Legal

Privacy Policy

Last updated: May 2026 · UK GDPR compliant

1. Who We Are (Data Controller)

CalmCalls is an assistive voice calling tool operated by an individual data controller based in the United Kingdom. We are the data controller for all personal data collected and processed through this application.

For all data protection enquiries, subject access requests, or complaints, contact us at: support@calmcalls.com. We will respond within 72 hours.

If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.

2. What Personal Data We Collect

We collect only the minimum personal data necessary to provide the Service ("data minimisation" principle under UK GDPR Article 5(1)(c)):

Account data: Your full name and email address, provided at registration via the Base44 authentication system.

Verified phone number: The UK telephone number you add and verify in Settings. This is stored on your account record and used as your caller ID when placing calls.

Recipient phone numbers: Numbers you dial or save as named contacts within the app.

Voice recordings (biometric-adjacent data): Audio files you personally record and store as voice notes. These are stored encrypted in private file storage and only played to a call recipient when you manually trigger playback during a live call. Recording is gated behind explicit consent.

Call metadata: Call start time, end time, duration (seconds), call status (initiated / active / completed / failed), recipient number, and internal Twilio identifiers (call SIDs, conference SIDs). No call audio is ever recorded or stored by us.

Identity verification status: A boolean flag indicating whether you have passed Stripe Identity verification. We do not store your identity documents — these are processed exclusively by Stripe.

Usage data: Your remaining call count and total calls used, tracked solely to enforce the pilot allocation limits.

Call feedback: Optional post-call ratings (a thumbs up or thumbs down) submitted after a call, linked to your account and the relevant call log. Used only to improve service quality.

Consent records: Timestamps recording when you provided or revoked consent for voice note storage (biohealth consent).

Error logs: When a backend operation fails, we log a short error record containing your user ID (if authenticated), the HTTP status code, a brief error message, the function name, and a timestamp. These are used solely to diagnose and fix service faults and are accessible only to administrators.

What we do NOT collect: We do not collect payment card details, location data, device identifiers, cookies for tracking, or any advertising or analytics data.

3. Lawful Basis for Processing

We process your personal data only where we have a clear lawful basis under UK GDPR Article 6 (and Article 9 for special category data):

Contractual necessity — Art. 6(1)(b): Your account data, verified phone number, contacts, and call metadata are processed because they are strictly necessary to perform the calling service you have requested. Without this data, calls cannot be placed.

Explicit consent — Art. 6(1)(a) and Art. 9(2)(a): Voice note audio recordings are only stored after you provide explicit, informed consent via the in-app consent gate. This consent can be withdrawn at any time, causing all voice notes to be permanently deleted. A timestamp of your consent grant or revocation is retained for compliance purposes.

Explicit consent — Stripe Identity: Biometric identity verification data (ID documents and selfie) is processed by Stripe Inc. only upon your explicit consent at the point of initiating verification. We ourselves never receive or store this data.

Legitimate interests — Art. 6(1)(f): Call metadata is retained for a short period (up to 14 days) to detect abuse patterns, enforce rate limits, and maintain service quality. We have assessed that these interests do not override your rights, as the data is minimal, access-controlled, and automatically deleted.

Legal obligation — Art. 6(1)(c): We require identity verification to comply with our obligations under UK telecommunications regulations and to prevent fraudulent or harmful use of telephony services.

4. How We Use Your Data

Your personal data is used exclusively for the following purposes:

To authenticate your identity and provide secure access to the Service.

To place and route outbound telephone calls to your chosen recipient on your behalf.

To present your verified phone number as the caller ID to the recipient.

To play voice note audio to the call recipient when you manually trigger playback.

To display your call history, contacts, and usage statistics within the app.

To enforce monthly call minute allocations and per-minute rate limits.

To detect and prevent fraudulent or abusive use of the telephony service.

To analyse optional call feedback ratings to improve service quality.

To process your account deletion request, including automated redaction with Stripe.

We do not sell your data. We do not share your data with any third party for marketing, advertising, or profiling purposes. We have no data broker relationships.

5. Third-Party Data Processors

The following companies process your personal data on our behalf as data processors. We have no other third-party data sharing relationships. All processors are bound by data processing agreements.

Twilio Inc. — Telephony Provider. Registered: USA (San Francisco, CA). Subject to UK adequacy decision via SCCs. Data processed: Your verified phone number (as caller ID), recipient phone numbers you dial, call audio routing (not recorded), call metadata (duration, status, SIDs). Each user's telephony activity is isolated within a dedicated Twilio subaccount. Why necessary: Twilio is our telephony infrastructure provider. Without Twilio, outbound calls cannot be placed or routed. UK GDPR transfer safeguard: Standard Contractual Clauses (SCCs) pursuant to UK GDPR Chapter V / UK IDTA. Retention: Twilio retains call records per their own data retention schedule. Your dedicated Twilio subaccount is permanently closed and deleted when you delete your CalmCalls account.

