Summary: Call Guardian runs entirely on your device.
There is no backend, no user account, no cloud sync, and no analytics or
crash reporting. Your call history, contacts, VIP list, blacklists,
per-contact rules, group memberships, schedules, and every other
preference stay on your phone unless you explicitly export them yourself.
We do not sell, share, monetise, or transmit any personal information —
because we never receive any.
This Privacy Policy explains how the Call Guardian Android application
("the App", "we", "us") handles information when you install and use it
on your device.
1. Information the App accesses
To perform its core function — screening incoming calls — Call Guardian
must access certain device data. Every optional feature that requires a
permission is clearly labelled at first launch (Permissions Onboarding
screen) and again when you toggle the specific feature on in Settings.
The following runtime and special permissions may be requested:
Call screening role. Required. Granted by you so
Android routes incoming-call decisions through the App.
Contacts (READ_CONTACTS). Used only to decide
whether an incoming caller is in your address book, and to let you
pick contacts for VIP, Bio-Lock, Groups, or Per-Contact Rules. We do
not read names, emails, photos or any other contact field beyond the
number match.
Phone state (READ_PHONE_STATE). Used by
Flip-to-Hush (to detect a ringing call so we can arm the
accelerometer) and by Bio-Lock (to dismiss the privacy overlay when
the call ends).
Notifications (POST_NOTIFICATIONS, Android 13+).
Used to show blocked-call alerts, Gatekeeper Allow/Block prompts,
Bio-Lock warnings, and Emergency-Password grant confirmations.
Receive SMS (RECEIVE_SMS). Used only by the
optional Emergency Password feature, which checks the body of
incoming SMS for a keyword you defined. Message content is never
uploaded and is not stored beyond the moment of comparison.
Send SMS (SEND_SMS). Used only by the optional
Auto-Reply feature to send your configured reply text to blocked
callers.
Microphone (RECORD_AUDIO). Used only by the Fake
Conversation feature during a Ghost Call, to detect when you pause
speaking so the fake voice reacts. Only rolling amplitude is read;
no audio is stored, no audio leaves the device.
Location (ACCESS_FINE_LOCATION, ACCESS_COARSE_LOCATION).
Used only by the optional Province Check feature to compare your
device location with the area code of an incoming call. Coordinates
are read on demand and are not stored.
Calendar (READ_CALENDAR). Used only by the
optional Meeting Shield feature. The App queries the CalendarContract
provider for events overlapping "now" that are marked busy and have a
title. Event bodies, attendees, and locations are never read.
Overlay / Display over other apps (SYSTEM_ALERT_WINDOW).
Used only by Bio-Lock to render the privacy overlay above the dialer
while a protected number rings.
Do Not Disturb access (ACCESS_NOTIFICATION_POLICY).
Used only by Flip-to-Hush to silence the ringer when the phone is
flipped face-down; the original ringer mode is restored when the
call ends.
Ignore battery restrictions
(REQUEST_IGNORE_BATTERY_OPTIMIZATIONS). Optional. Used to
keep the screening service responsive when the device is in Doze.
Exact alarms (SCHEDULE_EXACT_ALARM, USE_EXACT_ALARM).
Used by the Ghost Call scheduler to fire scheduled and recurring
fake calls at the exact time you asked for.
Boot completed (RECEIVE_BOOT_COMPLETED). Used to
re-arm any scheduled ghost calls after a reboot.
Accelerometer sensor. Used by Flip-to-Hush and by
the optional Panic Gesture (shake three times to trigger a ghost
call). No sensor data is stored.
Billing (com.android.vending.BILLING). Used only
by Google Play Billing to process the one-time purchase of Guardian
Premium. Google Play handles all payment data; the App never sees
your card, address, or Google account details.
The App does NOT request or use: the camera, network
access for any user data, advertising IDs, contact bodies (names / emails /
photos), call content or audio recording, background location, or any form
of tracking identifier.
2. Storage
The App stores the following on your device, inside app-private SQLite
databases and SharedPreferences:
A log of blocked calls (number, timestamp, reason, optional area).
Your VIP list, wildcard/prefix blacklist, Bio-Lock list, contact
groups.
Small per-sender counters (rate-limits for the Emergency Password
feature, gatekeeper de-duplication timestamps).
Premium entitlement flag (a boolean set to true only after a
successful Google Play purchase).
Nothing in this list is ever copied off your device. There is no
telemetry, no crash reporting, no analytics SDK.
3. Payments
Call Guardian offers a one-time in-app purchase called Guardian
Premium (product ID guardian_premium_lifetime, €5.99
or local equivalent). The purchase unlocks premium features permanently
on your Google account. The transaction is handled by Google Play
Billing. We never receive your card, address, email, or Google account
details — only a token confirming the purchase, which the App uses
locally to flip the entitlement flag.
4. Third parties
The App does not contain any third-party SDKs that report data,
serve ads, do analytics, or fingerprint the device. Google Play Services
Location may be used as a system component to obtain your device location
locally for the Province Check feature; that call stays on-device. Google
Play Billing is used for the Premium purchase.
External applications you may launch from the App (your dialer when
you tap "Call back", WhatsApp / Telegram via the Social Radar feature,
your email client when you submit feedback, the Play Store for "Rate")
are independent of Call Guardian and have their own privacy policies.
The App's marketing website
(https://callguardian.samcloud.online)
is a static informational site — it sets no cookies and collects no
personal data.
5. Data retention & deletion
Because no data leaves your device, deletion is entirely local:
Clear the blocked-call log from inside the App.
Remove individual list entries or entire lists in Settings.
Uninstall the App to wipe everything associated with it.
The Backup feature creates a JSON file at a location you pick; we
never see it. Restoring is a local operation that reads that file back
in.
6. Children's privacy
The App is not directed at children under 13 and does not knowingly
collect any information from anyone, regardless of age.
7. Security
Your data is protected by Android's app-sandboxing model. You may
further protect access to the App with a PIN and biometric unlock. We
cannot retrieve a forgotten PIN — by design, the PIN is stored only in
the app-private SharedPreferences and never leaves the device.
8. International data transfers
There are no data transfers because there is no data collection. The
App does not send any personal information across borders because it does
not send any personal information anywhere.
9. Your rights (GDPR / CCPA)
Since no personal data is collected, transmitted, or processed by
us, the classical rights to access, rectification, erasure, portability,
and objection have no external repository to be exercised against. You
retain full local control: view, edit, export, or delete every piece of
data the App holds by using the in-app controls.
10. Changes to this policy
If the App ever begins to transmit data off-device (for instance, if
optional cloud sync is added in a future version), this policy will be
updated and you will be shown a clear in-app notice before that feature
can be enabled. As of the "Last updated" date above, no such transmission
occurs.