Privacy Policy
Effective Date: July 23, 2026 · Last Updated: July 9, 2026
Operated by: Vindication Inc., 7901 4th St N Ste 300, St. Petersburg, FL 33702
support@getcallro.com · +1 (727) 354-3133 · getcallro.com
1. Introduction
Callro is an Android call screening application operated by Vindication Inc. This Privacy Policy explains precisely what data Callro collects, what it does not collect, how we use your information, and your rights as a user.
This policy complies with the Google Play Developer Program Policy, the California Consumer Privacy Act (CCPA/CPRA), the Virginia Consumer Data Protection Act (CDPA), and applicable US federal privacy standards.
By installing or using Callro, you agree to the practices described in this Privacy Policy.
2. Information We Do NOT Collect
Callro is built on a privacy-first architecture. We explicitly do not collect or request access to:
- Your contacts list or address book
- Your call log or call history
- Voicemail content or any audio recordings
- Your name, email address, or physical address (unless you voluntarily provide it via email)
- Precise location data (GPS, Wi-Fi triangulation, or cell tower positioning)
- SMS or text message content
- Any data from outbound calls you make
- Your payment card details (billing is handled entirely by Google Play)
None of these permissions are requested at install time. You can verify this at any time in Android Settings → Apps → Callro → Permissions.
3. Information We Collect
3.1 Incoming Call Metadata (On-Device Only)
When a call arrives, Android's CallScreeningService API provides Callro with the incoming phone number for the duration of the screening decision. This number is analyzed locally on your device by the Gauntlet Engine. It is never transmitted to our servers, never stored permanently in its raw form, and never shared with any third party. After the screening decision is made, the number is discarded from active memory.
3.2 Your Phone Number (Optional, Encrypted)
During onboarding, you may choose to provide your phone number via the Google Phone Number Hint API. If you provide your number:
- It is encrypted on your device using AES-256-GCM before transmission.
- The encrypted number is stored on our secure servers (Supabase Inc.).
- Only authorized Vindication Inc. personnel can decrypt it, using a device-specific encryption key derived via HKDF-SHA256.
- Your phone number is used solely for: (a) extracting your area code to enable neighbor-spoof detection, and (b) with your explicit consent, allowing a Callro team member to call you during your first week to ensure the App is working correctly.
- Providing your phone number is entirely optional. You may skip this step during onboarding or enter only your area code manually without providing a full number.
- You can request deletion of your stored phone number at any time via Settings → Delete All Data or by emailing support@getcallro.com.
3.3 Area Code
If you provide your phone number or enter your area code manually, the 3-digit area code is stored locally in encrypted on-device storage. The area code is also transmitted to Callro's servers solely to retrieve local medical facility data (hospitals, pharmacies, emergency services) for your region, so these callers are never blocked. No other server-side use is made of your area code.
3.4 Shield Log (On-Device Only)
Call screening decisions (ALLOW, SILENCE, BLOCK) and associated risk scores are stored locally in your Shield Log. This data never leaves your device unless you choose to submit a support request. You can clear your Shield Log at any time in Settings.
3.5 In-App Support Chat
The App includes an optional AI-powered support chat feature named Shield. When you use this feature, messages you send are transmitted to Anthropic, PBC (makers of Claude AI) to generate responses and stored on our secure servers (Supabase Inc.) for up to 12 months to maintain conversation continuity. Use of the support chat is entirely optional. You can request deletion of your chat history at any time by contacting support@getcallro.com.
3.6 Anonymous Device Identifier
A one-way cryptographic hash (SHA-256) of your device's Android device identifier is generated on your device. This hash is used for trial management, subscription state tracking, referral attribution, and support chat session management. The raw Android device identifier is never transmitted or stored by Callro. The hash cannot be reversed to identify you or your device.
3.7 Trial Management
To provide a free trial without requiring a payment method and to prevent unlimited trial abuse, the device identifier hash (described in Section 3.6) is transmitted to Google's Play Integrity API and to our secure servers to record whether this device has previously redeemed a free trial. This hash is stored on Google's servers per Google's retention policy and on our servers for the duration described in Section 7.
3.8 Subscription and Purchase Data
All payments are processed by Google Play Billing. We receive and store a Google Play purchase token (a unique identifier for your subscription transaction) to manage your subscription status, process referral rewards, and handle billing state synchronization. We also store your subscription status (active, expired, or cancelled) and the date your subscription started. We never receive, store, or process your payment card details.
