Privacy policy
Who we are
The Callogue application is provided by PWH Piotr Mikołajewicz, ul. Czarnoleska 25/19, 26-600 Radom, Poland, VAT ID PL9661848720, contact: support@callogue.com, phone +48 455 577 181.
In short
Callogue does not record calls. It reads recordings your phone has already saved in a folder you point to yourself, turns them into a summary and creates an entry in your calendar.
The App sends data through our own server (Google Cloud Run,
europe-central2 – Warsaw), and from there to two independent providers:
- the recording file goes to Cloudflare, Inc. (United States), where it is turned into text;
- the text of the transcript goes to a provider chosen by the language of the call – for Polish that is CloudFerro S.A. (Poland).
These providers do not talk to each other. Your phone is the only place where the whole call exists in one piece.
The result comes back to your phone and goes into your calendar. Our server passes the data on and stores none of it – no recordings, no transcripts, no summaries. Only a counter of processed calls remains.
The App does this only after your explicit consent and only for recordings you point to yourself. Without consent, the cloud features stay switched off.
What data we process
| Data | Where from | What for | Where it goes |
|---|---|---|---|
| Call recording file | folder you point to | transcription | our server → Cloudflare, Inc. (US) |
| Transcript of the call | result of transcription | summary | our server → provider by language, then your calendar |
| Caller label | from the recording's filename | event title | your calendar; as context in the request to the summary provider |
| A name from your address book | your address book, only with your consent and only where the recording carries no name | putting a name in the event title instead of a bare number | your calendar only – the summary provider receives the phone number in its place |
| Date and time of the call | from the recording's filename | event time | your calendar |
| Anonymous account identifier | created by the App | counting free calls | our server (Firestore, EU region) |
| Hashed device identifier | derived by the App from an identifier assigned by Android | recognising that the free allowance has already been used on this device | our server (Firestore, EU region) |
| Usage statistics and crash reports | generated automatically by the App | stability and development | Google (Firebase, USA – DPF) |
| App settings | you | running the app | phone storage only |
A call may contain information you raise yourself, including sensitive information (for example about health). The App does not single it out or analyse it; it processes the whole call as one piece of text, solely for the purpose described above.
The App does not collect: location, health data, financial data or your call history. It does collect usage statistics and crash reports, and the free version may show ads – all described below, because we would rather say it plainly than hide it in a footnote.
Who you are to us
The App creates an anonymous account – with no email address, phone number or name. You receive an identifier used solely to count the calls you have processed. That identifier is personal data under the GDPR, even though on its own it says nothing about you.
What deliberately never leaves your phone
- The filename. It carries the caller's name and phone number. Our server receives only a cryptographic digest of it, computed with a random value generated once per installation that never leaves your device.
- The full contact. Where the caller's name is in the recording's filename, only the display name is sent – the phone number does not leave the device at all. Where the caller is unknown, the number is the label and is sent, because nothing else identifies them.
- A name taken from your address book. Here it is the other way round: the name stays on the phone and the number is sent to the summary provider in its place – the same number that was sent before this feature existed. Described below.
- The content of the call – out of our logs. We log identifiers, lengths and status codes. Call metadata is never put in web addresses, because address parameters end up in access logs.
Access to your address book
Some call recorders write only the phone number into the filename, with no name. For their users the calendar would show a number instead of a person. The App can therefore read a name from your address book – but only on the terms below, and each of them is enforced in code, not merely promised:
- We ask conditionally. The request appears only once the App detects that your recorder does not save names. If it does save them, you will never see the request and we will not put a single question to your address book.
- We look up only what is missing. A recording whose name could be read is never checked against the address book at all.
- The name does not leave your phone. Matching a number to a name happens on the device. The summary provider receives the phone number in its place – the same number we sent before this feature existed.
- We do not copy your address book. We do not load it, transmit it or store it – we read a single match for a number that appeared in your recording.
- You can turn it off in Settings at any time, independently of the system permission. Once off, the App does not reach into the address book at all.
The legal basis is your consent (Art. 6(1)(a) GDPR), which you may withdraw in Settings.
Excluding a caller
You can mark a caller whose calls must never be processed. Their recordings are then sent neither for transcription nor for summarisation – they stay on your phone only. The list of excluded callers is kept in phone storage; we do not send it anywhere.
Device identifier
The free call allowance is tied to an anonymous account, and such an account disappears together with the App's data – clearing it would simply reset the allowance. To prevent this, the App sends us an irreversible hash of the identifier that Android assigns to it on your device.
Three things are worth stressing. First, the raw identifier never leaves your phone – we only ever receive a hash it cannot be reconstructed from. Second, Android derives this identifier separately for every app, so it cannot be used to track you across apps or linked to any other service. Third, it is not an IMEI or a serial number, and reading it requires no permission.
We use it solely to enforce the free allowance, that is to prevent abuse. The legal basis is our legitimate interest (Article 6(1)(f) GDPR).
Usage statistics, crash reports and ads
The App uses Google Firebase services:
- Firebase Analytics – automatically collected usage statistics (app opened, screen shown) together with an app-instance identifier. We define no custom events, and the statistics never contain the content of your calls.