Stripe Inc. — Identity Verification. Registered: USA (San Francisco, CA). Subject to UK adequacy decision via SCCs. Data processed: Government-issued photo ID document and a real-time selfie photograph, submitted during identity verification via Stripe Identity. This constitutes special category biometric data under UK GDPR Article 9. Why necessary: UK telecommunications regulations and our duty to prevent fraudulent and harmful use require us to verify that all users are real, identifiable individuals before granting access to outbound calling. Critical: CalmCalls never receives, transmits, or stores your ID documents or selfie. These are submitted directly from your device to Stripe's secure systems. We only receive a boolean verification result. UK GDPR transfer safeguard: Standard Contractual Clauses (SCCs) / UK IDTA. Stripe is also certified under the UK Extension to the EU-US Data Privacy Framework. Retention: Stripe retains identity documents only as required by their compliance obligations. Upon account deletion, an automated API call triggers a Stripe Identity redaction request for your verification session.

Base44 — Application Infrastructure. Registered: USA. Base44, Inc. is our cloud application platform provider. By default, Base44 stores application databases and uploaded files on United States-based servers. Role: Base44 acts as our Data Processor. We (CalmCalls) are the Data Controller responsible for deciding how and why your personal data is used. Data processed: Application database (account details, contacts, call log metadata, voice note metadata, consent timestamps); private encrypted file storage (voice note audio files); authentication session management and login credentials. Why necessary: Base44 provides the cloud application platform, database, and secure private file storage that powers the entire Service. Security: Base44 is SOC 2 Type II certified (confirmed by independent audit) and ISO 27001 certified. Voice note audio files are stored in private, access-controlled storage. Files are never publicly accessible. Temporary signed URLs (valid for a limited time only) are generated for playback during active call sessions. Row-Level Security (RLS) is configured so that no user can access another user's records. UK GDPR transfer safeguard: Transfers are protected under the UK Extension to the EU-US Data Privacy Framework (DPF) and Standard Contractual Clauses (SCCs) integrated into our Data Processing Agreement (DPA) with Base44, alongside the UK International Data Transfer Addendum (UK IDTA). Retention: All data is held for the duration of your account. Account deletion causes immediate and permanent removal of all associated data from Base44's infrastructure.

6. International Data Transfers & Data Residency

Because our infrastructure provider, Base44, Inc., hosts data on servers located in the United States, your personal data is transferred to and stored in the US. This constitutes an international data transfer under UK GDPR Chapter V, and the following safeguards apply.

Lawful transfer mechanisms: Transfers from the UK to the US are protected by a combination of the UK Extension to the EU-US Data Privacy Framework (DPF) — Base44 and its DPF-certified US sub-processors rely on the UK-US Data Bridge to transfer personal data from the UK to the US without additional safeguards — and Standard Contractual Clauses (SCCs): for any sub-processor not self-certified under the DPF, the EU Standard Contractual Clauses (Module 2 or 3) apply, alongside the mandatory UK International Data Transfer Addendum (UK IDTA).

Data Processing Agreement (DPA): We have executed Base44's Data Processing Addendum, which is incorporated into our Terms of Service and legally binds our workspace to the transfer safeguards described above. This DPA, combined with the mechanisms above, ensures our backend infrastructure meets UK GDPR requirements for transatlantic data flows.

What is stored where: Stored in the US — your database records (account details, contacts, call metadata, voice note metadata, consent records) and user login credentials, as well as any uploaded files (including voice note audio recordings), are held on US-based servers. Backend processing: certain automated triggers, backend functions, and external service APIs may route data through US endpoints depending on the integration. We minimise this to what is strictly necessary to provide the Service.

Please be aware that selecting an EU or UK data residency region on Base44 does not move 100% of data out of the US — uploaded files and some processing layers may still be handled by US-based servers.

App-level security (our responsibility): Under UK GDPR we remain responsible for the security of your data on our platform. To meet this obligation we have implemented Row-Level Security (RLS) so that User A cannot view User B's records, strict role-based permissions limiting who can read, write, or delete data, and private access-controlled file storage for voice notes.

Your transparency rights: In line with ICO guidance, this Privacy Policy explicitly informs you that your personal data is transferred to and stored in the United States, that Base44, Inc. is our infrastructure provider, and of the specific legal mechanisms used to protect those transfers. A Data Protection Impact Assessment (DPIA) has been carried out to document the risks of international transfers and the safeguards in place.

