Privacy First Approach
Comprehensive Privacy Policy
Transparency is at the heart of CallExa. We believe you should know exactly how your data is handled — and more importantly, what we never touch.
Last Updated: February 15, 2026
V1.0 Compliant
Local Processing First
Our Core Privacy Commitment
“The vast majority of your personal communications data — including all SMS/MMS messages, call logs, and contacts — is processed exclusively on your device and is never transmitted to or stored on Callexa's external servers. We are built on the principle of data minimization: we collect only what is strictly necessary, we store it only as long as needed, and we never sell it.”
1. Introduction and Scope of This Policy
1.1 About This Privacy Policy
Welcome to Callexa ("we", "our", "us", or "the Company"), a smart phone and messaging application developed and operated by Inflancer Technologies. We are committed to protecting the privacy and security of every individual who uses our application ("the App", "Application", or "Service").
This Privacy Policy ("Policy") explains, in plain and precise language, exactly what personal information we collect, how and why we collect it, how it is processed and stored, with whom it may be shared, how long we retain it, and what rights you have with respect to your data. This Policy forms part of our broader legal framework, which also includes our Terms and Conditions, Security Policy, and Data Retention Policy.
By downloading, installing, or using the Callexa App, you acknowledge that you have read, understood, and consent to the data practices described in this Policy. If you do not agree with any part of this Policy, you should discontinue use of the App and uninstall it from your device.
1.1.1 Anonymous and Guest Mode (No-Signup Use)
Callexa is designed with privacy-first principles. You can download and use most of the App's core functions — including local call dialing, local Caller ID matching, local SMS/MMS messaging, and local spam flagging — without registering, signing up, or creating an account. If you choose to use the App in this guest or unregistered mode, all personal communications data (contacts, call logs, messages) remains strictly on your device. We do not collect, transmit, upload, or store any of this local data on our external servers. Creating an account is completely optional and only required to access full cloud-based features (e.g. creating verified business directories, cloud synchronizations, or verified profile badges).
1.2 Who This Policy Applies To
This Policy applies to all individuals who interact with the Callexa App, including:
- Personal Users — individuals who download and use Callexa as their default phone and SMS application;
- Business Account Holders — businesses and individuals who register a verified business listing within the App's public business directory;
- Prospective Users — individuals who visit our website, app store listing, or otherwise engage with Callexa services without having completed installation.
1.3 Regulatory Compliance
Callexa is designed and operated in compliance with applicable data protection and privacy laws across jurisdictions in which we operate, including but not limited to:
- General Data Protection Regulation (GDPR) — EU Regulation 2016/679;
- California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA);
- Children's Online Privacy Protection Act (COPPA);
- Google Play Developer Distribution Agreement and User Data Policy;
- Apple App Store Review Guidelines and App Privacy Requirements;
- Other applicable national and regional data protection laws.
Important Notice Regarding Default Handler Status
Because Callexa functions as your device's default phone and SMS handler, it necessarily has access to your telephony and messaging data as part of its core operation. This access is entirely local to your device. Please review Section 3 (Information We Collect) carefully to understand the full scope of this access and how it is used.
This is a critical disclosure regarding our default handler functionality.
2. Definitions and Key Terms
Key Terms Table
The following definitions apply throughout this Privacy Policy.
| Term | Definition |
|---|---|
| Personal Data | Any information relating to an identified or identifiable natural person. |
| Processing | Any operation performed on personal data, including collection, storage, use, or erasure. |
| Data Controller | The entity that determines the purposes and means of processing personal data (Inflancer Technologies). |
| Sensitive Permissions | Device permissions granting access to personal data (e.g., READ_SMS, READ_CALL_LOG). |
| Default Handler | App designated to manage specific device actions like calls or texts. |
| Local Processing | Data operations that occur exclusively on the user's device. |
| Aggregate Data | Combined or modified information so no individual can be identified. |
3. Information We Collect
3.1 Data Processed Locally On Your Device
As the default phone and SMS handler, Callexa must access certain data stored on your device. This data is accessed and processed entirely within your device's secure environment. It is not transmitted to, copied to, or stored on our external servers.
| Data Category | What Is Accessed and Why |
|---|---|
| Contacts | Read to display donor names, photos and selection for new messages. |
| Call Logs | Read and write to display and sync your device's call history. |
| SMS and MMS | Read and write to enable viewing, sending and receiving messages. |
| Phone & SIM | Read basic state to route calls and support dual-SIM devices. |
| Network State | Read connection status to adapt app behavior. |
3.2 Business Account Data (Server-Side)
If you register a Business Account, we collect and store this information on our secure servers to enable your listing to be discovered.
