Privacy Policy
Last updated: 29 September 2026
Who is responsible for your data
ComputerCaller is the "controller" of your personal data under the EU General Data Protection Regulation (GDPR). You can reach us at [email protected].
We have not appointed a data protection officer, because our activities do not require one under the GDPR. Every privacy question goes to [email protected] and is answered by the people who run the service.
The short version
ComputerCaller lets you use your Android phone's calls and messages from a browser. Your phone data flows from your phone to your browser through our relay server. We don't read it, store it long-term, sell it, share it, or train AI on it.
What we collect
- Your account. Email address and a hashed password. Used to log you in and send service emails (account verification, password resets, subscription receipts).
- Your subscription status.Whether you're in a free trial or have a paid subscription, and when it renews or ends. Set by our payment provider (Whop). From Whop we keep your membership ID, plan, subscription status and billing dates. We never receive your card details.
- Pairing token. A random ID that lets your Android app connect to your browser session. Per account.
- Operational logs. Connection timestamps and error logs for keeping the service running. They can include your IP address, and your email address for sign-up and sign-in events. No message bodies, no contacts from your phone, no call recordings.
- IP addresses.We store the IP address you signed up from and the one you last signed in from, to detect and prevent fraud and abuse, such as multiple accounts created to get more than one free trial. We don't use them to ban anyone automatically, and we don't sell or share them.
- Your saved texts. Message templates and quick replies you create are saved in your account so you can use them on any device. We store only what you type into them.
- Encryption keys.If you turn on Encrypted mode, we keep the public key of each paired device and when it was replaced, so a removed device can't be used again. Private keys never leave your devices.
- File-transfer usage. How many bytes your account sent through file transfer each day, so we can apply the daily limit. No file names or contents.
- Website analytics.See "Cookies and analytics" below.
What flows through us but we don't store
- Calls.Dial commands go from your browser to your phone. Audio stays on the phone's cellular network — we don't handle voice.
- Messages. SMS and MMS bodies flow between your phone and your browser through our relay. They are not written to our database or to disk. The relay holds them in memory only long enough to forward them. If your phone or browser briefly loses connection, the relay keeps up to 200 recent items in memory — normally for up to 3 minutes, and at most 10 minutes after the extension stops being reachable — so they arrive when you reconnect. They are deleted on delivery or when that hold ends. Nothing is kept after delivery.
- Contacts and call history.While your phone is connected, the content of your messages, calls, contacts and alerts is held only in your browser's memory for the open tab. It is cleared when the connection ends, when you sign out, or when you close the tab. Message and call content is never written to disk and never stored on our servers. Your browser keeps small bookkeeping entries (which conversations you opened or marked as read) as identifiers; we are moving these to hashed form.
- Notifications.Notifications from the apps on your phone are shown in your browser in real time. This can include messages, sign-in codes, and alerts from any app. They pass through our relay to reach your browser, in the same way as messages above. We don't read, keep, or analyze their contents.
- Files.Files you send between your phone and your computer pass through our relay in small pieces. Each piece is forwarded and then discarded. Files are never saved on our servers, and nothing is sent until the other device accepts the file. While a transfer is running, the relay keeps a small record of it in memory (a random transfer ID, the file size, timings and how much has been sent), and deletes that record when the transfer finishes or fails. If the connection drops, the receiving device keeps the part it already received for up to 10 minutes so the transfer can continue, then deletes it. All transfers are encrypted in transit. They are end-to-end encrypted only when Encrypted mode is turned on: then only your own devices can read the file's name, type and contents, and our relay sees only its size and timing. With Encrypted mode off, the file passes through our relay unencrypted between your devices and our server, and we don't look at it. Files are not scanned for viruses, so only accept files you expect.
Why we use your data (legal basis)
Under the GDPR we need a legal reason for each use of your data. Here is ours:
- To provide the service you signed up for (performance of our contract with you, GDPR Art. 6(1)(b)): your account, sign-in, pairing, relaying your calls, messages, notifications and files, your saved texts, encryption keys, subscription status, file-transfer limits and service emails.
- To keep the service safe and working (our legitimate interest, Art. 6(1)(f)): IP addresses for fraud and abuse prevention, and operational logs for security and fixing errors. You can object to this at any time (see "Your rights").
- To keep legal and tax records (legal obligation, Art. 6(1)(c)): records of your purchases, which we and our payment providers must keep under tax and accounting law.
You need to give us an email address to create an account. Without it we can't provide the service. We don't make decisions about you by automated means that have legal or similarly significant effects.
Who we share with, and where your data goes
We use a small number of service providers. Some are in the United States. When your data leaves the EU/EEA, it is protected either by an EU adequacy decision (GDPR Art. 45 — for companies certified under the EU-U.S. Data Privacy Framework) or by the EU Standard Contractual Clauses (GDPR Art. 46). The safeguard is named next to each provider below. You can ask us for a copy of the safeguards at [email protected].
- Hetzner Online GmbH (Germany) — hosts our servers and database in Nuremberg, Germany (EU). Your data stays in the EU, so no transfer safeguard is needed. We have a data processing agreement (DPA) with Hetzner in place.
