Privacy Policy
1. Introduction
This Privacy Policy explains how 2 Bears Software Limited (“we”, “us”, “our”) handles personal data when you use Call My Phone (“the App”). The App allows users to create and schedule simulated incoming calls and simulated SMS-style alerts, including optional caller names, phone numbers, photos, custom voice recordings, ringtones, scheduling, pocket-trigger activation, and optional real-call blocking during a simulated call.
Most App data is stored locally on your device. The App also uses Google Play Billing for purchases and subscriptions, and Firebase Firestore to record early-adopter / premium entitlement status. We do not operate advertising in this App.
For personal data that we determine the purpose and means of processing, 2 Bears Software Limited is the data controller. Some third-party services, including Google Play and Firebase, may also process data as independent controllers or processors under their own terms and privacy policies.
Your use of the App is also governed by our Terms & Conditions, which include important restrictions on misuse, impersonation, harassment, fraud, false evidence, prank misuse, real-call blocking, and reliance on simulated content.
2. Data We Collect
2.1 Data Stored Locally on Your Device
The App stores the following data locally on your device using Android local storage, SharedPreferences, and a local database:
- Call and SMS template names
- Display names, caller names, and phone numbers entered by you
- Optional caller photo references selected by you
- Simulated SMS text entered by you
- Simulated SMS ringtone preferences
- Scheduled call and SMS times
- Pocket trigger settings
- Dark mode and other App preferences
- Optional custom voice clips recorded by you, including clip name, file path, duration, and pitch setting
- Local premium, purchase, and early-adopter access indicators
This locally stored data is used to provide the App’s features. It remains on your device unless you delete it, clear App data, or uninstall the App. Local template content, caller details, caller photos, custom voice recordings, and scheduled times are not sent to us.
We do not monitor, access, review, or moderate any caller names, photos, templates, voice recordings, message text, schedules, or other content you create within the App.
The App is not designed for storing highly sensitive information. You should avoid entering or recording sensitive personal data, confidential information, medical information, financial information, passwords, security codes, or other information that could harm you or another person if seen, overheard, lost, misused, or disclosed.
2.2 Data Not Collected by Us Through Core App Features
The App’s core simulated call and SMS features do not send us:
- Your real phone calls or call audio
- Your real SMS messages
- Your contacts list
- Your caller photos
- Your custom voice recordings
- Your schedule templates or simulated SMS text
- Payment card details
2.3 Firebase Early-Adopter and Premium Entitlement Records
The App uses Firebase Firestore to help manage early-adopter access and premium entitlement continuity. For this purpose, the App may transmit and store limited entitlement-management data on Google Firebase servers:
- A hashed device-linked user identifier derived from Android ID and the App package name
- First seen timestamp
- Last seen timestamp
- Whether free early-adopter access is enabled
- App version
- Package name
The App does not store your raw Android ID in Firebase. It uses a SHA-256 hash derived from Android ID and package name. This identifier is not intended to identify you by name or contact you. However, because it is device-linked, it may be treated as personal data or personal information under some laws.
The source of this entitlement data is your device and your use of the App. The App does not obtain entitlement-management data about you from third-party data brokers or public sources.
2.4 Purchases and Subscriptions
The App uses Google Play Billing for one-time purchases and subscriptions. Payment card details and transaction processing are handled by Google Play, not by us. The App may locally store whether premium access is active and may query Google Play to check whether a purchase or subscription remains valid.
We do not guarantee the continued availability of early-adopter access, premium access, entitlement restoration, or any particular premium feature. Such access may be modified, discontinued, suspended, or revoked where legally, technically, operationally, commercially, or fraud-prevention reasons make this necessary or appropriate, subject to any non-excludable rights you may have under applicable law or Google Play terms.
3. Voice Recording
The App requests microphone permission only if you choose to record a custom voice message. Voice recordings are saved locally on your device and are used only for simulated calls. They are not uploaded to us, Firebase, Google Play, or any other third party by the App.
You are responsible for ensuring that any voice recording you create, store, play, or use complies with applicable law, including privacy, consent, recording, harassment, and communications laws in your jurisdiction.
