Privacy Policy — Call Me If
Last updated: 29 September 2026
Contact: support@callmeif.app
Call Me If is an alert-escalation service. You connect a monitoring system or another trigger; when something happens, your phone rings until you acknowledge it.
This policy explains what we collect, why, how long we keep it, and how to remove it.
1. Who we are
Call Me If (the Android app, callmeif.app and api.callmeif.app) is run by Hamza Yousef, a sole trader based in Jordan, who is the data controller: the person responsible for your data under this policy.
You can contact us at support@callmeif.app. Our address is available on request to that address, and to any supervisory authority that asks for it.
2. What we collect
2.1 Account
-
Email address — to identify your account and send service messages such as deletion confirmations.
-
A display name, only if you add a backup contact — the name that person is shown when we invite them, and again if we ever have to contact them on your behalf. You choose it, and if you never add a backup contact we never ask for it. See §2.4.
-
Your own phone number, only if you add one — so that, if an alert you set to Ring, then call me is still not answered after two rings, we can phone you before we contact your backup person. You confirm it first: we call it and speak a code, or text the code to it, and you type the code into the app. Until a code comes back, we never phone that number for an alert. If such an alert ends with nobody answering, we also send that number one text saying an alert went unanswered — never what it was about — so the news waits on a phone that was off. You can change or remove it at any time in the app.
-
If you sign in with Google — the number Google uses for your Google account, so we recognise you the next time you choose Continue with Google, together with the email address Google has confirmed. Google also sends your name and profile picture as part of every Google sign-in; we read neither and store neither, and we never receive your Google password or access to anything else in your Google account. How Google handles the sign-in itself is covered by Google's own privacy policy. If your email address already has an account with us, signing in with Google opens that same account.
-
If you subscribe to Pro — what Google Play tells us about the subscription: the plan, whether it renews, until when it is paid, and Google's reference for the purchase (stored encrypted), so we know your account is on Pro. Google Play takes the payment; we never see your card or any payment details. Deleting your account does not cancel a Google Play subscription — cancel it in Google Play.
We do not collect your date of birth, gender, address, or advertising identifiers.
2.1b Newsletter (website only)
If you enter your email address in the newsletter form on our website, we store that address, the dates you gave it, confirmed it and — if you do — unsubscribed, and nothing else about you.
We deliberately do not record your IP address, your browser, the page you came from, or any link to a Call Me If account. Subscribing does not create an account, and having an account does not subscribe you.
You are not added to the list until you confirm. We send one email asking you to confirm, and if you do not click it we never send you anything else — this protects people whose address someone else typed into the form. Every message we send carries an unsubscribe link that works without signing in, because most subscribers have no account to sign in to.
2.2 Device
When you sign in on a phone we store:
- A push token (Firebase Cloud Messaging), so we can reach your device
- Manufacturer, model, Android version, app version
- Which permissions you have granted the app (for example full-screen alerts, Do Not Disturb bypass, battery exemption and notification access)
- The time of the last check-in, so we can tell you when your device is unreachable
- The language the app is set to, so that a phone call we make speaks it
The permission and manufacturer data exist for one reason: some Android manufacturers stop background apps aggressively. This is the data that lets us tell you why an alert did not arrive rather than guessing.
2.2b Crash and error reports
When the app or our server fails, a report goes to our error-monitoring provider (§5) so we can fix it. A report contains:
- What failed and where in our code — the error and the lines of code that led to it
- The phone's model, Android version and app version, and its state at the time: memory, storage, battery, and whether it was online
- The app's own recent steps — for example "alert received", "ring shown", "network lost" — so we can see what happened just before the failure
- A random identifier for the phone: its device number in our system, or, before you sign in, a random code the app creates. It is not linked to your name, email or phone number
A report never contains the content of your notifications or messages, your sentences, an alert's title or content, your phone number, your email address or your IP address, and we have set our provider to discard location. We remove these on your phone and on our server before a report is sent, not afterwards.
2.3 Alerts
- Title and body of each alert
- The raw content of the webhook that triggered it
- Timestamps for every step: received, sent, delivered, acknowledged
If you connect a monitoring system, its alerts may contain information about your systems and your customers. We do not inspect it or use it for anything other than delivering your alert. See §6.
