Every figure here was read from the running code, the live n8n workflows, the Railway settings or the CRM's database on 4 September. Nothing is taken from documentation. The fix is mostly switching duplicates off and about six days of build.
A person fills in a Leadshook quiz. Within a minute their submission is sent to a language model sixteen times by three different systems, and each time it is the complete raw record.
First and last name · email · phone · full street address to house number and postcode · IP address, latitude, longitude, internet provider · Google click ids · Leadshook lead token · a URL that opens the lead's results page · every UTM tag · and the actual insurance answers: business activity, turnover, employees, vehicles, property, current insurer, bankruptcy and claims disclosures. The summary prompt pastes the whole block in twice and adds name and phone again. The PDF prompt asks the model to write out the IP address and user agent.
Every completed call with a recording, inbound or outbound, is uploaded in full to two different providers.
Nine systems. The last two carry Gerrard's own marketing and training content, not client data, and are listed for completeness.
| # | System | Trigger | Provider → model | What is sent | Volume (30 days) | Status |
|---|---|---|---|---|---|---|
| A | Lead-distributionleads.gerrards.tech | Every web lead on ingest (Leadshook, SettledLoop, Global Digital Solutions, Meta) | OpenRouter → Claude Sonnet 4 no host constraint | 5 prompts, each with the whole payload (197 fields). Summary prompt includes it twice plus name and phone. PDF prompt adds full address and asks for IP and user agent back. | 427 leads 14/day → ~71 calls/day | Live |
| B | CRM shadow enrichmentgerrards-crm worker | Every lead teed from A | OpenRouter → Claude Sonnet 4 | The same 5 prompts on the same payload. Stored, never shown to anyone. | 323 leads 11/day → ~54 calls/day | Live, unused |
| C | n8n "FULL LEAD"Bridge Media n8n | Leadshook webhook, in parallel with A | OpenRouter → Claude Sonnet 4 | 6 chains per lead on the whole Leadshook item. Also writes raw model output into GHL tags. | 142 runs in Aug ~28 calls/day | Live, duplicate |
| D | n8n: five other flowsHome & Contents · Meta · Life · Health ×2 | Website forms and Meta lead ads. These never pass through lead-distribution. | OpenRouter → Sonnet 4, Claude 3.5 (June 2024), and OpenAI GPT-4o | 6 chains each on the whole form body plus name, phone, email. The Life and Health flows send health information. | low H&C 8 runs in Aug | Live, only path for these sources |
| E | Phone-referral appphone.gerrards.co.nz | Every completed call with a recording | OpenAI Whisper | The full recording. The client's voice and everything said: names, addresses, policy and claim details, card numbers if read out. | up to 94/day | Live |
| F | Call-agentRailway gerrards-call-agent | The same calls, own webhook | AssemblyAI, then OpenRouter → Claude Sonnet 4.6 | The same full recording (second upload), then the full transcript for scoring and voice-of-customer. | 948 transcripts (32/day) 561 scorecards (19/day) | Live sends, dry-run outputs |
| G | Guardian Smith portalpartner referrals | An adviser forwards a referral email | OpenRouter → Claude Sonnet 4.6 | Email subject and full body: client name, phone, email, situation, whatever else the thread holds. | new, low | Live |
| H | Social pipeline | Greg uploads a marketing video | AssemblyAI + Sonnet 4.6 | Gerrard's own video and transcript. | ad hoc | No client data |
| I | Sales libraryin build | Training video upload | AssemblyAI + OpenRouter | Internal training content, staff names. | not live | Staff data only |
Identity and contact: A B C D E F G · Precise location (address, coordinates, IP): A B C · Device and network: A B C · Financial (turnover, bankruptcy): A B C D · Criminal conviction disclosure where asked: A B C · Claims history: A B C E F · Health information: D, and E F when discussed on a call · Voice recordings: E F
OpenRouter, Anthropic, OpenAI and AssemblyAI are all outsource providers holding client data, all in the US, and none is on a register or has a due-diligence record. Whether any of this is a Privacy Act matter is a question for CBN; that it happens sixteen times per lead is a fact.
One gateway, used by every system. The model gets the risk, never the person. Anything that leaks past the filter stops the call. Every call is logged on our side.
Summary: the "Contact Information" block is no longer the model's job. The broker email and PDF print name, phone, email and address from the payload, as they mostly already do. The payload appears once, not twice.
PDF: the contact, email-validation and technical sections (IP, user agent, results links) go. Address is printed by code.
Client email and SMS: unchanged. They read the summary, which no longer carries contact details, and already forbid greetings.
| Where | Change | Why |
|---|---|---|
| B · CRM shadow copy | Switch off now. Remove the OpenRouter key from the CRM worker; the feed skips cleanly by design. | A second copy of every lead for a comparison that has been failing since July for unrelated reasons. |
| C · n8n FULL LEAD | Deactivate, once lead-distribution's GHL field map is confirmed to write the three summary fields brokers read. | Third copy of every lead, and the source of the junk-tag problem in GHL. |
| D · n8n other flows | Interim: a node in front of each chain that strips identity fields, health flows first. Then move the four sources into lead-distribution and switch the workflows off. | They are the only enrichment for those sources today, and two of them carry health information through a June 2024 model and OpenAI. |
| E · Whisper | Switch off. Brokers get the transcript from the call-agent's copy, which the CRM already mirrors. | Same audio, second provider, lower quality, unauthenticated webhook. |
| F · Call-agent | Keep as the single transcription path. Delete each transcript at AssemblyAI after ours is stored. Scoring calls go through the gateway with names and numbers masked. | Transcripts contain whatever the client said; the scorecard does not need who they are. |
| G · Partner portal | Regex pulls emails, phones and addresses first and replaces them with placeholders; the model classifies situation and dates. Add data_collection: deny today. | Extraction needs the client's name in prose to tell client from adviser. That is the one identity field this path keeps, and the log says so. |
About six days of build. The two switch-offs cost nothing and remove a third of the exposure on day one.
Nothing. The broker email and PDF carry the same contact details, from the payload instead of the model. The client email and SMS never held more than a first name. Summaries lose a block the model used to copy; the template prints it above instead. Call transcripts arrive from one system instead of two.
Pick an answer for each, add your name, and the button opens an email to Greg with your choices. Nothing is built until this comes back.
It names the risk and makes the broker summary useful. For a sole trader it is also the person's name.
After confirming lead-distribution writes the three GHL summary fields the brokers read.
One day side by side first, then off.
Pinned is one line of code today. Direct is the right end state once the outsourcing register exists and someone signs it.
It feeds a comparison that has been failing since July for reasons unrelated to enrichment.
Opens your mail app with the five answers filled in. Change your mind later by sending it again.
OpenRouter (router, US) · Anthropic (language model, US) · OpenAI (Whisper, US, to be removed) · AssemblyAI (transcription, US or EU). Each needs: role, data received, the provider's published retention position confirmed and dated, the account setting or request flag that enforces it, the ai_calls evidence, and a review date. They sit alongside Railway, Clerk, Mailgun and Cloudflare.
Sources: lead-distribution src/services/enrichmentEngine.js and prompts.js; CRM packages/core/src/enrichment.js and apps/worker/src/feeds/enrichment.js; the seven n8n workflows read via the n8n API; phone-referral src/routes/webhooks.js and services/transcription.js; partner portal src/services/extract.js and its Railway variables; call-agent models from the CRM's mirrored transcripts and scorecards tables; volumes from the CRM database, last 30 days to 4 September 2026. Companion documents: crm-gap-analysis.md, ai-data-flows-and-minimisation-design.md.