4. Contacts and Photos
The App may request contacts access so that you can select or use contact-style caller information and to support optional real-call blocking behaviour involving saved contacts. The App does not upload your contacts list to us.
The App may use Android's photo picker and/or media image access so that you can select a caller photo. Selected photos or photo references are stored locally for App display purposes and are not uploaded to us. Where Android requires or grants media image access, it is used only for selecting and displaying caller photos within the App.
5. Notifications, Simulated SMS, Call Screening, and Do Not Disturb
The App may request notification permission for foreground service and app status alerts. Simulated SMS-style alerts are generated locally by the App using an in-app screen or overlay-style presentation. They are not real SMS messages, are not sent through your mobile network, and are not read from your real messages.
The App may offer optional real-call blocking while a simulated call is running by asking you to set the App as your Android Caller ID & Spam / call screening provider. If enabled, the App may reject or silence incoming real calls during a simulated call and may request contacts access so that blocking can also include saved contacts where Android would otherwise treat them differently. Android, your device manufacturer, your dialer app, your carrier, and your own settings control how this behaves. We cannot guarantee that all real calls, notifications, visual alerts, missed-call records, voicemail behaviour, carrier call screens, or device call screens will be blocked or hidden in all circumstances.
The App may include a Do Not Disturb-related preference and may use alarm-style audio behaviour for scheduled App alerts. Android, your device settings, and your device manufacturer control Do Not Disturb behaviour. The App does not guarantee that alerts will bypass Do Not Disturb and does not use Do Not Disturb as its primary real-call blocking mechanism.
We do not control carrier-level call handling, voicemail behaviour, emergency call routing, device dialer behaviour, or network-level call routing.
6. Permissions Used
The App may request the following Android permissions:
- INTERNET — required for Firebase Firestore and Google Play-related connectivity.
- RECEIVE_BOOT_COMPLETED / LOCKED_BOOT_COMPLETED — allows the App to reschedule enabled alarms after device restart.
- SCHEDULE_EXACT_ALARM — allows simulated calls and SMS alerts to appear at the selected time.
- SYSTEM_ALERT_WINDOW — allows the simulated incoming-call screen to appear over other apps where permitted by Android.
- FOREGROUND_SERVICE / FOREGROUND_SERVICE_SPECIAL_USE — supports the fake call and pocket trigger services while active.
- RECORD_AUDIO — allows you to record custom voice messages.
- READ_CONTACTS — optional, used for contact-related caller information and call-blocking behaviour involving saved contacts.
- READ_MEDIA_IMAGES / Android photo picker — optional, used to select caller photos. Where media image access is granted, it is used only for caller photo selection and display.
- VIBRATE — allows vibration feedback, including pocket trigger confirmation.
- Do Not Disturb-related preference — optional local App setting related to scheduled App alerts. Android controls whether alerts bypass Do Not Disturb.
- WAKE_LOCK — helps the App wake the device for scheduled simulated calls.
- POST_NOTIFICATIONS — allows required app status and service notifications on Android 13+.
- REQUEST_IGNORE_BATTERY_OPTIMIZATIONS — helps reduce interruption of scheduled call features by battery management.
- USE_FULL_SCREEN_INTENT — supports full-screen simulated call display where Android permits it.
No permission is intended to be used beyond its stated purpose.
7. How We Use Data
We use data only to:
- Create, store, edit, and display your simulated call and SMS templates
- Schedule and trigger simulated calls and SMS alerts
- Play optional custom voice clips during simulated calls
- Apply your App settings and preferences
- Provide optional pocket trigger behaviour
- Provide optional Caller ID & Spam / call screening-based real-call blocking while a simulated call is running
- Manage premium access, purchases, subscriptions, and early-adopter entitlement
- Prevent abuse or loss of early-adopter entitlement records
The App does not use advertising profiling. The App does not make decisions based solely on automated processing which produce legal or similarly significant effects about you. Automated entitlement checks may affect whether premium App features are available, but they do not make legal, financial, employment, credit, housing, healthcare, or similar significant decisions about you.