| Data Field | Purpose |
|---|---|
| Business Name | Officially registered name displayed publicly. |
| Category | Used for categorization in directory searches. |
| Description | Products/services info for your public profile. |
| Email Address | Used for account management and verification. |
| Phone Number(s) | Displayed for users to contact you directly. |
| Physical Address | Used to generate map pin in directory view. |
| Verification Docs | Used exclusively for legitimacy checks (not public). |
3.2.1 Crowdsourced Spam Flagging and Privacy Protection
Callexa uses crowdsourced data to build its smart spam identification shields. When you mark a call or number as spam, we transmit ONLY the telephone number and the categorization tag (e.g. "Telemarketer", "Phishing Scam"). Callexa never transmits, stores, or processes the audio content of your phone calls, nor does it upload the text content of your SMS/MMS messages as part of this crowdsourcing mechanism. Spam database logs are aggregated pseudonymously.
3.3 Automatically Collected Technical Data
Technical and diagnostic information collected to maintain app stability.
| Data Type | Purpose |
|---|---|
| App Version | Correlate bug reports and ensure compatibility. |
| Device Model | Identify device-specific rendering issues. |
| Crash Reports | Transmitted to Firebase Crashlytics to fix bugs. |
| Installation ID | Pseudonymous identifier to correlate reports. |
| Usage Stats | Aggregated data for product improvement decisions. |
3.4 Information We Do NOT Collect
We are committed to transparency about what we do NOT collect:
- Content of phone calls (audio);
- Precise, real-time GPS location data;
- Photographs from your camera roll (except your profile photo);
- Browsing history or data from other apps;
- Financial info or payment card details;
- Biometric data (fingerprints, face data);
- Device sensor data (accelerometer, gyroscope);
- Clipboard contents.
4. Legal Basis for Processing
GDPR Grounds
Grounds for processing per GDPR (EEA/UK):
| Legal Basis | Activity |
|---|---|
| Performance of Contract | Accessing local data to provide core phone/SMS features. |
| Legitimate Interests | Crash reports and analytics for app stability. |
| Legal Obligation | Retaining records for regulatory or audit compliance. |
| Consent | For optional data processing beyond core functionality. |
5. How We Use Your Information
5.1 Core Application Functions
Primary purposes for data access:
- Connecting calls and ensuring accurate routing;
- Delivering and managing SMS/MMS messages;
- Caller ID identification using local contacts;
- Identifying potential spam and fraudulent callers;
- Maintaining searchable call history;
- Managing multi-SIM configurations.
What We Will Never Do With Your Data
Callexa will never:
- Sell your personal data to third parties;
- Use your data to serve behavioral advertising;
- Provide advertisers access to your communications;
- Use message content for anything other than displaying it to you.
6. Device Permissions Required
6.1 Android Permissions
Detailed technical justification and classifications for all Android permissions declared in Callexa's manifest:
| Permission | Justification | Classification |
|---|---|---|
| READ_PHONE_STATE | Detects incoming/outgoing call states (ringing, dialing, hung up) and reads cellular carrier and active SIM slot details to manage call routing. | Required (Default Dialer) |
| CALL_PHONE | Initiates standard cellular telephone calls directly from the Callexa dialer and contact list interfaces. | Required (Default Dialer) |
| ANSWER_PHONE_CALLS | Allows the user to answer incoming telephony calls directly from Callexa's custom incoming call screen. | Required (Default Dialer) |
| MANAGE_OWN_CALLS | Enables register and management of VoIP calling events with the Android Telecom subsystem. | Required (VoIP Integration) |
| BIND_INCALL_SERVICE | System-level permission that allows the Android system to route active call state events directly to Callexa's in-call controller. | Required (System-level) |
| BIND_TELECOM_CONNECTION_SERVICE | System-level permission used to establish connections for VoIP calls via the Android ConnectionService framework. | Required (System-level) |
| READ_CALL_LOG | Reads the device call history database to populate and show records of incoming, outgoing, and missed calls inside the Callexa dialer screen. | Required (Default Dialer) |
| WRITE_CALL_LOG | Saves dialed, received, and missed call records back to the device's system call history database. | Required (Default Dialer) |
| READ_CONTACTS | Accesses the device address book to match phone numbers with contact names, photos, and company details in the dialer and call log. | Required (Core Feature) |