3.9 Referral Program Data
If you participate in the referral program, we store your unique referral code linked to your device identifier hash, records of referral attributions (which devices used your code), referral reward statuses (pending, granted, held), and the purchase tokens needed to apply billing deferrals. When someone clicks your referral link, we record the click along with the country derived from the Cloudflare IP country header (a two-letter country code only — no IP address, city, or precise location is stored).
3.10 Community Spam Reports (Optional — Off by Default)
If you choose to enable Community Verdict in Settings, an anonymized cryptographic hash (HMAC-SHA256) of spam caller numbers is transmitted to our secure servers to improve spam detection for all users. Raw phone numbers are never transmitted under any circumstances. Community Verdict is disabled by default and requires your explicit opt-in to activate.
3.11 Push Notification Token
Your Firebase Cloud Messaging (FCM) device token is transmitted to and stored on our secure servers to deliver push notifications including daily summaries of blocked calls, trial status updates, subscription reminders, and referral reward confirmations. The FCM token is a device-level identifier assigned by Google and is not linked to your personal identity. It is updated automatically when your device rotates tokens.
3.12 App Usage Analytics
Callro collects anonymized, device-level behavioral analytics to improve the subscription experience and measure app effectiveness. These include paywall interaction events (viewed, subscribe tapped, remind later tapped), and subscription funnel events. All analytics are linked only to your anonymous device identifier hash — never to your name, email, or phone number. No analytics data is sold or shared with third parties for advertising purposes.
3.13 Crash and Performance Diagnostics
If the app crashes, diagnostic data is automatically transmitted to Firebase Crashlytics (Google LLC). App performance metrics are transmitted to Firebase Performance Monitoring in aggregated, non-identifiable form. Neither service receives call data, contact information, or personal identifiers.
3.14 Meta (Facebook) App Events
Callro uses the Meta (Facebook) SDK to measure the effectiveness of advertising campaigns. The following events are transmitted to Meta Platforms, Inc.: app install, trial activation, subscription purchase, and app open. Meta receives a device-level advertising identifier and event data. Meta does not receive your phone number, contacts, call data, or any call screening information. You can limit Meta's data collection via your device's advertising settings (Settings → Privacy → Ads on Android). For more information, see Meta's Data Policy at facebook.com/privacy/policy.
4. How We Use Your Information
| Data | Purpose | Legal Basis |
|---|---|---|
| Call metadata (on-device) | Screen incoming calls | App functionality |
| Phone number (encrypted) | Area code detection, follow-up support call | Consent (you opt in) |
| Area code | Neighbor-spoof detection, medical facility lookup | App functionality |
| Anonymous device hash | Trial management, subscription tracking, referral attribution | App functionality |
| Purchase token | Subscription state sync, referral reward billing deferral | App functionality |
| FCM token | Push notifications (summaries, reminders, rewards) | App functionality |
| Referral data | Referral attribution, reward tracking, fraud prevention | App functionality |
| Paywall analytics | Improve subscription experience | Legitimate interest |
| Crash diagnostics | Fix bugs and improve stability | Legitimate interest |
| Performance metrics | Optimize app speed | Legitimate interest |
| Support chat messages | Respond via Claude AI | Consent (you initiate) |
| Community hashes (opt-in) | Improve spam detection for all users | Consent |
| Meta app events | Measure advertising effectiveness | Legitimate interest |
| Referral click country | Fraud prevention, regional analytics | Legitimate interest |
We do not use any data for personalized advertising within the App, behavioral profiling for third parties, or sale of personal information to data brokers. Callro products are ad-free.
5. Third-Party Services
| Service | Provider | Data Received | Purpose |
|---|---|---|---|
| Firebase Crashlytics | Google LLC | Crash diagnostics | Stability monitoring |
| Firebase Performance | Google LLC | Performance metrics | Speed optimization |
| Firebase Cloud Messaging | Google LLC | FCM device token | Push notifications |
| Firebase Remote Config | Google LLC | No user data | App configuration |
| Claude AI | Anthropic, PBC | Support chat messages | AI support responses |
| OpenCNAM | OpenCNAM LLC | Incoming number (TLS, zero-retention) | Caller ID lookup |
| Supabase | Supabase Inc. | Device hash, encrypted phone, trial data, referral data, FCM token, support messages, analytics | Backend infrastructure |
| Google Play Integrity | Google LLC | SHA-256 device hash | Trial fraud prevention |
| Google Play Billing | Google LLC | Purchase tokens | Subscription management |
| Meta SDK | Meta Platforms, Inc. | App events, device advertising ID | Advertising measurement |
6. Permissions Requested by Callro
ROLE_CALL_SCREENING: Required to receive incoming call information from Android and make screening decisions. Does not grant access to contacts, call logs, microphone, or location data.