8. Legal Basis for Processing
Where required by law, we process data under:
- Performance of the App’s functions requested by you
- Your consent, where you grant optional permissions such as microphone, contacts, media images, notifications, overlay, call screening, or related access
- Legitimate interests in maintaining App functionality, purchase verification, entitlement continuity, abuse prevention, and fraud prevention
- Compliance with legal obligations where applicable
Where processing is based on consent, you may withdraw that consent by disabling the relevant permission in Android settings, disabling the related App feature, clearing App data, or uninstalling the App. Withdrawing a permission may prevent the related feature from working.
Local app alerts, overlay display, microphone recording, contacts access, media image access / photo picker use, exact alarms, full-screen display, Caller ID & Spam / call screening access, and Do Not Disturb-related preferences are used only where enabled by you or permitted through Android permissions/settings. These features are processed under your consent, the performance of App features you request, and/or our legitimate interests in providing the App functionality, depending on the feature and applicable law.
8A. Automated Decision-Making and Profiling
The App does not carry out advertising profiling. The App does not use solely automated decision-making to make decisions about you that produce legal or similarly significant effects.
Premium and early-adopter entitlement checks may automatically determine whether certain App features are available. These checks are limited to App access control and do not make legal, financial, employment, credit, housing, healthcare, education, insurance, immigration, public authority, or similar significant decisions about you.
9. Data Sharing
We do not sell, rent, or trade personal data. The third-party services involved are:
- Firebase Firestore — early-adopter and premium entitlement records
- Google Play and Google Play Billing — payments, subscriptions, purchase verification, and app distribution
- Android operating system services — notifications, alarms, Caller ID & Spam / call screening, Do Not Disturb-related behaviour, overlay display, contacts picker / access, media image access / photo picker use, audio playback, and microphone recording where enabled
These services operate under their own terms and privacy policies. We are not responsible for their independent processing, outages, policies, or continued availability.
We do not knowingly transfer App data to third countries other than through the Google services described in this Policy. Where Google processes data for Firebase or Google Play, data may be processed outside the United Kingdom. Such transfers are handled by Google under Google’s applicable data transfer safeguards and service terms, which may include appropriate safeguards such as standard contractual clauses, the UK International Data Transfer Agreement, or the UK Addendum where applicable. You should also review Google’s own privacy information and data transfer terms for those services.
10. Advertising
The App does not include third-party advertising and does not use advertising SDKs. If this changes in the future, this Privacy Policy will be updated.
11. Data Storage & Security
- Templates, schedules, selected caller information, settings, and voice clips are stored locally on your device.
- Local App storage relies on Android’s app sandboxing, permission model, and device-level security controls.
- Firebase entitlement records are stored on Google Firebase infrastructure.
- Google Play purchase and subscription data is handled by Google Play.
- Where data is transmitted to Google services, it is intended to use industry-standard encrypted transport mechanisms supported by those services.
- You are responsible for maintaining the security of your own device and backups.
- We do not control rooted devices, sideloaded operating systems, malware, device manufacturer modifications, carrier modifications, backup tools, screen recording tools, notification history tools, or other software that may affect device security or data visibility.
- No method of electronic storage or transmission is absolutely secure. We cannot guarantee absolute security.
- We are not responsible for data loss, disclosure, or compromise caused by device failure, user action, operating system changes, rooted or compromised devices, malware, backup/restore behaviour, or third-party services.
12. Data Retention
Locally stored App data remains on your device until you delete it, clear App data, or uninstall the App. Firebase entitlement records may be retained for as long as reasonably necessary to maintain early-adopter access, verify premium entitlement, prevent abuse, support reinstalls, or comply with legal or operational requirements.
Deleting the App or clearing local App data does not necessarily delete off-device records already held by Firebase or Google Play.
Because early-adopter and premium entitlement records may be needed to preserve your access after reinstall on the same device where technically possible, deleting those records may affect your ability to retain free or premium access. We may retain minimal records where necessary for fraud prevention, dispute handling, accounting, legal compliance, or security.
If you contact us by email for support, feedback, privacy requests, complaints, billing queries, or legal matters, we may retain your email and related correspondence for up to 24 months after the matter is closed. We may retain correspondence for longer where reasonably necessary for legal claims, dispute handling, fraud prevention, safeguarding, security, accounting, regulatory compliance, or to protect our legitimate interests.
