session ends when the tab closes, and no recording is stored.

Call any phone number in 220+ countries from your browser. Your first call is free, up to $0.25, then pay-as-you-go by the minute.

Pay-as-you-go by the minute · sign in required

Evaluating VoIP for legal use: the questions to ask

You do not need to be a security engineer to evaluate a tool. You need to ask a handful of direct questions and understand the answers. These are the ones that matter for confidential legal work.

Is the call end-to-end encrypted, or only transport-encrypted?
If the answer is transport encryption, the vendor can technically access call content. That may be acceptable, but you should know it, and it should shape what you say and how you document it.
Do you record or store calls, and if so, where and for how long?
If calls are recorded, the recording is the thing to secure. Ask where it lives, who can access it, whether it is encrypted at rest, and how long it is retained.
What metadata do you keep, and who can see it?
Call logs, numbers dialed, timestamps, and durations are often retained even when content is not. Understand what is kept and under what circumstances it is disclosed.
Will you sign a business associate or confidentiality agreement?
For regulated data, a signed agreement is often what moves a tool from casually acceptable to defensibly compliant. If a vendor cannot or will not sign one, that tells you what the tool is built for.
Where is data processed and stored, and under whose jurisdiction?
Cross-border processing changes which legal process can reach the data. For sensitive matters, jurisdiction can matter as much as the encryption.

Traditional phone lines are not necessarily more secure

It is tempting to assume a traditional landline is the "safe" default and VoIP is the risky newcomer. The reality is more even than that. The ordinary phone network, the PSTN, was not built with end-to-end encryption. Calls across it are generally not encrypted in the way a modern secure app is.

The signaling layer that connects those calls, SS7, has well-documented weaknesses that have been used to intercept calls and messages and to track locations. A landline call is not inherently protected against a capable adversary just because it is old technology.

Traditional carriers are also directly subject to lawful interception. Under CALEA, US telecom carriers are required to build their networks so that calls can be intercepted under legal authority. And carriers routinely retain call detail records, the CDRs that log who called whom and when, which are exactly the metadata a subpoena can reach.

None of this means landlines are unsafe for legal work. It means the honest comparison is not "secure landline versus risky VoIP." It is two channels with different properties, and a well-chosen VoIP call can be more confidential than a PSTN call, not less.

Where FreeCallMe fits (and where it does not)

In the interest of not overclaiming, here is exactly what FreeCallMe is, what it is not, and how that maps to confidential legal calling. There are two call types, and they behave very differently.

Browser-to-browser calls (free)
End-to-end encrypted, up to 20 participants, no account on either end. The session ends when the tab closes and no recording is stored. Good for a confidential conversation with someone who can open a link in a browser. Not a system of record, and there is no signed confidentiality agreement behind it.
VoIP-to-phone dialing (paid)
Pay-as-you-go outbound calling to real phone numbers, from $0.01/min with the exact rate shown before you dial, first call free up to $0.25, no subscription, 222 countries. Once a call reaches the ordinary phone network it is not end-to-end encrypted, because the phone network cannot be. That is a property of every service that dials a normal number, not a FreeCallMe limitation.
What FreeCallMe does not offer
No inbound calls, no voicemail, no SMS, no call recording, no business associate agreement, and no legal confidentiality agreement. If your workflow needs any of those, FreeCallMe is not the tool for that part of it, and you should not treat it as if it were.

For a related walkthrough of a regulated-industry calling decision, see HIPAA and VoIP for a dental practice, and FreeCallMe for business for how firms use the free browser calls.

Ethics opinions: a brief survey

The formal guidance is remarkably consistent, and it does not name a product. It sets a standard of reasonableness and leaves the judgment to you. Here is the short version across the ABA and two large states.

ABA Model Rule 1.6 and 'reasonable efforts'

The ABA Model Rules of Professional Conduct require a lawyer to make reasonable efforts to prevent the unauthorized disclosure of client information (Model Rule 1.6(c)). The standard is not perfection and not a specific technology. It asks whether the measures you took were reasonable given the sensitivity of the information and the cost and difficulty of stronger safeguards.

ABA Formal Opinion 477R applied this to electronic communication and concluded that lawyers must make reasonable efforts, assessed case by case, and that more sensitive matters may call for stronger protections such as encryption. It deliberately avoids mandating one tool, because reasonableness is contextual.

New York and California

State bars have echoed the reasonableness framing. The New York State Bar Association has issued guidance treating encryption and vendor diligence as part of a lawyer's competence and confidentiality duties, with the level of protection scaled to the sensitivity of the matter.

California's guidance similarly frames technology choices under the duties of competence and confidentiality, asking lawyers to weigh the sensitivity of the information, the available safeguards, and the client's own instructions and expectations before relying on a given method of communication.

The common thread

Across the ABA and the states, the rule is not 'use product X.' It is 'make a reasonable, documented judgment for the matter in front of you.' For routine matters, transport-encrypted VoIP may be entirely reasonable. For the most sensitive conversations, end-to-end encryption, a signed agreement, or a different channel entirely may be the reasonable choice. The obligation is to think it through, not to buy a specific badge.

Frequently asked questions

Is VoIP allowed for privileged client calls?
Generally yes. No ethics rule bans VoIP for lawyers. The ABA and state bars require reasonable efforts to protect client confidentiality, scaled to how sensitive the matter is. For most conversations, a reputable VoIP service is a reasonable choice; for the most sensitive matters, you may want end-to-end encryption or a signed confidentiality agreement. The duty is to make a reasonable, documented judgment, not to use one specific product.
What is the difference between transport encryption and end-to-end encryption?
Transport encryption protects the connection between your device and the provider's servers, but the provider can still access the call content because it is decrypted on their servers to route it. End-to-end encryption keeps the call readable only on the two endpoints, so nobody in between, including the provider, can access it. Browser-to-browser calls are end-to-end encrypted; the moment a call crosses onto the ordinary phone network, end-to-end encryption is no longer possible.
Does encryption protect call metadata?
Usually not. Encryption protects the content of the call, what was actually said. It does not typically hide the metadata: who called whom, when, and for how long. That record can itself be sensitive, and it is often retained even when the content is not, so it is worth asking a provider what metadata they keep and who can see it.
Does FreeCallMe offer a confidentiality or business associate agreement?
No. FreeCallMe does not offer a business associate agreement or a legal confidentiality agreement, and it does not provide inbound calls, voicemail, SMS, or call recording. Browser-to-browser calls are end-to-end encrypted and leave no stored recording, and VoIP-to-phone dialing is pay-as-you-go, but if your workflow requires a signed agreement or a formal system of record, FreeCallMe is not the tool for that part of it.

Make a call, understand the tradeoffs

Free browser-to-browser calls are end-to-end encrypted with no stored recording. Dialing a real number is pay-as-you-go from $0.01/min, shown before you dial, with your first call free up to $0.25.

Call any phone number in 220+ countries from your browser. Your first call is free, up to $0.25, then pay-as-you-go by the minute.

Pay-as-you-go by the minute · sign in required

JP

John Patino

Founder of FreeCallMe. Building the simplest way to call someone online.

Updated

Keep reading