- Firebase Crashlytics – crash reports: the stack trace, device model and system version. No call content.
- Firebase Remote Config – the App downloads configuration flags (for example whether ads are enabled on a given market).
The legal basis is our legitimate interest (art. 6(1)(f) GDPR) in keeping the App stable and understanding how it is used. Google processes this data for us, also in the United States, under its certification in the EU-US Data Privacy Framework. Google retains usage statistics for up to 14 months and crash reports for 90 days.
Ads. The free version of the App may show ads served by Google AdMob. In the free version ads are part of the service – together with the subscription they pay for processing your calls. AdMob processes your device's advertising identifier to serve and measure ads; in the European Economic Area ads will only be shown after the consent required by law has been collected. How Google uses this data is described in Google's policies.
Statistics for this website
This website counts page views using GoatCounter. The counter sets no cookies, creates no visitor identifier and does not track you across sites – you will see no consent dialogue here, because there is nothing to consent to.
GoatCounter stores already processed data rather than what it was derived from: your IP address and browser header are not kept. The dashboard shows how many times each page was opened, the country, the browser and system type, and the address you arrived from. None of it can be assembled into a profile or traced to a person.
The basis is our legitimate interest (Art. 6(1)(f) GDPR): finding out whether anyone reaches this site at all, and from where. Website statistics are never combined with any data from the app.
Who receives the data
Google (European Union / United States)
Google Cloud hosts our server (europe-central2 – Warsaw) and the counter
database (eur3 – Belgium and the Netherlands); access logs contain users' IP
addresses. Google also provides the anonymous sign-in and App Check (Play Integrity) used
for the anonymous account, and the statistics, crash-reporting and advertising services
described above. For transfers to the United States, Google
relies on its EU-US Data Privacy Framework certification.
Cloudflare, Inc. (United States)
Performs transcription of the recording. The basis for the transfer outside the European Economic Area is Cloudflare's certification under the EU-US Data Privacy Framework – an arrangement in which the European Commission recognised that certified US companies protect data to the standard required in the Union. In addition, a data processing agreement applies containing standard contractual clauses: a template contract prepared by the European Commission in which a company outside the Union undertakes to protect data to EU standards and submits to supervision by European authorities. Cloudflare declares that it does not train models on customer content and does not store inputs or outputs.
CloudFerro S.A. (Warsaw, Poland)
Produces the summary from the text of the transcript for Polish-language calls. Processing takes place entirely in Poland (WAW3-2 region), so this data does not leave the European Economic Area. CloudFerro applies a zero-retention policy – it stores neither the requests nor the results – and does not train models on them.
Other language providers
For other EEA languages the summary is produced by Mistral AI (France, data in the EU). For remaining languages it is produced by Groq, Inc. (United States, on the basis of the standard contractual clauses described above; by default it does not retain data from processing, and diagnostic logs may be kept for up to 30 days). The consent screen in the App tells you where your data actually goes.
We do not sell data and do not pass it to anyone else.
How long we keep the data
We do not keep it at all. The recording is sent, processed and returned as a single operation. The result is saved only in your calendar, which you control. What remains on our side is the counter of processed calls; markers of individual calls expire after 62 days. On your phone, only the app settings and the record of which recordings have already been processed remain.
Your rights
You have the right of access, rectification, erasure, restriction of processing, portability and objection, as well as the right to lodge a complaint with a supervisory authority – in Poland, the President of the Personal Data Protection Office (UODO).
In practice you exercise most of them yourself and immediately: deleting the calendar event deletes the summary and the transcript, and uninstalling the App clears the settings. The recordings in the folder are managed by your phone, not by us.
Deleting the data we hold
Open Settings → Your data in the App. That screen shows exactly what our server holds about your device, and Delete my data erases the counter of calls used and the record of processed calls. It takes effect immediately.
One thing does not disappear: the hash of the device identifier. It is the only thing preventing the free allowance from being reset over and over by clearing app data, so we keep it to prevent abuse, on the basis of our legitimate interest (art. 6(1)(f) GDPR). It is irreversible and it does not identify you outside this App.
You can also write to support@callogue.com. In that case include the two
identifiers from Settings → Your data – without them we cannot find your records,
because we hold no name, e-mail address or phone number that would let us recognise you.
The same address handles matters concerning our providers; we pass such requests on.
The person on the other side of the call
A call recording contains the voice and words of another person, who is not a user of the App. Recording that call is your decision and your responsibility. By using Callogue you declare that you have the right to process the recordings you point it to. The rules on recording calls differ between countries – in some, the consent of both parties is required. Check what applies where you are (there is a summary in the terms, section 4.1).
We have no way of contacting you directly – we do not know your identity or your contact
details, and the recording was made by a user of the App, not by us. Your data (your voice
and the words you spoke) is processed solely as described in this policy: a one-off
transcription and summary, with no storage by us and no use for any other purpose. You have
the rights described under „Your rights" – you can contact us at support@callogue.com.
Children
The App is intended for adults only and is not directed at children or teenagers.
Changes
We will give notice of material changes in the App before they take effect. The date of the last update is at the top of this document.
Contact
support@callogue.com