| WRITE_CONTACTS | Allows users to add, update, or remove contacts directly from Callexa's contact management UI. | Required (Core Feature) |
| READ_SMS | Accesses the local message storage to display SMS/MMS conversations in the chat list and message detail threads. | Required (Default SMS App) |
| SEND_SMS | Sends outbound SMS messages written by the user in chat conversations. | Required (Default SMS App) |
| RECEIVE_SMS | Listens for incoming SMS messages to process content, detect spam, and display notifications. | Required (Default SMS App) |
| BROADCAST_SMS | Secures incoming SMS broadcast messages, ensuring they are only delivered to Callexa's SMS handler. | Required (System-level) |
| SMS_DELIVER / WAP_PUSH_DELIVER | Permissions that enable Callexa to receive, write, and process incoming SMS and MMS message payloads locally. | Required (System-level) |
| SEND_RESPOND_VIA_MESSAGE | Allows Callexa to send a quick text template reply when rejecting an incoming phone call from the ringing screen. | Required (System-level) |
| RECORD_AUDIO | Enables microphone access to capture voice audio during active VoIP phone calls. | Required (VoIP Calling) |
| CAMERA | Accesses the front/rear camera to transmit video feed during active VoIP video calls, capture profile photos, and scan verification QR codes. | Optional |
| MODIFY_AUDIO_SETTINGS | Allows Callexa to control audio routing (toggling speakerphone, handset earpiece, or Bluetooth headset) during active calls. | Required (Calling) |
| INTERNET | Enables network requests to sync business directories, fetch spam databases, authenticate accounts, and transmit VoIP call data. | Required (Cloud Services) |
| ACCESS_NETWORK_STATE | Monitors cellular/WiFi connection status to dynamically adjust call quality, database synchronization, and alert of network dropouts. | Required (Core Performance) |
| ACCESS_WIFI_STATE | Checks WiFi connectivity details to optimize high-bandwidth operations like database downloads and VoIP calls. | Required (Core Performance) |
| READ_EXTERNAL_STORAGE | Reads document and media attachments from device storage to enable sending them via SMS/MMS on legacy Android versions (<= SDK 32). | Required on Android <= 12 |
| WRITE_EXTERNAL_STORAGE | Saves incoming SMS/MMS attachments (images, audio, PDF) to the device's public folders on legacy Android versions (<= SDK 32). | Required on Android <= 12 |
| READ_MEDIA_IMAGES | Accesses photo galleries to select and attach images to chats on modern Android versions (Android 13+). | Required on Android 13+ |
| READ_MEDIA_VIDEO | Accesses video galleries to select and attach video clips to chats on modern Android versions (Android 13+). | Required on Android 13+ |
| ACCESS_COARSE_LOCATION | Provides approximate city/neighborhood level location details for nearby business search in the Callexa business lookup directory. | Optional (Business Lookup) |
| ACCESS_FINE_LOCATION | Provides precise GPS coordinates to show your exact position on the local business directory map. | Optional (Business Lookup) |
| USE_BIOMETRIC | Allows locking private chat threads or the entire app behind device biometric authentication (fingerprint/face unlock). | Optional (App Security) |
| FOREGROUND_SERVICE | Keeps the application running in the background to handle active WebSocket connections, call monitoring, and database synching. | Required (Background Stability) |
| FOREGROUND_SERVICE_PHONE_CALL | Keeps the custom calling UI and Telecom link running in the background during active calls. | Required (Calling Stability) |
| FOREGROUND_SERVICE_DATA_SYNC | Allows background syncing of the local business directory, block lists, and call history logs in the background. | Required (Sync Stability) |
| FOREGROUND_SERVICE_SPECIAL_USE | Maintains real-time Caller ID overlays (OverlayService, SmsOverlayService) and background push signaling (SocketKeepAliveService). | Required (Caller ID & Sync) |
| WAKE_LOCK | Prevents the device CPU from sleeping when an active call or background message download is in progress. | Required (System-level) |
| DISABLE_KEYGUARD | Wakes up the device screen and unlocks the dialing overlay when a call is received, allowing immediate user action. | Required (Incoming Call UI) |
| USE_FULL_SCREEN_INTENT | Displays the full-screen interactive incoming call dialog immediately when the device screen is off or locked. | Required (Incoming Call UI) |
| POST_NOTIFICATIONS | Enables showing status bar notifications for active calls, SMS alerts, keepalive tasks, and spam warnings. | Required (User Alerts) |
