Who Called

Privacy Policy

Last updated : July 23, 2026

This policy covers the who-called.com website and the Who Called mobile apps for Android (com.devfi.whocalled) and iOS (coming soon), published by DEVFI. We apply strict data minimization: we only collect what is strictly necessary to filter unwanted calls. No account, no name, no email, no ads, no third-party trackers. We never sell or share your data.

1. Data controller

DEVFI (SASU (société par actions simplifiée unipersonnelle)), 60 rue François Ier, 75008 Paris, France. Privacy contact: privacy@who-called.com.

2. What we never collect

No account is required and no identity data is collected: no name, address, email, personal phone number, contacts, location, or content of calls or messages. The apps contain no advertising SDK and no third-party analytics. The source code is public and auditable.

3. Data stored on your device (never sent)

Your personal rules (blocked/allowed numbers), your settings, the local copy of the blocklist, the local log of filtered calls and hidden SMS, your mini-game progress (streaks, local records) and an anonymous technical identifier (random UUID generated on the device). This data stays on the device and is removed when you uninstall.

4. Data sent to our servers

Reporting a number (voluntary action): the reported number in international format, your vote (spam/legitimate), an optional category, the device's anonymous identifier, the date and the language. Checking a number: the number you search is sent to query the database, without being linked to your identifier. List sync: the request only carries the selected country and the last-update date — no identifier. Mini-games: see section 7.

5. Android app — permissions

Call screening (system role “Call screening apps”): each incoming number is checked locally against the list stored on the device; it is never sent to our servers. Call log (READ_CALL_LOG, optional and revocable): lets you report a recent number in one tap; reading stays local. Notifications (POST_NOTIFICATIONS, optional): suspicious-call alerts, blocked call/SMS notices and the daily mini-game reminder. Notification access (SMS shield, opt-in): only reads notifications from your SMS app to hide those coming from unwanted numbers; content is neither stored nor transmitted. Internet: list sync and sending your reports.

6. iOS app — permissions and extensions

Call blocking extension (CallKit Call Directory): the blocklist is handed to the system and evaluated by iOS offline; the app cannot see your calls. SMS filter extension (Message Filter): classification happens entirely on-device, with no network request; iOS prevents the app from accessing your messages by design. Share extension: only processes the text you voluntarily share to report a number. Local notifications (optional): reminders generated on the device, with no server involved.

7. Mini-games and anonymous leaderboard

The apps include two mini-games (DEFENSE and TRACE) with an anonymous daily leaderboard. If you play, the following is sent: the score, the number of waves/grids, the challenge day and the device's anonymous identifier. No nickname and no personal data — the leaderboard shows positions, not identities. Daily puzzles are downloaded from our servers without transmitting personal data.

8. Notifications and reminders

All notifications are generated locally on the device (no push notifications through a third-party service). The daily mini-game reminder is capped at one per day, never fires if you already played, mutes itself automatically if you ignore it several days in a row, and can be turned off in one tap from the notification or in the settings.

9. No third-party services

No advertising SDK, no social network, no third-party analytics, no third-party push service. The apps only communicate with our API (api.who-called.com), hosted in the European Union. No data is transferred outside the EU.

10. Purposes and legal bases

Spam filtering and improving the community list: legitimate interest (Article 6(1)(f) GDPR). Optional features backed by a system permission (call log, notifications, SMS shield): consent, revocable at any time in the system settings. Game leaderboards: legitimate interest, pseudonymized data.

11. Retention

Reports are kept for at most 365 days, then automatically deleted. A number left with no reports is removed from the community database. Game scores are tied to the anonymous identifier only and deleted together with your data. Local data stays on your device until uninstallation.

12. Hosting and security

Data is hosted in the European Union at Hetzner Online GmbH, Allemagne (Union européenne). All traffic is encrypted (HTTPS/TLS). The device identifier is a random UUID that cannot identify you.

13. Your rights (GDPR) and data deletion

Immediate, no-questions-asked deletion from the app: Settings → "Delete my data" — this erases from our servers all your reports, your game scores and your device record. You can also request the removal of a number you own, or exercise your rights (access, rectification, erasure, objection) by email: privacy@who-called.com. See also the website's “Data deletion” page. You may lodge a complaint with your data protection authority (in France: CNIL, cnil.fr).

14. Children

The app is not intended for children under 15 and does not knowingly collect any data about them.

15. Changes

Any change to this policy will be published on this page with its update date. In case of a substantial change, the app will say so.