POST_NOTIFICATIONS: Required to display alerts about screened or blocked calls and subscription status updates.
RECEIVE_BOOT_COMPLETED: Required to automatically restart call screening protection after the device reboots.
INTERNET: Required to download spam database updates, sync medical facility prefixes, deliver push notifications, and enable the optional AI support chat feature.
FOREGROUND_SERVICE: Required to maintain continuous call screening when the App is not in the foreground.
7. Data Retention
| Data | Retention |
|---|---|
| On-device Shield Log | Until you clear it or uninstall |
| Encrypted phone number (server) | Until you request deletion or 90 days after account inactivity |
| Area code (on-device) | Until you clear it or uninstall |
| Crash diagnostics | 90 days (Firebase default) |
| Performance metrics | 90 days (Firebase default) |
| Support chat messages | 12 months from last message, then deleted |
| Anonymous device hash | Until data deletion request or 90 days after inactivity |
| Trial management record | 90 days after trial expiry (our servers) / per Google's retention policy (Play Integrity) |
| Purchase token | Duration of subscription + 90 days |
| FCM token | Until token rotation or data deletion request |
| Referral records | Duration of subscription + 12 months |
| Referral click data | 12 months |
| Paywall analytics | 12 months |
| Community spam hashes | 90 days from last report, then purged |
| Meta app events | Per Meta's data retention policy |
8. Data Security
We implement commercially reasonable security measures including:
- TLS 1.3 encryption for all data transmitted between your device and any server
- AES-256-GCM encryption of phone numbers on-device before transmission, with device-specific keys derived via HKDF-SHA256
- Encrypted on-device storage using Android Keystore for all locally stored data
- Row-Level Security (RLS) on all Supabase database tables
- Service-role key isolation — all server-side data writes go through authenticated Edge Functions, never direct database access
- Anonymous identifiers — no data is linked to your real identity on our servers
- HMAC-SHA256 hashing for community spam reports — raw numbers never transmitted or stored
- SHA-256 one-way hashing for device identification — raw device identifiers never transmitted
- Google Play Integrity API validation for trial claims — prevents emulator and rooted device abuse
9. Your Privacy Rights
9.1 All Users
- Disable Community Verdict at any time in Settings
- Clear your Shield Log at any time in Settings
- Delete whitelist entries at any time in Settings
- Delete all local data via Settings → Delete All Data
- Request deletion of all server-side data by emailing support@getcallro.com or visiting getcallro.com/delete-data
- Request deletion of support chat history by emailing support@getcallro.com
- Uninstall the App to immediately remove all on-device data
- Revoke follow-up call consent at any time via Settings or by emailing support@getcallro.com
9.2 Do Not Sell or Share My Personal Information
Callro does not sell, rent, trade, or share your personal information with third parties for their own marketing or advertising purposes.
9.3 California Residents (CCPA/CPRA)
You have the right to know what personal information we collect, request deletion, correct inaccurate data, opt-out of sale (we do not sell), and non-discrimination for exercising your rights. Contact support@getcallro.com with subject "CCPA Privacy Request." We respond within 45 days.
9.4 Virginia Residents (CDPA)
You have the right to access, correct, delete, and obtain a copy of your personal data. Contact support@getcallro.com with subject "CDPA Privacy Request."
10. Children's Privacy
Callro is not directed at children under 13. We do not knowingly collect personal information from minors. If you believe a child under 13 has provided information through the App, contact us at support@getcallro.com and we will delete it promptly.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through a notice within the App and on our website. Material changes will not take effect until 14 days after notification. We review and update this policy at least once every 12 months in compliance with CCPA requirements.
12. Contact Us
Vindication Inc.
7901 4th St N Ste 300, St. Petersburg, FL 33702
support@getcallro.com
+1 (727) 354-3133
getcallro.com
This Privacy Policy is governed by the laws of the State of Florida, United States.
For a granular, technical breakdown of all data flows, on-device processing, and third-party interactions, view our Data Flow & Privacy Architecture Matrix.