- Resend (Plus Five Five, Inc., USA) — sends account emails (verification, password reset). Sees your email address and the email contents. Safeguard: EU-U.S. Data Privacy Framework (EU adequacy decision) and the EU Standard Contractual Clauses.
- Whop (Whop, Inc., USA) — payment processing and subscription billing. Whop collects your payment details directly from you at its checkout and acts as a separate controller under its own privacy policy (whop.com/privacy), which states that it protects transfers from the EU with the EU Standard Contractual Clauses. We share with Whop only your email address and account ID, so we can link your subscription to your account.
- Microsoft (Clarity) — website analytics on our public pages only (home, guides, terms, privacy), never inside the app. Safeguard: EU-U.S. Data Privacy Framework (EU adequacy decision) and the EU Standard Contractual Clauses.
- Google— only if you choose "Sign in with Google". Google acts as a separate controller under its own privacy policy. We receive only what is described under "Signing in with Google".
We don't sell your data. We don't share it with advertisers. We don't use it to train AI.
How long we keep it
- Account (email, password hash, Google account ID, settings, saved texts, encryption public keys): as long as your account exists. Deleted on request, by email.
- Messages, calls, notifications and files passing through the relay: not stored. Held in memory only while being forwarded, or for a few minutes during a reconnection (see above).
- File-transfer usage counter: 7 days.
- Subscription status: as long as your account exists. Payment and invoice records are kept by Whop for as long as tax and accounting law requires.
- Records of your purchases that we hold: as long as Bulgarian tax and accounting law requires, then deleted.
- Admin and billing-event records (records of changes to your account or access, and payment events, that contain your email address): kept after your account is deleted, as a record of those actions. Deleted on request, by email, unless the law requires us to keep them.
- IP addresses (sign-up, last sign-in): as long as your account exists.
- Server logs: application logs about 11 days on a rolling basis, and cleared whenever we update the service. Web server access logs, which include your IP address and the page requested, 15 days.
- Database backups: only the newest 3 are kept; older ones are securely deleted.
Android permissions
The ComputerCaller Android app asks for permissions only for the features that need them:
- Phone (calls). To place, answer, and end calls that you trigger from your browser.
- SMS. To send and receive text messages on your behalf and forward them to your browser tab.
- Contacts. To sync contact names so your call log and messages show readable names, not raw numbers.
- Call log. To show recent calls in your browser dashboard.
- Notification access. Optional. Lets you see notifications from the apps on your phone in your browser, and reply to or dismiss them.
All permission data stays on your phone or passes through our relay to your own browser tab. We don't keep that content on our servers.
Chrome extension
The ComputerCaller extension is a window onto your own ComputerCaller account. It stores a sign-in token and your settings in Chrome's extension storage on your computer, along with an encryption key for your paired phone whose private part never leaves your computer. It remembers which alerts you have already seen or read, as identifiers (we are moving these to hashed form, never the message text), on this computer until you sign out. It connects only to computercaller.com. It does not read the websites you visit, your browsing history, or anything outside ComputerCaller. Calls, messages and phone notifications shown in the extension pass through our relay exactly as described above and are not stored on our servers.
The use of information received by the extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Signing in with Google
If you choose Google sign-in, Google sends us your Google account email address, name and account ID. We keep the email address and the account ID to create and log in to your account; we don't keep your name. We don't get access to your Gmail, contacts or other Google data.
Cookies and analytics
We use cookies to keep you signed in and to count votes on feature ideas once per visitor. On our public pages (home, guides, terms, privacy) we also use Microsoft Clarity to see how visitors use those pages. Clarity is set to strict masking, and session recordings are turned off. Clarity never runs inside the app, where your calls, messages and contacts are shown.
Your choices
- Delete your account. Email [email protected] from the address on your account and we'll delete your account, your saved texts, device keys and settings. Cancel your Whop subscription separately.
- Revoke phone access. Uninstall the Android app or sign out of the browser. Either kills the pairing.
- Cancel your subscription. In your Whop account at any time. You keep access until the end of the period you paid for.
Your rights
You have the right to:
- see the personal data we hold about you and get a copy (access);
- have wrong data corrected (rectification);
- have your data deleted (erasure);
- ask us to limit how we use it (restriction);
- get the data you gave us in a common, machine-readable format, or have it sent to another service (portability);
- object to uses based on our legitimate interest, such as fraud-prevention logs (objection);
- withdraw any consent you gave, at any time, without affecting what we did before.
To use any of these rights, email [email protected] from the address on your account. We reply within one month. We may ask you to confirm it's you before we act.
If you think we have handled your data wrongly, please tell us first so we can put it right. You also have the right to complain to a data protection authority: in Bulgaria, where we are established, the Commission for Personal Data Protection (cpdp.bg); in Norway, Datatilsynet (datatilsynet.no); or the authority in the EU/EEA country where you live or work.
Children
ComputerCaller is not for users under 16. We don't knowingly collect data from minors.
Contact
Questions, requests or complaints about your privacy: email [email protected]. We answer.