2.4 Backup contacts — somebody else's details, given to us by you
If you add a backup contact — a person we may reach if you do not answer an urgent alert — we store their name and phone number, as you typed them, and whether they have agreed.
This is the only personal data in Call Me If that belongs to somebody who is not our user, and we treat it accordingly.
- ⭐ We contact nobody who has not agreed. They receive one text message with a link, naming you and explaining what being your backup would mean, and they tap to accept or decline. If they do not answer we send one reminder, and then nothing, ever. An unaccepted contact is never called and never texted again — and the app tells you plainly that this rung of your escalation is not covered.
- ⭐ If they decline, that is final. We keep the fact that they declined so that you can see it and arrange somebody else, and so that we never contact them again.
- ⭐ We record whether they also use Call Me If, because if they do we can alert them in the app instead of telephoning them. That record is a yes-or-no and nothing more: it gives you no access to their account, and gives them none to yours.
- What they are told is that you have not answered. Never what the alert was about, never its content, never who or what triggered it.
- If you remove them, or delete your account, their details are deleted with it.
2.5 What we do NOT collect
- ❌ We never receive the content of your notifications or messages. If you use personal triggers (for example "ring me if a specific person messages me"), those rules are evaluated entirely on your phone. The server is told only that an alert should fire — never what the message said, or who sent it. This is a deliberate architectural choice, not a policy promise.
- ❌ No SMS or call-log access.
- ❌ No location data.
- ❌ No advertising identifiers, no ad networks, no tracking or analytics SDKs. The one third-party library in the app that sends anything is the crash reporter described in §2.2b.
- ❌ We do not sell or share personal data, and we do not profile you.
3. Why we process it (legal bases)
| Purpose | Basis |
|---|---|
| Deliver alerts and let you acknowledge them | Performance of a contract |
| Keep the service secure; prevent abuse and runaway costs | Legitimate interests |
| Diagnose why an alert failed on a specific device | Legitimate interests |
| Send service emails (sign-in codes, confirmations, security notices) | Performance of a contract |
| Comply with tax and accounting obligations | Legal obligation |
| Send the newsletter, if you asked for it | Consent |
| Invite a backup contact, and reach them if you do not answer | Legitimate interests, narrowed in practice by their own agreement — we contact nobody who has not accepted (§2.4) |
| Sign you in with Google, if you choose it | Performance of a contract |
| Know whether your account is on Pro | Performance of a contract |
| Phone your own number, confirm it first, and text it once when an alert ends unanswered | Performance of a contract — you added it so we would reach you on it |
| Limit how often codes and invitations can be sent, to stop our calls and texts being abused | Legitimate interests — preventing fraud |
We do not rely on consent for anything except the newsletter, so for everything else there is nothing to withdraw — but you can delete your account at any time (§7).
Newsletter consent can be withdrawn at any moment, by clicking unsubscribe in any message or emailing us. Withdrawing it does not affect your account, and deleting your account does not by itself unsubscribe you — they are separate records on purpose, because most subscribers never had an account.
4. How long we keep it
| Data | Retention |
|---|---|
| Raw webhook payload | 30 days, then automatically and permanently erased |
| Alert record and its history | Until you delete your account |
| Device records | Until you unpair the device or delete your account |
| Account, including the Google account number if you sign in with Google | Until you delete it |
| Your own phone number | Until you remove it or delete your account. A number still waiting for its code is erased within an hour of the code expiring (a code lasts 10 minutes) |
| Record of codes and invitations sent | 48 hours, then erased. It holds a fingerprint of the number (a keyed code we cannot turn back into the number), what was sent and when. It is kept for those 48 hours even if you delete your account, with no account attached, so that deleting an account cannot be used to get around the limits |
| Encrypted backups | Up to 30 days, then destroyed |
| Crash and error reports | Up to 90 days at our error-monitoring provider, then deleted |
| Your Pro subscription's state and Google's purchase reference | Until you delete your account |
| Billing records | Held by our payment provider under their own retention rules |
| Newsletter — confirmed | Until you unsubscribe |
| Newsletter — never confirmed | 90 days, then erased. An address nobody confirmed is not something we should keep |
| Newsletter — unsubscribed | The address is kept solely to make sure we do not email you again, and is used for nothing else |
The 30-day payload window exists specifically to limit how long third-party data sits on our servers. Erasing it does not remove your alert history, which is reconstructed from event records rather than the payload.
