Privacy Policy
Effective Date: August 26, 2026 • DPDP Act 2023 & GDPR Compliant
Core Privacy Guarantee: WhoCaller operates on a Zero Contact Harvesting architecture. We never upload your personal phone book to public directories, never sell user data to advertisers, and protect all recordings with hardware Android KeyStore encryption.
1. Information We Collect and Process
WhoCaller is designed to minimize data collection strictly to what is required for core call protection and parental security features:
- On-Device Caller ID & Spam Lookup: FastCache indices operate locally on your smartphone. Spam defense checks are verified against encrypted hashes without exposing full address books.
- Dual-Voice Call Recordings: Audio captured during cellular or WhatsApp VoIP calls is stored strictly in your device's private sandbox encrypted with AES-256-GCM. We do NOT stream or store call audio on cloud servers.
- Parental Family Shield Telemetry: When child monitoring is explicitly configured and approved with parental PINs, real-time GPS coordinates are transmitted over TLS 1.3 to synchronized parent devices.
- Billing & Razorpay Transaction Metadata: For postpaid credits usage, we store only hardware pseudonymous identifiers, accrued active minutes, invoice identifiers, and payment reference tokens generated by Razorpay. Zero credit card numbers or UPI MPINs ever touch our infrastructure.
2. On-Device Encryption & Security Standards
We implement CMMI Level 5 and OWASP MASVS v2.0 defensive engineering standards:
- Master encryption keys are generated in the hardware Android KeyStore.
- No unencrypted plaintext logs or Personally Identifiable Information (PII) exist in crash dumps.
- All cloud communication is enforced over TLS 1.3 with strict certificate pinning and ephemeral session tokens.
3. Parental Controls & Instant Cloud Purge
Parental protection features are transparent and voluntary. When a parent or child initiates "Leave Family" via the in-app dashboard, all associated GPS tracking streams, device link records, and child telemetry are instantly and permanently purged from the cloud database.
4. Third-Party Service Providers
We integrate exclusively with PCI-DSS compliant, enterprise-grade payment infrastructure:
- Razorpay Software Private Limited: For secure UPI (GPay, PhonePe, Paytm), NetBanking, and Card processing in Indian Rupees (₹). Razorpay processes payments under strict RBI guidelines.
5. Data Retention & Deletion Rights
Under the Digital Personal Data Protection (DPDP) Act 2023 and GDPR, you have full rights to access, rectify, or request complete erasure of your account metadata at any time. Simply use the in-app Reset controls or email our Grievance Officer.
6. Contact Grievance & Data Protection Officer
For any privacy-related queries, concerns, or deletion requests, contact:
Data Protection Officer
WhoCaller Inc., Cyber Security & Privacy Division
Email: privacy@whocallerapp.com
Grievance Escalation: grievance@whocallerapp.com