13. Accuracy, Reliability, and Simulated Content
The App creates simulated calls and SMS-style alerts. These are not real calls or real SMS messages. We do not guarantee that scheduled alarms, overlay display, notifications, Caller ID & Spam / call screening behaviour, Do Not Disturb behaviour, ringtone playback, voice playback, or pocket trigger behaviour will work on every device, Android version, network, or configuration.
We cannot prevent screenshots, screen recordings, notification history, backup tools, accessibility tools, or other device-level capture of simulated content.
The App is provided on an “as is” and “as available” basis. We are not responsible for device issues, user misuse, reliance on simulated content, missed or silenced real calls, Android restrictions, device manufacturer behaviour, carrier behaviour, Google Play, Firebase, or other third-party services, except where liability cannot lawfully be excluded. Further liability limitations and prohibited-use restrictions are set out in the Terms & Conditions.
Nothing in this App or this Privacy Policy constitutes legal, safety, safeguarding, medical, professional, or emergency advice.
14. Children’s Privacy
The App is not intended for children under 13. We do not knowingly collect personal data from children.
15. International Use
The App may be available worldwide. Because the App uses Google services such as Firebase and Google Play, relevant data may be processed on servers located outside your country of residence. Regardless of your location, any disputes or claims will be governed by the laws of the United Kingdom, and legal proceedings must take place in the courts of England and Wales.
16. Your Rights
Depending on your location and the applicable legal basis, you may have rights to access, delete, correct, object to, restrict processing of, or receive a portable copy of your personal data. Locally stored App data can generally be deleted by clearing App data or uninstalling the App. For requests relating to off-device Firebase entitlement records connected with the App, you may contact us using the details below and we will consider and respond to your request in accordance with applicable law and the technical limits of the services involved.
Please note that in some cases we may be unable to delete or alter certain technical, billing, entitlement, security, fraud-prevention, or legal records immediately where retention is necessary for legitimate operational, legal, or compliance reasons.
You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection. You can contact the ICO at ico.org.uk or by telephone on 0303 123 1113. Our ICO Registration Number is ZC116025.
17. US Residents — CCPA / CPRA
If you are a resident of the United States, including California, you may have rights under the CCPA/CPRA to know, delete, and opt out of the sale or sharing of personal information.
We do not sell or share personal information. Local template data and content remains on your device and is not collected by us. Firebase entitlement records may include a pseudonymous device‑linked identifier; you may contact us to request deletion of off‑device records. Contact us at 2BearsSoftware@gmail.com with any privacy‑related requests.
18. Canadian Residents — PIPEDA
We collect only the limited entitlement‑management data described in this policy, for the purpose of managing early‑adopter and premium access. We do not share it with third parties beyond the Google services described above. You may request access to or deletion of any data we hold by contacting us.
19. Australian Residents — Privacy Act 1988
We handle personal information in accordance with the Australian Privacy Principles. You have the right to access and correct personal information we hold about you. Contact us at 2BearsSoftware@gmail.com.
20. Brazilian Residents — LGPD
We process your personal data on the basis of your consent (Art. 7, I, LGPD) and our legitimate interests in providing and maintaining App functionality and entitlement management (Art. 7, IX, LGPD). You have the rights of confirmation, access, correction, anonymisation, deletion, portability, and information about sharing. Contact us to exercise these rights.
21. Indian Residents — DPDPA 2023
We process personal data only for the purposes described in this policy and only with your consent. You have the right to access information, correct inaccuracies, and withdraw consent. Contact us at 2BearsSoftware@gmail.com.
22. Changes to This Policy
We may update this Privacy Policy from time to time. Continued use of the App after changes are published constitutes acceptance of the updated policy. The effective date at the top of this page will reflect the date of the most recent update.
If we introduce new features that materially change what personal data the App collects, stores, transmits, or shares, we will update this Privacy Policy before or when those features become available. Where a new feature requires a new Android permission, new consent, or a materially different use of personal data, we will request the relevant permission or consent before that feature is used.
23. Contact
71–75 Shelton Street
Covent Garden
London WC2H 9JQ
Email: 2BearsSoftware@gmail.com