Base44 platform certifications: Base44 is SOC 2 Type II certified (confirmed by independent audit) and ISO 27001 certified, providing independent assurance of its information security management controls.

7. Data Retention Schedule

We retain your personal data only for as long as necessary for the purpose it was collected:

Account data (name, email): Retained for the lifetime of your account. Deleted immediately upon account deletion.

Verified phone number: Retained for the lifetime of your account, or until you remove it via Settings. Deleted upon account deletion.

Contacts: Retained until you delete them individually, or upon account deletion.

Voice notes (audio files): Retained until you delete them individually via the Voice Notes page, until you use "Wipe Voice Notes & Revoke Consent" in Settings, or upon account deletion.

Call logs (metadata only — no audio): Automatically and permanently deleted 14 days after the call date. Also deleted upon account deletion.

Call feedback ratings: Retained for the lifetime of your account. Deleted upon account deletion.

Consent records: Timestamps of voice note consent grant/revocation are retained for compliance purposes for the lifetime of your account. Deleted upon account deletion.

Error logs: Retained for up to 30 days after the logged event, then automatically deleted. Also deleted upon account deletion.

Identity verification status: The boolean verified/not-verified flag is retained on your account record. Deleted upon account deletion. The underlying documents are held by Stripe and redacted upon account deletion.

Upon account deletion: All data held by us is permanently and irreversibly erased immediately. This action cannot be undone.

8. Your Rights Under UK GDPR

Under the UK GDPR and the Data Protection Act 2018, you have the following rights. Most can be exercised directly within the app:

Right of access (Art. 15): Obtain a copy of all personal data we hold about you — Settings → Export my data (machine-readable JSON format, immediate download).

Right to rectification (Art. 16): Correct your name — Settings → Edit name.

Right to erasure / "right to be forgotten" (Art. 17): Permanently delete all your data and close your account — Settings → Delete account data. This is irreversible and includes triggering Stripe Identity redaction.

Right to withdraw consent (Art. 7(3)): Revoke your voice note storage consent and permanently delete all recordings — Settings → Wipe voice notes & revoke consent.

Right to restrict processing (Art. 18): Contact us to limit how we process your data while a dispute is being resolved.

Right to data portability (Art. 20): Download your data in structured, machine-readable JSON format — Settings → Export my data.

Right to object (Art. 21): Object to processing based on legitimate interests — contact us at support@calmcalls.com. We will cease processing unless we can demonstrate compelling legitimate grounds.

Rights related to automated decision-making (Art. 22): We do not use automated decision-making or profiling that produces legal or similarly significant effects.

To exercise any right not available in-app, contact us at support@calmcalls.com. We will respond within one calendar month as required by UK GDPR Article 12(3).

9. Security Measures

We implement the following technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure:

Encryption in transit: All data between your device and our servers is encrypted using TLS 1.2 or higher.

Private file storage: Voice note audio files are stored in private, access-controlled cloud storage. Files have no public URL — access requires a short-lived, cryptographically signed URL generated at the time of use.

Telephony isolation: Each user account operates its own dedicated Twilio subaccount, preventing any cross-account access to call records or calling capabilities.

Secrets management: All API credentials, authentication tokens, and environment secrets are stored server-side only. They are never embedded in or exposed to client-side code.

Authentication: Access to your personal data is restricted to your authenticated session. We do not have shared admin interfaces that can access user call content.

Identity verification: Your identity documents never pass through our servers — they are submitted directly from your device to Stripe's PCI-DSS and SOC 2 certified infrastructure.

Despite these measures, no system is entirely without risk. In the unlikely event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and you without undue delay as required by UK GDPR Article 33–34.

10. Identity Verification — Why We Require It

Identity verification is a legal and safeguarding requirement before you can place calls. The three key reasons are: (1) compliance with UK KYC (Know Your Customer) obligations, (2) preventing misuse and protecting call recipients from anonymous abuse, and (3) confirming that you own and control the phone number that will receive calls on your behalf.

11. Cookies & Tracking

CalmCalls does not use tracking cookies, advertising cookies, or third-party analytics. We do not use Google Analytics, Meta Pixel, or any equivalent tracking technology. Session authentication is managed by Base44's infrastructure using secure, httpOnly session tokens.

12. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you via an in-app notice at least 14 days before changes take effect (except where changes are required urgently for security or legal reasons). The "Last updated" date at the top of this policy will always reflect the most recent revision.

Continued use of the Service following notification of changes constitutes your acceptance of the updated Privacy Policy.