| RECEIVE_BOOT_COMPLETED | Automatically restarts background keep-alive and Caller ID monitoring services immediately when the device boots up. | Required (Boot Persistence) |
| SYSTEM_ALERT_WINDOW | Renders the interactive Callexa spam warning and Caller ID popups as an overlay on top of other running applications. | Required (Caller ID Overlay) |
| REQUEST_IGNORE_BATTERY_OPTIMIZATIONS | Requests permission to bypass aggressive OS battery saver limits so background socket connections and Caller ID popups are never delayed. | Highly Recommended |
| USE_EXACT_ALARM | Schedules exact timing alarms for call/message reminders, backup schedules, and user-snoozed notifications. | Required (Reminders) |
6.2 iOS Permissions
Permission keys and descriptions declared in Callexa's iOS Info.plist:
| Permission Key | Usage Description / Purpose | Classification |
|---|---|---|
| NSContactsUsageDescription | Display caller names and photos | Required |
| NSMicrophoneUsageDescription | Enable audio during phone calls | Required |
| PushKit | Receive VoIP call push notifications in background | Required |
| CallKit | Natively display calls on system lock screen | Required |
8. Data Retention
Retention Periods
Data retention schedules for all categories of personal information:
| Data Category | Retention Period |
|---|---|
| SMS/MMS (Local) | Indefinite until user deletes them. |
| Call Logs (Local) | Indefinite until user deletes them. |
| Business Profile | Duration of active account + 30 days. |
| Verification Docs | Duration of status + 5 years for audit. |
| Crash Reports | 90 days (Google/Firebase standard). |
9. Data Security
9.1 Technical Security Measures
Technical mechanisms deployed to protect data at rest and in transit:
| Measure | Implementation |
|---|---|
| Encryption in Transit | TLS 1.2+ with certificate pinning. |
| Device Encryption | EncryptedSharedPreferences (Android) / Keychain (iOS). |
| Server Encryption | AES-256 for business and verification data. |
| Administrative Access | Always protected by Multi-Factor Authentication (MFA). |
10. Your Privacy Rights
10.1 Rights Available to All Users
Rights we honor for all users regardless of location:
| Your Right | Description |
|---|---|
| Right of Access | Request a copy of personal data we hold about you. |
| Right to Erasure | Request deletion of your personal data ('Right to be Forgotten'). |
| Right to Portability | Request a machine-readable export of your data. |
| Right to Object | Object to processing based on legitimate interests. |
10.2 California Residents (CCPA/CPRA)
Additional rights for California residents under CCPA/CPRA include the Right to Know specific pieces of info, Right to Opt-Out of sharing (though we never sell or share data), and Right of Non-Discrimination.
11. Special Categories & Children
11.1 Sensitive Data
We do not intentionally collect special categories of sensitive data (religion, health, biometric, etc.). We do not scan message content for such info.
11.2 Children's Privacy (Under 13)
Callexa is not intended for use by children under 13. We do not knowingly collect info from them. If discovered, it is deleted immediately.
12. International Data Transfers
When transferring Business Account data or crash reports to countries without adequacy decisions, we rely on Standard Contractual Clauses (SCCs) or UK International Data Transfer Agreements (IDTAs).
13. App Store Compliance
13.1 Google Play Store — Data Safety
| Data Type | Collected Remotely? | Shared? | Encrypted? |
|---|---|---|---|
| Contacts | No | No | N/A |
| SMS / MMS | No | No | N/A |
| Crash Reports | Yes (Anonymized) | Yes (Processor) | Yes |
13.2 Apple — Privacy Nutrition Labels
Data Linked to You: Name/Phone/Email (Business only). Data NOT Linked: Crash Data, Installation ID.
14. Cookies and Tracking
14.1 In-App Tracking
We do NOT use cookies or cross-app tracking. We only use session tokens for business account authentication.
Advertising — None
Callexa does not use advertising identifiers (IDFA/GAID).
15. Changes to This Policy
Material changes will be notified via in-app alerts at least 15 days in advance.
16. Contact Information
| Method | Details |
|---|---|
| Privacy Inquiries | privacy@callexa.app |
| Security Reports | security@callexa.app |
| General Support | support@callexa.app |
| Website | www.callexa.app/privacy |
17. Glossary
| Term | Explanation |
|---|---|
| AES-256 | Industry-standard encryption algorithm. |
| CallKit | Apple's native call UI integration framework. |
| GDPR | EU General Data Protection Regulation. |
| TLS | Transport Layer Security (encrypted transmission). |
You're all set!
Thank you for reading our Privacy Policy. Your trust is our most valuable asset.
Back to Home