Legal
Privacy policy
Last updated: July 13, 2026
What we collect
- Your email address and one verified phone number — to run your account.
- Call records: the number you dialed, when the call happened, its duration and cost — this is your call history and our billing ledger.
- Top-up records: amount, date, and a payment reference. Card details go directly to our payment provider; we never see or store them.
- Basic security signals (IP address, rough request metadata) used only for fraud prevention and rate limiting.
What we don't do
No advertising trackers, no analytics cookies, no selling or sharing data for marketing. The only cookie heyphone sets is the session cookie that keeps you signed in — which is why there is no cookie banner.
Who processes data for us
heyphone runs on infrastructure providers that process data on our behalf: Supabase (hosting and authentication), Twilio (call carriage), our payment provider (top-up processing), and Resend (transactional email). Each receives only what it needs to do its job.
Retention and deletion
You can delete your account in Settings at any time; this removes your profile and signs you out everywhere. Billing and call records are kept as long as accounting and anti-fraud law requires, then deleted.
Your rights
Under the GDPR you can request a copy of your data, correct it, or have it erased. Write to support@heyphone.app from your account email and we will respond within 30 days. The data controller is the heyphone operator, a sole trader registered in Cyprus (EU).