Skip to content
Call Me If

Privacy Policy — Call Me If

Last updated: 29 September 2026

Contact: support@callmeif.app

Call Me If is an alert-escalation service. You connect a monitoring system or another trigger; when something happens, your phone rings until you acknowledge it.

This policy explains what we collect, why, how long we keep it, and how to remove it.


1. Who we are

Call Me If (the Android app, callmeif.app and api.callmeif.app) is run by Hamza Yousef, a sole trader based in Jordan, who is the data controller: the person responsible for your data under this policy.

You can contact us at support@callmeif.app. Our address is available on request to that address, and to any supervisory authority that asks for it.

2. What we collect

2.1 Account

We do not collect your date of birth, gender, address, or advertising identifiers.

2.1b Newsletter (website only)

If you enter your email address in the newsletter form on our website, we store that address, the dates you gave it, confirmed it and — if you do — unsubscribed, and nothing else about you.

We deliberately do not record your IP address, your browser, the page you came from, or any link to a Call Me If account. Subscribing does not create an account, and having an account does not subscribe you.

You are not added to the list until you confirm. We send one email asking you to confirm, and if you do not click it we never send you anything else — this protects people whose address someone else typed into the form. Every message we send carries an unsubscribe link that works without signing in, because most subscribers have no account to sign in to.

2.2 Device

When you sign in on a phone we store:

The permission and manufacturer data exist for one reason: some Android manufacturers stop background apps aggressively. This is the data that lets us tell you why an alert did not arrive rather than guessing.

2.2b Crash and error reports

When the app or our server fails, a report goes to our error-monitoring provider (§5) so we can fix it. A report contains:

A report never contains the content of your notifications or messages, your sentences, an alert's title or content, your phone number, your email address or your IP address, and we have set our provider to discard location. We remove these on your phone and on our server before a report is sent, not afterwards.

2.3 Alerts

If you connect a monitoring system, its alerts may contain information about your systems and your customers. We do not inspect it or use it for anything other than delivering your alert. See §6.

2.4 Backup contacts — somebody else's details, given to us by you

If you add a backup contact — a person we may reach if you do not answer an urgent alert — we store their name and phone number, as you typed them, and whether they have agreed.

This is the only personal data in Call Me If that belongs to somebody who is not our user, and we treat it accordingly.

2.5 What we do NOT collect

3. Why we process it (legal bases)

Purpose Basis
Deliver alerts and let you acknowledge them Performance of a contract
Keep the service secure; prevent abuse and runaway costs Legitimate interests
Diagnose why an alert failed on a specific device Legitimate interests
Send service emails (sign-in codes, confirmations, security notices) Performance of a contract
Comply with tax and accounting obligations Legal obligation
Send the newsletter, if you asked for it Consent
Invite a backup contact, and reach them if you do not answer Legitimate interests, narrowed in practice by their own agreement — we contact nobody who has not accepted (§2.4)
Sign you in with Google, if you choose it Performance of a contract
Know whether your account is on Pro Performance of a contract
Phone your own number, confirm it first, and text it once when an alert ends unanswered Performance of a contract — you added it so we would reach you on it
Limit how often codes and invitations can be sent, to stop our calls and texts being abused Legitimate interests — preventing fraud

We do not rely on consent for anything except the newsletter, so for everything else there is nothing to withdraw — but you can delete your account at any time (§7).

Newsletter consent can be withdrawn at any moment, by clicking unsubscribe in any message or emailing us. Withdrawing it does not affect your account, and deleting your account does not by itself unsubscribe you — they are separate records on purpose, because most subscribers never had an account.

