Callmory Privacy Policy
Effective: September 2026 (pre-launch draft — the final wording will be reviewed by counsel before public release, and any change will be announced in the app).
Callmory is a private client-memory and promise-tracking app. Its whole premise is that your relationship data belongs to you. This policy describes, in plain language, exactly what data the app handles and where it goes.
What data the app stores
- Your account: the email address you sign in with (email/password, Google or Apple sign-in).
- People you add: only the contacts you hand-pick to add or import. Your address book is never uploaded in bulk and never read without an explicit selection.
- Your notes and promises: conversation notes, voice-note transcripts, call log entries you create, promises and their history.
- Voice recordings: voice notes you record or import, stored in your private cloud space.
What the app reads but never stores or uploads
- Calendar (optional, off by default): if you enable the calendar connection, upcoming events are read on your device only to show a meeting briefing. Events are never written, stored on our servers or sent anywhere.
- Call state: iOS tells the app that a call started or ended — never who was on it. A call is logged only when you confirm it.
Where your data lives
Without an account, app records stay in the app's SQLite database on your device. This local database is not the separately encrypted Private Space feature. Account records use Google Firebase (Firestore and Authentication); security rules restrict them to your account. Device records are not uploaded just because you sign in. The optional Copy device data action shows the destination account and requires your confirmation; it keeps the device copy. Audio files stay local unless you separately choose to upload them.
Backups and exports
Backup and export offers a password-encrypted .cnbackup file containing active app records and their audio, or a contacts-only vCard. The encrypted file can restore to device storage after you enter its passphrase and confirm the preview. Theme, language and follow-up interval can optionally be restored. Trash, Private Space, pending calls, location reminders, permissions, AI consent, sign-in, purchases and app-lock settings are not included. Total audio is limited to 30 MB; missing or larger audio prevents creation. We cannot recover a forgotten backup passphrase.
Legacy JSON, CSV and vCard exports are not encrypted. JSON preserves active app records but not the audio files themselves. You choose where to save or share a file. An email/share handoff does not prove remote delivery; protect the file and keep its passphrase separately.
Service providers
Nearby connections (optional): when you search for a meeting place, the address you enter is sent to Apple's geocoding service. Your selected place, radius and contact selections are saved on this device, separately for each account. With your location and notification permissions, iOS monitors arrival and delivers a local reminder. We do not collect a location history or track your contacts. The notification does not contain contact names. Turning the reminder off removes its pending and delivered notification; your saved configuration remains until you delete app data. These device preferences are not included in the current JSON export.
- Google Firebase — database, file storage, sign-in, crash reports and app integrity (App Check).
- Anthropic — only when you separately consent to AI note processing: the text of a note is sent to produce a summary and suggested next step, then returned. You can turn this off anytime in Settings; without consent the app works fully manually.
- RevenueCat — only if you subscribe to Pro: an anonymous app-user id and purchase state, to manage your subscription.
There are no advertising SDKs and no analytics that track your behavior. Crash reporting (Firebase Crashlytics) collects crash diagnostics only.
What we will never do
- No community database or caller-ID pool: Caller ID labels come only from your own contacts and stay on your device.
- No selling or sharing of your data with advertisers or data brokers.
- No secret or automatic recording of phone calls, and no reading of your message history or system call history.
Deletion and retention
Deleting a person moves them to the Trash, where you can restore them or delete them forever. "Delete forever" and "Delete all data" are real deletions of structured records: the records, notes and promises are removed, and the cloud deletion path removes associated cloud audio. Known local audio attachments are removed when no device record, trash entry or known account copy still references them. Failed local-file deletion is queued for retry; shared files and uncertain account copies are retained. Cleanup of older untracked or abandoned recordings is not yet complete in this development version, so record deletion does not erase every possible local audio copy. Previously exported files at destinations you control are not recalled. Where the law requires retaining something (for example subscription billing records held by Apple/RevenueCat), the final policy will spell that out explicitly.
Your rights
- Export active app records or contacts free from More → Backup and export; each option explains what it includes and leaves out.
- Delete any record, or your entire account data, from inside the app.
- Withdraw AI consent anytime in Settings.
- For any request or question: [email protected].
Waitlist
If you join the website waitlist we store only your email address and use it for a single launch announcement. Write to us to have it removed.