Template for legal review. Written to describe what the system actually does — if you change the code, change this.
The short version. The numbers of people who call you, and the contacts you choose to protect, are encrypted on your device under a key we do not hold. We cannot read them. We keep the minimum metadata needed to route and bill your calls, and we delete it on your plan's schedule.
| Data | Why | Readable by us | Kept |
|---|---|---|---|
| Email address | Your account | Yes | Life of account |
| Your own phone number | We must dial it | Yes | Life of account |
| Callers' real numbers | Your history | No — encrypted | 7 / 90 / 365 days by plan |
| Protected contacts & labels | Labelling your history | No — encrypted | Until you delete them |
| Call time, duration, coarse origin city | Billing and support | Yes | Same as history |
| Never-mask list | Matching while you're offline | Obscured, not encrypted | Until you delete |
| Payment details | Billing | No — held by Stripe | Per Stripe |
Twilio carries the calls, and therefore necessarily knows who called you and when. Using Kamo moves that trust from your carrier to Twilio; it does not eliminate it, and we will not claim otherwise. Stripe processes payments and holds card data — we never see it. Our hosting provider stores the database, which is ciphertext for everything sensitive.
We use no advertising networks, no analytics SDKs, and no session-replay tools. The dashboard's content security policy forbids external origins, because a script with page access could read your decrypted data.
Not to advertisers, data brokers, or anyone else, under any circumstance.
Call records are deleted automatically when your plan's retention window expires — actual deletion, not flagged-as-hidden. You can delete your entire history immediately from the dashboard. Closing your account removes your records; encrypted blobs in rotational backups age out on the backup schedule.
We respond to valid legal process. We can supply account records, billing data, call metadata, and encrypted blobs. We cannot supply plaintext contacts or history because we hold no key for them. Where lawful, we notify affected users.
Access, correction, deletion, export, and complaint to your data protection authority (in Canada, the Office of the Privacy Commissioner). Contact privacy@yourdomain.
Last updated: 15 August 2026.