4. How long we keep it

Data Retention
Raw webhook payload 30 days, then automatically and permanently erased
Alert record and its history Until you delete your account
Device records Until you unpair the device or delete your account
Account, including the Google account number if you sign in with Google Until you delete it
Your own phone number Until you remove it or delete your account. A number still waiting for its code is erased within an hour of the code expiring (a code lasts 10 minutes)
Record of codes and invitations sent 48 hours, then erased. It holds a fingerprint of the number (a keyed code we cannot turn back into the number), what was sent and when. It is kept for those 48 hours even if you delete your account, with no account attached, so that deleting an account cannot be used to get around the limits
Encrypted backups Up to 30 days, then destroyed
Crash and error reports Up to 90 days at our error-monitoring provider, then deleted
Your Pro subscription's state and Google's purchase reference Until you delete your account
Billing records Held by our payment provider under their own retention rules
Newsletter — confirmed Until you unsubscribe
Newsletter — never confirmed 90 days, then erased. An address nobody confirmed is not something we should keep
Newsletter — unsubscribed The address is kept solely to make sure we do not email you again, and is used for nothing else

The 30-day payload window exists specifically to limit how long third-party data sits on our servers. Erasing it does not remove your alert history, which is reconstructed from event records rather than the payload.

5. Who we share it with

We use a small number of processors:

Provider Purpose Location
Hetzner Online GmbH Our servers and database Helsinki, Finland (European Union)
Laravel Holdings Inc. (Laravel Forge) Setting up and updating our server. It can reach the server to do so, but does not store or read the service's data United States
Cloudflare, Inc. Our domain's DNS, and forwarding email sent to support@callmeif.app Global
Resend (Plus Five Five, Inc.) Sending our service emails: sign-in codes, confirmations and security notices. It receives the address and the email Sent from the European Union (Ireland); its account records and delivery logs are kept in the United States
Google (Firebase Cloud Messaging) Waking your phone when an alert fires. It receives an alert's id and its state — never its title, body or content, which your phone fetches from us directly Global
Functional Software, Inc. (Sentry) Diagnosing crashes and failures in the app and on our server. It receives the crash and error reports described in §2.2b — never message content, alert content, phone numbers, email addresses, IP addresses or location European Union
Twilio Inc. Phone calls and text messages: the code that confirms your own number, a call to your number when an alert you set to Ring, then call me is not answered, one text to it if that alert ends with nobody answering, and inviting and calling your backup contacts. It receives the phone number and what is spoken or texted — a code, the name of the person who did not answer, or that an alert went unanswered; never what an alert was about Global

Google Play (Google LLC / Google Ireland Ltd) sells Pro subscriptions as merchant of record: it handles payment, invoices, tax, refunds and chargebacks under its own terms with you, as an independent controller rather than our processor. We receive from it only the subscription's state, plan and paid-until date. Google also handles Continue with Google under its own privacy policy (§2.1).

We do not share your data with anyone else, and we never sell it.

The list of companies that process alert content on behalf of business customers, with what each receives and where, is published at https://callmeif.app/sub-processors, and we announce changes there before they happen.

6. If you use Call Me If for work

Where you connect a monitoring system and its alerts contain personal data about other people (for example a customer's email address inside an error report):

7. Your rights

You can:

Exporting your data: in the app, Settings → Export my data. You get a single JSON file containing your account (including your own phone number), your devices, your alert sources, your rules, your backup contacts, the codes and invitations sent in the last 48 hours, and your full alert history, which you can save or send anywhere. ⭐ It deliberately contains no passwords, tokens or keys — those authenticate you, they are not information about you, and an exported file travels further than an account does.

Deleting your account:

  1. In the app: Settings → Delete account
  2. Or on the web, with no app required: https://callmeif.app/delete-account

Deletion removes your account, devices, tokens, alert sources, sentences kept on our server, backup contacts, alerts and history. It cannot be undone. In the app it takes effect immediately. On the web we email you a link, valid for one hour, to a page where you confirm; it takes effect the moment you do. Encrypted backups are destroyed within 30 days.

For any other request, email support@callmeif.app. We respond within 30 days.

8. Security

No system is perfectly secure. If a breach affects your personal data we will notify you and the relevant authority as required by law.

9. Children

Call Me If is not directed at children under 16 and we do not knowingly collect their data.

10. International transfers

We are based in Jordan and use providers that may process data outside your country, including in the EU and the United States. Where required we rely on Standard Contractual Clauses or an equivalent safeguard.

11. Changes

We will update this page and change the date above. For material changes affecting how we use your data, we will notify you by email or in the app before they take effect.

12. Contact

support@callmeif.app