5. Who we share it with
We use a small number of processors:
| Provider | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Our servers and database | Helsinki, Finland (European Union) |
| Laravel Holdings Inc. (Laravel Forge) | Setting up and updating our server. It can reach the server to do so, but does not store or read the service's data | United States |
| Cloudflare, Inc. | Our domain's DNS, and forwarding email sent to support@callmeif.app | Global |
| Resend (Plus Five Five, Inc.) | Sending our service emails: sign-in codes, confirmations and security notices. It receives the address and the email | Sent from the European Union (Ireland); its account records and delivery logs are kept in the United States |
| Google (Firebase Cloud Messaging) | Waking your phone when an alert fires. It receives an alert's id and its state — never its title, body or content, which your phone fetches from us directly | Global |
| Functional Software, Inc. (Sentry) | Diagnosing crashes and failures in the app and on our server. It receives the crash and error reports described in §2.2b — never message content, alert content, phone numbers, email addresses, IP addresses or location | European Union |
| Twilio Inc. | Phone calls and text messages: the code that confirms your own number, a call to your number when an alert you set to Ring, then call me is not answered, one text to it if that alert ends with nobody answering, and inviting and calling your backup contacts. It receives the phone number and what is spoken or texted — a code, the name of the person who did not answer, or that an alert went unanswered; never what an alert was about | Global |
Google Play (Google LLC / Google Ireland Ltd) sells Pro subscriptions as merchant of record: it handles payment, invoices, tax, refunds and chargebacks under its own terms with you, as an independent controller rather than our processor. We receive from it only the subscription's state, plan and paid-until date. Google also handles Continue with Google under its own privacy policy (§2.1).
We do not share your data with anyone else, and we never sell it.
The list of companies that process alert content on behalf of business customers, with what each receives and where, is published at https://callmeif.app/sub-processors, and we announce changes there before they happen.
6. If you use Call Me If for work
Where you connect a monitoring system and its alerts contain personal data about other people (for example a customer's email address inside an error report):
- You are the data controller for that content.
- We are your processor, handling it only to deliver your alerts.
- We will sign a Data Processing Agreement on request — email support@callmeif.app.
- Payload content is erased after 30 days (§4).
7. Your rights
You can:
- Access the data we hold about you
- Correct it
- Delete your account and data
- Object to processing based on legitimate interests
- Export your data in a portable format
- Complain to your data protection authority
Exporting your data: in the app, Settings → Export my data. You get a single JSON file containing your account (including your own phone number), your devices, your alert sources, your rules, your backup contacts, the codes and invitations sent in the last 48 hours, and your full alert history, which you can save or send anywhere. ⭐ It deliberately contains no passwords, tokens or keys — those authenticate you, they are not information about you, and an exported file travels further than an account does.
Deleting your account:
- In the app: Settings → Delete account
- Or on the web, with no app required: https://callmeif.app/delete-account
Deletion removes your account, devices, tokens, alert sources, sentences kept on our server, backup contacts, alerts and history. It cannot be undone. In the app it takes effect immediately. On the web we email you a link, valid for one hour, to a page where you confirm; it takes effect the moment you do. Encrypted backups are destroyed within 30 days.
For any other request, email support@callmeif.app. We respond within 30 days.
8. Security
- All traffic is encrypted in transit (TLS).
- Access tokens are stored hashed; we cannot read them back.
- On your phone, your token is held in Android's encrypted storage.
- Only the operator can reach production data: the server accepts key-based logins only, and the administration panel requires two-factor authentication.
- In webhook payloads, fields named like passwords, secrets, tokens, API keys, authorization headers,
credentials and private keys are replaced with
[redacted]before they are stored.
No system is perfectly secure. If a breach affects your personal data we will notify you and the relevant authority as required by law.
9. Children
Call Me If is not directed at children under 16 and we do not knowingly collect their data.
10. International transfers
We are based in Jordan and use providers that may process data outside your country, including in the EU and the United States. Where required we rely on Standard Contractual Clauses or an equivalent safeguard.
11. Changes
We will update this page and change the date above. For material changes affecting how we use your data, we will notify you by email or in the app before they take effect.