Privacy Policy — Pyfone for Android
Draft for legal review. Every factual statement below was checked against the app’s source and is accurate as of 2026-07-20. What it is not is a lawyer’s work: the wording, the legal bases, the retention periods and the governing law still have to be set by counsel. Placeholders are marked
[LIKE THIS].Publish at https://pyfone.com/legal/privacy-policy/ and enter the same URL in the Play Console listing — Google compares the two, and the Data Safety form must not contradict this page.
Last updated: [DATE]
1. Who we are
Pyfone (“we”) provides the Pyfone VoIP application. The data controller is ROVEX TELECOM LTD, registered in England and Wales under company number 15946534, registered office 347 Barking Road, London, E13 8EE, United Kingdom. For any privacy question, contact [PRIVACY CONTACT EMAIL].
As a UK controller, processing is subject to the UK GDPR and the Data Protection Act 2018 — counsel should confirm the legal bases and the wording of section 9 before this is published.
2. What the app does
Pyfone is a business telephony client. It connects to your organisation’s PBX to place and receive voice and video calls, show your colleague directory, and send chat messages. It is provisioned by your organisation, not sold to consumers.
3. What we collect, and why
| Data | Why | When |
|---|---|---|
| Email address | To sign you in — we email a one-time code | At sign-in |
| Device name and a generated device identifier | To show which devices are signed in, and for the security audit log | At sign-in |
| SIP account name and domain | To route calls to your extension | While signed in |
| Push notification token (Google FCM) | So the phone can be woken for an incoming call | While signed in |
| Call audio and video | To connect the call — media passes through our servers | During a call only |
| Chat messages | To deliver them to the recipient | When you send one |
We do not use analytics, advertising, crash-reporting or any third-party tracking SDK. The app contains no advertising identifiers.
4. What stays on your phone and is never sent to us
- Your phone’s contacts. The app reads them only to search names while you dial. They are never uploaded, stored on our servers, or shared.
- Your call history. Kept in the app’s private storage on the device only.
- Your credentials. Your session and SIP password are held in Android’s encrypted storage on the device.
5. Permissions the app asks for
| Permission | Used for |
|---|---|
| Microphone | Your voice during a call |
| Camera | Video calls, and scanning the sign-in QR code |
| Contacts | Searching your address book while dialling — read on the device only |
| Notifications / full-screen notifications | Showing an incoming call, including on the lock screen |
| Manage own calls | Integrating calls with the Android phone UI |
| Network state, wake lock | Keeping the connection alive and waking the screen for a call |
Every permission is requested for a feature you use; declining one disables that feature rather than the app.
6. Who else processes your data
- Google (Firebase Cloud Messaging) — delivers the wake-up notification for an incoming call. It receives the notification token and the fact that a call is arriving; it does not receive call content.
- Your organisation. Pyfone accounts are provisioned by your employer or service provider, who administers your extension and may see call records held by the PBX.
We do not sell personal data and do not share it for advertising.
7. Security
All traffic between the app and our servers uses TLS (HTTPS/WSS). Session tokens and SIP credentials are stored using Android’s encrypted preferences. Call media is carried over our media servers; the media leg between the app and the server is encrypted when the account uses WebRTC.
8. Retention
[RETENTION PERIODS — how long sign-in records, audit logs, push tokens and PBX call records are kept. Must be filled in by the operator of the backend.]
9. Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, and to object to processing. To exercise any of these, contact [PRIVACY CONTACT EMAIL]. [ADD GDPR LEGAL BASES AND SUPERVISORY-AUTHORITY WORDING IF OFFERING THE APP IN THE EU.]
Deleting the app removes the locally stored data. To have your account and server-side records removed, contact us or your organisation’s administrator.
10. Children
Pyfone is a workplace tool and is not directed at children under [AGE].
11. Changes
We will update this page when the app’s data handling changes, and revise the “last updated” date above.
Appendix — filling in the Play Data Safety form
Answer consistently with the sections above:
- Data collected: email address; device or other IDs (device id, push token); app activity limited to call setup. Audio/video is transmitted for the call but not stored by us — declare it as collected-in-transit only if the Console wording requires it, and never as “stored”.
- Contacts: answer not collected — they never leave the device. Note in the form that the permission is used on-device only.
- Data shared with third parties: Google, for push delivery.
- Encryption in transit: yes.
- Users can request deletion: yes — via [PRIVACY CONTACT EMAIL].
- Analytics / advertising: none.