Privacy Policy
The short version
- We never ask for your name, email address or phone number, and you do not create an account.
- We do not record your calls. Call audio passes through to connect the call and is never stored by us.
- We do keep a record of what you dialled, when, and for how long — we have to, in order to bill you correctly and to stop fraud.
- We do not sell or share your data, we do not use it for advertising, and we do not track you across other companies' apps or websites.
Last updated: 17.07.2026
1. Who is responsible for your data
Telvio is a mobile VoIP application provided by Vast Flow, LLP, which is the data controller for the personal data described in this policy. For any privacy question or request, contact [email protected].
Telvio places outgoing calls only. It does not assign you a phone number, cannot receive incoming calls, and does not support emergency calls — see our Terms of Service for what that means for you.
2. What we collect
We collect the minimum needed to connect calls and charge for them correctly.
- Anonymous installation identifier — a random ID generated on your device, used to hold your credit balance. It is not linked to your identity, and we cannot use it to work out who you are.
- Call records — the destination number you dialled, the time the call started, its duration in seconds, the rate applied and the amount deducted. This is what a phone bill contains, and we need it to charge you correctly, to answer billing questions, and to detect fraud.
- Purchase records — transaction identifiers from the App Store or Google Play, and which pack was bought, so that credit is granted correctly and receipts can be verified.
- Technical and diagnostic data — IP address, device model, operating system version, app version, network type, and crash reports. This keeps the app working and helps us diagnose call quality problems.
About your IP address. Connecting to any internet service necessarily discloses your IP address, and an IP address indicates your approximate region — typically a city or country, not a street address. We do not collect GPS or precise location, and we do not attempt to determine where you physically are beyond what an IP address implies for routing, fraud prevention and security.
3. What we do not collect
- Your name, email address or phone number
- The content of your calls — calls are not recorded, stored, listened to or analysed
- Your contact list — we never upload or store it. If you allow the app access to your contacts, it is read on your device only, so that you can pick a number to dial.
- Precise or GPS location
- Payment card details — these go to Apple or Google, never to us
- Advertising identifiers. We show no ads and run no cross-app tracking, which is why Telvio never asks for permission to track you.
4. Microphone access
Telvio needs microphone access for the obvious reason: without it, the person you call cannot hear you. Audio is transmitted, in encrypted form, only for as long as it takes to carry the live call. It is not recorded, not stored, and not used for any other purpose. Denying microphone access means calls cannot work; you can grant or revoke it at any time in your device settings.
5. Why we are allowed to process this (legal bases)
For users in the EEA and the UK, we rely on the following legal bases under the GDPR:
- Performance of a contract — connecting your calls, maintaining your credit balance, and billing per second. Without call records we cannot provide the service at all.
- Legitimate interests — preventing fraud and abuse, keeping the service secure, and diagnosing technical faults. We have weighed these against your rights and use the least data that works.
- Legal obligation — retaining transaction and accounting records where tax or telecommunications law requires it, and responding to lawful requests from authorities.
6. Who else processes your data
A call has to reach the telephone network, so the number you dial is necessarily passed to a carrier. We use the following processors, each bound to handle data only on our instructions:
| Processor | What it does | What it receives |
|---|---|---|
| Zadarma | Primary VoIP call routing — connects your calls to the telephone network | Destination number, call start time and duration |
| Telnyx | VoIP call routing on some destinations and as a fallback route | Destination number, call start time and duration |
| Firebase (Google) | Anonymous authentication, analytics, crash reporting | Anonymous installation ID, IP address, device model, OS and app version, crash diagnostics |
| RevenueCat | In-app purchase management and receipt validation | Anonymous installation ID, store transaction identifiers, purchase history |
| Apple App Store / Google Play | Payment processing and app distribution | Your payment details are handled entirely by them and are never shared with us |
Onward carriers: to complete a call, our routing providers must in turn pass the destination number to the operator that terminates the call in the destination country. This is how every telephone call on earth works, and it is outside our control.
We may also disclose data where we are legally required to — a valid court order or lawful request from a competent authority — or where necessary to establish or defend legal claims. We do not sell your personal data, and we do not share it for anyone else's marketing.
7. International transfers
We and our processors operate internationally, so your data may be processed outside the country you live in, including in countries whose data protection laws differ from your own. Where we transfer personal data out of the EEA or the UK, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses. Contact us if you would like details of the safeguards that apply to a particular transfer.
8. How long we keep it
- Call records — up to 12 months, for billing enquiries, dispute resolution and fraud detection, then deleted or aggregated into statistics that cannot identify an installation.
- Purchase and accounting records — for as long as tax and accounting law requires us to keep them, which may be up to 5 years.
- Crash and diagnostic data — up to 90 days.
- Credit balance and its installation ID — for as long as the installation exists and holds credit, because that record is your balance.
9. Security
Call signalling and audio are encrypted in transit, as is all traffic between the app and our servers. Access to call records is restricted to the people who need it to run the service. No system is perfectly secure, but because we hold no names, no email addresses, no phone numbers and no card details, a breach of our systems would expose very little about you.
10. Your rights
Depending on where you live, you have rights to access your data, correct it, delete it, restrict or object to its processing, receive it in a portable form, and withdraw consent where processing is based on consent.
A practical catch worth knowing. Because we deliberately hold no identifying information, we cannot find “your” data from your name or email — there is nothing to match it to. To exercise a right you will need to send us your installation ID from the app's settings screen, which is the only handle that connects you to your records. If you cannot supply it, we may be unable to identify your data, and the GDPR does not require us to collect more information about you simply to make identification possible.
Deletion. Email [email protected] with your installation ID and we will delete your records. Deleting them forfeits any remaining credit, since the record is the balance. We may retain what the law obliges us to keep, such as transaction records for tax purposes.
If you are in the EEA or the UK, you can also lodge a complaint with your national data protection authority. We would rather you came to us first.
11. If you are in California
We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are defined under the CCPA/CPRA. We do not use or disclose sensitive personal information beyond what is needed to provide the service. You have the right to know, delete, and correct your personal information, and not to be discriminated against for exercising these rights. Use the same contact address above; the identification limits in section 10 apply equally here.
12. Children
Telvio is not directed at children and is not intended for anyone under 13. We do not knowingly collect data from children under 13 — and since we ask for no personal details at all, we have no way to identify a user's age. If you believe a child has used Telvio and you would like their records removed, contact us and we will delete them.
13. Changes to this policy
We may update this policy. We will change the “last updated” date above, and for material changes we will give notice in the app before they take effect.
14. Contact
Vast Flow, LLP — [email protected]. We aim to respond within 24 hours, and within the time limits the law sets for privacy requests.